News linked to both this project and an event.
the U.S. Department of Commerce's AI Standards and Innovation Center, in collaboration with the UK AI Safety Institute, tested the cyber attack capabilities of Kimi K3, emphasizing that "the United States still leads."However, the value of the evaluation is debated due to limitations in the testing scope. Due to hosting environment constraints, Kimi K3 only participated in partial testing, with its overall cyber capabilities estimated primarily based on 41 exploit benchmarks. In contrast, other models underwent more comprehensive testing, resulting in a larger margin of error for Kimi K3's results.In the exploit testing, Kimi K3 scored approximately 32%, higher than GLM-5.2's 24%, but lower than the average of approximately 76% for leading U.S. models. In a simulated attack chain test, Kimi K3 completed an average of 17 out of 32 steps in the attack chain and successfully breached the network once in 10 attempts, while U.S. frontier models completed an average of 28.5 steps.The report notes that Kimi K3 already possesses a certain level of autonomous attack capability, and its security guardrails did not prevent the model from developing exploits or executing attacks. However, the report also emphasizes that the testing scope was limited.
: BNB Chain Agent commercial clearing layer TermiX announced that Web3 security infrastructure GoPlus and smart contract security auditing firm Salus have officially become Provider Agents on the Agent.family platform. They have launched two production-grade security audit services, promoting the autonomous invocation and settlement of "security capability as a service" for AI Agents in on-chain commercial scenarios.GoPlus has packaged its verified token contract deep scanning capability as a standard Provider Agent service. DeepScan conducts comprehensive security checks on token contracts, identifying risk patterns such as Rug Pulls, honeypot scams, contract permission abuse, and trading restrictions, and generates structured audit reports.Salus has launched smart contract auditing and penetration testing services, encompassing formal verification, fuzz testing, machine learning-based vulnerability detection, and manual expert auditing. It covers high-risk vulnerability categories such as reentrancy attacks, access control issues, integer overflows, and DoS attacks. Salus, a seed-stage investment from Binance Labs, is a core security partner within the BNB Chain ecosystem.
Cardano ecosystem wallet SecondFi announced that due to a cryptographic defect in its wallet software, approximately 16.1 million ADA (worth around $2.6 million) were stolen. The platform will gradually shut down the SecondFi and Yoroi wallet services. This incident has affected 374 wallets. SecondFi stated that an independent investigation by blockchain intelligence agency Groom Lake identified the attackers as a sophisticated external actor and found indicators potentially linked to North Korea's Lazarus Group, though attribution has not yet been confirmed. SecondFi is developing a recovery tool based on zero-knowledge proofs to help affected users recover assets while limiting the information that needs to be shared. The tool is still being tested and will undergo third-party audits before its planned release in August. SecondFi is also preparing a wallet export feature to allow users to migrate their assets to other services. The platform has not announced a direct compensation plan, nor has it indicated whether it will use its own funds to compensate users.
the cross-chain protocol Allbridge has issued an official statement confirming that an attacker has withdrawn approximately $1.65 million in assets from the Allbridge Core liquidity pool. A detailed analysis of the incident is currently being compiled, and the full investigation results will be published subsequently. The team emphasizes that there is no further risk to current user liquidity and that the Allbridge Next service is operating normally.In response to this incident, Allbridge plans to relaunch the Core version but will remove the liquidity pool design. Future cross-chain transfers will be facilitated via Circle CCTP and the LayerZero router to eliminate the risk of liquidity pool imbalance and the model vulnerabilities exploited in this attack. This incident has accelerated the previously initiated migration plan to fully transition to the more secure new infrastructure, Allbridge Next. According to the plan, Allbridge Core and Allbridge Classic will cease operations in their current form within the next three months, and users are advised to withdraw their relevant liquidity in advance.It is understood that this attack has exposed the risks inherent in the traditional cross-chain liquidity pool model and has further driven the protocol's transition towards a cross-chain architecture based on message passing and native asset transfer.
According to the latest report released by the Financial Action Task Force (FATF) on July 16, FATF conducted the seventh targeted review on the implementation of Recommendation 15 (R.15) across global jurisdictions. The report points out that since the last update in 2025, countries have continued to advance in the regulation of Virtual Assets (VA) and Virtual Asset Service Providers (VASP), including conducting risk assessments, improving licensing and registration frameworks, implementing the Travel Rule, and strengthening enforcement actions. However, the report also points out that significant gaps still exist, mainly reflected in: the difficulty in effectively translating risk assessment outcomes into mitigation measures, insufficient implementation of licensing and registration frameworks, difficulties in identifying entities engaged in VASP activities, and insufficient effectiveness of risk-based supervision and enforcement. Regarding emerging risks, the report focuses on the following areas: the intensified "industrialization" trend of organized crime groups using virtual assets to commit fraud, increased risk of stablecoin abuse, risks associated with non-custodial wallet peer-to-peer (P2P) transactions, offshore VASPs operating outside regulatory oversight, and ongoing challenges in the DeFi sector. FATF calls on the public and private sectors to jointly strengthen the implementation of R.15, enhance risk mitigation capabilities, and deepen domestic, international, and public-private cooperation mechanisms.
