Onchain Diary
onchaindiary.org
Onchain Diary
@onchaindiary.org
Onchain Diary is an independent Web3 safety education site

Visit our website👉: https://theonchaindiary.com/
Blast L2 is shutting down — costs beat revenue. Oct 26 is the last day the normal withdrawal interface works; after that it's manual L1 bridge-contract exits. Withdrawal runbook + the phishing wave every shutdown attracts:
https://theonchaindiary.com/articles/blast-l2-shutdown-withdrawal-guide/
Blast L2 Is Shutting Down: How to Withdraw Safely Before October 26 — Onchain Diary
Blast announced on October 2, 2026 that it is winding down its Ethereum L2. Users have until October 26 to withdraw through the normal interface. Full timeline, the L1 bridge-contract path after the deadline, and the scam wave every shutdown attracts.
theonchaindiary.com
October 3, 2026 at 5:45 AM
NEAR Intents lost $3.87M Oct 1 — no user signed anything wrong. The vault pays whoever holds a note signed by the service's backend; the bug sat in that bookkeeping layer. 76% was already Bitcoin by the time the team posted.
https://theonchaindiary.com/articles/near-intents-hack-explained/
NEAR Intents Hack Explained: How a Signed-Note Bug Drained $3.87M — Onchain Diary
NEAR Intents lost $3.87 million on October 1, 2026 when a bug in its Omni deposit-and-withdrawal system let an attacker withdraw funds with valid signed notes. Full timeline, where the money went, and why no user signature could have prevented it.
theonchaindiary.com
October 2, 2026 at 4:58 AM
A real CAPTCHA never asks you to open Run or Terminal. The 2026 ClickFix campaign hid on 5,400+ hacked sites, pulled payloads from BSC testnet smart contracts, and stole crypto with commands victims pasted themselves.
https://theonchaindiary.com/articles/clickfix-fake-captcha-scam-explained/
ClickFix Scam Explained: How a Fake CAPTCHA Drains Crypto Wallets — Onchain Diary
ClickFix shows you a fake CAPTCHA, then talks you into pasting one command into Run or Terminal. Here is the full chain, the on-chain dead drop, and what it does to wallets.
theonchaindiary.com
September 27, 2026 at 6:34 AM
NFTs sold out of hundreds of wallets for exactly 0 ETH today. The bug lived in a contract Magic Eden stopped using in Oct 2024. The marketplace died in March; the approvals never did. Inside the .7M whitehat evacuation.
https://theonchaindiary.com/articles/magic-eden-payment-processor-exploit/
Magic Eden Exploit Explained: A Dead Marketplace, Living Approvals, and a $5.7M Whitehat Rescue — Onchain Diary
NFTs left wallets for 0 ETH on September 25. The vulnerable contract was one Magic Eden stopped using in October 2024, but the approvals users gave it never expired.
theonchaindiary.com
September 25, 2026 at 1:25 PM
Bitget lost $351.6M and not one private key was stolen. Attackers hit a wallet backend, spoofed the data inside it, and let the exchange's own signing process approve the transfers. Bybit pattern: keys safe, transactions not.
https://theonchaindiary.com/articles/bitget-hot-wallet-hack-explained/
Bitget Hack Explained: $351M Moved Without a Single Private Key Stolen — Onchain Diary
Bitget lost $351.6M when attackers spoofed transaction data inside its wallet backend. How the signing-layer attack worked, where the funds went, and what users should watch for.
theonchaindiary.com
September 25, 2026 at 8:34 AM
Wallet drained? Drainer proceeds increasingly route through mixers, not exchanges. What still works: revoke live approvals, report same-day, treat every 'recovery expert' who DMs you as attack #2. https://theonchaindiary.com/articles/after-wallet-drainer-what-now/
September 23, 2026 at 7:41 AM
FomoPeek passed App Store review as a read-only whale tracker. Inside: an iOS kernel exploit that decrypts the Keychain and steals keys from other apps. Domain Aug 28, live Sep 7, payload Sep 13, burned Sep 20. Our forensics:
https://theonchaindiary.com/articles/fomopeek-app-malware-explained/
FomoPeek Malware: How a Read-Only Whale Tracker Stole iOS Private Keys — Onchain Diary
FomoPeek passed App Store review as a read-only whale tracker, then shipped an iOS kernel exploit that decrypts the Keychain. Timeline, forensics, victim steps.
theonchaindiary.com
September 20, 2026 at 4:00 AM
A blind auction on Zcash cleared 12,000 ZEC for 8,000 pixel 'shielded identities.' What winners actually hold: a database claim — ZSA isn't on mainnet yet. And the 2 ZEC floor is unauditable by design.
https://theonchaindiary.com/articles/zksnarks-auction-what-bidders-bought/
zkSNARKs Auction Cleared 12,000 ZEC. Here Is What the Winners Actually Hold — Onchain Diary
Zcash's zkSNARKs identity auction drew 16,971 bids and cleared at 1.5 ZEC; the secondary floor sits near 2 ZEC on Zilkroad. But with ZSA not on mainnet, ownership lives in a database — and the market data is unverifiable by design.
theonchaindiary.com
September 19, 2026 at 11:23 AM
Shipped: Diary Key, a solve-to-mint NFT. Answer one question from my on-chain safety field reports, mint a key. 5,000 total, 3 per wallet, free (gas is cents on Arc). 256-cell hash grid, fully on-chain art, bronze to diamond. I minted #1. Bronze. Great.
