GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Ostium Attack Post-mortem: Off-chain Oracle Permissions Stolen, Forged BTC Price to Arbitrage 23.75 Million USDC

According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.

Cryptocurrency May Become Primary Target of Quantum Computing Attacks, Governance Speed Poses Greatest Risk

According to CoinDesk, Eddy Zervigon, CEO of quantum computing security infrastructure company Quantum Xchange, stated that cryptocurrencies, due to their decentralized nature, will become the "canary in the coal mine" for quantum computing attacks—that is, the area where vulnerabilities will be exposed first. Latest assessments by Google researchers show that the number of physical qubits required to break Bitcoin's elliptic curve encryption has decreased 20-fold compared to previous estimates, and multiple institutions have brought forward the expected date of "Q-Day" (the day quantum computers can break existing encryption systems) to 2029. Deutsche Digital Assets pointed out that the real risk lies not in the encryption technology itself, but in the speed of governance—Bitcoin upgrades require 90% miner consensus, which has historically triggered hard forks (such as the 2017 SegWit upgrade leading to the birth of Bitcoin Cash), whereas traditional financial institutions only need a board resolution to complete encryption infrastructure migration. Additionally, experts caution that the quantum threat is not a binary event that "arrives suddenly on a certain day"; even if quantum computers require months to crack data, as long as the cracking is completed while the data is still valuable, the threat is established.

Drift hacker transferred 23,000 ETH into Tornado Cash, worth approximately $44.4 million

According to on-chain analyst PeckShield (@PeckShieldAlert), the address labeled "Drift Exploiter" has deposited 23,095.1 ETH (approximately $44.4 million) into Tornado Cash for mixing, and additionally transferred 0.85 ETH to Bybit.

Specter: Malicious EIP-7702 Signature Attack Results in $2.96M Loss for PancakeSwap LP

on-chain security analyst Specter has detected that a long-dormant PancakeSwap liquidity provider (LP) suffered a loss of approximately $2.96 million after signing a malicious EIP-7702 authorization. It is reported that the attacker removed approximately $1.48 million in BSC-USD and $1.48 million in BUSD liquidity provided by the victim, subsequently swapping the BUSD for ETH. Currently, the attacker has deposited approximately $1.46 million into Tornado Cash, while the remaining $1.48 million in USDT remains in the attacker's address.

Drift Protocol $285M Attacker Moves Funds via Tornado Cash After 3-Month Dormancy

that, according to Onchain Lens monitoring, after a $285 million attack on Drift Protocol on Solana in April, the attacker has begun moving funds through Tornado Cash following a 3-month dormant period. The attacker is rapidly depositing ETH into the Tornado Cash Router in batches of 100 ETH, with multiple transactions occurring per minute.

Most of the stolen funds have been moved; Summer Fi attacker still holds approximately $565,100 in ETH

according to Onchain Lens monitoring, on July 6, the Summer Fi attacker received 6.017 million DAI from the Summer Fi exploit, and subsequently swapped and routed the funds through Tornado Cash. The original wallet (0x7bf...dca) retains 11.3 ETH, worth approximately $21,600; the second wallet (0x46e...ba7) retains 282.9 ETH, worth approximately $543,500.

TeleSwap Bridge Protocol Suspected of Attack, Over $735,000 in Funds Stolen and Flowed into Tornado Cash

on-chain investigator ZachXBT stated that the cross-chain bridge protocol TeleSwap was suspected of being attacked on July 15, 2026, resulting in losses exceeding $735,000. However, as of five days after the incident, the project team has not yet publicly disclosed the relevant situation.ZachXBT stated that shortly after suspicious fund outflows were detected, TeleSwap's Bitcoin hot wallet stopped processing transactions. About two hours ago, the attacker transferred the stolen funds into the privacy mixing protocol Tornado Cash.

ether.fi selects Nexus Mutual to provide slashing coverage for up to 15,000 ETH

: On-chain digital asset management neobank ether.fi has selected Nexus Mutual to provide ETH slashing coverage, covering slashing penalties for its validators up to 15,000 ETH. ether.fi stated that it operates a large-scale validator set on Ethereum, and slashing is a tail risk. This coverage is used to cover validator losses, with a scale exceeding the total historical ETH slashing losses. ether.fi currently manages over $6 billion in assets across products such as Cash, Stake, and Liquid. Since 2019, Nexus Mutual has provided over $7 billion in coverage for smart contract attacks, slashing, and other digital asset risks. (Decrypt)

Ostium trading remains paused, user margin funds remain frozen

Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.

Ostium OLP Vault Attacked, Approximately $24 Million USDC Stolen and Transferred to Tornado Cash

According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), the public OLP vault of decentralized perpetual contract protocol Ostium (@Ostium) was attacked, with approximately 24 million USDC stolen. The attacker subsequently swapped the stolen funds for 12,080 ETH and has transferred 10,540 ETH into the mixer Tornado Cash to obscure the fund flow. On-chain tracing shows that the attacker's initial funds originated from ChangeNow and Bybit, with 1 ETH transferred from each to the attacker's wallet (0x321D...8bfD9).

