News linked to this event type.
Secret Network 团队提议将隐私区块链从 Cosmos 迁移至 Arbitrum,称 AI 使旧代码更易被攻击的安全风险及生态流动性下降是主要考量。
According to official sources, Summer.fi released a post-mortem stating that on July 6, the attacker manipulated the share prices of two Lazy Summer USDC vaults by injecting overvalued Silo tokens into an offline Ark still included in the NAV, and extracted approximately $6.04 million in a single atomic transaction.
Odaily Zcash's native token ZEC rose over 12% on Tuesday after the team responsible for developing its privacy pool said it is nearing completion of a mathematical proof to confirm that there are no undetectable counterfeit minting vulnerabilities in the latest Zcash shielded pool.The verification work, driven by Project Tachyon, is aimed at Zcash's upcoming Ironwood shielded pool. Zcash founder Zooko Wilcox stated that the project is on the verge of producing a mathematical proof, with the goal of proving that the latest Zcash privacy pool has no undetectable minting vulnerabilities.This development follows the disclosure last month of a serious counterfeit vulnerability in the Zcash Orchard shielded pool. At the time, the flaw sparked market concerns about the potential for undiscoverable, hidden inflation risks within Zcash's privacy system, causing ZEC to drop by over 40% within two days.Developers say that with the help of AI-assisted formal verification, proof work that previously might have taken years has now been compressed to a few weeks. The news pushed ZEC back above $500, its highest level since early June. (The Block)
Odaily, on-chain security firm Specter has released preliminary findings on the BONK DAO governance attack. After tracing on-chain fund flows, significant suspicions have emerged: the Realms founder, an address associated with Crypto Notte, shows signs of capital flow interaction with the suspected attacker's wallet.According to the review, the attacker published a malicious governance proposal on June 30. The proposal required 1% of the total BONK circulating supply in voting power to pass. Between July 4 and 5, the attacker acquired sufficient voting weight by purchasing tokens through exchanges and borrowing from Marginfi, totaling approximately $4 million, thereby pushing forward and executing the governance attack.
the Zcash development team announced plans to introduce formal verification through the upcoming new privacy pool Ironwood, using mathematical proof methods to eliminate the risk of "Undetectable Counterfeiting."Previously, although the vulnerability in the Orchard shielded pool has been fixed and there is no evidence of exploitation, the community decided to launch a completely new Ironwood shielded pool and perform comprehensive formal verification on its protocol, as it is theoretically impossible to confirm through on-chain history whether covert counterfeiting has occurred.
Du Jun, co-founder of ABCDE Capital, publicly stated that Li Bojie, founder of Metagent, is "the founder with the least sense of contract" he has ever worked with.Du Jun said that Li Bojie founded Metagent in 2024 and secured investment from ABCDE Capital, but subsequently refused to fulfill the basic obligations stipulated in the investment agreement, including keeping investors informed of business progress and financial status, and then even went completely missing. Du Jun stated that while venture capital can accept project failures, it cannot tolerate fraudulent behavior such as founders "absconding" with the investment funds.
According to Onchain Lens monitoring, the Summer.fi attacker is actively transferring funds. The relevant address is splitting 6.017 million DAI into multiple small transactions and swapping them for ETH via Uniswap.
According to official announcements, Summer.fi released a security notice stating that the team discovered an active vulnerability affecting Lazy Summer Protocol earlier today. As a precautionary measure, Guardians have paused all vaults and set deposit limits to zero across all networks. The incident is currently under assessment, and the team advises users not to interact with the protocol until further notice. A full update will be published as soon as possible.
据官方消息,BonkDAO 表示,其 DAO 金库 因一项恶意治理提案遭攻击,约价值 2000 万美元的 BONK 代币被盗。调查显示,相关地址曾在提案发起前通过交易所钱包购买 BONK。BonkDAO 正与交易所、跨链桥及 Solana 基金会合作处理此事,执法部门已获通知,后续将继续推进资金追回及责任追查。
the official Bonk Inu X account announced that BonkDAO was attacked via a malicious governance proposal, resulting in the theft of approximately $20 million worth of BONK tokens from its DAO treasury.According to reports, the attacker exploited a suspicious governance proposal to transfer assets from the BonkDAO treasury. The stolen BONK subsequently began flowing to exchanges, putting downward pressure on the BONK price. Data from The Block shows that the BONK price has dropped over 9%.South Korean exchange Upbit subsequently issued a notice stating that it has temporarily suspended BONK deposits and withdrawals to address the incident and mitigate potential risks. (The Block)
Odaily, Web3 security firm CertiK has released the "Hack3D: First Half of 2026 Report." The report shows that the Web3 ecosystem experienced 344 security incidents in the first half of 2026, with cumulative losses of approximately $1.32 billion. Although this figure represents a 46.8% decrease compared to the same period last year, excluding the impact of the $1.45 billion security incident involving Bybit, the scale of losses in the first half of this year actually increased by approximately 28% year-on-year, indicating that the overall security environment in the industry has not materially improved.The report points out that wallet theft has become the attack type causing the greatest financial loss, accounting for approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks fell by more than 50% year-on-year, the loss amount only decreased by approximately 10.8%, reflecting that attackers are shifting towards high-net-worth individuals and institutional targets, carrying out more targeted high-value attacks.Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running legacy smart contracts that lack re-audits. The report also shows that mega-attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents alone causing approximately $577 million in losses, accounting for 44% of the total losses in the first half of the year. Looking at the number of incidents, the impact of single attacks, and the changing attack patterns, the Web3 industry is facing more complex and continuously escalating security challenges.
