News linked to both this project and an event.
The GoPlus Chinese community released a security alert stating that on September 12, a newly activated external account address submitted a malicious governance proposal to Ampleforth. Under the guise of applying for funding for completed work on the SPOT ecosystem analytics tool, the proposal attempted to transfer 2.5 million USDC from the treasury to the proposer themselves, an amount that nearly comprised all of the treasury's liquid funds.
Odaily News – A Hyperliquid user's account was compromised through unauthorized access, with approximately 738,600 USDC transferred out and an additional 10,287 HYPE unstaked. The affected account is identified by a specific address, with some of the stolen funds flowing to an address suspected to be associated with Bitget. As of the time of verification, the 10,287 HYPE remained in the staking balance and had not yet entered the withdrawal queue. If the attacker proceeds to initiate cWithdraw, the affected assets would be further transferred after a 7-day waiting period. In two similar recent cases, staked assets were stolen a second time due to the lack of a user-triggerable emergency pause mechanism, resulting in losses exceeding $1.1 million. Relevant recommendations include introducing a Guardian or Recovery mechanism that users can pre-enable, which would only temporarily pause withdrawals, transfers, and authorization changes. The pause would expire automatically, and restoration would require a time lock and evidence review, with all actions recorded on-chain.
According to the post-incident report released by Tectonic, the Cronos blockchain lending protocol Tectonic suffered an oracle manipulation attack at 12:49 UTC on August 30, 2026. By repeatedly borrowing and re-collateralizing TONIC tokens 98 times within a single transaction, the attacker drove up the TONIC collateral price by approximately 195 times. Leveraging this artificially inflated value, they subsequently extracted assets with a nominal value of $120.4 million from nine lending markets, spanning USDC, USDT, WBTC, WETH, and other assets. The attacker then bridged the stablecoins to Ethereum and converted them to ETH, while selling the remaining assets for CRO on the Cronos chain before withdrawing them. Approximately $9.19 million in total successfully escaped before the network halt. At 14:32 UTC, Cronos validators emergency-paused the network, rolling back the on-chain state to pre-attack conditions and restoring assets still held on Cronos. Currently, Tectonic's supply and borrowing functions remain suspended, while withdrawal and repayment capabilities continue normally. Tracing efforts for the stolen funds are being coordinated by blockchain forensics firms, law enforcement agencies, and stablecoin issuers, with freeze requests already filed with the relevant issuers.
Odaily News: The decentralized lending protocol Secured Finance's lending market was attacked on September 5, resulting in a loss of approximately $104,000. The root cause was that collateral was priced based on the average execution price of the order book for the current block, allowing attackers to influence the price through self-trading, causing fraudulent lending positions to be counted as valid collateral. The attacker initially deployed the contract but did not execute immediately, then used flash loans and self-trading to inflate the price and withdraw USDC. The original attacking wallet was rolled back due to insufficient gas fees; approximately 48 seconds later, the general-purpose sandwich bot coffeebabe took about 0.9 WBTC, worth approximately $72,000, and transferred about 28.8 ETH of it to the ultra sound money builder, keeping only about $29 for itself. Subsequently, another bot took part of the USDC.
Odaily News: Bitcoin fork asset BTCB2 hit an all-time high of $1,799 on September 5. Over the past 4 hours, its price has fluctuated between 750 and 1,000 USDC; the Neoxa USDC market recorded a 24-hour trading volume of approximately $1 million.BTCB2 originated from a chain split that occurred on August 8, 2026, at block height 961,632. The network subsequently changed its proof-of-work algorithm to Blake2 and reduced block size, and it can now be mined using Blake2-compatible ASIC miners.Neoxa Exchange and Nonkyc.io have listed BTCB2, with the former offering BTC, USDC, and USDT trading pairs, and the latter offering a USDT trading pair. Both platforms have limited liquidity, and CoinMarketCap and CoinGecko have not yet listed the asset.Based on a BTCB2 price of $1,000, its fully diluted valuation stands at approximately $20.9 billion. Since UTXOs need to be split from Bitcoin first, transactions may otherwise be vulnerable to replay attacks; the network's hash rate has risen by 30.41% over the past 7 days, reaching approximately 5.1 PH/s. (Bitcoin.com News)
According to PeckShieldAlert citing Specter's monitoring, Notional Finance's custody contract may have been exploited, resulting in approximately $1.7 million in DAI and USDC losses. The attacker has converted the stolen funds into 689.2 ETH and deposited them into Tornado Cash.
