GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Garden Finance Hacked, Loss of Approximately $450,000 USDT

According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.

Arbitrum ecosystem protocol AFX cross-chain bridge attacked, approximately 24.15 million USDC lost

据 Blockaid 监测,Arbitrum 生态协议 AFX 于北京时间 7月 23日 5:30 遭攻击。此次攻击针对 AFX 运营的跨链桥,迄今已导致协议约 2415 万枚 USDC 被转移。Blockaid 称,正与 Arbitrum 团队协作响应事件,并协助相关协议控制被盗资金风险。

Cascade CLS Treasury Attacked, Resulting in $1.3 Million in User Fund Losses

Odaily Odaily News According to MAX monitoring, on July 16, the Cascade CLS treasury suspectedly experienced a security vulnerability, resulting in approximately $1.3 million in user fund losses. The platform has suspended all trading and withdrawals and has invited SEAL 911 and other third-party security teams to investigate and handle the incident. Cascade is a 24/7 multi-asset perpetual contract platform headquartered in New York, targeting the US market. It supports deposits via Arbitrum USDC or bank accounts and is currently still in an invitation-only private testing phase.

Ostium suffers oracle attack, losing 18 million USDC; approximately one-third of liquidity drained

Ostium, a decentralized perpetual exchange, suffered an oracle attack on Wednesday, resulting in losses of approximately 18 million USDC. The attacker submitted false price reports for future dates using compromised oracle signing keys, generating fictitious trading profits and receiving payouts from the Ostium liquidity vault. Ostium stated that it has identified the issue with the OLP vault, has suspended all trading, and the team is currently investigating. Deployed on Arbitrum, Ostium offers perpetual futures trading for real-world assets including stocks, commodities, forex markets, and indices. At the time of the attack, the total value locked (TVL) in the Ostium protocol was approximately $63 million. The attack drained nearly one-third of this liquidity. In the first five months of 2026, DeFi protocols have lost over $840 million to exploits, including $292 million from KelpDAO and $285 million from Drift Protocol.

DeBank user musti_akrep exploits Ostium vulnerability to profit 23.75 million USDC and exchange for 12,085 ETH

according to on-chain analyst Yujin's monitoring, half an hour ago, an address (0x321...bfd9) with the DeBank username musti_akrep profited 23.75 million USDC by exploiting a vulnerability on Perp DEX Ostium and withdrew it. The 23.75 million USDC was withdrawn to the Arbitrum chain and immediately exchanged for 12,085 ETH at a price of $1,965. Currently, these 12,085 ETH remain on the Arbitrum chain.

Ostium Attacked, Losses Approximately $18 Million

Blockaid stated that it detected a vault exploit incident involving Ostium on Arbitrum. The attacker fabricated false trading profits through registered PriceUpKeep Forwarders and authorized oracle reports with future timestamps, triggering a payout of approximately 18 million USDC from the vault.

Lumi Finance Suspected to Be Attacked, Current Losses Approximately $270,000

According to Blockaid monitoring, the Lumi Finance protocol on Arbitrum is under attack, and approximately $270,000 in funds have been transferred out so far.

Secret Network 因 AI 风险拟迁至 Arbitrum

Secret Network 团队提议将隐私区块链从 Cosmos 迁移至 Arbitrum,称 AI 使旧代码更易被攻击的安全风险及生态流动性下降是主要考量。

Radiant Capital Announces Shutdown, Unable to Recover from $50 Million Hack

According to The Block, the DeFi lending protocol Radiant Capital has announced it will officially cease operations. The protocol suffered a hack in October 2024, losing approximately $51 million; the attacker gained unauthorized access by deploying backdoor contracts on Arbitrum and BNB Chain. Earlier in 2024, the protocol had also been hit by a flash loan attack, resulting in a loss of roughly 1,900 ETH (approximately $4.5 million). After 18 months of recovery efforts, Radiant Capital stated that it has neither recovered a significant portion of the stolen funds nor secured new financing, declaring that “the DAO has no viable path forward.” The protocol will now enter a “maintenance mode”: its frontend and smart contracts remain accessible, allowing users to withdraw funds, repay loans, and manage positions. Any funds recovered in the future will be returned to affected users.

