Rekt News turns crypto failures into source-linked incident records, alongside a leaderboard, newsletter, video archive, public report repository, and a 2026 security summit.
Rekt News is a crypto security publication known for turning protocol failures into readable incident records. Its reporting combines technical reconstruction, source credits, and an adversarial voice, occupying territory between investigative journalism, security research, and a public memory of what broke.
The main site was publishing new security reporting as recently as July 14, 2026. Rekt's archive now ranges beyond exploit reports into governance, tokenization, privacy, AI infrastructure, software supply chains, and institutional security. That range is visible across its research index, Poisoned Pipeline, The Economy of Access, and Fork in the Code.
From “Hello World” to an Incident Archive
Rekt launched on September 23, 2020. Its first post described an anonymous team of DeFi participants, traders, and developers led by Julien Bouteloup, and offered the site as a platform for anonymous authors. The original scope already extended beyond exploits: investigative journalism, breaking news, opinion, and governance were part of the pitch.
That origin helps explain the publication's tone. Rekt writes from inside crypto culture rather than translating every event into institutional language. Reports often follow a failure narrative: what a project promised, what changed, how an attacker or market exploited the weakness, and what the episode says about incentives or oversight. The theatrical voice is part of the product, but the useful layer is evidentiary.
By its first anniversary, Rekt reported that it had published 100 pieces and recorded more than 50 protocols representing over $1 billion in losses. Those are historical first-party figures from September 2021, not current totals. They show how quickly the incident archive became a core product without freezing today's changing leaderboard into a dated count.

TrustedVolumes loses $5.87M after custom RFQ proxy lets attacker drain inventory

How a Rekt Incident Report Works
The strongest Rekt reports perform several jobs at once. They establish a chronology, explain a failure mechanism, connect the event to primary evidence, and place it in a longer record of losses. The prose may deliver a sharp verdict, but the links let readers inspect what sits underneath it.
The 2022 Nomad Bridge report, which Rekt called the hundredth incident on its leaderboard, illustrates the pattern. It linked contract state and transactions, credited outside researchers, tracked copycat behavior, and connected the exploit to bridge design and audit history.
Its investigations visibly connect narrative reporting to credit blocks, source links, and, where relevant, onchain transactions and addresses. All the Wrong Moves demonstrates the credit-and-source structure in a governance and token-market investigation, while TrustedVolumes connects a technical reconstruction to addresses and transaction evidence.
That distinction matters. A vivid narrative can make a technical incident legible, yet it can also compress uncertainty. Loss estimates may change as assets are recovered, frozen, minted, repriced, or disputed. Readers should treat each report as a sourced reconstruction and the leaderboard as a maintained editorial dataset rather than an immutable accounting system.
DeFi / Crypto - The AI protocol wired to your org has been exploited a dozen times since 2025. The creator called the flaw expected behavior. One hacker used Claude to breach nine ...

The Leaderboard Is a Public Index
Its public leaderboard organizes incidents by reported loss and displays dates and audit labels alongside the entries. The format makes incidents easier to compare across protocols and years and gives researchers an entry point into a specific event.
Comparable columns can still conceal different economic events. A bridge mint can create unbacked assets. An oracle attack can leave bad debt rather than an immediately transferred treasury balance. A governance attack may change control without a clean dollar loss. Returned funds can shrink the ultimate damage long after publication, while token-denominated losses move with price.
The public leaderboard does not publish a methodology explaining loss revisions, recoveries, duplicate incidents, historical pricing, or audit-label scope. Current ranks, aggregate losses, and incident counts are therefore omitted from this account. An audit-related label is also not treated as proof that the affected component or code version was within a particular review's scope.

"Rektrospective: Crypto's Investigative Journalists" Live now!

