News linked to this event type.
according to D2 Finance monitoring, derivatives strategy protocol D2 Finance has raised five public questions regarding Tori Finance's operations to cover the shortfall after the Term Finance incident. These include: why 250,500 trUSD tokens were minted in advance instead of directly using existing USDC reserves; the source of the collateral used for minting; the other half of the funds coming from Kraken's hot wallet; the transparency page showing a buffer range of only approximately $17,600, or roughly 3 basis points, far below the scale of the incident's impact; as well as Delta Neutrality verification, high-yield money market positions, and hedging methods. Previously, the Term Finance governance vulnerability incident affected RockawayX Tori USDC Vault, resulting in a loss of approximately 454,000 USDC. RockawayX and Tori Finance subsequently stated that the loss has been fully covered by both parties.
Odaily News: Ethereum client Besu has fixed 5 security vulnerabilities discovered by blockchain security firm CertiK in version 26.7.1 released on July 27, and published 4 detailed security advisories on August 14. Vulnerability details were disclosed after a delay to allow node operators to complete upgrade deployments.Jialiang Chang, Director of Security Engineering and Senior Audit Partner at CertiK, stated that the arrangement of releasing patches first and details later provided an 18-day buffer period, allowing node operators to identify affected deployments, test new versions, and coordinate with validators or consortium participants to complete upgrades.The vulnerabilities involve block broadcast handling, caching of future-height consensus proposals, WebSocket subscription limits, and JSON-RPC filter creation. If left unpatched, attackers could exhaust node memory or thread resources, impacting node availability and consensus processing.Using the Chain Scan methodology, CertiK conducted adversarial testing on peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi-node test network, and provided reproducible testing tools to the Besu team. CertiK is updating Chain Scan to expand round-the-clock multi-node testing on public chain networks. (Bitcoin.com News)
Renowned gold bull and economist Peter Schiff posted on social media to refute Bitcoin advocates' strategy of bundling artificial intelligence (AI) with Bitcoin for speculative trading, bluntly stating that AI poses a threat to Bitcoin rather than offering any benefits. Schiff pointed out that AI and Bitcoin compete directly for speculative capital, electricity, and data center resources. More critically, AI could uncover vulnerabilities in Bitcoin's code, cryptographic algorithms, wallets, or network that remain undetected by humans, thereby undermining the foundations of its security and scarcity.
Term Labs 发文更新漏洞事件进展。目前所有 Term Meta Vault 已关闭,DAO 治理角色已被撤销。此关闭不可逆,永久禁止进一步存款,但提款仍开放。本次事件涉及 Term Vault 治理。底层 Term 协议及其直接借贷市场尚未受到影响,团队正在继续核实影响范围。若仍存在资金缺口,团队将寻找解决途径。 此前消息,据 CertiK 监测,Term Finance 于昨日遭遇治理攻击,损失约 850 万美元。
Odaily News: Cryptocurrency wallet project SafePal has released an update on the security incident, stating that it is continuously tracking phishing websites and impersonating accounts. The company plans to bring in a professional anti-phishing security firm to expedite the takedown of malicious information, aiming to protect user asset security.SafePal stated that it is currently in the final selection process among 4 professional anti-phishing security firms. Once a partner is chosen, it will further enhance the efficiency of handling threats such as imitation websites and fraudulent accounts. The team is also continuously monitoring whether affected data has been sold or made public, including channels such as dark web forums and trading markets. In the event that any signs of data leakage are detected, affected users will receive risk alerts as a top priority.In terms of security auditing, SafePal stated that it is making a final selection among 3 established independent security agencies, which will conduct a comprehensive security review of the order system. Meanwhile, the team is re-evaluating the order and logistics processes to reduce the scale of data that needs to be stored during the initial phase of the system, thereby lowering potential risks at the source.For affected users, SafePal stated that it will continue to provide one-on-one assistance through official support channels and will keep updating its fraud prevention page with event progress, frequently asked questions, and analysis of scam cases.SafePal once again reminds users: The official team will never ask users for their Seed Phrase. Users should not disclose their seed phrase to anyone, should not scan unknown QR codes or click on suspicious links, and should verify information sources through official channels.
