GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar
Blockaid

Blockaid

Active

Web3 security firm

News Heat Trend

Project Overview

Blockaid is a Web3 security tools stop malicious transactions before they happen, protecting web3 users from scams, phishing, and hacks.

Lumi Finance Suspected to Be Attacked, Current Losses Approximately $270,000

According to Blockaid monitoring, the Lumi Finance protocol on Arbitrum is under attack, and approximately $270,000 in funds have been transferred out so far.

Taiko bridge attack may result in losses up to $1.7 million

Ethereum Layer 2 blockchain Taiko has stated its chain state verification mechanism has been compromised, and the security assumptions of all bridges deployed on Taiko can no longer be relied upon. It urges users to immediately withdraw funds from the relevant bridges. Taiko says it is coordinating with partners to control the incident and has suspended the affected systems.Crypto security firm Blockaid stated that the root cause appears to be a flaw in the way Taiko's bridge validates source signals. Attackers can submit message proofs on Ethereum that lack legitimate proof from the Taiko chain, thereby registering and withdrawing fraudulent bridge messages. This leads to the unauthorized release of assets from the ERC20 treasury. Blockaid estimates at least $1 million was stolen, while Lookonchain and PeckShield believe the value of stolen assets could be as high as $1.7 million.PeckShield reported that the attacker has transferred approximately 1.99 million TAIKO tokens to MEXC, valued at around $189,000. Data from blockchain intelligence firm Arkham shows that the Taiko attacker's wallet holds approximately $1.5 million in assets, primarily in Ether. (Cointelegraph)

JaredFromSubway’s MEV Bot Attacked, Suffers $7.5 Million Loss

According to on-chain analyst Blockaid (@blockaid_), the well-known Ethereum MEV bot JaredFromSubway (@jaredsmev) has been attacked, resulting in losses of approximately $7.5 million. The attacker constructed a deceptive MEV arbitrage path to trick the bot into automatically approving token transfers. Leveraging these open approvals—before they were revoked—the attacker drained WETH, USDC, and USDT from the bot’s contract. The stolen funds ultimately flowed to the attacker’s wallet address. Blockaid noted that this attack was not a conventional phishing attempt or smart contract vulnerability, but rather a targeted exploitation of the bot’s automated execution mechanism.

MILC Platform Cross-Chain Bridge Suffers Private Key Leak Attack, Sustaining ~$161,000 in Losses

According to on-chain security platform Blockaid (@blockaid_), the MILC Platform cross-chain bridge suffered a private key leak on both the BNB Chain and Ethereum networks. The attacker exploited a historical bridge administrator wallet to grant the DEFAULT_ADMIN_ROLE and MANAGER_ROLE permissions to the attacker’s address. Subsequently, assets were withdrawn from the bridge contract, and administrative control was transferred to the attacker’s wallet. Confirmed losses currently stand at approximately $97,003 USDT (on BNB Chain) and approximately 39.21 ETH (on Ethereum, transferred out via Rhino.fi), totaling roughly $161,000.

Blockaid: Alephium-Ethereum Bridge Attacked, Approximately $815,000 in Assets Stolen

Blockaid disclosed on X that the Alephium TokenBridge Ethereum cross-chain bridge was attacked. The attacker compromised three out of four Guardian private keys, forged a Verified Action Approval (VAA) message, and executed the attack within approximately seven minutes, stealing roughly $815,000 worth of assets. During the attack, the attacker minted 13.76 million Wrapped ALPH tokens out of thin air—exceeding the pre-attack circulating supply by over 100%—and simultaneously unlocked and withdrew assets including USDT, USDC, WBTC, and WETH from the custody pool. As of now, the attacker’s address still holds approximately $815,000 in stolen assets and 13.76 million uncollateralized Wrapped ALPH tokens; the largest anomalous transaction involved the out-of-thin-air minting of 13.76 million Wrapped ALPH tokens.

Crypto DAO's Pro token suffered an attack, with the attacker and profit addresses holding approximately 8.2 million USDT.

According to Blockaid monitoring, Crypto DAO's Pro token was attacked. As of 00:23 early this morning, the attacker and related profit addresses currently hold a combined total of approximately 8.2 million USDT.

In the first half of 2026, crypto hack losses exceeded $1 billion, with Ethereum and Solana leading the losses.