Decentralized lending protocol Ajna tweeted that Ajna v2 was exploited and is investigating abnormal fund flows, advising users to withdraw all funds, repay loans, and pause interactions with the protocol. The incident caused approximately $775,000 in losses across pools including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI, attributed to a liquidation accounting manipulation attack.
Odaily News, Avici announced that its card partner Rain discovered today a vulnerability in an old Solana card contract used by Avici and a few other projects. The relevant contract has now been upgraded across all projects, and no further unauthorized activity has been detected. This incident only affected the standalone Solana contract used to hold post-deposit card balances; users' Avici wallets and card balances are isolated from each other, and funds in Solana and EVM self-custody wallets are safe and unaffected. Upon review, a total of 1,685 users were affected, with combined card balances of approximately $500,900. Avici has committed to fully refunding card balances to all affected users and has filed a report with the FBI's Internet Crime Complaint Center (IC3). Previously reported, Avici, a crypto banking project, saw its native token AVICI allegedly suffer a hacker attack, with losses of approximately $1.02 million. The attacker transferred 10,000 SOL stolen from the project to another wallet, converted it into approximately $1.02 million USDC, and then swapped the funds into approximately 418 ETH via cross-chain operations.
Odaily News, according to Onchain Lens monitoring, AVICI has been attacked, with losses of approximately $1.02 million. An address transferred 10,000 SOL to another wallet, exchanged it for approximately $1.02 million USDC, and then bridged the funds across chains to exchange for about 418 ETH.
according to D2 Finance monitoring, derivatives strategy protocol D2 Finance has raised five public questions regarding Tori Finance's operations to cover the shortfall after the Term Finance incident. These include: why 250,500 trUSD tokens were minted in advance instead of directly using existing USDC reserves; the source of the collateral used for minting; the other half of the funds coming from Kraken's hot wallet; the transparency page showing a buffer range of only approximately $17,600, or roughly 3 basis points, far below the scale of the incident's impact; as well as Delta Neutrality verification, high-yield money market positions, and hedging methods. Previously, the Term Finance governance vulnerability incident affected RockawayX Tori USDC Vault, resulting in a loss of approximately 454,000 USDC. RockawayX and Tori Finance subsequently stated that the loss has been fully covered by both parties.
Odaily News, SlowMist Security Team disclosed that the cross-chain bridge project Allbridge suffered an attack on August 19, 2026, with losses of approximately $190,000. Notably, this attack was not executed instantaneously—the attacker began laying the groundwork nearly a month in advance, bypassing the verification mechanism through forged cross-chain messages.According to SlowMist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as CCTP-style, claiming a transfer of 1 million USDC, despite no actual USDC burn operation occurring. Subsequently, Circle generated a valid attestation for this complete message following standard procedures.Approximately 24 days later, on August 19, the attacker waited for the Base Router to receive a genuine CCTP deposit, bringing its balance to approximately 191,000 USDC, then launched the attack just 6 seconds later. Using the previously forged message and attestation, the attacker called Allbridge's receiveCctpMessage function. Due to the project's lack of critical validation, the system mistook the fraudulent cross-chain message for a genuine deposit and recorded a 1 million USDC credit.Subsequently, the attacker borrowed approximately 809,000 USDC temporarily via an Aave flash loan to match the Router's balance with the forged amount, then utilized the internal credit record to call the transfer function, ultimately moving out approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800 in profit. The root cause of this vulnerability lies in Allbridge's failure to verify the identity of the cross-chain message sender and receiver, as well as its failure to confirm whether USDC was genuinely minted or whether the balance actually increased—instead directly trusting the amount and message hash data constructed by the attacker.SlowMist emphasized that on-chain message verification does not equate to actual asset arrival. Cross-chain protocols must not only verify message authenticity but also ensure the message source is trustworthy, confirm the receiver is Circle's official TokenMessengerV2, and only record assets after confirming actual minting and balance changes. This incident once again highlights the security risks in cross-chain bridges' message verification and asset settlement processes.