Odaily News, SlowMist Security Team disclosed that the cross-chain bridge project Allbridge suffered an attack on August 19, 2026, with losses of approximately $190,000. Notably, this attack was not executed instantaneously—the attacker began laying the groundwork nearly a month in advance, bypassing the verification mechanism through forged cross-chain messages.According to SlowMist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as CCTP-style, claiming a transfer of 1 million USDC, despite no actual USDC burn operation occurring. Subsequently, Circle generated a valid attestation for this complete message following standard procedures.Approximately 24 days later, on August 19, the attacker waited for the Base Router to receive a genuine CCTP deposit, bringing its balance to approximately 191,000 USDC, then launched the attack just 6 seconds later. Using the previously forged message and attestation, the attacker called Allbridge's receiveCctpMessage function. Due to the project's lack of critical validation, the system mistook the fraudulent cross-chain message for a genuine deposit and recorded a 1 million USDC credit.Subsequently, the attacker borrowed approximately 809,000 USDC temporarily via an Aave flash loan to match the Router's balance with the forged amount, then utilized the internal credit record to call the transfer function, ultimately moving out approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800 in profit. The root cause of this vulnerability lies in Allbridge's failure to verify the identity of the cross-chain message sender and receiver, as well as its failure to confirm whether USDC was genuinely minted or whether the balance actually increased—instead directly trusting the amount and message hash data constructed by the attacker.SlowMist emphasized that on-chain message verification does not equate to actual asset arrival. Cross-chain protocols must not only verify message authenticity but also ensure the message source is trustworthy, confirm the receiver is Circle's official TokenMessengerV2, and only record assets after confirming actual minting and balance changes. This incident once again highlights the security risks in cross-chain bridges' message verification and asset settlement processes.
Odaily News: Metaverse gaming platform The Sandbox has confirmed a vulnerability in its cross-chain bridge, allowing attackers to mint unbacked SAND on Base and BNB Smart Chain. Blockchain security firm PeckShield detected on August 21 that two addresses had collectively minted approximately 14.9 billion SAND. The Sandbox subsequently shut down bridging functionality on both networks.The Sandbox stated that the affected assets are bridged assets on Base and BNB Smart Chain, while SAND on Ethereum and Polygon, user wallet assets, and the Ethereum-locked assets backing the token remain unaffected. The proportion of genuinely collateralized assets involved in this incident is less than 0.01% of the total SAND supply.The Sandbox is developing a compensation plan for affected liquidity providers and advises users not to trade SAND on Base or BNB Smart Chain until bridging is restored. Coinbase plans to delist 10 perpetual futures contracts, including SAND, on August 26, with open positions to be automatically settled at that time. (Bitcoin.com News)
According to monitoring by CertiK Alert, the DeFi lending protocol Term Labs has been targeted by a governance attack, resulting in approximately $8.5 million in asset losses. Currently, around 2,843 ETH and approximately $1.6 million worth of DAI have been transferred to address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Term Labs has confirmed that its Term Vaults fell victim to a governance exploit, stating that the team is continuing to investigate the incident and will release further details upon completion of the investigation. Official sources have yet to disclose the specific attack vectors or the scope of the impact.
The Sandbox has officially confirmed and fully secured the recent SAND cross-chain bridge vulnerability affecting the Base and BNB Smart Chain (BSC) networks. Attackers exploited the flaw to mint uncollateralized SAND tokens across both networks, but the impact remains limited, accounting for less than 0.01% of the total SAND supply. SAND on Ethereum and Polygon, along with user wallets, remain unaffected. The Sandbox has since disabled cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable and non-redeemable. The official team advises users to avoid buying, selling, or trading SAND on the aforementioned networks.
