News linked to this event type.
According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.
According to Nikkei XTECH, Microsoft has developed a new system to address cyberattacks involving autonomous AI, using three types of AI agents to support the process from vulnerability identification to remediation. Microsoft will also launch its first self-developed AI model for cyber defense.
According to CNBC, the AI sandbox escape incident disclosed by OpenAI earlier this month has been confirmed to affect a second company. Modal Labs Chief Technology Officer Akshat Bubna confirmed that an AI agent being tested by OpenAI, after escaping the sandbox and infiltrating Hugging Face, further penetrated an account of a Modal Labs customer. Bubna stated that the Modal platform itself was not affected; the vulnerability stemmed from the customer exposing executable endpoints to the public network. The compromised account belongs to an AI security testing benchmark project named ExploitGym; the agent allegedly actively sought out cybersecurity testing environments and successfully penetrated them.
According to e27, the Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) jointly established the "AI-Driven Cyber and Tech Risk Taskforce" (ACT) in May 2026, with membership including major financial institutions such as DBS, OCBC, UOB, Singapore Exchange, NETS, and BCS. The taskforce focuses on three key areas: first, promoting industry-wide sharing of AI cybersecurity experience; second, conducting proof-of-concept tests for AI defense tools to enhance institutions' operational capabilities; third, developing security controls and response guidelines for AI threats. MAS Assistant Managing Director Vincent Loy pointed out that frontier AI is increasing the severity, scale, and complexity of cyber attacks, and the financial industry must respond with a high sense of urgency and strong collaboration.
The SlowMist Security Team stated that MistEye discovered a recruitment scam campaign targeting Web3 practitioners. Attackers impersonated recruiters and induced victims to install a malicious application disguised as the AI meeting tool "Relay".
Benchmark partner Chetan Puttagunta posted on X, expressing confusion over Anthropic's public call for stricter regulation on AI model distillation. He noted that Anthropic is currently a company valued at approximately $1 trillion with vast technical and financial resources. At the scale described, so-called "large-scale distillation attacks" should theoretically be easier to identify and track. If Anthropic chooses to restrict such activities, the real cost may not be a lack of technical capability, but rather the sacrifice of some API revenue. "The only cost required seems to be reducing revenue from related API businesses."Previously, AI companies like Anthropic have been paying close attention to the issue of model distillation. Model distillation typically refers to using the output of a large model (the teacher model) to train another model (the student model), aiming to reduce costs and improve efficiency. Some AI companies are concerned that competitors might obtain model outputs by calling a large number of APIs, which could then be used to train their own models, thereby bypassing the original R&D investment. According to Puttagunta's perspective, the controversy surrounding model distillation in the AI industry essentially involves the balance between commercial interests, open competition, and intellectual property protection. For leading AI companies, finding the balance between protecting core technology and maintaining an open ecosystem will become an important issue for future industry competition.
1,178 employees from leading AI companies have jointly released a statement titled "Pacing the Frontier," urging the U.S. government to support international cooperation in developing technologies and governance tools to proactively regulate the pace of frontier AI development.The statement says that global leading AI companies believe the future may be approaching the point where automated AI research becomes achievable. Although it is impossible to predict exactly how this will accelerate AI progress, there is a risk that AI capabilities could rapidly surpass human understanding and control.The signatories stated that the industry, governments, and society need to retain the option to "buy time" to address emerging risks, improve safety measures, and strengthen regulation. However, due to competitive pressures faced by both companies and nations, the world currently lacks governance mechanisms capable of proactively controlling the pace of frontier AI development.The statement notes that frontier AI agents are already capable of discovering and exploiting real software vulnerabilities, and could be used for large-scale cyberattacks in the absence of safety measures.Employees from multiple organizations including OpenAI, Anthropic, Google, and Meta have signed the statement, and believe there is a need to establish international coordination mechanisms to reduce potential risks while advancing AI development.
Anthropic stated that Claude Mythos Preview discovered improved attack methods against the post-quantum signature candidate scheme HAWK during cryptographic research, and reduced the effective key strength of HAWK-256 from 264264 to 238238, lowering the theoretical cracking cost.
According to TenArmorAlert monitoring, its system detected a suspicious attack involving the LULA token on the BSC chain, resulting in losses of approximately $578,100.
区块链安全公司 AmericanFortress 提出新加密方案,可保护现有 BTC、ETH、SOL 钱包免受未来量子攻击,用户无需转移资金或更改地址。
The PPP Prediction Market Tool shows that the probability of a "ceasefire between the US and Iran before July 24" on Polymarket has dropped to 36%, down 15% in 24 hours.This event will settle as "Yes" if the US does not take any military actions that meet the defined criteria against Iran for 14 consecutive days before the specified deadline; otherwise, it will settle as "No."Qualifying military actions include only US-initiated airstrikes or surface-to-surface missile attacks that directly strike Iranian territory, including bombs, air-to-surface missiles, air-launched drones, cruise missiles, and ballistic missiles. Excluded actions include intercepted or destroyed munitions, surface-to-air missiles, small-scale skirmishes, ground operations, cyberattacks, naval shelling, artillery attacks, and unexecuted threats or authorized actions.If there is a dispute regarding the occurrence, attribution, or timing of relevant military actions, the event will await consensus from official information and credible media before being adjudicated. If disagreements persist after three full calendar days, a comprehensive judgment will be made based on all available information at that time. The settlement basis includes official information from the US and Iranian governments and militaries, as well as reports from credible media outlets.Join the PPP Signal Push Community to stay ahead and seize the opportunity.
