News linked to both this project and an event.
: A security report for the first half of 2026 released by on-chain security platform Blockaid shows that the crypto industry suffered losses exceeding $1 billion during the period, with a record number of hacker incidents in six months. Blockaid tracked 212 security incidents, including a single attack on KelpDAO that resulted in a loss of $292 million. Ethereum and Solana were the networks with the largest amounts of stolen funds during the period, with losses of approximately $332 million and $326 million, respectively. Blockaid stated that the number of high-threshold attacks in the first half of 2026 was 3.4 times that of the entire year of 2025. Ethereum incidents were primarily driven by code vulnerabilities, with attack vectors including bridge and smart contract exploits, unauthorized access to privileged accounts, and market manipulation. Solana's losses increased significantly from approximately $127 million in 2025, with over 98% of losses stemming from key leaks, primarily involving incidents related to Drift Protocol and Step Finance.
Ethereum Layer 2 blockchain Taiko has stated its chain state verification mechanism has been compromised, and the security assumptions of all bridges deployed on Taiko can no longer be relied upon. It urges users to immediately withdraw funds from the relevant bridges. Taiko says it is coordinating with partners to control the incident and has suspended the affected systems.Crypto security firm Blockaid stated that the root cause appears to be a flaw in the way Taiko's bridge validates source signals. Attackers can submit message proofs on Ethereum that lack legitimate proof from the Taiko chain, thereby registering and withdrawing fraudulent bridge messages. This leads to the unauthorized release of assets from the ERC20 treasury. Blockaid estimates at least $1 million was stolen, while Lookonchain and PeckShield believe the value of stolen assets could be as high as $1.7 million.PeckShield reported that the attacker has transferred approximately 1.99 million TAIKO tokens to MEXC, valued at around $189,000. Data from blockchain intelligence firm Arkham shows that the Taiko attacker's wallet holds approximately $1.5 million in assets, primarily in Ether. (Cointelegraph)
Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)
According to MetaMask’s official blog, MetaMask has officially launched its first self-custodial wallet designed specifically for AI agents—MetaMask Agent Wallet—and will begin its Early Access Program on June 8, 2026. The wallet connects to AI agent frameworks via a command-line interface (CLI) and supports the full suite of DeFi functionalities—including token swaps, perpetual contracts, prediction markets, and liquidity provision—across all EVM-compatible chains (Ethereum, Arbitrum, Base, Avalanche, Optimism, Polygon, BSC, Linea, Sei) as well as Hyperliquid. On security, the wallet offers two operational modes: - Default “Guard Mode” allows users to set daily spending limits and protocol allowlists; transactions exceeding these rules require manual two-factor authentication (2FA) approval before execution. - “Beast Mode” grants advanced users greater autonomy, but malicious transaction detection and mandatory 2FA verification remain enforced. All transactions undergo transaction simulation, Blockaid threat scanning, and MEV protection. Secure transactions are backed by up to $10,000 per month in transaction protection. Users retain full control of their private keys and can export their seed phrase at any time. The full public release is expected this summer.
MetaMask has officially launched Agent Wallet, a self-custody wallet designed for AI agents. It enables automated trading, perpetual contracts, and liquidity provision on Ethereum, multiple EVM-compatible chains, and the Hyperliquid network. The product is equipped with multiple security mechanisms, including transaction simulation, spending limits, and address whitelisting. It integrates with Blockaid's risk scanning, requiring user secondary confirmation for high-risk transactions. The platform also introduces a transaction guarantee service, offering up to $10,000 in compensation for compliant and secure transactions. Currently, the product is only being tested by a small group of users via the command line, with plans for a full public release this summer. (The Block)
Blockaid disclosed on X that the Alephium TokenBridge Ethereum cross-chain bridge was attacked. The attacker compromised three out of four Guardian private keys, forged a Verified Action Approval (VAA) message, and executed the attack within approximately seven minutes, stealing roughly $815,000 worth of assets. During the attack, the attacker minted 13.76 million Wrapped ALPH tokens out of thin air—exceeding the pre-attack circulating supply by over 100%—and simultaneously unlocked and withdrew assets including USDT, USDC, WBTC, and WETH from the custody pool. As of now, the attacker’s address still holds approximately $815,000 in stolen assets and 13.76 million uncollateralized Wrapped ALPH tokens; the largest anomalous transaction involved the out-of-thin-air minting of 13.76 million Wrapped ALPH tokens.
Felix Leupold, Technical Lead of CoWSwap, posted an update on X stating that the CoWSwap frontend has been restored and users can now access it at swap.cow.finance. The official notice reminds users to authorize only the address 0xc92e8bdf79f0507f65a392b0ab4667716bfe0110 (i.e., the original GPv2VaultRelayer contract). Earlier, Blockaid reported that its system had detected an attack on the frontend of the decentralized exchange CowSwap; CoW Swap subsequently issued an announcement confirming a frontend outage and advising users not to transact on the platform temporarily.