News linked to both this project and an event.
据 Wanchain 官方 X 账号发文,2026 年 7 月 20 日,Wanchain Bridge Cardano 跨链桥遭到攻击,黑客盗取 NIGHT 代币。Wanchain 随即向攻击者发出公告,要求其在 8 月 6 日 UTC 12:00 前归还 90% 被盗 NIGHT 代币,可保留 10% 作为白帽赏金,并承诺不追究民事责任。 目前,有社区用户指出黑客已将 NIGHT 代币在 DEX 上完成兑换,NIGHT 代币价格下跌逾 30%,现报 0.0188 美元。
According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.
According to an official post from Midnight Foundation (@midnightfdn), the Wanchain Cardano<>BNB cross-chain bridge suffered a security attack. Currently, multiple major exchanges including KuCoin, Kraken, Binance, Bybit, OKX, and MEXC have responded rapidly, taking preventive measures to restrict the flow of stolen assets, including freezing relevant accounts and addresses, blacklisting the attacker's wallets, and suspending NIGHT token deposit and withdrawal services. The exchanges confirmed that this incident is an isolated third-party bridge vulnerability and is unrelated to the Midnight Network mainnet and the NIGHT asset itself.
the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.
on-chain investigator ZachXBT stated that the cross-chain bridge protocol TeleSwap was suspected of being attacked on July 15, 2026, resulting in losses exceeding $735,000. However, as of five days after the incident, the project team has not yet publicly disclosed the relevant situation.ZachXBT stated that shortly after suspicious fund outflows were detected, TeleSwap's Bitcoin hot wallet stopped processing transactions. About two hours ago, the attacker transferred the stolen funds into the privacy mixing protocol Tornado Cash.
According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), a total of 40 major hacking incidents occurred in the cryptocurrency sector in June 2026, with total losses of approximately $75.87 million, down 7.13% month-over-month from May ($81.7 million). The top three incidents with the largest losses this month were: $31 million stolen from Humanity Protocol, $10 million lost from Syscoin Bridge, and $7.5 million stolen from the JaredFromSubway.eth MEV bot.
Cosine, founder of SlowMist, posted on X stating that Aztec appears to have been hacked again. Aztec’s Private Rollup Bridge is suspected to have been exploited, resulting in the abnormal transfer of approximately 1,158 ETH, 150,000 DAI, and 0.46963295 renBTC, with a total value of roughly $2.15 million.
Syscoin has released a security incident report detailing the UTXO-to-NEVM bridge vulnerability. According to the report, this incident resulted in the unauthorized release of approximately 5 billion SYS tokens on the UTXO side. The affected funds have since been returned to the official recovery address and permanently destroyed using the standard OP_RETURN mechanism, rendering them unusable by the protocol. As a result, the on-chain SYS supply has reverted to its expected value. The bridge functionality remains suspended while the team completes its final review and remediation efforts.
Humanity announced the independent investigation results from Quantstamp, stating that the security incident—exceeding $31 million—originated from a phishing attack that led to the leakage of private keys. The attackers subsequently gained control of the smart contract and dumped tokens; the tools and tactics employed exhibit characteristics commonly associated with North Korean hacker groups.
According to on-chain security platform Blockaid (@blockaid_), the MILC Platform cross-chain bridge suffered a private key leak on both the BNB Chain and Ethereum networks. The attacker exploited a historical bridge administrator wallet to grant the DEFAULT_ADMIN_ROLE and MANAGER_ROLE permissions to the attacker’s address. Subsequently, assets were withdrawn from the bridge contract, and administrative control was transferred to the attacker’s wallet. Confirmed losses currently stand at approximately $97,003 USDT (on BNB Chain) and approximately 39.21 ETH (on Ethereum, transferred out via Rhino.fi), totaling roughly $161,000.
Humility Protocol released a security incident update on the X platform, stating that its H token suffered a coordinated attack on the Ethereum and BSC chains yesterday, with confirmed losses exceeding $36 million in stolen and dumped assets.Preliminary investigations indicate the incident originated from a compromised employee computer, which led to the leakage of private keys for the multi-signature wallet controlling the Hyperlane Bridge ProxyAdmin. Specifically, the attacker obtained 3 out of 6 private keys of the Gnosis Safe wallet on the Ethereum chain, transferred ownership of the ProxyAdmin to a wallet under their control, upgraded the bridge contract to a malicious implementation, and subsequently transferred approximately 141.2 million H tokens in a single transaction.Simultaneously, the attacker also gained control of 3 out of 5 private keys of the Safe wallet on the BSC chain, took over the ProxyAdmin using the same method, deployed a malicious contract with unlimited minting functionality, and minted 200 million H tokens in two separate transactions to their own wallet.Humility stated that it has suspended all deposit and withdrawal operations on the affected bridge services and is collaborating with partners such as exchanges to mitigate losses. Meanwhile, it is cooperating with the police investigation and attempting to recover part of the stolen funds.
