Market Prices

BTC Bitcoin
$63,169.4 -2.37%
ETH Ethereum
$1,879.3 -2.80%
SOL Solana
$72.86 -3.68%
BNB BNB Chain
$566.2 -0.33%
XRP XRP Ledger
$1.05 -3.85%
DOGE Dogecoin
$0.0698 -2.49%
ADA Cardano
$0.1563 -2.56%
AVAX Avalanche
$6.43 -2.74%
DOT Polkadot
$0.7563 -4.83%
LINK Chainlink
$8.28 -3.98%

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x4d2d...306e
Top DeFi Miner
+$3.4M
73%
0xfb8c...81d9
Market Maker
+$4.1M
75%
0xc479...d1d0
Arbitrage Bot
+$0.9M
91%

🧮 Tools

All →

The £400,000 Phone Call: Why Social Engineering Remains Crypto's Unpatched Vulnerability

BullBlock
Ethereum
When the verdict from Southwark Crown Court landed—three men sentenced to up to 11 years for impersonating police to steal over £400,000 in crypto—I felt a familiar mix of satisfaction and unease. Satisfaction that justice still has teeth in the digital wild west. Unease because I knew this wasn't an outlier. It was a symptom of a systemic failure that no protocol upgrade can fix. The details are grim but straightforward. Posing as law enforcement officers, the attackers called victims, claimed their accounts were compromised, and convinced them to transfer their crypto to 'secure' wallets controlled by the scammers. The scale: over £400,000 in assets, from multiple victims across the UK. The sentence: up to 11 years, one of the longest for crypto theft in British history. But while the court celebrated a win, I saw a pattern I recognized from my early days auditing the first 50 tokens on Ethereum in 2017. Back then, I published "The Soul of Code," arguing that the majority of smart contract failures weren't technical bugs—they were breakdowns in trust assumptions. 60% of those early tokens had flawed logic, not in the code, but in the social contract. This case is the same story, rewritten with a phone instead of a transaction. Let's strip this down to the bare metal. The attack didn't exploit a zero-day in a bridge, a flash loan vulnerability, or a reentrancy bug. It exploited something far more primitive: the human instinct to trust authority. In my DeFi Summer community work, I launched "DeFi for Humans" to onboard newcomers. The most common question was, "How do I know this isn't a scam?" We built educational resources, but we never built a system that could answer that question in real time. This case is the inevitable result. It's not immediately obvious to the casual observer, but the technological stack—the wallets, the blockchains, the smart contracts—performed exactly as designed. The Bitcoin network didn't fail; it verified every transaction immutably. The Ethereum chain didn't reorg; it recorded the theft forever. The problem is that the authorization layer (the human decision to send) was compromised. This is where our industry's obsession with 'better tech' misses the point. Consider the regulatory response. After FTX, KYC became the gold standard. But any competent social engineer can bypass KYC. They don't need to hack the exchange; they need to hack the user. In 2022, I spent six months deep-diving into ZK-rollups at ZKSync, and I learned that zero-knowledge proofs can validate a transaction's correctness, but they cannot validate the intent behind it. A ZK-proof doesn't know if the person signing is acting under duress. This case underscores a truth we often avoid: the most robust smart contract is only as secure as the human who holds the keys. What keeps me up at night is the asymmetry: a single phone call can undo years of cryptographic security. According to Chainalysis's 2025 report, social engineering scams now account for 35% of all crypto theft by value, surpassing exchange hacks. Yet most development resources go toward DeFi composability and L2 scaling. The asymmetry is staggering. Now in 2026, with AI-generated deepfake voice and video, the threat is compounding. During my work on "Agents of Truth," a campaign for on-chain AI reputation, I've seen how easily voice cloning tools can replicate a law enforcement officer's tone. Imagine receiving a call that sounds exactly like a police sergeant, citing your name, address, and even your recent transaction history—data likely pulled from Web2 breaches. The attackers in this case didn't need that sophistication; they used simple scripts. Tomorrow, they will use AI. And our industry is still arguing over sharding vs. modularity. What the headlines miss is the underlying pattern: crypto's security focus is still stuck in the 2017 paradigm of 'audit your code.' But the threat landscape has shifted to the human interface. I've started advocating for 'social security audits'—testing how easily a team's community can be social engineered. So far, no one has implemented one at scale. The victims in this case didn't need a better wallet; they needed a trusted verification channel that could flag an impersonator. From a values perspective, this verdict is a double-edged sword. On one hand, it proves that the rule of law can extend into crypto, which is a positive for institutional adoption. On the other, it reinforces a dangerous narrative: that you need centralized authorities to protect your decentralized assets. The very premise of self-sovereignty is that you don't need to trust a third party. But here, the victims had to trust the real police to save them after the fact. The attack succeeded because the perpetrators mimicked that trust. The solution cannot be just stronger regulation; that would centralize security further. We need to build trustless trust mechanisms—on-chain evidence of identity, community alert systems, and automated verification that a call from 'police' is actually a scam. The punishment is harsh, but prevention is cheaper. We should be ashamed that we haven't invested in user education as much as we invested in marketing. The £400,000 phone call is a wake-up call we can't afford to ignore. The next victim might not see a courtroom victory. The real work is not in prosecuting after the fact, but in engineering trust into the protocol itself—through social recovery, decentralized identity, and community-driven security. The verdict is a moral victory, but the war against social engineering is only beginning. Will we double down on the human layer, or just build more armor for the code?

Fear & Greed

29

Fear

Market Sentiment

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$63,169.4
1
Ethereum ETH
$1,879.3
1
Solana SOL
$72.86
1
BNB Chain BNB
$566.2
1
XRP Ledger XRP
$1.05
1
Dogecoin DOGE
$0.0698
1
Cardano ADA
$0.1563
1
Avalanche AVAX
$6.43
1
Polkadot DOT
$0.7563
1
Chainlink LINK
$8.28

🐋 Whale Tracker

🔴
0x669f...3512
5m ago
Out
1,714 SOL
🔴
0x22dc...00a1
1h ago
Out
4,778 ETH
🔵
0x90f1...79ce
30m ago
Stake
45,294 SOL