Harmony ONE Crashes 37% as Hacker Mints 4B Tokens [2026]
Harmony's ONE token lost more than a third of its value in a matter of hours on August 12, 2026, after an attacker found a way to mint roughly 4 billion new tokens out of thin…
Harmony's ONE token lost more than a third of its value in a matter of hours on August 12, 2026, after an attacker found a way to mint roughly 4 billion new tokens out of thin…
Cloudflare's status page logged 13 separate incidents between August 7 and August 14, 2026, touching R2 object storage,…
Rainbow Six Siege ranks stopped meaning what they used to on June 2, 2026. That's when Ubisoft shipped…
Fifteen DeFi exploits had already been logged by late March 2026, according to CoinPaprika's 2026 exploit tracker, and the pace hasn't slowed…
Ask five Counter-Strike 2 players what rank they are and you might get three different answers from three different systems. One number…
Two NIST algorithms now sit at the center of every serious post-quantum migration plan. ML-KEM handles the key exchange that protects a…
An attacker needed just 97 minutes to empty a cross-chain bridge linking the XRP Ledger to the tx blockchain (formerly Coreum), draining…
Cloudflare shipped more changes to Workers between June and August 2026 than in almost any other stretch since the product launched: a…
Rainbow Six Siege dropped hidden MMR in June 2026, and that single change turned rank tracking into something worth doing right. Under…
This domain has been home to the SHAttered SHA-1 collision project since 2017, and is now a hub for cryptography, security and privacy reporting. The full origin story of the project, the two proof PDFs and the research credits live below.
On 23 February 2017, researchers at CWI Amsterdam and Google showed the world the first real collision for the SHA-1 hash function. The project was called SHAttered, and this domain has been its home ever since. The two files that prove the break are still here to download.
A cryptographic hash takes any file and returns a short fixed-length fingerprint. The promise is simple: change a single bit of the file and the fingerprint changes too, and no two different files should ever share one. A collision breaks that promise. It is a pair of distinct inputs that produce the exact same hash. For a function used to sign software, certificates and documents, a collision is not a curiosity. It is a crack in the foundation.
The team did not just argue that SHA-1 was weak on paper. They built the evidence. Two PDF files, visibly different and carrying different content, share one identical SHA-1 value: 38762cf7f55934b34d179ae6a4c80cadccbb7f0a. Run either file through SHA-1 and the answer matches. Run them through SHA-256 and the answer differs, which is how anyone can confirm they are genuinely two separate files.
The break was expensive, and that was part of the point. Producing the collision took roughly nine quintillion SHA-1 computations, the work of about 6,500 CPU-years and 110 GPU-years run in parallel. That scale kept the attack out of reach for a casual attacker in 2017, yet it ran thousands of times faster than trying every possibility by brute force. The direction of travel was clear: the cost would only fall.
Once a working collision exists, trust in a hash erodes quickly. Within months the result pushed browsers, certificate authorities and version-control systems to drop SHA-1 for anything security-sensitive. Git added collision detection. TLS certificates signed with SHA-1 were phased out. The lesson reached far past one algorithm: a function can look safe for years and still fall the moment the maths and the hardware line up.
SHAttered was the work of Marc Stevens and Pierre Karpman at CWI Amsterdam, together with Elie Bursztein, Ange Albertini and Yarik Markov at Google. It built on years of earlier cryptanalysis of the SHA-1 design. The full technical paper that documents the method is preserved here.
The same questions that drove SHAttered run through everything we cover here: how hashing works, where it is used, and how systems prove they have not cheated. These guides pick up where the research leaves off.
Hash functions, the SHA family, encryption and digital signatures.
Breaches, passwords, TLS and staying secure online.
VPNs, Tor, encrypted messaging and staying anonymous.
How blockchains use hashing, wallets and crypto safety.
How SHA-256 lets you verify an outcome for yourself.
Beyond the original SHA-1 collision proof, the site now publishes ongoing coverage across cryptography, cybersecurity, privacy, cryptocurrency and provably-fair systems. Every article is editorial, lightly-opinionated and built on primary sources where possible.
Deep-dives into the maths that secures the internet: hash functions, digital signatures, the SHA family and the SHAttered collision that gave this site its name. Explainers and reporting for people who want to understand how the primitives actually work.
Breaches, CVE post-mortems, zero-day reporting and practical defense. We cover how attacks happen, what went wrong, and the concrete steps that keep accounts, devices and infrastructure safe.
VPNs, Tor, encrypted messaging and the surveillance landscape. Reporting and guides on protecting your data, understanding tracking, and taking back control of what you share online.
Blockchain hashing, wallets and on-chain incidents. Clear-eyed coverage of how crypto works under the hood, the security trade-offs, and the hacks and exploits worth learning from.