Toxic Combinations: When Cross-App Permissions Stack into Risk
The Hacker News·60-word summary·1 min read
On January 31, 2026, researchers revealed Moltbook, an AI social network, left its database exposed, risking data for 35,000 email addresses and 1.5 million API tokens. The breach also exposed private messages containing plaintext third-party credentials, including OpenAI API keys shared among 770,000 active agents, highlighting significant security vulnerabilities in cross-app permissions.
Palantir (PLTR) signed a $300 million Blanket Purchase Agreement with the U.S. Department of Agriculture in April 2026 to enhance farmland security. The deal supports the National Farm Security Action Plan and the “One Farmer, One File” initiative, building on Palantir’s existing work with the USDA’s Landmark platform. The agreement aims to improve data security for U.S. farmers facing economic pressures.
Volo Protocol on the Sui blockchain lost $3.5 million in a security breach on April 21, 2026, due to a compromised vault admin private key. The exploit affected three vaults and prevented a WBTC bridge attempt. Security firms GoPlus Security and ExVul confirmed the incident, highlighting vulnerabilities in the platform’s key management.
Aave’s deposits have dropped by $15 billion following the Kelp DAO bridge exploit, causing users to withdraw funds amid concerns over potential losses related to rsETH-linked shortfalls. The incident, which occurred in April 2026, has heightened security fears within the DeFi sector, leading to a significant decline in Aave’s supplied balance and increased caution among investors.
A new supply chain attack in the npm ecosystem has emerged, targeting developer credentials and spreading through compromised package accounts. The attack self-propagates by stealing authentication tokens, posing a significant security threat to developers and projects relying on npm packages. The incident highlights ongoing vulnerabilities in software supply chains and the need for enhanced security measures.
Solana's price neared $90 again on April 22, marking its eighth attempt to break resistance amid heightened market volatility. The crypto sector has experienced multiple exploits this month, including the KelpDAO breach and RAVE price crash, which have increased trader caution. Despite these security concerns, Solana quickly rebounded from local support, reflecting ongoing resilience in a turbulent market.
North Korea-linked hackers stole over $578 million in April, following the Kelp DAO exploit. The theft highlights ongoing security threats across various protocols, companies, and users. The incident underscores the increasing scale of state-sponsored crypto heists, with North Korea continuing to be a major actor in the sector’s security challenges.