News linked to both this project and an event.
According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.
According to CoinDesk, Eddy Zervigon, CEO of quantum computing security infrastructure company Quantum Xchange, stated that cryptocurrencies, due to their decentralized nature, will become the "canary in the coal mine" for quantum computing attacks—that is, the area where vulnerabilities will be exposed first. Latest assessments by Google researchers show that the number of physical qubits required to break Bitcoin's elliptic curve encryption has decreased 20-fold compared to previous estimates, and multiple institutions have brought forward the expected date of "Q-Day" (the day quantum computers can break existing encryption systems) to 2029. Deutsche Digital Assets pointed out that the real risk lies not in the encryption technology itself, but in the speed of governance—Bitcoin upgrades require 90% miner consensus, which has historically triggered hard forks (such as the 2017 SegWit upgrade leading to the birth of Bitcoin Cash), whereas traditional financial institutions only need a board resolution to complete encryption infrastructure migration. Additionally, experts caution that the quantum threat is not a binary event that "arrives suddenly on a certain day"; even if quantum computers require months to crack data, as long as the cracking is completed while the data is still valuable, the threat is established.
According to on-chain analyst PeckShield (@PeckShieldAlert), the address labeled "Drift Exploiter" has deposited 23,095.1 ETH (approximately $44.4 million) into Tornado Cash for mixing, and additionally transferred 0.85 ETH to Bybit.
on-chain security analyst Specter has detected that a long-dormant PancakeSwap liquidity provider (LP) suffered a loss of approximately $2.96 million after signing a malicious EIP-7702 authorization. It is reported that the attacker removed approximately $1.48 million in BSC-USD and $1.48 million in BUSD liquidity provided by the victim, subsequently swapping the BUSD for ETH. Currently, the attacker has deposited approximately $1.46 million into Tornado Cash, while the remaining $1.48 million in USDT remains in the attacker's address.
that, according to Onchain Lens monitoring, after a $285 million attack on Drift Protocol on Solana in April, the attacker has begun moving funds through Tornado Cash following a 3-month dormant period. The attacker is rapidly depositing ETH into the Tornado Cash Router in batches of 100 ETH, with multiple transactions occurring per minute.
according to Onchain Lens monitoring, on July 6, the Summer Fi attacker received 6.017 million DAI from the Summer Fi exploit, and subsequently swapped and routed the funds through Tornado Cash. The original wallet (0x7bf...dca) retains 11.3 ETH, worth approximately $21,600; the second wallet (0x46e...ba7) retains 282.9 ETH, worth approximately $543,500.
on-chain investigator ZachXBT stated that the cross-chain bridge protocol TeleSwap was suspected of being attacked on July 15, 2026, resulting in losses exceeding $735,000. However, as of five days after the incident, the project team has not yet publicly disclosed the relevant situation.ZachXBT stated that shortly after suspicious fund outflows were detected, TeleSwap's Bitcoin hot wallet stopped processing transactions. About two hours ago, the attacker transferred the stolen funds into the privacy mixing protocol Tornado Cash.
: On-chain digital asset management neobank ether.fi has selected Nexus Mutual to provide ETH slashing coverage, covering slashing penalties for its validators up to 15,000 ETH. ether.fi stated that it operates a large-scale validator set on Ethereum, and slashing is a tail risk. This coverage is used to cover validator losses, with a scale exceeding the total historical ETH slashing losses. ether.fi currently manages over $6 billion in assets across products such as Cash, Stake, and Liquid. Since 2019, Nexus Mutual has provided over $7 billion in coverage for smart contract attacks, slashing, and other digital asset risks. (Decrypt)
Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.
According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), the public OLP vault of decentralized perpetual contract protocol Ostium (@Ostium) was attacked, with approximately 24 million USDC stolen. The attacker subsequently swapped the stolen funds for 12,080 ETH and has transferred 10,540 ETH into the mixer Tornado Cash to obscure the fund flow. On-chain tracing shows that the attacker's initial funds originated from ChangeNow and Bybit, with 1 ETH transferred from each to the attacker's wallet (0x321D...8bfD9).
