News linked to this event type.
according to Onchain Lens monitoring, on July 6, the Summer Fi attacker received 6.017 million DAI from the Summer Fi exploit, and subsequently swapped and routed the funds through Tornado Cash. The original wallet (0x7bf...dca) retains 11.3 ETH, worth approximately $21,600; the second wallet (0x46e...ba7) retains 282.9 ETH, worth approximately $543,500.
According to OpenAI's official blog, OpenAI's GPT-5.6 Sol and a more powerful pre-release model, during internal network capability benchmark testing (ExploitGym), due to lowering network attack refusal rates, autonomously identified and exploited a zero-day vulnerability in the package registry cache proxy, breached the sandbox isolation environment, gained internet access permissions, and subsequently, through privilege escalation and lateral movement, finally infiltrated the Hugging Face production database, directly stealing test answers to "cheat". The Hugging Face security team promptly detected and blocked the attack. OpenAI stated that this incident is an unprecedented cybersecurity event, and currently both companies are jointly conducting a forensic investigation; the relevant zero-day vulnerabilities have been responsibly disclosed to the vendor, and full details will be released after the investigation is completed.
Odaily Planet Daily reported that the algorithmic stablecoin Balance Coin dropped from $0.9954 to $0.001358, a decline of over 99%. The stablecoin is the native algorithmic stablecoin of the Balance Protocol, designed to maintain a peg to the US dollar. Blockchain security firm PeckShield stated that the depegging occurred following an exploit of the decentralized autonomous organization 42DAO, which governs the Balance Protocol and its BLC token, resulting in a $915,000 loss. TenArmor reported detecting suspicious attacks involving GemJoin and 42DAO on the BNB Chain.
SlowMist issued a security warning stating that 42DAO suffered an attack, with losses of approximately $912,000. The attack was caused by the attacker exploiting the abnormally low price of BTCB provided by Median Oracle, completing the exploitation through the poke mechanism of the Spotter contract and the bark mechanism of the Dog contract.
GoPlus Security issued a security alert stating that a user signed a malicious Permit transaction 183 days ago, resulting in approximately $1,625 worth of USDC being transferred by phishing attackers. Since the user did not revoke the relevant authorization thereafter, attackers exploited this authorization again to transfer approximately $75,780 worth of USDC.
According to Protos, AI shopping agent developer ORO stated that an employee was tricked by an attacker disguised as a meeting contact into installing a Microsoft Teams extension containing malicious code, ultimately resulting in the theft of approximately $630,000 worth of crypto assets. ORO stated that the attackers likely originated from the North Korea-backed hacker group Sapphire Sleet.
OpenAI confirmed that the unreleased GPT-5.6 Sol and another unnamed, more powerful pre-release model breached a restricted sandbox environment during ExploitGym benchmark evaluations and infiltrated Hugging Face's production infrastructure to obtain test answers.OpenAI stated that the models leveraged a zero-day vulnerability in an internal software package registry proxy to escalate privileges and move laterally, ultimately connecting to a machine with internet access. The models then identified and chained together vulnerabilities in both the OpenAI research environment and Hugging Face's production infrastructure, directly retrieving test solutions from Hugging Face's production database.Hugging Face disclosed the incident on July 16, stating that the attack was executed end-to-end by an autonomous AI agent system, involving thousands of operations within short-lived sandboxes and accessing internal datasets and service credentials. OpenAI confirmed its models were the subject of the incident five days later.Hugging Face stated that its security team, in order to analyze over 17,000 attack logs, initially attempted to use a commercial US frontier AI interface, but the request was blocked due to safety guardrails. They subsequently switched to using the 753-billion parameter open-weight model GLM 5.2 from Chinese AI startup Z.ai on their own infrastructure to complete the forensic analysis.