security firm Project Eleven has introduced a post-quantum proof technology designed to help users prove ownership of their Bitcoin wallets after quantum computers become capable of deriving private keys and generating valid signatures. Project Eleven CEO Alex Pruden stated that the technology utilizes the wallet's key derivation path, enabling users to prove control without disclosing the parent key, thus distinguishing legitimate owners from attackers. The solution was developed in collaboration with Jim Posen, a primary maintainer of the open-source Binius zero-knowledge proof system, and is based on the "signature lifting" technique proposed by Alon Sattath and Robert Wyborski. Project Eleven noted that the prototype has not yet been audited and requires blockchain protocol support before it can be deployed. It is primarily aimed at users who miss the window to migrate to quantum-resistant addresses in the future.
According to Odaily Planet Daily, Ethereum ZK Layer2 Starknet has officially launched the compliant privacy framework STRK20, providing native privacy transaction capabilities for various digital assets on-chain. The framework operates based on a privacy pool mechanism. Once user assets are deposited into the privacy pool, all transactions are encrypted, with details such as transfer addresses and amounts being invisible to the outside. Developers can quickly integrate this privacy system using the accompanying SDK and wallet API, catering to the private transfer needs of various ERC-20 assets. STRK20 incorporates a complete compliance process: users must undergo pre-screening before entering the privacy pool; only upon receiving a legally effective formal query request and after an independent assessment, will the platform selectively disclose specific users, corresponding time periods, or designated transfer records, without revealing the private data of unrelated users.
Haseeb posted on X, stating that with models like GLM 5.2, Fable, and GPT 5.6 already launched and actively used by attackers, DeFi has not experienced the anticipated "hacker apocalypse." Chart data shows that based on the current year's data and running rate, the annualized amount stolen from DeFi in 2026 is approximately $1.89 billion. The cumulative stolen amount for the year is around $986 million, lower than the 2025 level and still within the historical range. Haseeb noted that the deeper change now is that while the number of hacker attacks has increased, the scale of individual attacks is declining more rapidly. Attackers are increasingly targeting smaller protocols and abandoned projects, while large protocols have implemented more security enhancements. As a result, overall fund security has not significantly deteriorated.
Odaily reports: A court in the state of São Paulo, Brazil, has ordered Coinbase to refund nearly $100,000 to a user who claimed funds deposited in their Coinbase Wallet disappeared in an unauthorized transaction. Coinbase argued that the private keys to the wallet were entirely under the user's control. However, it failed to prove that the transaction was initiated by the wallet holder or that adequate security measures were in place to prevent the incident. The court ruled based on relevant provisions of the Consumer Protection Code and ordered Coinbase to return the full amount plus statutory interest. (Bitcoin.com News).
Bonzo Finance, a lending protocol based on Hedera, suffered an oracle attack, resulting in a loss of approximately $9 million. The attacker exploited collateral whose SAUCE token price had been artificially inflated to borrow assets far exceeding their actual value from the protocol. According to a preliminary incident report released by Bonzo Finance, the attacker deposited only 250 SAUCE tokens, then submitted a single price update that artificially inflated the token's price by approximately 12 orders of magnitude. Subsequently, the address borrowed 6.63 million USDC and 34.5 million wrapped HBAR from the lending pool.This attack was not due to a vulnerability in Bonzo Finance's smart contracts or the underlying Hedera network itself, but rather stemmed from a flaw in the on-chain oracle verifier of the oracle service provider Supra. It erroneously accepted a SAUCE price data point where the signature had been zeroed out. Supra has since confirmed the issue and completed a fix.
prosecutors from Wisconsin and New York have expressed dissatisfaction with stablecoin issuer Circle, as the company has repeatedly refused to cooperate with law enforcement agencies in recovering stolen funds.According to the report, multiple law enforcement agencies had requested Circle to help victims of fraud and hacking incidents recover their losses by burning and reissuing USDC. However, Circle declined these requests based on its own policy stance.Circle stated that modifying the blockchain ledger to reverse transactions would undermine the fundamental properties of the USDC stablecoin and could set a dangerous precedent for the entire crypto industry. This incident highlights the conflict between the immutability of blockchain and the need for law enforcement to recover assets. (Protos)
Gate issued an announcement regarding the recent "user asset theft incident," sharing internal comprehensive verification results, analysis of the incident's cause, and progress on subsequent handling. Regarding the verification process and key facts, the announcement stated that after comprehensive verification, materials submitted by the applicant at the time, including account information, real-name information, transaction records, Alipay screen recordings, etc., matched the account completely. According to analysis by the technical team, Alipay screen recordings can only be made by the customer themselves or someone with access to the customer's Alipay account. Alipay possesses an extremely strict real-time risk control system; logging into Alipay on a different device will mandate multi-factor authentication. This indicates a situation involving serious leakage of customer information or device compromise. Regarding the Gate platform audit mechanism, the announcement stated that the Company's security unbinding audit mechanism strictly executes the four-fold verification process of "Multi-channel advance notification + System risk control preliminary screening + Manual multi-layer review + Time protection," and never has nor will it approve any security item change application based on a single material alone. Gate always takes information security and customer data protection as the Company's core management requirements. The issue of internal information leakage mentioned by some parties does not exist. Regarding fund recovery and subsequent handling, the announcement stated that Gate processed the matter with the highest priority immediately after the incident occurred, coordinating security, compliance, legal, business, and other teams to carry out on-chain analysis and asset tracking and freezing. It continues to coordinate with third-party institutions such as Tether to advance fund freezing. Subsequently, it will also actively cooperate with judicial authorities in investigations and data collection. Any substantive progress will be communicated immediately.