: According to monitoring by on-chain analyst Yu Jin, the hacker (0x18B...E66) who stole funds from a Coinbase user spent 7.378 million DAI early this morning to buy 4,049.7 ETH at a price of $1,822. Meanwhile, the address (0xa13...628) that received ETH from Tornado Cash last November had previously transferred out 4,978 ETH and exchanged them for 16.294 million DAI at a price of $3,273. Today, two hours ago, this address spent 4.34 million DAI to repurchase 2,405 ETH at a price of $1,804.
Odaily Odaily News According to Onchain Lens monitoring, on July 6, the Summer.fi attacker wallet (0x7BF...b3bdca) received 6.017 million DAI from the Summer.fi attack incident; subsequently, 1.35 million DAI have been transferred, swapped for ETH via Uniswap, and then sent to Tornado Cash through a second wallet (0x46e...eba7). The original wallet still holds approximately 4.67 million DAI, while the second wallet still holds 50 ETH.
According to Lookonchain, the Step Finance attacker, after 5 months of inactivity, sold all 261,933 SOL, worth $21.4 million. The funds were then bridged to Ethereum to purchase 12,128 ETH, which were subsequently deposited into Tornado Cash to launder the money.
decentralized privacy protocol hinkal has released an update on a security incident, confirming that an attacker extracted approximately 797,000 USDC from its Ethereum contract through a series of transactions and exchanged it for about 454 ETH. Of this, roughly 410 ETH was subsequently transferred to Tornado Cash, while the remaining approximately 44.67 ETH was bridged to the Bitcoin network via THORChain. hinkal is currently collaborating with an external security team to trace the flow of funds.hinkal stated that the impact of this security incident is limited to the relevant fund pools on the Ethereum chain, and contracts on other chains remain unaffected. However, all contracts have been temporarily suspended for fixes and security verification. All affected users will be fully compensated at a 1:1 ratio, with specific compensation procedures and timelines to be announced in a subsequent update.
According to Onchain Lens monitoring, the UXLINK hacker swapped $10.54 million in DAI for 6,001 ETH at an average price of $1,757, and subsequently transferred the funds to Tornado Cash.
L2BEAT researcher @sergeyshemyakov posted on X platform, stating that a suspicious DAO proposal appeared on Tornado Cash on June 25, and the target contract of the proposal has not been verified.The address of the proposal creator obtained funds through Railgun 4 days ago. If the proposal passes and is executed, the governance contract will make a delegatecall to this target contract. The Tornado Cash fund pool itself is secure, but this proposal may directly target the Tornado Cash DAO for an attack. The DAO currently holds TORN tokens worth approximately $23 million.
according to PeckShieldAlert monitoring, the address labeled as the KyberSwap attacker has again transferred 2,000 ETH to Tornado Cash. Over the past two years, the attacker has laundered a total of 16,100 ETH (approximately $40 million) through this mixer, accounting for over 80% of the $48.8 million stolen in the November 2023 attack.
According to on-chain analyst Onchain Lens (@OnchainLens), the attacker behind the well-known MEV bot Jaredfromsubway laundered 2,000 ETH via Tornado Cash, worth approximately $3.44 million at current prices.
According to on-chain analyst PeckShield (@PeckShieldAlert), the well-known MEV bot “JaredFromSubway” has reportedly been attacked, resulting in the theft of approximately $7.5 million worth of crypto assets—including 1,474.58 WETH, 2.87 million USDC, and 2 million USDT. The attacker has exchanged the stolen funds for 4,400 ETH and transferred 1,000 ETH to the mixer Tornado Cash to obfuscate the fund’s trail.
according to PeckShield monitoring, the OLPC/LABUBU liquidity pool on BNB Chain's PancakeSwap was attacked. The attacker stole approximately $1.1 million worth of assets. After the incident, the attacker cross-chain transferred the stolen funds to Ethereum and subsequently deposited 633.4 ETH into the mixing protocol Tornado Cash. Additionally, the attacker sent 0.0221 BNB and 0.0411 ETH to a deprecated address. Relevant attack details and fund flows are still under continuous tracking.