News linked to both this project and an event.
Odaily讯 According to Cyvers Alert monitoring, an Address Poisoning attack incident has been detected, resulting in the victim losing approximately $100,000 in USDT. The attacker carried out the "address poisoning" against the victim's wallet about 66 days ago by sending a transaction to create a malicious address record resembling an address the victim normally interacts with. Today, the victim failed to verify the full wallet address and mistakenly transferred funds to the attacker's address.Following the incident, in order to avoid potential freezing risks, the attacker has converted the stolen USDT into ETH, and the wallet currently holds approximately 52.8 ETH.Cyvers reminds users to always fully verify wallet addresses when making on-chain transfers, and to avoid relying solely on address records from transaction history. Meanwhile, security agencies recommend adopting AI-based on-chain security tools for real-time detection of abnormal transaction behavior, in order to reduce risks such as address poisoning and phishing attacks. Address poisoning attacks have become one of the common fraud methods in the crypto asset space in recent years. Attackers typically exploit users' habit of copying addresses from historical transactions by forging similar-looking addresses to trick users into transferring assets mistakenly.
Odaily News: The North Korean regime stole at least $2.8 billion in crypto assets between January 2024 and September 2025, increasingly laundering them through established criminal networks. According to a report by the Royal United Services Institute (RUSI), a UK-based defense and security think tank, the funds are believed to support its weapons programs. Stolen tokens frequently change ownership before being converted into cash, with third parties sometimes purchasing them at a discount or mixing them with proceeds from investment scams such as "pig butchering" schemes. Cashing out primarily relies on "money mules" recruited in the Philippines, Indonesia, and China, where stablecoins are typically split up and sold through peer-to-peer markets. After the Bybit hack, ZeroShadow found that TraderTraitor moved funds through over-the-counter (OTC) desks, peer-to-peer traders, and Chinese organized crime syndicates. Bybit has recovered $48.4 million and frozen $30.5 million in assets, accounting for roughly 5% of the stolen amount in total. (Decrypt)
Odaily News: Hardware wallet Coldcard has suffered a hack, with no confirmed total loss amount yet. Blockchain analytics platform CryptoQuant has confirmed losses of 1,432 BTC, while Galaxy Research places a high-confidence minimum estimate at 1,730 BTC. Other analyses suggest the scale of losses could be even higher. Research firm Galaxy Research stated that its earlier estimate of 1,816 BTC represents a potential figure, not a confirmed total. As of Tuesday, the firm's confirmed high-confidence minimum loss stands at 1,730 BTC, with over 450 BTC directly confirmed based on victim reports. Blockchain intelligence firm TRM Labs estimates that the attacker moved approximately 1,816 BTC from more than 5,200 addresses in four phases. CryptoQuant stated that its confirmed figures only include addresses publicly disclosed by victims and verified through on-chain patterns, meaning the tally could rise as more victims come forward with information. (Cointelegraph)
Odaily News: On-chain detective ZachXBT has disclosed that a threat actor codenamed "Tiffany" is suspected of involvement in multiple crypto asset thefts, using stolen funds from victims for gambling on crypto casinos, and even making calls to taunt the victims. The platform Shuffle has frozen related accounts based on evidence submitted by ZachXBT. Tiffany previously shared a Connecticut search and seizure warrant, with a document date earlier than some of the incidents involved in this case. ZachXBT has obtained chat logs, recordings, and on-chain evidence, and predicts that this individual may face further legal consequences. The threat actor is also linked to the case of John Daghita (Lick), who is suspected of stealing over $46 million in crypto assets from a wallet seized by the U.S. government.
Odaily News: DefiLlama data shows that hackers stole $247 million in crypto assets in July, making it the second-highest month since 2026, trailing only April's $644 million; this figure represents a significant increase from June's $75 million and May's $60 million. Galaxy Digital stated that the Coldcard vulnerability was the largest attack event of the month, confirming three rounds of attacks involving 7,300 wallets, with at least $100 million in Bitcoin stolen; the firm also identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million. DefiLlama's hack tracker estimates losses related to this vulnerability at $115 million. Other attacks in July include a $9 million exploit on decentralized finance protocol Bonzo Lend, a $2.6 million theft from Cardano-based wallet SecondFi, a $24 million theft from Arbitrum-based perpetual trading platform AFX, and a $7.5 million theft from the Verus Ethereum Bridge.