https://puzzle.onchaindiary.org
September 19, 2026 at 4:20 AM
ZEC is top-10 and new holders are learning that Zcash cold storage is not Bitcoin cold storage. Trezor officially does not support shielded addresses at all. Three setups that actually work:
https://theonchaindiary.com/articles/zcash-cold-storage-guide/
Zcash Cold Storage: How to Store ZEC Offline in 2026 — Onchain Diary
ZEC holders moving funds off exchanges face a fork in the road: transparent addresses work on any hardware wallet, shielded addresses mostly don't. What Trezor and Ledger actually support, three working cold-storage setups, and the scams targeting new Zcas
theonchaindiary.com
September 17, 2026 at 4:28 PM
Polygon isn't 'part of Ethereum' — it runs its own validators, and QuickSwap vets nothing. The six checks that work on every EVM chain, with the 2021 Poly Network exploit as the standing lesson.
https://theonchaindiary.com/articles/polygon-token-safety/
Polygon Token Safety: How to Avoid Scams on the MATIC Chain — Onchain Diary
Polygon's low fees and Ethereum association attract legitimate DeFi and every clone-token scam that follows. The exact steps to verify any Polygon token before you buy.
theonchaindiary.com
September 17, 2026 at 12:47 PM
SQUID ran on BNB Chain: buyers could buy, nobody could sell, over $3.3M walked out the door in 2021. The pattern never retired. Six checks before touching any BEP-20 token.
https://theonchaindiary.com/articles/bnb-chain-token-safety/
BNB Chain Token Safety: How to Avoid Scams on Binance's Chain — Onchain Diary
The SQUID token let people buy but never sell, and it ran on BNB Chain. Learn the specific scam patterns on BSC and the exact steps to verify any BEP-20 token before you buy.
theonchaindiary.com
September 17, 2026 at 12:35 PM
ZecBit charged for a testnet-only NFT and ended with a public 0.1 ZEC complaint. zaddr.net is free and asks for a read-only X login and a shielded address. The free one collects something too: an identity-to-address map.
https://theonchaindiary.com/articles/zcash-whitelist-what-you-hand-over/
Zcash Whitelist Season: One Takes Your ZEC, One Takes Your Identity Map — Onchain Diary
ZecBit charged for a testnet NFT and left a 0.1 ZEC complaint in its wake. zaddr.net is free and asks for almost nothing. The second one is the more interesting case. Here is what each model actually collects.
theonchaindiary.com
September 17, 2026 at 11:56 AM
One hour into Arc mainnet: two contracts named SCOUT born 35 min apart, two COCOAs, a token up 6,475%, and fake 'ARC airdrop' pages live before any official token exists. Day-one chain data + the real USDC contract to verify.
https://theonchaindiary.com/articles/arc-mainnet-day-one-risks/
Arc Mainnet Day-One Risks: Copycat Tokens and Fake Airdrops in the First Hours — Onchain Diary
Arc, Circle's stablecoin L1, is live. One hour of on-chain data already shows duplicate-ticker copycats, +6,475% pumps, and fake-airdrop warnings. A field guide with real numbers.
theonchaindiary.com
September 16, 2026 at 7:07 PM
A real Telegram pitch, dissected: 'launching tonight at 19:00 on Sushi, Base.' We read the scammer's script back to him — he spotted it instantly, then pitched his own anyway. Six beats, one table, a one-line honeypot test.
https://theonchaindiary.com/articles/telegram-crypto-pitch-script/
The Telegram Crypto Pitch, Read Back to the Scammer: A Real Chat, Dissected Line by Line — Onchain Diary
A real Telegram solicitation captured this week: a stranger pitching a token 'launching tonight at 19:00 on Sushi, Base.' We annotate every beat of the script — and what happened when we pitched the same script back at him.
theonchaindiary.com
September 15, 2026 at 8:43 AM
"Share your public key so we can verify your wallet." No legitimate service needs this — the request is a fishing trip for your seed phrase. New: the 3 wallet strings, and the scam attached to each layer of confusion:
https://theonchaindiary.com/articles/public-key-private-key-wallet-address/
Public Key vs Private Key vs Wallet Address: The Difference Scammers Hope You Never Learn — Onchain Diary
Every wallet scam that has ever worked relies on one thing: the victim not knowing which of the three wallet strings does what. The one-way chain from seed phrase to private key to public key to address, what leaking each one actually costs you, and the fo
theonchaindiary.com
September 14, 2026 at 1:37 PM
Ask ChatGPT to pick 12 seed-phrase words and your wallet reportedly gets drained within minutes — bots watch the handful of phrases AI tends to output. Online generators are worse. The real safety ladder:
https://theonchaindiary.com/articles/seed-phrase-generator-risk/
Why You Should Never Generate a Seed Phrase Online — Onchain Diary
Online seed phrase generators are one of two things: a phishing tool that logs or pre-loads the phrase it hands you, or a negligent service that produces unauditable randomness over an untrusted channel. How legitimate wallets generate phrases on-device, w
theonchaindiary.com
September 14, 2026 at 12:18 PM
Hello, bluesky!
September 13, 2026 at 7:16 AM