Anonymous Contributions Change the Trust Model
Rekt's original identity as a platform for anonymous authors is not a minor branding choice. Anonymous or pseudonymous contributors can investigate powerful actors without attaching every claim to a legal name. In crypto, they may also bring direct technical or market experience that a conventional beat reporter lacks.
The trade-off is accountability. Readers may not know an author's employment, token exposure, personal disputes, or prior work. Editing and verification therefore carry more weight, while links, transaction evidence, explicit attribution, and visible updates substitute for some of the trust normally supplied by a byline and newsroom biography.
As of July 15, 2026, the site footer identified Julien Bouteloup as founder and RektHQ as operator. Rekt's current boilerplate continues to describe a platform for anonymous authors; whether that describes every publishing lane is unconfirmed. Those are attributed public descriptions, not a claim about a complete newsroom roster, ownership structure, or editorial chain.
Beyond Exploit Write-Ups
Rekt's early multimedia work included a 2021 Hopium Diaries production with French, Spanish, Chinese, and Russian subtitles. That historical production does not establish which translated surfaces remain maintained today, but it shows that video and translation were part of the publication's early experiments.
The newsletter describes itself as a weekly security record and displayed “30,000+ subscribers” on July 15, 2026; neither current cadence nor audience size is independently audited. Dating and attributing the figure preserves what the publisher said without turning a marketing number into a permanent audience fact.
RektHQ maintains a public repository currently containing a Security Summit War Room report. The repository's existence documents a report-distribution surface; it does not by itself establish a recurring release schedule or independent peer review.
In March 2026, Rekt hosted the first Rekt Security Summit in Cannes. The official event site described a program focused on exploit analysis, audits, bounties, and investigator accounts, and a post-event account from Stake Capital described the gathering as its first edition. That supports the event's occurrence without assuming it will recur.
Editorial Strengths and Boundaries
Rekt's strongest contribution is cumulative. Individual incident threads disappear into social feeds; Rekt gives them a stable page, a narrative, source links, and a place in a longer history. Its style also refuses the euphemisms that can surround protocol failures. That adversarial posture is useful in an industry where teams often control the first account of what happened.
The same posture makes visible evidence especially important. Readers benefit when loss calculations, audit labels, corrections, contributor disclosures, and the boundary between reporting, opinion, commissioned research, and promotion are explicit. Where those policies are not public, the underlying links and attributed claims remain the safest way to use the archive.
Readers using Rekt as a security source should follow the linked transactions and primary material, check whether figures changed after recoveries, inspect the scope and date of any cited audit, and distinguish a project's statement from Rekt's conclusion. A sharp editorial voice can reveal evasions while still requiring readers to separate evidence from judgment.
This page was reviewed against the linked public sources on July 15, 2026. Rekt News and RektHQ have not reviewed it. Source-linked factual corrections are always free. A response, correction, or use of an official asset would not imply endorsement, sponsorship, partnership, or co-authorship.
Latest Rekt News news
TrustedVolumes loses $5.87M after custom RFQ proxy lets attacker drain inventory
DeFi / Crypto - The AI protocol wired to your org has been exploited a dozen times since 2025. The creator called the flaw expected behavior. One hacker used Claude to breach nine ...
"Rektrospective: Crypto's Investigative Journalists"
Live now!
The economy of access -Imagine a world with smart locks on property, biometric gates on money, algorithms that execute without appeal. Early experiments left people locked out, stranded, starving. Now it could be tokenized at scale. Were dystopian writers telling fiction or prophecy?
Vladimir S. of http://t.me/officer_cia discusses OpSec with Rekt News
From our friends at Rekt.news: USPD - Rekt
Attacker Exploits Known CPIMP Vulnerability to Front-Run USPD Proxy Deployment, Hide a Backdoor for 78 Days, and Mint 98M Unbacked Tokens for $1M—Even After Researchers Publicly Documented and Patched the Vector Months EarlierSources
- Hello World
- One year of rekt.news
- rekt:TV - Hopium Diaries - Dystopian Dreams
- Nomad Bridge - REKT
- Rekt News home
- Rekt News Leaderboard
- Explore Research
- Blockchain Security Brief
- REKT Security Summit - March 27, 2026 - Cannes, France
- RektHQ Reports
- All the Wrong Moves
- Poisoned Pipeline
- The Economy of Access
- Fork in the Code
- TrustedVolumes - Rekt
- Stake Capital post-event account of the first Rekt Security Summit
Community notes
Spot something off or out of date? Drop a note. Editors review topic notes daily and roll accepted fixes into the explainer — contributors are recognized in the monthly $SQUID drop.
Loading notes…
Help improve this topic
Have a story or tip about this topic? Submit it. See something missing? Leave a note. Editors review daily; accepted submissions and fixes count toward the monthly $SQUID drop.
