News linked to this event type.
The LayerZero research team, in collaboration with Oblivious Labs and researchers from Carnegie Mellon University, has published a paper introducing OTTER, a novel automated market maker mechanism designed to enhance resilience against maximum extractable value (MEV). OTTER employs a batch clearing mechanism modeled after Vickrey-Clarke-Groves (VCG) auctions, making truthful reporting of valuations and budgets a dominant strategy for traders, while diminishing block builders' ability to profit from transaction ordering, sandwich attacks, or injecting false bids.
Odaily News, lawyer Ariel Givner stated that hardware wallet manufacturer Ledger is facing a class action lawsuit in New York. The complaint alleges that a security incident in December 2023 exposed customers' personally identifiable information such as names, email addresses, and phone numbers, and that the company failed to disclose the breach in a timely and complete manner. Hackers subsequently used the contact information to impersonate official representatives, tricking customers into approving fraudulent transactions and stealing crypto assets. The compromised information was also circulated on the dark web.
Malwarebytes researchers discovered a website disguised as a Grand Theft Auto VI (GTA 6) fan countdown page that lured users into purchasing the so-called leaked version of the game and loaded a wallet drainer program after users connected their cryptocurrency wallets. The malicious code checks wallet balances, identifies tokens and NFTs, and transfers assets once users approve transactions or grant authorizations.
Odaily News: According to monitoring by Galaxy's Head of Research, the COLDCARD Wave 3 attacker has moved stolen funds for the first time, exchanging them for ETH via the THORChain cross-chain DEX. This marks the first on-chain transfer of funds from the original hacker address across Waves 1, 2, or 3.
Federal law enforcement agencies of the U.S. Department of Justice, in collaboration with organizations including CrowdStrike, have successfully disrupted the long-running Sality botnet. The group used malware to alter users' clipboard addresses, stealing approximately $150,000 in cryptocurrency.
According to CoinDesk, US cybersecurity firm CrowdStrike has partnered with federal law enforcement agencies to successfully dismantle the Russian botnet Sality, which has been operating for over two decades. Over the past eight years, the network has continuously stolen cryptocurrency through clipboard hijacking; its core payload, "EggJagger," resides on infected machines, monitoring the user's clipboard. Once a Bitcoin or Ethereum wallet address is detected, it is replaced with the attacker's address, causing victims to unknowingly complete transfers. Sality employs a decentralized P2P architecture with no central server, checking node online status every 40 minutes, and self-propagates via network-shared drives and USB devices. By exploiting an authentication vulnerability, CrowdStrike replaced legitimate node addresses with those of its own servers, successfully severing the network connections of over 15,000 infected machines. The operation was demonstrated live at the Day Zero summit in Las Vegas. Estimates indicate that the attackers stole at least 12.1 million rubles (approximately $150,000) over the eight-year period. Undisturbed crypto assets appreciated alongside the broader market, reaching a value of roughly $1.35 million by early 2025. Security experts advise users to always verify the first and last characters after pasting a wallet address to defend against such attacks.
According to The Block, the Wyoming Stable Token Committee announced the adoption of Chainlink Proof of Reserve to provide near-real-time on-chain reserve validation for its official stablecoin, Frontier Stable Token (FRNT). The Network Firm will audit FRNT reserves in accordance with AICPA standards, while Chainlink will post verification data on-chain in real time to bridge information gaps between reporting cycles. Previously, Wyoming fully migrated FRNT from LayerZero to Chainlink CCIP last month as its sole cross-chain infrastructure. The committee is also advancing the Chainlink Proof of Reserve Secure Mint feature, which requires verifying that reserves do not fall below FRNT's total supply before minting new tokens to prevent infinite minting attacks. FRNT launched in January this year and is the United States' first government-issued stable token, backed by U.S. dollars and short-term U.S. Treasuries.
Odaily News: CrowdStrike, in coordination with the U.S. Department of Justice, announced the dismantling of the Sality peer-to-peer botnet, isolating over 15,000 infected devices worldwide. The network has been active since 2003, and over the past eight years has primarily deployed a clipboard hijacking tool known as EggJagger to steal funds from Bitcoin and ETH transfers. EggJagger monitors cryptocurrency wallet addresses copied by victims and replaces them with addresses controlled by the attackers, redirecting transfer funds to the attackers. CrowdStrike estimates that this tool alone has stolen at least $150,000 in crypto assets; since most of the funds were not moved, the value of the associated holdings rose to approximately $1.35 million in January 2025. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service have seized related domains within the U.S., while police in Bulgaria, Hungary, and Romania have also shut down infrastructure in Europe. Currently, infected devices have been redirected to traffic reception servers controlled by CrowdStrike, but the original malware on the devices remains active until manually removed.
According to a report by the Securities Times, at the 4th Cyberspace Security (Tianjin) Forum, Zhou Hongyi, founder of the 360 Group, delivered a keynote presentation, stating that AI has reshaped the cyber attack and defense landscape, rendering traditional solutions unsustainable. It is essential to build a new automated cyber defense and offense system centered on "governing models with models," leveraging AI capabilities to mitigate AI risks, ensure the inherent security of large models, the reliability of generated content, and the trustworthiness of output results; and to implement full lifecycle management of AI agents, establishing control mechanisms that are auditable, subject to intervention, and capable of being blocked.