RWA Layer 1 blockchain MANTRA Chain announced that the vulnerability in the Cosmos-EVM module has been patched, the network has resumed operations and block production, and the incident did not affect user funds. The team will release a complete post-incident analysis report in the coming days.
According to earlier reports, the SAND contract for The Sandbox on the Base chain is suspected of anomalous minting, resulting in the issuance of over 500 million additional tokens.
According to monitoring by PeckShield, an address labeled Bofur Capital was targeted by an address poisoning attack after withdrawing from Compound, resulting in losses of approximately $2 million. The attacker had previously sent 0.0002 USDC via a similar-looking address. Subsequently, due to mistakenly copying the wrong address, the controller of the Bofur Capital address transferred assets worth roughly $2 million to the attacker's address. The stolen funds have since been swapped for approximately 2 million DAI and are now held in a wallet beginning with 0xe2eB.
Odaily News - The U.S. Internal Revenue Service (IRS) has issued a warning about an advanced email phishing campaign targeting cryptocurrency holders in the United States. Attackers are using forged official tax letters to trick users into scanning malicious QR codes, aiming to steal crypto wallet credentials and private keys.According to reports, the attackers are impersonating the IRS by sending physical letters that create a sense of urgency under the guise of "tax compliance" or "account verification," and include QR codes within the correspondence. Once users scan these codes, they may be redirected to counterfeit websites, potentially exposing wallet login information, recovery phrases, or private keys, ultimately leading to the theft of digital assets.The IRS reminds taxpayers that official agencies will never request users to provide crypto wallet private keys, recovery phrases, or perform similar "wallet verification" procedures through unofficial channels. Cryptocurrency holders should remain vigilant against any suspicious emails or letters that ask them to scan QR codes, connect wallets, or submit sensitive information.As the number of crypto asset holders continues to grow, social engineering attacks targeting digital wallets are on the rise. Regulatory and security agencies are stepping up efforts to raise awareness and prevent such fraudulent activities. (CoinDesk)
BounceBit Chain 已于 8 月 20 日 02:36:37(UTC)在区块高度 20,702,857 停止出块。团队决定永久停止 BounceBit Chain,不再进行网络升级,并将在 BNB Chain 上以 BEP-20 代币形式重新发行 BB。新 BB 余额将依据 8 月 19 日 21:02:35(UTC)区块高度 20,697,260 的快照确定,攻击期间被转移的 286,543,148 枚 BB 不会计入重新发行代币。
Odaily News: Ethereum co-founder Vitalik Buterin has published his latest article "Obfuscation (Part 3): Local Mixing," providing an in-depth introduction to an emerging cryptographic obfuscation approach — "Local Mixing" — and describing it as a potential new fundamental cryptographic tool following elliptic curves, RSA, and lattice-based cryptography.Vitalik noted that current mainstream obfuscation techniques primarily rely on complex mathematical assumptions but often incur extremely high computational costs. Local mixing, by contrast, takes a completely different approach. Rather than depending on elliptic curves, large integer factorization, or lattice cryptography, it draws on design principles from symmetric cryptography and hash functions, continuously shuffling, restructuring, and hiding circuit architecture to eliminate information leakage while preserving functionality.He explained that the local mixing technique mainly involves steps such as reversibility, hardening, mixing, splitting, crossing walk, and "gadgetization." By introducing random structures into circuits, rearranging logic gates, and employing nonlinear hiding mechanisms, it makes it difficult for attackers to recover the original computational logic.Vitalik pointed out that the technique remains in its early stages, with security not yet subject to long-term validation, and it still faces challenges such as random attacks and linear analysis. Nevertheless, he believes local mixing represents an entirely new path of cryptographic exploration aimed at building more efficient indistinguishability obfuscation (iO) schemes.He stated that if local mixing achieves a breakthrough, it could lead to new quantum-resistant public-key encryption schemes and advance the development of general-purpose obfuscation techniques. While the field still requires years of cryptanalysis and optimization validation, AI-assisted research could significantly accelerate this maturation process.Vitalik described obfuscation as the "final frontier" of cryptography, as theoretically all other cryptographic primitives can be constructed from obfuscation and one-way functions. Local mixing not only has the potential to reduce the cost of traditional obfuscation schemes but could also become an important direction for future cryptographic infrastructure.