Syscoin released a preliminary post-mortem of the cross-chain bridge incident, stating that due to a verification issue in the bridging process, the attacker exploited an abnormal transaction proof validation to generate approximately 5 billion SYS tokens abnormally on the UTXO side via the affected bridging path.
According to on-chain security firm CertiK (@CertiKAlert), the Gravity Bridge attacker recently deposited another 1,180 ETH (approximately $2.06 million) into Tornado Cash. Earlier, on May 30, the attacker exploited the permissionless deployERC20() function by forging the Osmosis token string, tampering with the token registry, and mapping fake balances to real custodial assets—thereby stealing approximately 2,600 ETH (around $5.4 million) from Gravity Bridge. To date, 2,020 ETH of the stolen funds have been transferred to Tornado Cash via two externally owned accounts (EOAs); the remainder has been dispersed across centralized exchanges, making fund recovery significantly challenging.
according to Specter, in collaboration with ChangeNOW, $91,000 of the funds stolen from Gravity Bridge have been frozen. The attacker still holds the majority of the funds, which have not yet been transferred.Previously, it was reported that the private key for Gravity Bridge's bridging contract was leaked, leading to the theft of $5.4 million in assets. The assets extracted by the attacker include: $4.3 million in USDC, 274 WETH (worth approximately $553,000), $434,000 in USDT, and $64,000 in PAYG. The involved addresses are 0x7B58...1F9 and 0x4d3c...A47.
The Cosmos ecosystem’s cross-chain bridge Gravity Bridge was reportedly attacked due to a leaked signature key, resulting in approximately $5.4 million in stolen assets. The official team has confirmed the security incident and has urgently suspended bridging services to conduct an investigation. Validators have also been instructed to halt their validator nodes and coordinators. It is reported that the bridge’s contract keys may have been compromised.
Blockaid disclosed on X that the Alephium TokenBridge Ethereum cross-chain bridge was attacked. The attacker compromised three out of four Guardian private keys, forged a Verified Action Approval (VAA) message, and executed the attack within approximately seven minutes, stealing roughly $815,000 worth of assets. During the attack, the attacker minted 13.76 million Wrapped ALPH tokens out of thin air—exceeding the pre-attack circulating supply by over 100%—and simultaneously unlocked and withdrew assets including USDT, USDC, WBTC, and WETH from the custody pool. As of now, the attacker’s address still holds approximately $815,000 in stolen assets and 13.76 million uncollateralized Wrapped ALPH tokens; the largest anomalous transaction involved the out-of-thin-air minting of 13.76 million Wrapped ALPH tokens.
On-chain monitoring shows that the cross-chain bridge Gravity Bridge may have suffered a security incident due to a smart contract private key leak, affecting assets including USDC, WETH, and USDT, with total losses amounting to approximately $5.4 million.
According to PeckShield monitoring, the Verus-Ethereum Bridge has been hacked, resulting in the loss of assets including 103.6 tBTC, 1,625 ETH, and 147,000 USDC. The hacker subsequently swapped the stolen assets for approximately 5,402.4 ETH. The attacker's address received an initial 1 ETH approximately 14 hours ago via the mixing protocol Tornado Cash.
Odaily News: Blockaid posted on platform X, stating that its vulnerability detection system has discovered an attack on the Verus Ethereum cross-chain bridge, which has so far caused losses of approximately $11.58 million.
Sky (formerly MakerDAO) announced on X that the cross-chain bridging of USDS OFT on the Solana network, which was suspended due to the security review of the rsETH vulnerability incident, has resumed operation.Sky emphasized that during the review, its USDS-related contracts and the protocol itself were not affected. USDS has always maintained a fully overcollateralized state as designed, which can be verified in real-time on-chain. The suspension was a precautionary security measure. Currently, the bridging function on the Solana side has been reopened, while the Avalanche-related bridging will resume after further review is completed.