In the first half of 2026, losses from hacker attacks on cryptocurrency projects have exceeded $1 billion, with the number of verified attack incidents reaching a record high for the same period in history, described as "the half-year with the most hacker attacks on record." However, in terms of value, overall losses remain lower than the same period last year, mainly because a $1.5 billion attack incident occurred at Bybit in 2025, raising the baseline.
According to Blockaid monitoring, Crypto DAO's Pro token was attacked. As of 00:23 early this morning, the attacker and related profit addresses currently hold a combined total of approximately 8.2 million USDT.
Robinhood CEO Vlad Tenev stated that his X account was compromised last week. Attackers deceived X customer support through social engineering tactics, bypassing security measures such as two-factor authentication and login alerts, and posted false content related to meme coins. Subsequently, the X security team assisted in swiftly removing the relevant posts and restored account access on the same day.
Odaily News: The Thai Securities and Exchange Commission (SEC) has filed a criminal complaint against cryptocurrency exchange Bitkub Online and two former directors, Sakolkorn Sakavee and Thaweesap Rawan, accusing them of submitting false financial reports between May and October 2021. The case has been referred to the Thai Economic Crime Suppression Division (ECD) for investigation, and prosecutors will determine whether to formally indict. The SEC stated that Bitkub suffered a cyberattack in May 2021, resulting in the theft of 16 types of digital assets, with losses exceeding $50 million. Regulatory investigations revealed that Bitkub failed to reflect the related losses in its Form DA 1 daily net capital reports from May 10 to October 30, 2021. The SEC alleges that the involved executives made false entries in the company's official documents, leading regulators to believe that client assets were intact and the company had not suffered financial losses. Bitkub subsequently completed the acquisition of replacement assets in late October 2021, but the SEC maintains that the reports during that period constituted false statements. In a statement on July 23, Bitkub stated that current customer holdings were secure and accounts were complete. Bitkub claimed that its co-founders purchased replacement assets of the same type and quantity, bearing the losses themselves, and noted that the cyber theft incident had been reported to law enforcement authorities on May 10, 2021.
According to official announcements, Zcash has officially activated the Ironwood NU6.3 network upgrade at mainnet block height 3,428,143 and launched the new shielded pool Ironwood. This upgrade aims to address the previously discovered Orchard soundness vulnerability, improve protocol security, and enhance the independent verifiability of ZEC circulating supply integrity.
: A security report for the first half of 2026 released by on-chain security platform Blockaid shows that the crypto industry suffered losses exceeding $1 billion during the period, with a record number of hacker incidents in six months. Blockaid tracked 212 security incidents, including a single attack on KelpDAO that resulted in a loss of $292 million. Ethereum and Solana were the networks with the largest amounts of stolen funds during the period, with losses of approximately $332 million and $326 million, respectively. Blockaid stated that the number of high-threshold attacks in the first half of 2026 was 3.4 times that of the entire year of 2025. Ethereum incidents were primarily driven by code vulnerabilities, with attack vectors including bridge and smart contract exploits, unauthorized access to privileged accounts, and market manipulation. Solana's losses increased significantly from approximately $127 million in 2025, with over 98% of losses stemming from key leaks, primarily involving incidents related to Drift Protocol and Step Finance.
据 PeckShield 监测,Across Protocol 攻击者标记地址已向 Across Protocol Hub Pool Owner 多签地址返还 331.8 枚 ETH,约合 62.39 万美元。
According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), the Solido Money protocol suffered a vulnerability attack, with approximately 293.7 million SUPRA stolen, of which approximately 220 million SUPRA have been transferred to deposit addresses suspected to be associated with Gate exchange. According to Solido Money's official report, approximately 90% of the compromised funds were held by the foundation.
Anthropic CEO Dario Amodei has responded to the controversy over open-weight models, stating that the company has never advocated for a total ban on open models. Previously, companies including OpenAI, Google, and SpaceX joined the open-source coalition, while Anthropic was the only major frontier model company not to sign on.Amodei acknowledged that open-weight models can lower costs, promote competition, and support customer self-deployment. He stated that open models without dangerous capabilities can be considered a "public good."However, he believes that open models are not necessarily safer, nor do defenders necessarily gain more advantages over attackers. Once model weights are made public, security restrictions may be removed and cannot be revoked.Anthropic proposed three alternative measures, including restricting the flow of advanced chips and manufacturing equipment to China, cracking down on industrial-scale model distillation, and requiring all models that reach a certain capability threshold—whether open-source or closed-source—to undergo testing for cyber attacks, biological risks, and alignment.