News linked to both this project and an event.
Odaily News: The State Attorney General's Office of Mexico (FGJEM) stated that two suspects are accused of killing four people in search of a cold wallet believed to contain millions of dollars in Bitcoin. The two are scheduled to appear in court on Wednesday, where a judge will determine whether there is sufficient evidence to continue criminal proceedings.The surnames of suspects Diego Sebastián and Gerardo have not been disclosed. Prosecutors allege that the pair killed Jonathan Meléndez, keyboardist for the rock band Camilo Séptimo, his pregnant wife, their daughter, and an employee at a residence in the city of Atizapán de Zaragoza. The family's golden retriever was also killed.Mexico's Secretary of Security, Omar García Harfuch, stated that one of the suspects was a business partner of the victim and allegedly used that relationship to gain entry into the residence. If convicted, the two could face sentences ranging from 25 to 70 years in prison for each victim.Blockchain security firm CertiK reported that 52 violent coercion attacks against cryptocurrency holders were recorded globally in the first half of 2026, a 33.3% increase from 39 during the same period in 2025. Blockchain analysis company Chainalysis estimates that the value of stolen cryptocurrency from related attacks exceeded $30 million. (Cointelegraph)
Bitcoin News posted on X platform, stating that France disclosed this month that its tax administration had been hacked, with data of approximately 678,000 individuals and businesses stolen. The stolen data allegedly includes names, addresses, income, and property information. Analysis of the alleged database found 26,805 records showing income exceeding €100,000, including 386 records exceeding €1 million. According to CertiK data, out of 52 verified cryptocurrency wrench attacks globally in the first half of 2026, France accounted for 33. French prosecutors have also accused a tax department employee of using government databases to identify cryptocurrency investors and selling personal information to criminals involved in physical assaults and extortion. The latest data breach has no publicly linked physical attacks yet, but sensitive financial and location data of hundreds of thousands of people may now no longer be under government control.
Odaily News: Ethereum client Besu has fixed 5 security vulnerabilities discovered by blockchain security firm CertiK in version 26.7.1 released on July 27, and published 4 detailed security advisories on August 14. Vulnerability details were disclosed after a delay to allow node operators to complete upgrade deployments.Jialiang Chang, Director of Security Engineering and Senior Audit Partner at CertiK, stated that the arrangement of releasing patches first and details later provided an 18-day buffer period, allowing node operators to identify affected deployments, test new versions, and coordinate with validators or consortium participants to complete upgrades.The vulnerabilities involve block broadcast handling, caching of future-height consensus proposals, WebSocket subscription limits, and JSON-RPC filter creation. If left unpatched, attackers could exhaust node memory or thread resources, impacting node availability and consensus processing.Using the Chain Scan methodology, CertiK conducted adversarial testing on peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi-node test network, and provided reproducible testing tools to the Besu team. CertiK is updating Chain Scan to expand round-the-clock multi-node testing on public chain networks. (Bitcoin.com News)
Term Labs 发文更新漏洞事件进展。目前所有 Term Meta Vault 已关闭,DAO 治理角色已被撤销。此关闭不可逆,永久禁止进一步存款,但提款仍开放。本次事件涉及 Term Vault 治理。底层 Term 协议及其直接借贷市场尚未受到影响,团队正在继续核实影响范围。若仍存在资金缺口,团队将寻找解决途径。 此前消息,据 CertiK 监测,Term Finance 于昨日遭遇治理攻击,损失约 850 万美元。
According to monitoring by CertiK Alert, the DeFi lending protocol Term Labs has been targeted by a governance attack, resulting in approximately $8.5 million in asset losses. Currently, around 2,843 ETH and approximately $1.6 million worth of DAI have been transferred to address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Term Labs has confirmed that its Term Vaults fell victim to a governance exploit, stating that the team is continuing to investigate the incident and will release further details upon completion of the investigation. Official sources have yet to disclose the specific attack vectors or the scope of the impact.
Odaily News: Brazil's crypto market has recorded $318.8 billion in on-chain transaction value over the past 12 months, ranking fifth globally in cryptocurrency adoption, with nearly one-third of Latin America's related activity conducted through Brazilian wallets and platforms. Blockchain security firm CertiK stated that virtual asset service providers must submit authorization applications to the Central Bank of Brazil (BCB) by October 30, 2026, accompanied by independent audit reports. On November 10, 2025, the Central Bank of Brazil issued three resolutions clarifying the licensing scope, minimum capital requirements, and foreign exchange rules for virtual asset service providers. Minimum capital requirements for different license categories range from approximately R$10.8 million to R$37.2 million. Among the current approximately 120 service providers, most have not yet obtained formal licenses, and overseas operators must relocate their operations to Brazil within 270 days. Approximately 80% of Brazil's declared cryptocurrency transaction volume is settled via dollar-pegged tokens, with USDT accounting for 88.7% of that share. Total stablecoin transaction volume from 2019 to 2025 reached R$1.13 trillion. CertiK statistics show that the crypto industry suffered losses of $1.32 billion due to hacker attacks and exploit incidents in the first half of 2026, involving 344 events. (Decrypt)
CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。
According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.