: A security report for the first half of 2026 released by on-chain security platform Blockaid shows that the crypto industry suffered losses exceeding $1 billion during the period, with a record number of hacker incidents in six months. Blockaid tracked 212 security incidents, including a single attack on KelpDAO that resulted in a loss of $292 million. Ethereum and Solana were the networks with the largest amounts of stolen funds during the period, with losses of approximately $332 million and $326 million, respectively. Blockaid stated that the number of high-threshold attacks in the first half of 2026 was 3.4 times that of the entire year of 2025. Ethereum incidents were primarily driven by code vulnerabilities, with attack vectors including bridge and smart contract exploits, unauthorized access to privileged accounts, and market manipulation. Solana's losses increased significantly from approximately $127 million in 2025, with over 98% of losses stemming from key leaks, primarily involving incidents related to Drift Protocol and Step Finance.

Garden Finance Hacked, Loss of Approximately $450,000 USDT

According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.

Arbitrum ecosystem protocol AFX cross-chain bridge attacked, approximately 24.15 million USDC lost

据 Blockaid 监测,Arbitrum 生态协议 AFX 于北京时间 7月 23日 5:30 遭攻击。此次攻击针对 AFX 运营的跨链桥,迄今已导致协议约 2415 万枚 USDC 被转移。Blockaid 称,正与 Arbitrum 团队协作响应事件,并协助相关协议控制被盗资金风险。

Ostium Halts Trading; Oracle Vulnerability Causes Tens of Millions of Dollars in Losses

Decentralized trading protocol Ostium paused trading due to suspected exploitation of its oracle system, with security firms Blockaid and CertiK estimating losses between $18 million and $22 million.

Ostium Attacked, Losses Approximately $18 Million

Blockaid stated that it detected a vault exploit incident involving Ostium on Arbitrum. The attacker fabricated false trading profits through registered PriceUpKeep Forwarders and authorized oracle reports with future timestamps, triggering a payout of approximately 18 million USDC from the vault.

In the first half of 2026, crypto hack losses exceeded $1 billion, with Ethereum and Solana leading the losses.

: A security report for the first half of 2026 released by on-chain security platform Blockaid shows that the crypto industry suffered losses exceeding $1 billion during the period, with a record number of hacker incidents in six months. Blockaid tracked 212 security incidents, including a single attack on KelpDAO that resulted in a loss of $292 million. Ethereum and Solana were the networks with the largest amounts of stolen funds during the period, with losses of approximately $332 million and $326 million, respectively. Blockaid stated that the number of high-threshold attacks in the first half of 2026 was 3.4 times that of the entire year of 2025. Ethereum incidents were primarily driven by code vulnerabilities, with attack vectors including bridge and smart contract exploits, unauthorized access to privileged accounts, and market manipulation. Solana's losses increased significantly from approximately $127 million in 2025, with over 98% of losses stemming from key leaks, primarily involving incidents related to Drift Protocol and Step Finance.

Taiko bridge attack may result in losses up to $1.7 million

Ethereum Layer 2 blockchain Taiko has stated its chain state verification mechanism has been compromised, and the security assumptions of all bridges deployed on Taiko can no longer be relied upon. It urges users to immediately withdraw funds from the relevant bridges. Taiko says it is coordinating with partners to control the incident and has suspended the affected systems.Crypto security firm Blockaid stated that the root cause appears to be a flaw in the way Taiko's bridge validates source signals. Attackers can submit message proofs on Ethereum that lack legitimate proof from the Taiko chain, thereby registering and withdrawing fraudulent bridge messages. This leads to the unauthorized release of assets from the ERC20 treasury. Blockaid estimates at least $1 million was stolen, while Lookonchain and PeckShield believe the value of stolen assets could be as high as $1.7 million.PeckShield reported that the attacker has transferred approximately 1.99 million TAIKO tokens to MEXC, valued at around $189,000. Data from blockchain intelligence firm Arkham shows that the Taiko attacker's wallet holds approximately $1.5 million in assets, primarily in Ether. (Cointelegraph)

Well-known MEV bot Jaredfromsubway.eth suffers reverse attack, losing over $7.5 million

Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)

MetaMask Launches AI Agent Wallet Supporting Cross-Chain DeFi Operations with Built-in Transaction Security Protection

According to MetaMask’s official blog, MetaMask has officially launched its first self-custodial wallet designed specifically for AI agents—MetaMask Agent Wallet—and will begin its Early Access Program on June 8, 2026. The wallet connects to AI agent frameworks via a command-line interface (CLI) and supports the full suite of DeFi functionalities—including token swaps, perpetual contracts, prediction markets, and liquidity provision—across all EVM-compatible chains (Ethereum, Arbitrum, Base, Avalanche, Optimism, Polygon, BSC, Linea, Sei) as well as Hyperliquid. On security, the wallet offers two operational modes: - Default “Guard Mode” allows users to set daily spending limits and protocol allowlists; transactions exceeding these rules require manual two-factor authentication (2FA) approval before execution. - “Beast Mode” grants advanced users greater autonomy, but malicious transaction detection and mandatory 2FA verification remain enforced. All transactions undergo transaction simulation, Blockaid threat scanning, and MEV protection. Secure transactions are backed by up to $10,000 per month in transaction protection. Users retain full control of their private keys and can export their seed phrase at any time. The full public release is expected this summer.

