News linked to this event type.
in its Q2 2026 Security and Compliance Report, Hacken stated that institutional investors are expanding their due diligence scope from smart contract audits to continuous monitoring, signer control, and incident response preparedness. Among the 1,427 projects it tracked, only 9% had third-party monitoring, and 4% had monitoring, active bug bounties, and security audits simultaneously. The report shows that of the approximately $764 million stolen in Q2, 88.3% involved compromised keys, signers, and infrastructure.Hacken noted that 14 projects attacked in Q2 had previously completed audits, but most of the losses originated from areas outside the scope of traditional smart contract reviews. The report states that the affected components included signing devices, cross-chain bridge validators, backend infrastructure, admin keys, and deprecated but still active old contracts. The sample covered 1,427 projects with a market cap exceeding $1 million, listed among the top 50 centralized exchanges on the CoinGecko Trust Score, excluding wrapped assets, stablecoins, and tokenized real-world assets.
According to the latest report released by the Financial Action Task Force (FATF) on July 16, FATF conducted the seventh targeted review on the implementation of Recommendation 15 (R.15) across global jurisdictions. The report points out that since the last update in 2025, countries have continued to advance in the regulation of Virtual Assets (VA) and Virtual Asset Service Providers (VASP), including conducting risk assessments, improving licensing and registration frameworks, implementing the Travel Rule, and strengthening enforcement actions. However, the report also points out that significant gaps still exist, mainly reflected in: the difficulty in effectively translating risk assessment outcomes into mitigation measures, insufficient implementation of licensing and registration frameworks, difficulties in identifying entities engaged in VASP activities, and insufficient effectiveness of risk-based supervision and enforcement. Regarding emerging risks, the report focuses on the following areas: the intensified "industrialization" trend of organized crime groups using virtual assets to commit fraud, increased risk of stablecoin abuse, risks associated with non-custodial wallet peer-to-peer (P2P) transactions, offshore VASPs operating outside regulatory oversight, and ongoing challenges in the DeFi sector. FATF calls on the public and private sectors to jointly strengthen the implementation of R.15, enhance risk mitigation capabilities, and deepen domestic, international, and public-private cooperation mechanisms.
according to Zilliqa's monitoring, it has learned of a security incident involving a CEX partner, where some ZIL has been stolen from a cold wallet. The incident is currently under investigation, and the team is working with relevant parties to determine the root cause and the scope of the impact. As a precautionary measure, Zilliqa has notified all CEX partners to temporarily suspend ZIL deposits and withdrawals to prevent the stolen funds from being transferred or sold through centralized platforms. The official stated that further updates will be released after verifying the information and reminded the community to only follow information published through official channels.
according to Hinkal monitoring, full refunds will be issued this week to users who have completed the recovery process, with completion expected by July 22. Users who have not yet completed the recovery can still submit applications. Previously, Hinkal suffered an attack resulting in a loss of approximately 797,000 USDC, which the attacker exchanged for about 454 ETH.
that, according to DeFi researcher @Zun2025 posted on X platform, "MetaMask hired a DPRK-linked hacker as a developer without even conducting a proper background check that could have revealed his identity.The hacker's GitHub username is imyugioh, and he has been publicly listed on the Lazarus Group website since September 2025, yet MetaMask still hired this individual in March 2026. Source: lazarus.group/team/mauro-liu. Imagine that one of the largest wallets granted core code repository access to someone already on a publicly known list of DPRK hackers. Now think about what might happen to those small protocols with absolutely no security teams."Earlier reports stated that a North Korean hacker, Tyler Knapp, infiltrated the MetaMask team. He entered MetaMask through a long-term cooperating human resources supplier via an outsourcing arrangement, bypassing the background checks of the company's direct recruitment process. He worked at the company for a month and participated in the development of the wallet's fiat on/off ramp functionality. During this period, his IP address and behavioral anomalies were detected by the company's security monitoring. The company immediately revoked all his access permissions and suspended the release of all products he had worked on. No substantial data or financial losses have been caused so far.