Aave: 116,500 rsETH Released During April 18 rsETH Incident; Asset Backing Fully Restored

Aave has published a post-mortem of the April 18 rsETH incident, stating that the rsETH LayerZero V2 cross-chain bridge of liquid staking protocol Kelp accepted a forged message during a cross-chain transfer from Unichain to Ethereum. This caused the adapter on the Ethereum side to release 116,500 rsETH without a corresponding burn on the Unichain side. Aave stated that the attack occurred on a third-party cross-chain bridge infrastructure. However, the attacker deposited the stolen rsETH into 8 Aave V3 positions, borrowing 82,650 WETH and 821 wstETH, which impacted the Aave market.Aave stated that the attacker's rsETH on Arbitrum has now been burned. The LayerZero OFT adapter has replenished 116,131.72 rsETH in 5 batches, and the asset backing for rsETH has been fully restored. The affected WETH and rsETH markets have returned to normal.

Stake DAO Responds to Security Incident: Do Not Interact with vsdCRV for Now

Stake DAO posted a response on platform X regarding the security incident, stating that its team has taken note of the incident and that users should not interact with vsdCRV for the time being.In addition, contracts related to Stake DAO on Arbitrum exhibited abnormal behavior, resulting in the minting of 5.4 trillion vsdCRV tokens. Security teams have classified this as a suspected infinite minting exploit.

PeckShield: StakeDAO’s vsdCRV infinite minting vulnerability exploited; attacker cashed out over $90,000

According to on-chain analyst PeckShield (@PeckShieldAlert), StakeDAO (@StakeDAOHQ) on the Arbitrum network was exploited via an infinite minting vulnerability. The attacker minted a total of 5.4 trillion vsdCRV tokens, then swapped a portion of them for 43.781 ETH (approximately $91,200) and bridged the funds cross-chain to the Ethereum address 0xeF3C...aa25.

StakeDAO deployer's private key leaked on Arbitrum, attacker mints approximately 5.45 trillion vsdCRV and exchanges for ETH

StakeDAO deployer's private key leaked on Arbitrum, attacker mints approximately 5.45 trillion vsdCRV and exchanges for ETH.

Chainalysis Tracks THORChain Attack Source: Proficient Money Laundering Skills, Cross-Chain Fund Transfer Weeks Before Attack

Odaily Chainalysis posted on X platform, stating that prior to the THORChain theft, wallets suspected to be linked to the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several consecutive weeks. As early as late April, the attacker-associated wallets deposited funds into Hyperliquid positions via Hyperliquid and the Monero privacy bridge. These funds were subsequently converted to USDC and transferred to Arbitrum, then bridged to Ethereum. Some of the ETH was then moved to THORChain to stake as RUNE for a newly joined node, which is believed to be the source of the attack.Subsequently, the attacker bridged a portion of the RUNE back to Ethereum and split it into four chains. One chain went directly to the attacker, passing through intermediate wallets before transferring 8 ETH to the wallet that would ultimately receive the stolen funds, just 43 minutes before the attack. The funds from the other three chains flowed in reverse. Between May 14 and 15, these wallets bridged the ETH back to Arbitrum again, deposited it into Hyperliquid, and transferred it into Monero via the same privacy bridge, with the final transaction occurring less than 5 hours before the attack commenced. As of Friday afternoon, the stolen funds remain untouched, but the attacker has demonstrated sophisticated cross-chain money laundering capabilities. The Hyperliquid to Monero path may be the next move.

A New York judge postponed the hearing on Aave’s application to unfreeze $71 million worth of ETH, requesting both parties to submit additional explanations.