MetaMask Launches AI Agent Self-Custody Wallet "Agent Wallet", Supporting Multi-Chain Automated Trading

MetaMask has officially launched Agent Wallet, a self-custody wallet designed for AI agents. It enables automated trading, perpetual contracts, and liquidity provision on Ethereum, multiple EVM-compatible chains, and the Hyperliquid network. The product is equipped with multiple security mechanisms, including transaction simulation, spending limits, and address whitelisting. It integrates with Blockaid's risk scanning, requiring user secondary confirmation for high-risk transactions. The platform also introduces a transaction guarantee service, offering up to $10,000 in compensation for compliant and secure transactions. Currently, the product is only being tested by a small group of users via the command line, with plans for a full public release this summer. (The Block)

Blockaid: Alephium-Ethereum Bridge Attacked, Approximately $815,000 in Assets Stolen

Blockaid disclosed on X that the Alephium TokenBridge Ethereum cross-chain bridge was attacked. The attacker compromised three out of four Guardian private keys, forged a Verified Action Approval (VAA) message, and executed the attack within approximately seven minutes, stealing roughly $815,000 worth of assets. During the attack, the attacker minted 13.76 million Wrapped ALPH tokens out of thin air—exceeding the pre-attack circulating supply by over 100%—and simultaneously unlocked and withdrew assets including USDT, USDC, WBTC, and WETH from the custody pool. As of now, the attacker’s address still holds approximately $815,000 in stolen assets and 13.76 million uncollateralized Wrapped ALPH tokens; the largest anomalous transaction involved the out-of-thin-air minting of 13.76 million Wrapped ALPH tokens.

Related news

Crypto DAO's Pro token suffered an attack, with the attacker and profit addresses holding approximately 8.2 million USDT.

According to Blockaid monitoring, Crypto DAO's Pro token was attacked. As of 00:23 early this morning, the attacker and related profit addresses currently hold a combined total of approximately 8.2 million USDT.

In the first half of 2026, crypto hack losses exceeded $1 billion, with Ethereum and Solana leading the losses.

: A security report for the first half of 2026 released by on-chain security platform Blockaid shows that the crypto industry suffered losses exceeding $1 billion during the period, with a record number of hacker incidents in six months. Blockaid tracked 212 security incidents, including a single attack on KelpDAO that resulted in a loss of $292 million. Ethereum and Solana were the networks with the largest amounts of stolen funds during the period, with losses of approximately $332 million and $326 million, respectively. Blockaid stated that the number of high-threshold attacks in the first half of 2026 was 3.4 times that of the entire year of 2025. Ethereum incidents were primarily driven by code vulnerabilities, with attack vectors including bridge and smart contract exploits, unauthorized access to privileged accounts, and market manipulation. Solana's losses increased significantly from approximately $127 million in 2025, with over 98% of losses stemming from key leaks, primarily involving incidents related to Drift Protocol and Step Finance.

Garden Finance Hacked, Loss of Approximately $450,000 USDT

According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.

Arbitrum ecosystem protocol AFX cross-chain bridge attacked, approximately 24.15 million USDC lost

据 Blockaid 监测,Arbitrum 生态协议 AFX 于北京时间 7月 23日 5:30 遭攻击。此次攻击针对 AFX 运营的跨链桥,迄今已导致协议约 2415 万枚 USDC 被转移。Blockaid 称,正与 Arbitrum 团队协作响应事件,并协助相关协议控制被盗资金风险。

Ostium Halts Trading; Oracle Vulnerability Causes Tens of Millions of Dollars in Losses

Decentralized trading protocol Ostium paused trading due to suspected exploitation of its oracle system, with security firms Blockaid and CertiK estimating losses between $18 million and $22 million.

Ostium Attacked, Losses Approximately $18 Million

Blockaid stated that it detected a vault exploit incident involving Ostium on Arbitrum. The attacker fabricated false trading profits through registered PriceUpKeep Forwarders and authorized oracle reports with future timestamps, triggering a payout of approximately 18 million USDC from the vault.