据彭博社报道,区块链安全公司 CertiK 最新报告显示,2026 年上半年全球针对数字资产持有者的暴力"扳手攻击"(即以人身威胁强迫受害者交出加密货币)事件共记录 52 起,同比增长 33%。其中法国以 33 起攻击案例独占近三分之二,成为全球最严重的受害国。报告指出,加密犯罪分子的攻击目标正从数字钱包转向现实中的持币个人,暴力手段日趋普遍。
Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.
CertiK published an analysis stating that the Solana ecosystem protocol DeFiTuna was attacked on July 16, with losses of approximately 569,601 USDC. The attacker first created an extremely low-liquidity TUNA/USDC pool and swapped borrowed USDC into the pool via Jupiter routing. Since only a minimal amount of TUNA was ultimately obtained, the protocol experienced rounding down during the position asset value calculation, causing the total assets to be recorded as 0, thereby incorrectly passing the health and solvency checks.
Decentralized trading protocol Ostium paused trading due to suspected exploitation of its oracle system, with security firms Blockaid and CertiK estimating losses between $18 million and $22 million.
according to CertiK's monitoring, CodexField's X account and website have been taken offline. Earlier, on-chain analyst Specter had warned that the project might be a scam and exit scam, and tracked abnormal cross-chain fund transfers totaling over 17.3 million USDT.
Odaily, Web3 security firm CertiK has released the "Hack3D: First Half of 2026 Report." The report shows that the Web3 ecosystem experienced 344 security incidents in the first half of 2026, with cumulative losses of approximately $1.32 billion. Although this figure represents a 46.8% decrease compared to the same period last year, excluding the impact of the $1.45 billion security incident involving Bybit, the scale of losses in the first half of this year actually increased by approximately 28% year-on-year, indicating that the overall security environment in the industry has not materially improved.The report points out that wallet theft has become the attack type causing the greatest financial loss, accounting for approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks fell by more than 50% year-on-year, the loss amount only decreased by approximately 10.8%, reflecting that attackers are shifting towards high-net-worth individuals and institutional targets, carrying out more targeted high-value attacks.Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running legacy smart contracts that lack re-audits. The report also shows that mega-attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents alone causing approximately $577 million in losses, accounting for 44% of the total losses in the first half of the year. Looking at the number of incidents, the impact of single attacks, and the changing attack patterns, the Web3 industry is facing more complex and continuously escalating security challenges.
CertiK warned that the decline in losses was primarily due to a single massive Bybit hack incident worth $1.4 billion during the same period last year; excluding this factor, attacks are becoming "more targeted and more destructive per incident," with private key and multi-signature wallet management remaining the most critical security risk exposures.
according to CertiK's monitoring, suspicious transactions occurred in the Hinkal Protocol. An address (0xbB3...fc20) executed multiple "Transact" transactions after initiating a "Proofless Deposit," siphoning approximately $800,000 USDC from the Hinkal contract.
Odaily French Interior Minister Laurent Nuñez confirmed that France recorded 77 crypto-related kidnapping and extortion cases in the first half of 2026, a significant rise from 45 cases throughout the entire year of 2025. Authorities have launched a rapid alert system, with 724 people registered, and emergency measures have led to 200 arrests. Nuñez pledged to introduce a three-part plan to strengthen security measures in the crypto industry, including enhanced intelligence sharing, deeper cooperation with ADAN, and improved coordination among security agencies.CertiK stated that France has become a center for attacks, citing reasons including the presence of multiple leading crypto companies and their executives based locally, a “culture of炫耀 and voluntary disclosure of identity” within the community, and multiple sensitive data breaches. (cointelegraph)
According to monitoring by security firm CertiK Alert (@CertiKAlert), the Edel Finance lending market suffered a vulnerability exploit, with the attacker manipulating the collateral price of the wGOOGLx token (which relies on its GOOGLx balance) to extract approximately $204,000 in funds through the lending function.
According to on-chain security firm CertiK (@CertiKAlert), the Gravity Bridge attacker recently deposited another 1,180 ETH (approximately $2.06 million) into Tornado Cash. Earlier, on May 30, the attacker exploited the permissionless deployERC20() function by forging the Osmosis token string, tampering with the token registry, and mapping fake balances to real custodial assets—thereby stealing approximately 2,600 ETH (around $5.4 million) from Gravity Bridge. To date, 2,020 ETH of the stolen funds have been transferred to Tornado Cash via two externally owned accounts (EOAs); the remainder has been dispersed across centralized exchanges, making fund recovery significantly challenging.
data from blockchain security firm CertiK shows total losses in the crypto sector from hacks, vulnerabilities, and scams in May 2026 were approximately $68.3 million. This represents a nearly 90% decline from the over $650 million in losses recorded in April, making it the third month this year where losses fell below $100 million. Phishing attacks accounted for about $2.6 million of the losses.In April, industry losses surged due to two major attacks on Drift Protocol and KelpDAO, which together accounted for approximately 95% of the month's losses, making April one of the most devastating months for losses in recent years.The institution reminds that while large-scale protocol-level attacks have decreased, risks such as phishing, deepfakes, and credential leaks are on the rise, with the focus of attacks increasingly shifting towards personnel and identity systems. The decline in losses this time is merely due to the absence of major security incidents; the overall security risks in the industry have not been fundamentally eliminated. Cross-chain bridge vulnerabilities and insider threats remain primary risks. (Financefeeds)