Two hackers today spent a total of 11.718 million DAI to purchase 6,454.7 ETH

: According to monitoring by on-chain analyst Yu Jin, the hacker (0x18B...E66) who stole funds from a Coinbase user spent 7.378 million DAI early this morning to buy 4,049.7 ETH at a price of $1,822. Meanwhile, the address (0xa13...628) that received ETH from Tornado Cash last November had previously transferred out 4,978 ETH and exchanged them for 16.294 million DAI at a price of $3,273. Today, two hours ago, this address spent 4.34 million DAI to repurchase 2,405 ETH at a price of $1,804.

Summer.fi Attacker Moves 1.35 Million DAI, Swaps for ETH via Uniswap and Transfers to Tornado Cash

Odaily Odaily News According to Onchain Lens monitoring, on July 6, the Summer.fi attacker wallet (0x7BF...b3bdca) received 6.017 million DAI from the Summer.fi attack incident; subsequently, 1.35 million DAI have been transferred, swapped for ETH via Uniswap, and then sent to Tornado Cash through a second wallet (0x46e...eba7). The original wallet still holds approximately 4.67 million DAI, while the second wallet still holds 50 ETH.

After 5 months of silence, Step Finance attacker sells $21.4 million in SOL and transfers to Tornado Cash

According to Lookonchain, the Step Finance attacker, after 5 months of inactivity, sold all 261,933 SOL, worth $21.4 million. The funds were then bridged to Ethereum to purchase 12,128 ETH, which were subsequently deposited into Tornado Cash to launder the money.

hinkal will fully compensate user funds, confirming approximately 797,000 USDC was extracted by an attacker and swapped for 454 ETH

decentralized privacy protocol hinkal has released an update on a security incident, confirming that an attacker extracted approximately 797,000 USDC from its Ethereum contract through a series of transactions and exchanged it for about 454 ETH. Of this, roughly 410 ETH was subsequently transferred to Tornado Cash, while the remaining approximately 44.67 ETH was bridged to the Bitcoin network via THORChain. hinkal is currently collaborating with an external security team to trace the flow of funds.hinkal stated that the impact of this security incident is limited to the relevant fund pools on the Ethereum chain, and contracts on other chains remain unaffected. However, all contracts have been temporarily suspended for fixes and security verification. All affected users will be fully compensated at a 1:1 ratio, with specific compensation procedures and timelines to be announced in a subsequent update.

UXLINK hacker swaps $10.54 million DAI for 6,001 ETH

According to Onchain Lens monitoring, the UXLINK hacker swapped $10.54 million in DAI for 6,001 ETH at an average price of $1,757, and subsequently transferred the funds to Tornado Cash.

Tornado Cash suspicious DAO proposal emerges, potentially threatening $23 million in DAO funds

L2BEAT researcher @sergeyshemyakov posted on X platform, stating that a suspicious DAO proposal appeared on Tornado Cash on June 25, and the target contract of the proposal has not been verified.The address of the proposal creator obtained funds through Railgun 4 days ago. If the proposal passes and is executed, the governance contract will make a delegatecall to this target contract. The Tornado Cash fund pool itself is secure, but this proposal may directly target the Tornado Cash DAO for an attack. The DAO currently holds TORN tokens worth approximately $23 million.

KyberSwap Attacker Transfers Another 2,000 ETH to Tornado, with Over $32 Million ETH Transferred in Two Years

according to PeckShieldAlert monitoring, the address labeled as the KyberSwap attacker has again transferred 2,000 ETH to Tornado Cash. Over the past two years, the attacker has laundered a total of 16,100 ETH (approximately $40 million) through this mixer, accounting for over 80% of the $48.8 million stolen in the November 2023 attack.

Jaredfromsubway Attacker Transfers 2,000 ETH and Sells 1,422 ETH

According to on-chain analyst Onchain Lens (@OnchainLens), the attacker behind the well-known MEV bot Jaredfromsubway laundered 2,000 ETH via Tornado Cash, worth approximately $3.44 million at current prices.

PeckShield: The JaredFromSubway attacker has converted the stolen funds into 4,400 ETH, with some of the proceeds flowing into Tornado Cash.

According to on-chain analyst PeckShield (@PeckShieldAlert), the well-known MEV bot “JaredFromSubway” has reportedly been attacked, resulting in the theft of approximately $7.5 million worth of crypto assets—including 1,474.58 WETH, 2.87 million USDC, and 2 million USDT. The attacker has exchanged the stolen funds for 4,400 ETH and transferred 1,000 ETH to the mixer Tornado Cash to obfuscate the fund’s trail.

PancakeSwap's OLPC/LABUBU trading pool was attacked, with approximately $1.1 million in assets stolen

according to PeckShield monitoring, the OLPC/LABUBU liquidity pool on BNB Chain's PancakeSwap was attacked. The attacker stole approximately $1.1 million worth of assets. After the incident, the attacker cross-chain transferred the stolen funds to Ethereum and subsequently deposited 633.4 ETH into the mixing protocol Tornado Cash. Additionally, the attacker sent 0.0221 BNB and 0.0411 ETH to a deprecated address. Relevant attack details and fund flows are still under continuous tracking.