Odaily News: According to Defimon monitoring, YAM Finance has suffered a governance takeover attack. The attacker self-delegated approximately 504,000 YAM tokens, accounting for about 3.3% of the total supply, slightly above the legal voting threshold, and subsequently submitted proposal #45 to YamGovernorAlpha. The proposal description is empty and only contains an operation to call the setPendingAdmin method of the YAM Timelock contract, redirecting permissions to the attacker's address. If the proposal passes and is executed, the attacker will become pendingAdmin and can then fully control the Timelock through acceptAdmin, thereby gaining administrative access to all YAM protocol contracts and the DAO treasury, involving a risk amount of approximately $337,000. As the YAM protocol is currently in a dormant state, Defimon Alerts reminds YAM holders to vote against this proposal before block height 25897343, with approximately 34 hours remaining until that block.
Odaily News: Blockchain project Core DAO has announced a coordinated emergency hard fork, caused by validators receiving CORE rewards exceeding the blockchain's originally scheduled issuance. Core DAO stated that the incident is under control, malicious validators can no longer continue to obtain excess rewards, and the upgrade will not roll back the network or revoke confirmed transactions.Core DAO previously stated that a small number of validators had accumulated rewards significantly higher than the protocol's set issuance, and that the incident only involved reward distribution, with user assets remaining secure. Coinbase, Bithumb, Coinone, Bitget, and LBank had restricted CORE deposits, withdrawals, or transfers.Core DAO has not yet disclosed the amount of excess CORE issued, the duration of the related activity, whether the extra tokens entered circulation, or the cause of the vulnerability, and stated that it will publish a technical post-mortem report. (Cointelegraph)
Odaily News: The Fogo mainnet has restarted and is operating normally. A total of 400 million FOGO tokens were stolen in this incident, of which 237 million have been recovered and permanently removed from the total supply. The team stated that they are cooperating with exchanges and law enforcement to continue recovering the remaining affected assets, and the investigation is still ongoing.
The Sui ecosystem DeFi protocol Full Sail stated that its protocol has been affected by the Switchboard oracle security incident and has decided to gradually wind down operations. Affected protocols include Virtue Money, which reported losses of approximately $455,000, with 45 users liquidated. Switchboard has issued a statement regarding the incident, but as of September 1, it has not provided the technical details requested by Full Sail, nor has it committed to compensation. Mysten Labs rejected Full Sail's request for financial support. Full Sail stated that all remaining liquidity from the protocols will be prioritized for distribution to users, with the team covering any shortfall to ensure community depositors receive priority compensation.
Clashes between the US and Iran erupted twice within three days, as Iran retaliated for the US strike. Trump warned that if Iran continues to counterattack, it will face a more intense assault, noting that a final strike is currently being prepared.
US-Iran military conflict escalates sharply as both sides exchange strikes on energy and military targets; a senior Federal Reserve governor warns of interest rate hikes, while Russia signals it will strike Ukrainian energy infrastructure.
Odaily News: Blockchain intelligence firm TRM Labs reports that 32 price manipulation attacks have been recorded in 2026, surpassing the total of any previous full year; 2025 saw 12 incidents throughout the year. Such attacks account for roughly one-eighth of hacker incidents, up from one-seventeenth in 2022.Attackers typically first inflate the price of low-liquidity tokens, then use them as collateral to borrow other assets from lending protocols. Subsequently, they cause the collateral price to plummet and abandon the collateral, potentially leading to bad debt in the lending pools.According to DeFiLlama data, the total value locked in crypto-collateralized lending protocols has grown by approximately 56% over the past two years, approaching $50 billion, with active loan volume nearing $29 billion. The sector currently hosts over 570 lending protocols.Recently, Tectonic suffered losses exceeding $70 million after the TONIC price was artificially inflated, with the attacker ultimately extracting approximately $6 million in assets after the Cronos chain was rolled back; Moonwell also previously incurred losses of around $8.7 million due to manipulation of the MAMO oracle price. (Bitcoin.com News)
The UK National Crime Agency announced the freezing of assets belonging to NFT platform Sorare, seizing approximately £1 million in funds. The case involves cryptocurrency fraud and money laundering using proceeds from the Binance hack.
US President Trump stated that the US military is striking Iranian targets near the Strait of Hormuz in response to Iran laying naval mines and firing eight missiles at bases in Jordan. He warned that if Iran retaliates, it will face even more intense and lethal follow-up strikes.
According to CoinDesk, several prominent figures in the cryptocurrency industry and CoinDesk employees received numerous unsolicited password reset emails via the X platform on Tuesday, with some users receiving up to 10 within a few hours. Crypto investor Nic Carter urged users to enable X's "password reset protection" feature as soon as possible. Currently, there is no evidence that the X system has been breached or that accounts were hijacked en masse, and X has not issued an official statement regarding the incident.
According to Cointelegraph, cybersecurity firm Morphisec has revealed that a counterfeit desktop application masquerading as Anthropic’s "Claude Opus 5 Free Desktop" is being leveraged to distribute the Windows malware RevStealer. The malicious program can exfiltrate data from over 50 cryptocurrency wallets, while simultaneously harvesting sensitive information including browser passwords, cookies, VPN configurations, message logs, and screenshots. RevStealer incorporates anti-detection measures, performing system environment checks on the target device prior to execution. If traces of debugging or virtualized environments are detected, it aborts its operation. Additionally, Russian cybersecurity company Kaspersky has disclosed OkoBot, a novel malware framework targeting crypto investors capable of harvesting wallet files, injecting malicious extensions, and capturing wallet application windows to siphon assets.