Odaily reports, according to monitoring by Onchain Lens, Allbridge Core has been exploited on Solana. The attacker borrowed $1.12 million USDC via a Kamino flash loan, then rapidly executed a USDC/USDT swap, distorting the stablecoin pool ratio of Allbridge. They withdrew liquidity at the manipulated exchange rate and repaid the flash loan within the same transaction, extracting approximately $1.1 million in funds. The funds were subsequently mixed through a privacy protocol. The maximum single withdrawal from Allbridge was $2.24 million USDC. Further analysis of the vulnerability exploit and the affected pools is ongoing.
Odaily news, David Sacks, Chairman of the President's Council of Advisors on Science and Technology, posted on X platform stating that the Kimi K3 model recently completed 15 critical security vulnerability repair tasks, while Codex and Fable refused to process related requests due to "network security protection mechanisms". He indicated that there is no reason to restrict US models from performing these tasks due to security limitations, while Chinese models can complete them normally. Doing so will only reduce US competitiveness.
According to Yonhap News Agency, the South Korean Financial Supervisory Service has sent an inspection opinion letter to Upbit's operating company, officially initiating the sanction procedure. Subsequently, the sanction content will be finally determined after going through procedures such as company explanation, the Sanction Deliberation Committee, the Securities and Futures Commission, and the Financial Services Commission. Yonhap News Agency stated that since the current "Virtual Asset User Protection Act" mainly targets user protection and unfair trading, it lacks direct and clear sanction provisions for hacking/system accidents, resulting in uncertainty regarding the severity of the sanctions.
Odaily News: Headline: "Loss of 23.75 Million USDC: Ostium Price Data Attacked". According to Ostium's monitoring, Ostium has released an update on the security incident. Its liquidity provider treasury was attacked on July 15, resulting in a loss of 23,752,746 USDC. Preliminary investigations indicate that the attacker compromised the off-chain infrastructure that supplies price data to the protocol, submitting disguised, fraudulent price reports. By rapidly opening and closing multiple large positions, the attacker extracted artificially generated profits from the treasury. Ostium stated that trader collateral is stored in separate, isolated smart contracts and was unaffected by this incident; all trading positions remain open. The team paused trading and froze all trading contracts within 60 minutes of the first attack transaction. Currently, Ostium is cooperating with Mandiant, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies, and is coordinating with trading platforms, bridge contracts, and stablecoin issuers to advance the investigation. The engineering team is repairing and strengthening the relevant infrastructure to support a safe resumption of trading. Ostium stated it will notify at least 24 hours in advance before thawing the trading contracts. Once trading resumes, existing positions will be marked at the price at the time of reopening, unaffected by price fluctuations during the suspension.
据链上分析师余烬监测,BONK 财库攻击者于 5 小时前再次向 Coinbase 转入 4000 亿枚 BONK ,价值约 111 万美元。
Bitcoin News posted on X platform stating that Dathon Pwn claims to have discovered a late-upgrade consensus vulnerability in BIP 110. This could cause nodes upgraded from older software to retain chain history, while newly deployed BIP 110 nodes would reject this history, potentially resulting in a hidden chain split.
According to EmberCN monitoring, the address that previously drained the BONK treasury via a governance attack transferred another 400 billion BONK (approximately $1.19 million) to Coinbase 20 minutes ago. This address spent approximately $4.4 million 10 days ago to purchase sufficient BONK tokens to reach the governance voting approval threshold, subsequently initiated a governance proposal and forced it through, transferring 4.426 trillion BONK valued at approximately $21.2 million from the BONK treasury.
Odaily Odaily News: Cybersecurity firm Kaspersky has disclosed that a new malware framework called OkoBot is targeting cryptocurrency investors through social engineering tactics and trojanized GitHub applications. The malware can steal crypto wallet files, browser data, and user credentials, as well as inject malicious extensions and intercept wallet application windows to steal assets. Kaspersky reports that attacks involving this malware family have been detected since January 2026. The framework evolved from TookPS, which was first identified in 2025 and was previously distributed via trojan downloaders through fake software websites. Separately, cybersecurity firm SlowMist has disclosed that a new wave of malicious activity is infiltrating Web3 developers' devices through fake LinkedIn recruitment opportunities. Attackers, impersonating Web3 recruiters, send fake GitHub repositories, tricking developers into pulling code, installing dependencies, and running projects, ultimately stealing project keys, cloud credentials, or wallet extension data.