Mersinger pointed out that the bill explicitly prohibits the portion of stablecoin holding rewards equivalent to bank deposit interest, but allows reward mechanisms based on user activity, consistent with the credit card points model; regarding DeFi regulation, Section 10301 of the bill requires the SEC to establish rules for protocols that are "nominally decentralized, substantially controllable," rather than exempting them, while Section 10201 has incorporated digital commodity brokers into the full reporting obligations under the "Bank Secrecy Act" and allocated $3 billion to support state-level enforcement, contrary to the "Wall Street Journal"'s claim of "inadequate regulation of illicit finance."
According to CoinDesk, the S&P 500 index has risen 3.12% this month, adding approximately $2.1 trillion in market value (equivalent to the total market cap of the entire crypto market), reaching a record high total market cap of $70.5 trillion, but Bitcoin has only risen about 2% this month, hovering near $64,600. Analysts point out that this round of stock market rise is mainly driven by AI and semiconductor individual stock narratives, rather than a broad-based recovery in risk appetite at the macro level, and Bitcoin lacks direct beneficial exposure to this. Meanwhile, the crypto market also faces multiple internal pressures: the Coldcard platform suffered a $120 million exploit, the prospects of the "Clarity Act" remain uncertain, MicroStrategy has reduced its BTC holdings for three consecutive months, and stablecoin supply continues to shrink—USDT's market cap dropped from $190 billion in April to $183 billion, and USDC's dropped from $79.5 billion to $72 billion.
Galaxy Digital Head of Research Alex Thorn stated that based on new victim reports received following the incident, the number of attackers exploiting the Coldcard vulnerability has reached at least 15.Thorn noted that information provided by victims helped the research team uncover previously unidentified attack activity. Unlike thefts from centralized exchanges, correlations between the attackers in this vulnerability exploit require confirmation through on-chain analysis and victim feedback.He added that a single victim reporting less than 1 BTC stolen helped the team discover a previously unknown attack, which siphoned approximately 12 BTC from 126 addresses.According to Galaxy Research's earlier estimates, the Coldcard vulnerability has led to at least three rounds of attacks, with losses amounting to approximately $100 million in BTC. Additionally, Galaxy has identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million.Meanwhile, the incident has also sparked discussions regarding the security of Bitcoin self-custody. Dragonfly Managing Partner Haseeb Qureshi stated that "AI security hardening costing around $2" could potentially have prevented this vulnerability, and noted that some AI models were able to rediscover related vulnerabilities within a relatively short timeframe. However, industry insiders pointed out that current claims about the speed of AI discovering vulnerabilities lack rigorous blind testing and verification.Researchers believe that as AI model capabilities improve, the costs of vulnerability discovery and attacks in the crypto industry may continue to decline, requiring wallet developers to further strengthen code audits and security protections. (Cointelegraph)
According to TechCrunch, Apple Inc. has formally applied for a preliminary injunction against OpenAI, requiring it to stop developing AI devices and related products based on Apple technology. Apple's latest investigation shows that, in addition to Senior Systems Engineer Chang Liu and Chief Hardware Officer Tang Yew Tan named in the previous complaint, another 11 former Apple employees may be involved in trade secret theft, with some having privately retained work equipment issued by Apple upon departure. Apple has simultaneously applied for an expedited discovery process, involving parties including OpenAI, its foundation, and the device startup io co-founded by Jony Ive. In response, OpenAI publicly stated that Apple's allegations are "based on misinformation and completely unnecessary," and counterclaimed that Apple has security procedure vulnerabilities, resulting in former employees still being able to access its internal systems.
