News linked to this event type.
PancakeSwap has issued a notice regarding abnormal activity in the BNB Chain OLPC/LABUBU liquidity pool, stating that the team has acknowledged community reports and initiated a preliminary investigation.PancakeSwap indicated that initial findings confirm no issues at the smart contract level, and the relevant incident is still under further review. The team will continue to monitor the situation and provide updates as more information becomes available.The platform reminds users to rely on information released through PancakeSwap's official channels and to be cautious of unverified rumors.
according to PeckShield monitoring, the OLPC/LABUBU liquidity pool on BNB Chain's PancakeSwap was attacked. The attacker stole approximately $1.1 million worth of assets. After the incident, the attacker cross-chain transferred the stolen funds to Ethereum and subsequently deposited 633.4 ETH into the mixing protocol Tornado Cash. Additionally, the attacker sent 0.0221 BNB and 0.0411 ETH to a deprecated address. Relevant attack details and fund flows are still under continuous tracking.
According to Odaily, the privacy-focused public chain project Namada officially stated that the protocol encountered a vulnerability attack incident. The team is currently investigating and has contacted relevant parties to assist in handling the matter.Officials stated that if the operator behind this attack is a white hat hacker, they hope the individual will proactively contact the team to further understand the vulnerability and facilitate a resolution.On-chain data shows that some ATOM assets related to the incident were allegedly transferred to a Cosmos Hub network address via IBC (Inter-Blockchain Communication protocol). According to on-chain tracking information, this address received approximately 228,517 ATOM on June 18. The funds were subsequently drained within hours through IBC transfers and multiple outgoing transactions. Currently, only a small balance remains in this address.As of now, Namada has not disclosed the type of vulnerability, the attack method, or the specific scale of losses. The relevant investigation is still ongoing.
According to Lookonchain, the Humanity Protocol attacker has converted part of the stolen funds into USDC and deposited them into KuCoin.
CZ shared the interview video on X, discussing the potential impact of quantum computing on Bitcoin’s cryptographic system—including threats to Satoshi Nakamoto’s Bitcoin holdings. If future quantum attacks break the legacy cryptographic system, the community may face three possible options.
mySwap, an automated market maker in the Starknet ecosystem, has issued a security alert stating that its concentrated liquidity protocol was exploited today, nearly draining all remaining liquidity from the protocol. As its frontend interface has not accepted new liquidity deposits for over six months, the affected funds primarily consist of residual liquidity scattered across more than 100,000 LP positions. After completing the theft, the attacker transferred the stolen funds across chains and obfuscated the transaction trail using the privacy protocol Railgun to conceal the asset flow. An investigation into the vulnerability details is ongoing, and potential remediation measures are being assessed.
The Zodiac team released a security incident analysis report regarding the impact on the Zodiac Roles Modifier, disclosing that the root cause of the vulnerability lies in a flaw in the ERC-1271 transaction signature verification logic: the system determines signature validity solely based on the returned “magic value,” without verifying whether the call itself succeeded—thus potentially allowing failed verifications to be masqueraded as valid signatures and bypassing the module’s authentication mechanism.
Axelar stated that, upon discovering the incident, its emergency response committee immediately disabled the Secret and Secret-SNIP connections. The team is currently coordinating with relevant exchanges and law enforcement agencies. This incident is confined solely to assets bridged from Axelar to Secret via IBC; all other IBC connections, Secret tokens, other Axelar integrations, and the Axelar core protocol remain unaffected.
Odaily Aave, a DeFi lending protocol, successfully maintained operations after experiencing capital outflows totaling approximately $8.45 billion. However, the incident has simultaneously triggered renewed market discussion regarding its risk structure and the fragility of the DeFi system.This stress event originated from a vulnerability exploit on the KelpDAO rsETH cross-chain bridge in April 2026, resulting in the theft of approximately $292 million in assets. This triggered market concerns over the safety of rsETH collateral. As this asset was widely used as collateral on Aave, panic spread rapidly, leading to concentrated withdrawals by users.During the capital outflow process, liquidity in certain lending markets was quickly depleted, with utilization rates briefly approaching 100%. Aave managed the situation by adjusting risk parameters and activating emergency mechanisms, although localized withdrawal restrictions did occur.Nevertheless, Aave's core smart contracts were not compromised. Protocol founder Stani Kulechov stated that the event validated the system's stability and resilience under extreme stress conditions.However, analysts pointed out that this incident exposed structural risks within DeFi: high coupling of assets across protocols, reliance on external bridged assets for collateral, and the potential for liquidity to rapidly evaporate in extreme scenarios.Industry observers believe that while DeFi's "composability" enhances efficiency, it also accelerates risk transmission, potentially causing a single asset event to trigger systemic cascading effects. Although Aave successfully navigated this stress test, the outcome does not equate to the elimination of risk.Overall, this event is viewed as a genuine extreme stress test for the DeFi lending system: the system can function, but its stability remains highly dependent on the quality of external assets and the market liquidity environment. (Cointelegraph)
on-chain security researcher Specter posted on X, stating that THORChain has not resumed normal operations for over a month after suspending all transactions due to a security vulnerability incident. The protocol previously did not choose to suspend transactions during other security incidents or suspicious fund flows; it even continued operating simple ETH-BTC paths. However, after becoming the affected party this time, it completely halted cross-chain transactions, sparking community discussion about the consistency of its risk management. Currently, THORChain on-chain trading remains completely stagnant, with almost no transactions on the entire chain. The recovery timeline remains unclear, and Specter reminds community users to "stay alert."
