News linked to this event type.
Odaily reports, according to Onchain Lens monitoring, the ResolvLabs attacker has moved funds again after stealing approximately $25.9 million in March. Over the past few hours, 580 ETH, worth about $1.09 million, has been transferred and is being routed through a mixer.
security firm Project Eleven has introduced a post-quantum proof technology designed to help users prove ownership of their Bitcoin wallets after quantum computers become capable of deriving private keys and generating valid signatures. Project Eleven CEO Alex Pruden stated that the technology utilizes the wallet's key derivation path, enabling users to prove control without disclosing the parent key, thus distinguishing legitimate owners from attackers. The solution was developed in collaboration with Jim Posen, a primary maintainer of the open-source Binius zero-knowledge proof system, and is based on the "signature lifting" technique proposed by Alon Sattath and Robert Wyborski. Project Eleven noted that the prototype has not yet been audited and requires blockchain protocol support before it can be deployed. It is primarily aimed at users who miss the window to migrate to quantum-resistant addresses in the future.
: X platform product lead Nikita Bier announced that the platform is upgrading the anti-cheat mechanism of its Creator Revenue Share Program, targeting engagement baiting and content plagiarism.Bier stated that if an account posts "engagement baiting" content multiple times—such as "reply to me and I'll follow everyone" or similar actions to solicit engagement—cumulatively three times or more, it will be removed from the creator revenue share program and referred to the policy team for further action, including the risk of account suspension. Currently, X has identified such behaviors through the Grok AI system, and nearly 4,000 accounts have been removed from the revenue program today.Additionally, X's updated content identification model can detect duplicate content three times more efficiently than before. The platform stated that merely adding watermarks, intros, or making simple modifications will not qualify for revenue. The related commercial display revenue will be returned to the original content poster. This mechanism also applies to copying popular text posts, such as high-engagement content like "Twitter is the smoking area of the internet."According to Nikita Bier, during this detection cycle, X found approximately 1.5 million instances of stolen content. For accounts that repeatedly or deliberately attempt to evade detection, the platform will revoke their creator revenue eligibility.X stated that through these governance measures, it is expected that over $1 million in revenue will be redistributed to original content creators, aiming to improve the quality of the platform's content ecosystem.
Odaily Odaily A new study by the Cambridge Centre for Alternative Finance reveals that approximately 31% of Ethereum node activity is located in the United States, with another 39% distributed across EU countries excluding the UK, indicating that the geographic distribution of Ethereum nodes remains relatively concentrated in Western nations.Lead researcher Alexander Neumuller stated that while node distribution is not currently concentrated in any single country, it is heavily reliant on a few major cloud service providers, including Hetzner, Amazon AWS, and OVH. Notably, the Ethereum network does not require half of its validators to fail for problems to arise. If more than one-third of validators go offline simultaneously, the network may be unable to finalize block checkpoints (finalization). Neumuller pointed out that nodes and validators do not have a one-to-one correspondence; a single node may run multiple validators. Therefore, it is currently impossible to precisely assess the actual impact on the validator network from the failure of a specific node or service provider.Furthermore, the study reassessed the energy consumption of Ethereum following The Merge. Data shows that Ethereum's current annual energy consumption is approximately 7.9 GWh, equivalent to a continuous power draw of about 1 MW. This represents only about 0.02% of pre-merge levels, a reduction of approximately 99.98%. Currently, over 56% of the energy used by the Ethereum network comes from sustainable sources, exceeding the global average.The study also noted that client software diversity is another potential risk. If a dominant client software has a vulnerability, it could affect a large number of network participants. The report was published by the Cambridge Centre for Alternative Finance and supported by the Ethereum Foundation. (The)
Bank of America CEO Brian Moynihan has joined a group of Wall Street leaders in expressing serious concerns about artificial intelligence models such as "Mythos" developed by Anthropic. "This marks a significant shift in workload, as well as the speed at which these tools can impact system vulnerabilities, and how quickly we must respond," Moynihan stated. In recent months, the rapid evolution of AI models has prompted the financial industry and the U.S. government to begin assessing potential threats.Anthropic claims that the Mythos model, launched earlier this year, has demonstrated excellent performance in identifying system vulnerabilities. Bank of America is among the Wall Street institutions authorized to use Mythos, employing the model to test its own systems and share information with peers. Currently, the model has not been made available to the public; JPMorgan Chase CEO Jamie Dimon warned earlier this week that broadly opening the system to the public would be as dangerous as "giving a ballistic missile to an individual." (Bloomberg)
PPP Prediction Market Tool monitoring shows that Polymarket has launched a market for "When will the US and Iran achieve a two-week ceasefire." Currently, the probability for July 18 stands at 5%; for July 24, it is 15%; for July 31, it is 23%; for August 14, it is 43%; and for August 31, it is 54%.The settlement rules for this event are as follows: If the US takes no military action against Iran between the market creation and 11:59 PM on the specified end date, this market will be settled as "Yes." Otherwise, the market will be settled as "No." The first day of this 14-day period will be the calendar date (Eastern Time) of the most recent qualifying military action that occurs. This period lasts until 12:00 PM Eastern Time on the 14th day. If the most recent qualifying military action during this period occurs on or before the specified end date, the market will be considered "Yes."So-called "qualifying military actions" refer to airstrikes or surface-to-surface missile strikes initiated by the US directly targeting Iran. Airstrikes may include the use of bombs, air-to-surface missiles, and aerial drones launched from the air. Surface-to-surface missile strikes include one-way attack drones and surface-to-surface missiles such as cruise missiles or ballistic missiles.Qualifying military actions include: munitions that are destroyed or intercepted before impact; surface-to-air missile strikes; small arms fire; ground invasions; cyber operations; naval gunfire and artillery; howitzer, cannon, mortar, and rocket artillery (e.g., Multiple Launch Rocket Systems); small-scale surface-to-surface strikes, including short-range cruise missiles, close-air support drones, and anti-tank missile attacks; any threats, authorizations, or declarations of force that have not yet been acted upon.Join the PPP Signal Push Community to stay ahead and seize the opportunity.
Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.
Odaily Odaily News According to MAX monitoring, on July 16, the Cascade CLS treasury suspectedly experienced a security vulnerability, resulting in approximately $1.3 million in user fund losses. The platform has suspended all trading and withdrawals and has invited SEAL 911 and other third-party security teams to investigate and handle the incident. Cascade is a 24/7 multi-asset perpetual contract platform headquartered in New York, targeting the US market. It supports deposits via Arbitrum USDC or bank accounts and is currently still in an invitation-only private testing phase.
According to Korean media EToday, the Korea Financial Services Commission announced that it has approved the 2026 Recovery and Resolution Plans for a total of 10 financial institutions, including the five major financial groups Shinhan, KB, Hana, Woori, and Nonghyup, along with their main banks, and has formally incorporated cyber attacks and "digital bank run" risks into the crisis management system for large financial institutions. The Korea Financial Services Commission added that as the scale of online financial transactions expands, funds may flow out rapidly within a short period. It will further improve digital bank run monitoring indicators to identify liquidity risks earlier. At the same time, it requires financial institutions to strengthen cyber security incident response mechanisms and consider scenarios in crisis contingency plans where multiple institutions simultaneously sell off assets and compete for liquidity under market shocks.
Robinhood Chain launchpad Pons has officially responded to earlier reports about a token authorization vulnerability in its front end, stating that the Pons launchpad trading page does not have any Multicall3 functionality. The Multicall3 feature mentioned in the tweet originated from the previous Debank Chain old version bridge and was released before the Pons launchpad, thus it does not affect launchpad users. It is currently confirmed that only 0.60 NOXA tokens, valued at approximately $0.66, are affected.As a security precaution, Pons recommends that users who previously used the old version bridge revoke token authorizations via revoke.cash. The team is currently working with audit firms to investigate potential risks and has stated that Pons' front-end services will be restored after confirming the absence of any actual vulnerabilities.
According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), the public OLP vault of decentralized perpetual contract protocol Ostium (@Ostium) was attacked, with approximately 24 million USDC stolen. The attacker subsequently swapped the stolen funds for 12,080 ETH and has transferred 10,540 ETH into the mixer Tornado Cash to obscure the fund flow. On-chain tracing shows that the attacker's initial funds originated from ChangeNow and Bybit, with 1 ETH transferred from each to the attacker's wallet (0x321D...8bfD9).
Decentralized trading protocol Ostium paused trading due to suspected exploitation of its oracle system, with security firms Blockaid and CertiK estimating losses between $18 million and $22 million.
Ostium, a decentralized perpetual exchange, suffered an oracle attack on Wednesday, resulting in losses of approximately 18 million USDC. The attacker submitted false price reports for future dates using compromised oracle signing keys, generating fictitious trading profits and receiving payouts from the Ostium liquidity vault. Ostium stated that it has identified the issue with the OLP vault, has suspended all trading, and the team is currently investigating. Deployed on Arbitrum, Ostium offers perpetual futures trading for real-world assets including stocks, commodities, forex markets, and indices. At the time of the attack, the total value locked (TVL) in the Ostium protocol was approximately $63 million. The attack drained nearly one-third of this liquidity. In the first five months of 2026, DeFi protocols have lost over $840 million to exploits, including $292 million from KelpDAO and $285 million from Drift Protocol.
according to on-chain analyst Yujin's monitoring, half an hour ago, an address (0x321...bfd9) with the DeBank username musti_akrep profited 23.75 million USDC by exploiting a vulnerability on Perp DEX Ostium and withdrew it. The 23.75 million USDC was withdrawn to the Arbitrum chain and immediately exchanged for 12,085 ETH at a price of $1,965. Currently, these 12,085 ETH remain on the Arbitrum chain.
Summer.fi announced that following the attack on the Lazy Summer protocol on July 6, the team assessed that there was no viable path to continue business operations, and therefore will gradually cease operations.
Blockaid stated that it detected a vault exploit incident involving Ostium on Arbitrum. The attacker fabricated false trading profits through registered PriceUpKeep Forwarders and authorized oracle reports with future timestamps, triggering a payout of approximately 18 million USDC from the vault.
Musk said X will open source its entire codebase without exception once the security vulnerability review is completed. Additionally, X will invite third-party auditors to verify the actual running system to confirm it is consistent with the public source code.
According to PeckShield monitoring, the previously detected unusual fund activity in the LayerZero Executor wallet was not an attack incident, but part of normal operational adjustments. User funds are not at risk.
according to on-chain detective Specter's monitoring, the LayerZero_Core Executor wallet may have been compromised, resulting in a total multi-chain loss of $2.1 million. The attacker bridged the stolen funds to Ethereum via Stargate and Relay, and is currently holding 955 ETH (worth $1.78 million) and 322,000 USDC. CyversAlerts first identified this suspicious activity.
According to BlockSec monitoring, the BarnBridge SMART Yield cUSDC protocol was attacked on Ethereum, resulting in losses of approximately $776,000, suspected to be a governance attack. The attacker first gained DAO governance rights, then upgraded the SmartYield/controller proxy to a malicious implementation contract. This contract called the _takeUnderlying privileged function of CompoundProvider, utilizing pre-existing USDC approvals from 50 user accounts, and via transferFees, moved the aggregated funds to the attacker.