Odaily News: Apple has limited the number of vulnerability reports a single researcher can submit at one time because its security team has received a large number of submissions generated by AI, many of which do not actually contain real flaws. Apple stated that researchers can request a higher limit at any time, and the company is also using AI internally to triage submissions.Bynario, a Milan-based cybersecurity startup, said it used OpenAI's ChatGPT to discover more than 50 vulnerabilities in the latest version of macOS within three weeks, including a privilege escalation chain that could give attackers full control of a Mac device.Bynario stated that it was unable to report this vulnerability because Apple had already rejected further submissions. Bynario CEO Alfredo Pesoli estimated the vulnerability's value on the criminal market at $100,000 to $200,000. Apple said it has reached out to the company and reviewed its work. In June, Apple added a submission cap and a 30-day cooldown period to its security portal. In a recent security update, Apple listed vulnerabilities discovered with the assistance of Anthropic and OpenAI software, with the number of fixes approximately five times that of a normal cycle. (Decrypt)
According to Onchain Lens monitoring, COLDCARD users have experienced another incident of stolen funds, with over 5,200 affected addresses seeing approximately 1,816 BTC stolen, worth around $114 million. The confirmed first to third waves involve 1,367.05 BTC, valued at approximately $88.6 million. The fourth wave, matching a pattern, involves 462 potential victims, adding 388.93 BTC. Onchain Lens is currently identifying associated clusters based on on-chain data. As of now, the attacker has not yet moved the stolen funds. The cluster remains active, with the latest transaction recorded just minutes ago.
Odaily News: Bitcoin wallet service provider Nunchuk has issued an important update regarding the recent Coldcard security incident, recommending that users with multisig wallets containing Coldcard-generated keys migrate their funds as soon as possible.Nunchuk has categorized response levels based on the number of affected Coldcard keys in a multisig wallet: if the number of Coldcard-generated keys has reached the signing threshold, attackers could theoretically transfer funds directly, and such users should migrate immediately; if the wallet contains only 1 Coldcard-generated key and it is below the signing threshold, a single compromised key cannot move funds independently, making the risk relatively lower, but migration is still strongly recommended. If users cannot confirm the exact number of Coldcard keys in their wallet, they should treat it as a high-risk situation.Additionally, Nunchuk announced that an upcoming mobile update will automatically enable the Slipstream channel for paid users. At that point, any auxiliary multisig wallet transaction containing at least one Coldcard key will bypass the public mempool and be submitted via Slipstream, reducing the risk of transaction monitoring and replacement. For users who wish to act immediately or for free-tier users, Nunchuk offers a manual migration option: users need to create a migration transaction, complete multisig signing without broadcasting, and then submit the raw transaction data to the Slipstream platform.
Odaily News: Galaxy Research Head Alex Thorn analyzed that a new wave of Bitcoin sweeping attacks targeting Coldcard wallet addresses is underway, and cumulative losses from vulnerabilities related to Coldcard hardware wallets could approach $114 million. This attack primarily affects single-signature wallets, with no multi-signature wallets found to be impacted so far. No direct victim reports have been received yet; the assessment is mainly based on on-chain transaction pattern analysis, with some attack transactions still in an unconfirmed state.
Odaily News — According to official sources, OKX.AI has announced that registration for its inaugural trading hackathon is now open. Following the previous Genesis hackathon for Agent Service Providers (ASP), this hackathon focuses on AI Agent live trading capabilities. Participants are required to deploy their trading strategies as Trading ASPs and conduct live trading with no less than 300 USDT in equivalent funds. Rankings will be updated in real time based on yield (PnL %). The total prize pool is $20,000, with the champion receiving a $5,000 reward.It is reported that OKX.AI is an economic system built specifically for Agents, where users and Agents can discover and utilize professional services provided by ASPs. This event supports two development frameworks: Onchain OS and Agent Trade Kit. Registration runs from July 31 to August 11 at 12:00 (UTC+8), and the competition will take place from August 11 to August 25.
Odaily News, OpenAI recently disclosed that it has successfully disrupted a cyber fraud organization based in Cambodia that used ChatGPT to assist in investment scams, romance scams, gambling fraud, and impersonation of law enforcement agencies. The investigation originated from leads shared with WhatsApp's security team. The organization was found to have used ChatGPT to create fake online identities, generate and translate scam scripts, produce promotional content for fraudulent schemes, and assist with daily operational tasks.OpenAI stated that it has banned ChatGPT accounts associated with the operation, shared relevant threat indicators with industry partners and concerned institutions, and taken measures to prevent these attackers from regaining access to its services. The specific financial losses caused by this fraud network have yet to be confirmed, but according to communications among the scammers themselves, the organization may have reached hundreds of victims, with some conversations mentioning victims losing thousands of dollars.