Odaily French Interior Minister Laurent Nuñez confirmed that France recorded 77 crypto-related kidnapping and extortion cases in the first half of 2026, a significant rise from 45 cases throughout the entire year of 2025. Authorities have launched a rapid alert system, with 724 people registered, and emergency measures have led to 200 arrests. Nuñez pledged to introduce a three-part plan to strengthen security measures in the crypto industry, including enhanced intelligence sharing, deeper cooperation with ADAN, and improved coordination among security agencies.CertiK stated that France has become a center for attacks, citing reasons including the presence of multiple leading crypto companies and their executives based locally, a “culture of炫耀 and voluntary disclosure of identity” within the community, and multiple sensitive data breaches. (cointelegraph)
Odaily, Cardano wallet service provider SecondFi has launched an asset recovery wallet check tool, allowing users to preliminarily check whether their relevant wallets have been affected by the previous security incident.SecondFi stated that the addresses currently displayed in the tool are based on the team's preliminary review data of the security incident and are not final. The list may not be complete and does not represent the final scope of recovery.
zero-knowledge scaling company StarkWare has released a Starknet quantum resistance roadmap, stating that the roadmap is divided into three phases to address the risk of future quantum computing attacks. StarkWare CEO Eli Ben-Sasson stated that Starknet can leverage its architectural advantages to achieve quantum resistance, as its underlying cryptography is based on zero-knowledge STARK proofs. According to reports, the first phase of the roadmap includes replacing part of the existing secure mathematical mechanism, Pedersen hash, with a quantum-resistant version, and adding quantum-resistant signatures; the second phase focuses on migration tools, upgrading existing smart contracts without requiring developers to manually rebuild applications; the third phase involves dependencies that Starknet cannot solve alone, primarily relying on Ethereum's quantum upgrade roadmap. Circle, Ethereum, Solana, Tezos, and Algorand have all proposed quantum resistance roadmaps. (Cointelegraph)
: In response to the recent security incident involving Cardano ecosystem project SecondFi, SlowMist founder Cos said on social media that after continuously monitoring the relevant on-chain data, he believes that if the two addresses starting with "addr1q" are both controlled by the attacker, the actual losses for SecondFi users may have exceeded $20 million.Cos stated that based on on-chain behavior analysis, the aforementioned addresses are highly likely related to the attacker, involving stolen assets potentially exceeding 129 million ADA and other tokens.Previously, SecondFi disclosed that this security incident affected approximately 16 million ADA, stating that the issue originated from the web wallet generation software.
: Cross-chain protocol Axelar Network has issued a statement regarding the recent security incident related to Secret Network, clarifying that there is a misunderstanding within the community. Neither Axelar nor the Inter-Blockchain Communication Protocol (IBC) was attacked or compromised. The affected token smart contract was not developed, deployed, or maintained by Axelar. Furthermore, Axelar's firewall mechanism prevented the impact from spreading to other chains.It is reported that the exploited contract was a fork based on the CW20-ICS20 implementation, but the developers removed two core security checks, leading to an "infinite mint" vulnerability. By deleting the verification mechanisms originally designed to prevent such issues, this fork altered the contract's original trust model and was not subjected to a new security audit.Axelar Network explained that anyone can deploy contracts via IBC for wrapping cross-chain assets, and similar contracts are used to wrap tokens from other chains onto Secret Network. However, the specific fork on the Secret side in this incident contained a vulnerability due to the removal of critical security checks. This incident was not caused by an inherent logic flaw or an issue with the IBC protocol itself, but rather a security risk introduced by modifications made to the third-party contract.
The Zodiac team released a security incident analysis report regarding the impact on the Zodiac Roles Modifier, disclosing that the root cause of the vulnerability lies in a flaw in the ERC-1271 transaction signature verification logic: the system determines signature validity solely based on the returned “magic value,” without verifying whether the call itself succeeded—thus potentially allowing failed verifications to be masqueraded as valid signatures and bypassing the module’s authentication mechanism.
Microsoft’s Threat Intelligence Team has disclosed a Windows clipboard cryptojacking trojan that has been active since February 2026. This malware employs a combination of “worm-like propagation,” “clipboard hijacking,” and “Tor-based anonymous communication” to target cryptocurrency users.
Humanity has announced the $H incident recovery plan: The legacy version of H on Ethereum, BNB Smart Chain, and Humanity Mainnet has been deprecated. A new Ethereum ERC-20 version of H will be airdropped 1:1 to eligible holders based on a pre-attack snapshot. Attackers and associated addresses have been excluded.