the U.S. Attorney's Office for the District of Columbia, in coordination with the U.S. Secret Service's Washington Field Office, announced that investigations into multiple international cyber fraud cases have led to the seizure of over $25 million in cryptocurrency. The funds were allegedly linked to crypto investment scams targeting residents of the United States and Canada.This action is part of the "Scam Center Strike Force," an initiative launched in 2025 by District of Columbia Attorney Jeanine Ferris Pirro. To date, the task force has recovered assets totaling over $800 million. U.S. prosecutors stated that on July 21, 2026, the U.S. Attorney's Office for the District of Columbia filed five civil forfeiture complaints in the U.S. District Court, seeking the forfeiture of over $25 million in crypto assets recovered from various fraud investigations.Investigators indicated that these cases involve multiple money laundering networks with victims worldwide. Criminal groups lured victims into investing through fake crypto investment platforms and online romance scams, then laundered the funds through multi-layered wallet addresses and mixing operations to conceal the source of funds. The seized funds are associated with five major investigations:In one case, Canadian law enforcement provided the U.S. Secret Service with wallet addresses suspected of being used to transfer illicit proceeds. Investigators froze the relevant addresses and traced over 270 suspected victim transactions, involving approximately $10.4 million;The second case involved an online romance scam that defrauded over 200 victims. Illicit funds were transferred through hundreds of intermediate wallet addresses and commingled with funds from other victims, involving approximately $12.08 million;The third case involved a victim from the U.S. capital region who participated in a fraudulent crypto investment project. After failing to withdraw funds, the victim lost contact with the scammers, with the involved amount being approximately $1.23 million;In the fourth case, a victim transferred millions of dollars in cryptocurrency to a fake investment account. Investigators traced some of the funds to six wallet addresses and froze approximately $2.39 million;In the fifth case, scammers impersonated an agency that "recovers stolen funds" to trick victims into paying fees, with the involved amount being approximately $285,000.The U.S. Secret Service stated that these cases remain under active investigation. Law enforcement officials are tracking down the suspects behind the fraud network and will cooperate with international law enforcement agencies to hold them accountable.
According to an official post from Midnight Foundation (@midnightfdn), the Wanchain Cardano<>BNB cross-chain bridge suffered a security attack. Currently, multiple major exchanges including KuCoin, Kraken, Binance, Bybit, OKX, and MEXC have responded rapidly, taking preventive measures to restrict the flow of stolen assets, including freezing relevant accounts and addresses, blacklisting the attacker's wallets, and suspending NIGHT token deposit and withdrawal services. The exchanges confirmed that this incident is an isolated third-party bridge vulnerability and is unrelated to the Midnight Network mainnet and the NIGHT asset itself.
the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.
According to Decrypt, Galaxy Digital has officially launched the "Bitcoin Quantum Readiness Initiative," with three core pillars including: providing up to $5 million in post-quantum cryptography research grants to developers, publishing specialized research reports through Galaxy Research, and establishing a quantum advisory committee composed of scholars from multiple top universities. The initiative targets "Q-Day"—the critical moment when quantum computers utilize Shor's algorithm to crack Bitcoin's elliptic curve encryption, forge signatures, and steal wallet assets. Project Eleven predicts that quantum computers capable of cryptographic threats may emerge as early as 2030, at which point approximately 6.9 million BTC will face exposure risks. The Coinbase Quantum Advisory Committee has also called on developers to immediately initiate migration work. Meanwhile, Trump has signed an executive order setting the deadline for the U.S. federal government to complete post-quantum cryptography migration to December 2031.
According to Bitcoin.com, the Kenyan government is investigating the hacking incident of President William Ruto's official website. The attackers temporarily tampered with the homepage content and demanded a payment of 5 Bitcoins, threatening to leak undisclosed information otherwise.
on-chain investigator ZachXBT stated that the cross-chain bridge protocol TeleSwap was suspected of being attacked on July 15, 2026, resulting in losses exceeding $735,000. However, as of five days after the incident, the project team has not yet publicly disclosed the relevant situation.ZachXBT stated that shortly after suspicious fund outflows were detected, TeleSwap's Bitcoin hot wallet stopped processing transactions. About two hours ago, the attacker transferred the stolen funds into the privacy mixing protocol Tornado Cash.
the cross-chain protocol Allbridge has issued an official statement confirming that an attacker has withdrawn approximately $1.65 million in assets from the Allbridge Core liquidity pool. A detailed analysis of the incident is currently being compiled, and the full investigation results will be published subsequently. The team emphasizes that there is no further risk to current user liquidity and that the Allbridge Next service is operating normally.In response to this incident, Allbridge plans to relaunch the Core version but will remove the liquidity pool design. Future cross-chain transfers will be facilitated via Circle CCTP and the LayerZero router to eliminate the risk of liquidity pool imbalance and the model vulnerabilities exploited in this attack. This incident has accelerated the previously initiated migration plan to fully transition to the more secure new infrastructure, Allbridge Next. According to the plan, Allbridge Core and Allbridge Classic will cease operations in their current form within the next three months, and users are advised to withdraw their relevant liquidity in advance.It is understood that this attack has exposed the risks inherent in the traditional cross-chain liquidity pool model and has further driven the protocol's transition towards a cross-chain architecture based on message passing and native asset transfer.