According to monitoring by on-chain analysis firm Galaxy Research (@glxyresearch), the ColdCard wallet hacking incident has developed into a third wave, with an additional 207.73 BTC stolen. Currently, the three waves of attacks have cumulatively stolen 1,367.05 BTC (approximately $88.6 million), involving 4,585 addresses. On-chain data shows that the three waves of attacks exhibit highly similar characteristics: identical fund consolidation topology, identical P2WPKH target addresses, and mixed derivation paths. Each wave occurred approximately 27 hours apart, suggesting they were carried out by the same attacker, but there is currently no direct evidence to confirm this. Currently, all terminal addresses controlled by the hackers hold a total of 1,366.39 BTC (approximately $88.6 million), all of which are in an unspent state on-chain. Galaxy Research noted that the above data is based solely on Bitcoin block data and UTXO set analysis, and has not yet computationally verified whether the victim addresses have vulnerabilities due to low-entropy generation.
Odaily News, according to Bitcoin News monitoring, Nunchuk stated that some Nunchuk platform keys are generated by Coldcard Mk4, but these keys will not be used directly. Nunchuk derives independent keys through custom logic, making them less susceptible to lookup table attacks based on compromised Coldcard seeds. Nunchuk added that, given enough time, it believes attackers may eventually incorporate these derived keys as well.
The PPP Prediction Market Tool shows that the probability of a "ceasefire between the US and Iran before July 24" on Polymarket has dropped to 36%, down 15% in 24 hours.This event will settle as "Yes" if the US does not take any military actions that meet the defined criteria against Iran for 14 consecutive days before the specified deadline; otherwise, it will settle as "No."Qualifying military actions include only US-initiated airstrikes or surface-to-surface missile attacks that directly strike Iranian territory, including bombs, air-to-surface missiles, air-launched drones, cruise missiles, and ballistic missiles. Excluded actions include intercepted or destroyed munitions, surface-to-air missiles, small-scale skirmishes, ground operations, cyberattacks, naval shelling, artillery attacks, and unexecuted threats or authorized actions.If there is a dispute regarding the occurrence, attribution, or timing of relevant military actions, the event will await consensus from official information and credible media before being adjudicated. If disagreements persist after three full calendar days, a comprehensive judgment will be made based on all available information at that time. The settlement basis includes official information from the US and Iranian governments and militaries, as well as reports from credible media outlets.Join the PPP Signal Push Community to stay ahead and seize the opportunity.
The PPP Prediction Market Tool monitoring shows that the probability of "effective ceasefire between the US and Iran before July 31" on Polymarket has risen to 59%, up 19% in a single day.This event will settle as "Yes" if the US takes no qualifying military action against Iran for 14 consecutive days before the specified deadline; otherwise, it will settle as "No."Qualifying military actions include only US-initiated airstrikes or surface-to-surface missile attacks that directly strike Iranian territory, including bombs, air-to-surface missiles, air-launched drones, cruise missiles, and ballistic missiles.Actions not counted include intercepted or destroyed munitions, surface-to-air missiles, small-scale skirmishes, ground operations, cyber attacks, naval shelling, artillery attacks, and unexecuted threats or authorized actions.If there is a dispute regarding the occurrence, attribution, or timing of a military action, the event will await a consensus formed by official information and credible media before being adjudicated. If differences persist after three full calendar days, a comprehensive judgment will be made based on all available information at that time.Settlement will be based on official information from the US and Iranian governments and military, as well as credible media reports.Join the PPP Signal Push Community to stay ahead and seize the opportunity.
the WEMIX team has issued an announcement stating it is urgently investigating a potential security incident involving the WEMIX 3.0 network. Signs have been detected suggesting that contract ownership may have been compromised. The relevant team is currently verifying the facts and assessing the impact of the incident, and will release the investigation results and subsequent response measures as soon as possible based on the progress of the investigation. Until further official updates are released, WEMIX reminds users to exercise caution regarding unverified information and to maintain a high level of vigilance when transacting or investing in related assets.