CertiK warned that the decline in losses was primarily due to a single massive Bybit hack incident worth $1.4 billion during the same period last year; excluding this factor, attacks are becoming "more targeted and more destructive per incident," with private key and multi-signature wallet management remaining the most critical security risk exposures.
according to Onchain Lens monitoring, Summer.fi's Lazy Summer Protocol was attacked in a single transaction, resulting in a loss of approximately $6.1 million. This attack was not a typical ERC-4626 donation attack; the attacker exploited the trust relationship between the parent vault and one of its allocation strategies to introduce fake assets into the vault's accounting records.
According to Blockaid monitoring, Summer.fi was attacked, resulting in a loss of approximately $6 million in funds.
According to official social media announcements, the HTX Genesis Hackathon, hosted by HTX DAO and B.AI and co-organized by OpenCSG, TinTinLand, and OpenCity, has entered the initial screening phase. Over 100 developer teams have registered to participate, including teams from more than 30 top universities across 22 cities globally, such as Tsinghua University, Fudan University, National University of Singapore, the University of Edinburgh, and others. Reportedly, the total prize pool for this event reaches 20,000 USDT, with over $100,000 in computing power support provided. Participating teams will innovate in areas including $HTX application scenarios, B.AI ecosystem applications and computing power services, AI Agent finance, on-chain asset management, trading infrastructure, DAO tools, and intelligent financial operating systems. The HTX Genesis finals will be held offline on July 19 during the Shanghai WAIC World Artificial Intelligence Conference.
On-chain investigator ZachXBT stated that unless the case occurred recently, individual victim losses exceed $250,000, the jurisdiction is actionable, the incident occurred on a blockchain he supports, and it does not involve Meme tokens or prediction markets, he will not review or respond.
According to Lookonchain, the Step Finance attacker, after 5 months of inactivity, sold all 261,933 SOL, worth $21.4 million. The funds were then bridged to Ethereum to purchase 12,128 ETH, which were subsequently deposited into Tornado Cash to launder the money.
according to monitoring by Coinspect Security, by analyzing crypto wallet seeds generated using insecure code since 2018, it was discovered that thousands of seeds have been used in practice. In the past month alone, $3.14 million in suspected stolen funds was identified in related wallets. Coinspect Security stated that some funds exhibited patterns of being consolidated into a single address and money laundering. One affected address transferred out another $2 million just hours after the alert was issued, and it remains unclear whether this was part of the theft. Additionally, Coinspect Security issued a special warning to the Chinese-speaking community, indicating that many users whose assets may still be at risk are likely located in China.
According to CoinDesk, researchers at blockchain security company Hexens discovered an "expired cache" type confusion vulnerability in the Aptos blockchain Move virtual machine. Attackers require only about $3,000 in server costs to launch attacks in a simulated environment with a success rate of nearly 90%, without needing validator privileges or internal knowledge. Researchers ran approximately 20 attacks in simulated tests, succeeding 17-18 times, and verified the potential ability to control management permissions of cross-chain protocols such as LayerZero, Wormhole, and USDC CCTP. Hexens assessed that the vulnerability directly threatens protocols on the Aptos chain such as DeFi, stablecoins, and liquid staking, involving assets in the low single-digit billions of dollars; if spread through paths such as cross-chain bridges, stablecoin minting, and centralized exchanges, the systemic risk exposure could reach up to $70 billion. The Aptos team completed the fix and deployed it to the mainnet within hours after receiving the vulnerability report on February 25, and currently no user funds have been compromised.
David Bailey, Chairman and CEO of Nasdaq-listed Bitcoin treasury company Nakamoto, stated that the failure of the so-called long-standing "BIP-110" controversy constitutes an "extremely bullish" outcome for Bitcoin, and believes this further validates the network's attack resistance and anti-splitting capabilities.