According to Com Feed monitoring, the TrustedVolumes attacker has returned 1,122 ETH, worth approximately $2 million, while retaining about $2 million as a "bounty." Previously, the attacker had exploited a vulnerability to steal approximately $5.8 million in funds.
As the conflict between the United States and Iran continues to escalate, Pakistan has conveyed a clear stance to Iran that any attack on Saudi Arabia will be considered an attack on Pakistan. The Pakistani government and military have communicated this position to the highest levels of Iran. According to the Joint Strategic Defense Agreement signed between Pakistan and Saudi Arabia in 2025, an attack on either party will be regarded as aggression against both. Sources revealed that Iran has informed the Houthis that if the United States attacks Iranian power facilities, the Houthis will consider blocking the Bab el-Mandeb Strait. The Houthis are reportedly deploying missiles and drones near the Strait. Pakistan stated that it hopes all parties will exercise restraint and ease regional tensions through diplomatic means.
Cos, founder of SlowMist, shared a tweet on X platform regarding potential poisoning attack risks in Claude Code and published a detailed analysis of poisoning attacks targeting Grok Build CLI and Claude Code CLI. The analysis pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, and the gaps between them serve as channels for attackers.Attackers may exploit malicious project configuration files to execute arbitrary commands without the user's knowledge, thereby stealing API keys, cloud credentials, or gaining control over local devices. Researchers constructed a test environment and found that on Mac systems, if Claude Code is compromised, executing a specific test command could trigger the launch of a local calculator, demonstrating a potential command execution risk. If the attack succeeds, attackers could further steal API keys from AI services such as Claude and OpenAI, causing account cost losses; obtain credentials for cloud services like AWS, Alibaba Cloud, and Tencent Cloud to access servers and data; tamper with code repositories to implant backdoors; and leverage local devices as a springboard to attack internal enterprise networks. It is reported that the relevant vulnerability has existed for one year.
SlowMist founder Cosine retweeted a post about the potential poisoning attack risks of Claude Code, pointing out that attackers could execute arbitrary commands without the user's knowledge through malicious project configuration files, thereby stealing API keys, cloud credentials, or controlling local devices. Researchers constructed a test environment and found that in Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks. If the attack succeeds, attackers may further steal API Keys for AI services such as Claude and OpenAI, causing account fee losses; obtain cloud service credentials for AWS, Alibaba Cloud, Tencent Cloud, etc., to access servers and data; tamper with code repositories to implant backdoors; and use local devices as a springboard to attack enterprise internal networks.
According to monitoring by Yu Jin, the address that previously transferred BONK worth $21.2 million from the Bonk treasury through a governance proposal, after moving 1.186 trillion BONK (approximately $4.11 million) to Binance yesterday, has today transferred another 400 billion BONK (worth about $1.28 million) to Coinbase.Data shows that of the 4.426 trillion BONK removed from the Bonk treasury via the governance proposal by this address, 1.626 trillion BONK (approximately $5.58 million) have been moved to centralized exchanges. Additionally, in the 11 days since the address began withdrawing assets from the Bonk treasury, the price of BONK has fallen by approximately 36%, dropping from $0.0000047 to $0.000003.
security researchers have discovered an information-stealing malware targeting MacOS devices that is attacking crypto users. It can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Affected wallets and applications include: Exodus, Atomic, Electrum, Wasabi, Monero, and others.Security experts advise that users with potentially infected devices should immediately treat them as "untrusted devices," terminate all active Telegram sessions, and change both their Telegram two-factor authentication password and desktop app password. Additionally, users should not enter seed phrases, private keys, or wallet passwords on the infected device, and should generate a new wallet and migrate their assets. (FinanceFeeds)
: On-chain digital asset management neobank ether.fi has selected Nexus Mutual to provide ETH slashing coverage, covering slashing penalties for its validators up to 15,000 ETH. ether.fi stated that it operates a large-scale validator set on Ethereum, and slashing is a tail risk. This coverage is used to cover validator losses, with a scale exceeding the total historical ETH slashing losses. ether.fi currently manages over $6 billion in assets across products such as Cash, Stake, and Liquid. Since 2019, Nexus Mutual has provided over $7 billion in coverage for smart contract attacks, slashing, and other digital asset risks. (Decrypt)