Odaily Planet Daily reports that "on-chain detective" ZachXBT released a case analysis stating that in a crypto asset case involving an Indian fraud gang, the individuals involved reported themselves to law enforcement after their assets were frozen, drawing attention.The incident began when a user sought help from ZachXBT, claiming that approximately 5.73 BTC (about $475,000) was frozen on Changelly in March 2025. Subsequent on-chain analysis revealed that these funds could be traced back to multiple social engineering attacks targeting US users and Bitcoin ATM-related thefts, with cumulative losses exceeding $1 million and involving several elderly victims.Investigations showed that the individual provided multiple different explanations for the source of the funds, including "loans," "transfers from the boss," and "investments from 2014–2015," with clear contradictions in the chain of evidence.More notably, the user filed a police report in India in December 2025 attempting to recover the frozen funds (case number 3207-P/2025). Subsequent on-chain forensics and email data analysis indicated that the individual may have acted as a money "mule," with some bank documents inconsistent with their identity information.ZachXBT stated that such cases demonstrate that social engineering attacks and cross-border fund transfers continue to occur, reminding users to avoid interacting with funds from suspicious sources to prevent triggering compliance freezes or legal risks.
Microsoft’s Threat Intelligence Team has disclosed a Windows clipboard cryptojacking trojan that has been active since February 2026. This malware employs a combination of “worm-like propagation,” “clipboard hijacking,” and “Tor-based anonymous communication” to target cryptocurrency users.
According to on-chain analyst PeckShield (@PeckShieldAlert), the Humanity attacker’s address has bridged 130 ETH (approximately $220,600) from Ethereum to BNB Chain (381 BNB).
DeFi lending protocol Ionic Protocol announced on X platform that due to the escalating impact of a security breach incident in 2025, the project has been forced to immediately cease all operations. All users are required to withdraw their assets from all deployments as soon as possible. Ionic Protocol added that the decision to shut down was made with "no other option," and related services are now in the termination process.
leaders of the Group of Seven (G7) issued a statement at the G7 summit in Évian-les-Bains, France, once again calling for joint action to combat North Korean cryptocurrency theft and cybercrime. United Nations security researchers have linked North Korea's cryptocurrency theft to the funding of its weapons programs.Previously, attacks suspected to be linked to North Korean hackers included a $285 million attack on Drift Protocol in April and a $36 million breach on Humanity Protocol in June. According to Chainalysis data, North Korean hackers stole at least $2 billion in cryptocurrency in 2025, bringing their historical total theft amount to at least $6.75 billion. (Cointelegraph)
according to Aztec Labs monitoring, the team is investigating a potential vulnerability affecting an Aztec payments product that was discontinued in 2021. Approximately $2 million was transferred from an immutable smart contract. This discontinued product is an immutable Stage 2 Rollup version that was deactivated in 2022. Aztec Labs does not hold the admin keys or any control over the system, and thus cannot pause or upgrade it. This incident is separate from the attack on the Aztec Connect product on June 14. The Aztec Foundation stated that the product affected by this attack is not associated with any smart contracts of the current network or the AZTEC ERC20 token.
Cosine, founder of SlowMist, posted on X stating that Aztec appears to have been hacked again. Aztec’s Private Rollup Bridge is suspected to have been exploited, resulting in the abnormal transfer of approximately 1,158 ETH, 150,000 DAI, and 0.46963295 renBTC, with a total value of roughly $2.15 million.
after the White House issued an emergency takedown order for the Fable 5 and Mythos 5 models, it sparked concerns among Anthropic employees regarding the company's IPO plans. According to reports, management faced pressure to respond after receiving a 90-minute limited-time takedown order, and some employees were confused by the shifting rationale for the takedown between "national security" and "security vulnerabilities," while also worrying that related regulatory pressure could affect the company's listing process. (New York Times)
According to on-chain analyst PeckShield (@PeckShieldAlert), the address labeled as the UXLINK attacker has swapped approximately 14.6 million DAI for 8,298.6 ETH. Subsequently, this address deposited 8,340 ETH into Tornado Cash and bridged 2.64 ETH (approximately $4,630) from Ethereum to a Bitcoin address.
According to Lookonchain monitoring, over the past 30 minutes, the UXLINK attacker spent 6.5 million DAI to buy 3,686 ETH at an average price of $1,764, and laundered the funds through Tornado Cash.