in its Q2 2026 Security and Compliance Report, Hacken stated that institutional investors are expanding their due diligence scope from smart contract audits to continuous monitoring, signer control, and incident response preparedness. Among the 1,427 projects it tracked, only 9% had third-party monitoring, and 4% had monitoring, active bug bounties, and security audits simultaneously. The report shows that of the approximately $764 million stolen in Q2, 88.3% involved compromised keys, signers, and infrastructure.Hacken noted that 14 projects attacked in Q2 had previously completed audits, but most of the losses originated from areas outside the scope of traditional smart contract reviews. The report states that the affected components included signing devices, cross-chain bridge validators, backend infrastructure, admin keys, and deprecated but still active old contracts. The sample covered 1,427 projects with a market cap exceeding $1 million, listed among the top 50 centralized exchanges on the CoinGecko Trust Score, excluding wrapped assets, stablecoins, and tokenized real-world assets.
According to the latest report released by the Financial Action Task Force (FATF) on July 16, FATF conducted the seventh targeted review on the implementation of Recommendation 15 (R.15) across global jurisdictions. The report points out that since the last update in 2025, countries have continued to advance in the regulation of Virtual Assets (VA) and Virtual Asset Service Providers (VASP), including conducting risk assessments, improving licensing and registration frameworks, implementing the Travel Rule, and strengthening enforcement actions. However, the report also points out that significant gaps still exist, mainly reflected in: the difficulty in effectively translating risk assessment outcomes into mitigation measures, insufficient implementation of licensing and registration frameworks, difficulties in identifying entities engaged in VASP activities, and insufficient effectiveness of risk-based supervision and enforcement. Regarding emerging risks, the report focuses on the following areas: the intensified "industrialization" trend of organized crime groups using virtual assets to commit fraud, increased risk of stablecoin abuse, risks associated with non-custodial wallet peer-to-peer (P2P) transactions, offshore VASPs operating outside regulatory oversight, and ongoing challenges in the DeFi sector. FATF calls on the public and private sectors to jointly strengthen the implementation of R.15, enhance risk mitigation capabilities, and deepen domestic, international, and public-private cooperation mechanisms.
according to Zilliqa's monitoring, it has learned of a security incident involving a CEX partner, where some ZIL has been stolen from a cold wallet. The incident is currently under investigation, and the team is working with relevant parties to determine the root cause and the scope of the impact. As a precautionary measure, Zilliqa has notified all CEX partners to temporarily suspend ZIL deposits and withdrawals to prevent the stolen funds from being transferred or sold through centralized platforms. The official stated that further updates will be released after verifying the information and reminded the community to only follow information published through official channels.
according to Hinkal monitoring, full refunds will be issued this week to users who have completed the recovery process, with completion expected by July 22. Users who have not yet completed the recovery can still submit applications. Previously, Hinkal suffered an attack resulting in a loss of approximately 797,000 USDC, which the attacker exchanged for about 454 ETH.
that, according to DeFi researcher @Zun2025 posted on X platform, "MetaMask hired a DPRK-linked hacker as a developer without even conducting a proper background check that could have revealed his identity.The hacker's GitHub username is imyugioh, and he has been publicly listed on the Lazarus Group website since September 2025, yet MetaMask still hired this individual in March 2026. Source: lazarus.group/team/mauro-liu. Imagine that one of the largest wallets granted core code repository access to someone already on a publicly known list of DPRK hackers. Now think about what might happen to those small protocols with absolutely no security teams."Earlier reports stated that a North Korean hacker, Tyler Knapp, infiltrated the MetaMask team. He entered MetaMask through a long-term cooperating human resources supplier via an outsourcing arrangement, bypassing the background checks of the company's direct recruitment process. He worked at the company for a month and participated in the development of the wallet's fiat on/off ramp functionality. During this period, his IP address and behavioral anomalies were detected by the company's security monitoring. The company immediately revoked all his access permissions and suspended the release of all products he had worked on. No substantial data or financial losses have been caused so far.
Odaily reports, according to monitoring by Onchain Lens, Allbridge Core has been exploited on Solana. The attacker borrowed $1.12 million USDC via a Kamino flash loan, then rapidly executed a USDC/USDT swap, distorting the stablecoin pool ratio of Allbridge. They withdrew liquidity at the manipulated exchange rate and repaid the flash loan within the same transaction, extracting approximately $1.1 million in funds. The funds were subsequently mixed through a privacy protocol. The maximum single withdrawal from Allbridge was $2.24 million USDC. Further analysis of the vulnerability exploit and the affected pools is ongoing.