According to monitoring by PeckShield, an address labeled Bofur Capital was targeted by an address poisoning attack after withdrawing from Compound, resulting in losses of approximately $2 million. The attacker had previously sent 0.0002 USDC via a similar-looking address. Subsequently, due to mistakenly copying the wrong address, the controller of the Bofur Capital address transferred assets worth roughly $2 million to the attacker's address. The stolen funds have since been swapped for approximately 2 million DAI and are now held in a wallet beginning with 0xe2eB.
Odaily News: On-chain security firm PeckShield (@PeckShieldAlert) monitoring shows that an attacker, through controlling address 0x920d…9708, stole approximately 500,000 USDC from a victim wallet 0x3a53…0B5c on the Base chain. However, when the attacker subsequently attempted to swap the USDC into ETH, insufficient slippage protection parameters were set, causing the transaction to be sandwiched and arbitraged by MEV bots. In the end, the attacker only received approximately 67 WETH, valued at around $129,000, meaning the stolen funds suffered a loss rate exceeding 75%.
According to CoinDesk, the S&P 500 index has risen 3.12% this month, adding approximately $2.1 trillion in market value (equivalent to the total market cap of the entire crypto market), reaching a record high total market cap of $70.5 trillion, but Bitcoin has only risen about 2% this month, hovering near $64,600. Analysts point out that this round of stock market rise is mainly driven by AI and semiconductor individual stock narratives, rather than a broad-based recovery in risk appetite at the macro level, and Bitcoin lacks direct beneficial exposure to this. Meanwhile, the crypto market also faces multiple internal pressures: the Coldcard platform suffered a $120 million exploit, the prospects of the "Clarity Act" remain uncertain, MicroStrategy has reduced its BTC holdings for three consecutive months, and stablecoin supply continues to shrink—USDT's market cap dropped from $190 billion in April to $183 billion, and USDC's dropped from $79.5 billion to $72 billion.
According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.
According to SlowMist monitoring, the decentralized finance protocol Lien Finance suffered an attack. The attacker exploited a smart contract vulnerability to mint unbacked bond tokens and stole approximately $542,000 worth of USDC. Leveraging this vulnerability, the attacker successfully minted new, non-anomalous BondTokens without burning the corresponding input bonds. Subsequently, the attacker exchanged the tokens for USDC via a pre-authorized address, ultimately transferring approximately 542,144.63 USDC from the victim's address. Analysis indicates that the incident was essentially caused by a verification flaw in the bond token exchange logic, which allowed the attacker to bypass asset collateral constraints and mint unsupported assets.
据 Blockaid 监测,Arbitrum 生态协议 AFX 于北京时间 7月 23日 5:30 遭攻击。此次攻击针对 AFX 运营的跨链桥,迄今已导致协议约 2415 万枚 USDC 被转移。Blockaid 称,正与 Arbitrum 团队协作响应事件,并协助相关协议控制被盗资金风险。
GoPlus Security issued a security alert stating that a user signed a malicious Permit transaction 183 days ago, resulting in approximately $1,625 worth of USDC being transferred by phishing attackers. Since the user did not revoke the relevant authorization thereafter, attackers exploited this authorization again to transfer approximately $75,780 worth of USDC.
the cross-chain protocol Allbridge has issued an official statement confirming that an attacker has withdrawn approximately $1.65 million in assets from the Allbridge Core liquidity pool. A detailed analysis of the incident is currently being compiled, and the full investigation results will be published subsequently. The team emphasizes that there is no further risk to current user liquidity and that the Allbridge Next service is operating normally.In response to this incident, Allbridge plans to relaunch the Core version but will remove the liquidity pool design. Future cross-chain transfers will be facilitated via Circle CCTP and the LayerZero router to eliminate the risk of liquidity pool imbalance and the model vulnerabilities exploited in this attack. This incident has accelerated the previously initiated migration plan to fully transition to the more secure new infrastructure, Allbridge Next. According to the plan, Allbridge Core and Allbridge Classic will cease operations in their current form within the next three months, and users are advised to withdraw their relevant liquidity in advance.It is understood that this attack has exposed the risks inherent in the traditional cross-chain liquidity pool model and has further driven the protocol's transition towards a cross-chain architecture based on message passing and native asset transfer.
according to Hinkal monitoring, full refunds will be issued this week to users who have completed the recovery process, with completion expected by July 22. Users who have not yet completed the recovery can still submit applications. Previously, Hinkal suffered an attack resulting in a loss of approximately 797,000 USDC, which the attacker exchanged for about 454 ETH.