According to Cointelegraph, a New York judge has postponed the hearing on Aave’s emergency motion to unfreeze approximately $71 million worth of ETH and ordered Aave and Gerstein Harrow LLP to submit additional case briefs. A new hearing is scheduled for June 5. The court noted that Aave previously failed to adequately explain why users’ funds would suffer “derivative losses” if the restraining order remained in effect. The assets in question are linked to the Kelp DAO hack, which involved approximately $293 million and was previously frozen by Arbitrum. The judge also directed both parties to further clarify several legal issues, including the applicable law governing the hacker’s transactions, the legal distinction between fraud and theft, the priority ranking of creditors’ claims, the applicability of constructive trust, and whether assets can be proportionally returned to victims.

Aave: First Phase of rsETH Technical Recovery Plan Completed, Including Burning Attacker's rsETH on Arbitrum

Aave posted on X, stating that the first phase of the rsETH technical recovery plan has been completed, including the burning of the attacker's rsETH on Arbitrum.In the coming days, funds will be gradually replenished for the LayerZero OFT adapter, and rsETH-related operations will be restored.

US Judge Approves Aave to Proceed with Transfer of $71 Million in ETH Linked to North Korean Hackers

Odaily News: Margaret Garnett, a U.S. District Judge in Manhattan, has approved Aave's asset recovery proposal, allowing the transfer of approximately $71 million in ETH previously frozen on Arbitrum and linked to North Korean-linked attacks, to a wallet controlled by Aave LLC, while preserving the legal claims of terrorism victim plaintiffs over the funds. The ruling also amended the earlier freeze notice against the Arbitrum DAO, permitting the transfer to be executed through an on-chain governance vote and exempting those who propose, vote on, or participate in the transfer from liability under the freeze order. The transfer is still subject to an official vote by Arbitrum's on-chain governance. (CoinDesk)

Aave: rsETH Recovery Plan Clears Hacker Positions and Approves Transfer of $71 Million in ETH

Odaily Odaily: Aave posted on the X platform stating that the second phase of the technical solution for the rsETH incident recovery has progressed. On May 6, eight positions of the hacker on Aave V3 were liquidated, and the recovered rsETH collateral has been transferred to the recovery guardian. The Arbitrum DAO has passed a proposal to return the previously recovered $71 million in ETH.Regarding the application for asset freezing filed by the plaintiff, the judge has approved Aave LLC's proposal, allowing the transfer of the $71 million in ETH to Aave LLC through an on-chain vote by the Arbitrum DAO. Subsequent plans include burning rsETH on Arbitrum and restoring the rsETH reserve. After the reserve is restored, withdrawals will be reopened, and the WETH Loan-to-Value (LTV) ratio on the Aave V3 Ethereum mainnet will be restored.

The Arbitrum DAO voted to release $70 million worth of ETH, but a court order has temporarily frozen the transfer.

According to The Block, the Arbitrum DAO voted to release 30,765.6 ETH (approximately $70 million), previously frozen, to support the DeFi United initiative—aimed at offsetting Kelp DAO’s $292 million exploit loss last month. The vote passed with 90.96% support (182.2 million votes). The attack was allegedly carried out by the North Korean Lazarus hacking group, which exploited a vulnerability in LayerZero’s OFT cross-chain bridge—a single-validator configuration—which allowed attackers to steal 116,500 rsETH and pledge most of the stolen assets as collateral on Aave, resulting in roughly $190 million in bad debt. DeFi United has secured contributions from multiple parties, including 30,000 ETH from Consensys and Joseph Lubin, a 30,000-ETH loan from Mantle, and 5,000 ETH from LayerZero.

Aave has completed the liquidation of the rsETH attacker’s positions, and the related assets have been transferred to the Recovery Guardian address.

Aave stated that, per the previously disclosed technical recovery plan, the attacker’s rsETH positions on Ethereum and Arbitrum have been liquidated on Aave, and the associated collateral assets have now been transferred to the Recovery Guardian address designated by the AIP. Aave noted that this action did not impact other users, nor did it affect the Umbrella mechanism, and emphasized that this step is a critical milestone in the overall recovery roadmap, with further recovery efforts continuing as planned.