According to The Block, TRM Labs' latest report shows that AI applications in cryptocurrency crime grew by 40% year-over-year over the past year, primarily driven by fraud activities. In the first half of 2026, digital asset hacking incidents reached 201, a new record high, with approximately 75% of the losses concentrated in just 4% of the incidents. North Korean-linked activities caused approximately $600 million in losses, accounting for 61% of the total losses in the first half of the year. TRM Labs noted that AI has not created new types of crime, but has significantly lowered the barrier to criminal activity and expanded the scale of attacks.
SlowMist warned that legitimate crates in the Rust ecosystem—[email protected], [email protected], and [email protected]—were targeted in a supply chain attack. A malicious dependency, proc-macro1, was injected into these packages, enabling the download and execution of cross-platform malware during the Cargo build process. The attack poses risks including remote code execution at build time, host information collection, persistence, and browser data gathering.
According to Cryptopolitan, cybersecurity firm Adversa AI has disclosed that xAI's AI assistant Grok contains a security vulnerability known as "Encrypted Context Injection." Attackers can embed encrypted commands within standard web pages. When a user requests Grok to summarize such a page, Grok automatically decrypts and executes the hidden command, forwarding the user's name, geographic location, subscription tier, and complete chat history to the attacker's server. The vulnerability was reported to xAI through the HackerOne platform on June 3, 2026. Researcher Rony Utevsky followed up on August 4 and August 10, respectively. However, as of August 19, the vulnerability remains unpatched on Grok.com, and xAI has not provided a timeline for a fix.
According to reporter Kate Irwin (@kateirwin), GalaChain experienced an anomalous on-chain capital outflow this Tuesday. Approximately 1.99 billion GALA tokens (worth roughly $2.9 million), along with other tokens, were transferred from five major addresses to a newly created wallet, subsequently bridged out and swapped for ETH within approximately one hour. Of these, approximately 1.639 billion GALA (representing roughly 82%) originated from a wallet linked to Gala Games CEO and co-founder Eric Schiermeyer, which simultaneously transferred out other tokens valued at over $500,000. Within hours of the incident, the Gala development team urgently merged a fix commit on GitHub, classifying the event as resulting from a GalaChain EIP-712 unsigned field injection vulnerability. The Gala Ethereum cross-chain bridge has since been halted, with the Solana bridge concurrently deactivated. While officially cited as routine maintenance, users have been unable to access the cross-chain bridge services normally for several consecutive days.
According to CryptoSlate, researchers from USENIX Security publicly disclosed a clock attack vulnerability against Solana’s Proof of History (PoH) mechanism on August 12. The vulnerability had been privately reported to the Solana development team as early as December 2025. Research indicates that a malicious scheduler leader could manipulate the PoH logical clock through "re-anchoring," slowing the progression of logical time. This would yield a longer transaction selection window within physical time, allowing the attacker to isolate honest leaders' blocks via the TowerBFT fork-choice mechanism, with the required stake for the attack falling below 33%. The Alpenglow security contest hosted by Anza, which offered a 50,000 SOL prize pool, concluded on August 19. However, the vulnerability was excluded from the evaluation scope because the contest rules explicitly excluded "behaviors that can only be triggered when Alpenglow is inactive." The Solana development team confirmed awareness of the issue, stating that the probability of the worst-case scenario occurring under current conditions is low. They expect the Alpenglow upgrade to fundamentally eliminate the attack's prerequisites. The Alpenglow code is already integrated into the Agave 4.2 client but remains inactive on the mainnet, with full deployment expected alongside Agave 4.3. Until then, the transitional risks associated with this vulnerability have yet to receive public implementation-level analysis or official responses.