News linked to both this project and an event.
According to official sources, Summer.fi released a post-mortem stating that on July 6, the attacker manipulated the share prices of two Lazy Summer USDC vaults by injecting overvalued Silo tokens into an offline Ark still included in the NAV, and extracted approximately $6.04 million in a single atomic transaction.
According to CoinDesk, researchers at blockchain security company Hexens discovered an "expired cache" type confusion vulnerability in the Aptos blockchain Move virtual machine. Attackers require only about $3,000 in server costs to launch attacks in a simulated environment with a success rate of nearly 90%, without needing validator privileges or internal knowledge. Researchers ran approximately 20 attacks in simulated tests, succeeding 17-18 times, and verified the potential ability to control management permissions of cross-chain protocols such as LayerZero, Wormhole, and USDC CCTP. Hexens assessed that the vulnerability directly threatens protocols on the Aptos chain such as DeFi, stablecoins, and liquid staking, involving assets in the low single-digit billions of dollars; if spread through paths such as cross-chain bridges, stablecoin minting, and centralized exchanges, the systemic risk exposure could reach up to $70 billion. The Aptos team completed the fix and deployed it to the mainnet within hours after receiving the vulnerability report on February 25, and currently no user funds have been compromised.
decentralized privacy protocol hinkal has released an update on a security incident, confirming that an attacker extracted approximately 797,000 USDC from its Ethereum contract through a series of transactions and exchanged it for about 454 ETH. Of this, roughly 410 ETH was subsequently transferred to Tornado Cash, while the remaining approximately 44.67 ETH was bridged to the Bitcoin network via THORChain. hinkal is currently collaborating with an external security team to trace the flow of funds.hinkal stated that the impact of this security incident is limited to the relevant fund pools on the Ethereum chain, and contracts on other chains remain unaffected. However, all contracts have been temporarily suspended for fixes and security verification. All affected users will be fully compensated at a 1:1 ratio, with specific compensation procedures and timelines to be announced in a subsequent update.
according to CertiK's monitoring, suspicious transactions occurred in the Hinkal Protocol. An address (0xbB3...fc20) executed multiple "Transact" transactions after initiating a "Proofless Deposit," siphoning approximately $800,000 USDC from the Hinkal contract.
zero-knowledge scaling company StarkWare has released a Starknet quantum resistance roadmap, stating that the roadmap is divided into three phases to address the risk of future quantum computing attacks. StarkWare CEO Eli Ben-Sasson stated that Starknet can leverage its architectural advantages to achieve quantum resistance, as its underlying cryptography is based on zero-knowledge STARK proofs. According to reports, the first phase of the roadmap includes replacing part of the existing secure mathematical mechanism, Pedersen hash, with a quantum-resistant version, and adding quantum-resistant signatures; the second phase focuses on migration tools, upgrading existing smart contracts without requiring developers to manually rebuild applications; the third phase involves dependencies that Starknet cannot solve alone, primarily relying on Ethereum's quantum upgrade roadmap. Circle, Ethereum, Solana, Tezos, and Algorand have all proposed quantum resistance roadmaps. (Cointelegraph)
According to on-chain analyst PeckShield (@PeckShieldAlert), the well-known MEV bot “JaredFromSubway” has reportedly been attacked, resulting in the theft of approximately $7.5 million worth of crypto assets—including 1,474.58 WETH, 2.87 million USDC, and 2 million USDT. The attacker has exchanged the stolen funds for 4,400 ETH and transferred 1,000 ETH to the mixer Tornado Cash to obfuscate the fund’s trail.
Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)
According to on-chain analyst Blockaid (@blockaid_), the well-known Ethereum MEV bot JaredFromSubway (@jaredsmev) has been attacked, resulting in losses of approximately $7.5 million. The attacker constructed a deceptive MEV arbitrage path to trick the bot into automatically approving token transfers. Leveraging these open approvals—before they were revoked—the attacker drained WETH, USDC, and USDT from the bot’s contract. The stolen funds ultimately flowed to the attacker’s wallet address. Blockaid noted that this attack was not a conventional phishing attempt or smart contract vulnerability, but rather a targeted exploitation of the bot’s automated execution mechanism.
According to Lookonchain, the Humanity Protocol attacker has converted part of the stolen funds into USDC and deposited them into KuCoin.
According to PeckShield monitoring, structured products protocol ThetanutsFi has been attacked, resulting in a loss of approximately $2.1 million. Of this, roughly $2 million in option tokens have been recovered by a white hat address. The attacker has exchanged $105,000 USDC for approximately 60 ETH, and still holds USDC option tokens worth around $34,000.
blockchain security analyst Specter posted on X platform, stating that an old liquidity pool of the Solana DeFi protocol Raydium is suspected of being attacked, with the attacker stealing approximately $1.34 million in assets, mainly including USDC, RAY, and wSOL. Currently, the hacker has transferred the stolen funds to Ethereum via a bridge and subsequently deposited them into Tornado Cash for mixing.
according to Specter, in collaboration with ChangeNOW, $91,000 of the funds stolen from Gravity Bridge have been frozen. The attacker still holds the majority of the funds, which have not yet been transferred.Previously, it was reported that the private key for Gravity Bridge's bridging contract was leaked, leading to the theft of $5.4 million in assets. The assets extracted by the attacker include: $4.3 million in USDC, 274 WETH (worth approximately $553,000), $434,000 in USDT, and $64,000 in PAYG. The involved addresses are 0x7B58...1F9 and 0x4d3c...A47.
Blockaid disclosed on X that the Alephium TokenBridge Ethereum cross-chain bridge was attacked. The attacker compromised three out of four Guardian private keys, forged a Verified Action Approval (VAA) message, and executed the attack within approximately seven minutes, stealing roughly $815,000 worth of assets. During the attack, the attacker minted 13.76 million Wrapped ALPH tokens out of thin air—exceeding the pre-attack circulating supply by over 100%—and simultaneously unlocked and withdrew assets including USDT, USDC, WBTC, and WETH from the custody pool. As of now, the attacker’s address still holds approximately $815,000 in stolen assets and 13.76 million uncollateralized Wrapped ALPH tokens; the largest anomalous transaction involved the out-of-thin-air minting of 13.76 million Wrapped ALPH tokens.
Odaily Odaily founder Rand posted on platform X, stating that with the assistance of on-chain detective ZachXBT, the team has identified the root cause of the recent cUSDC freeze incident, which is unrelated to the Zama protocol itself or privacy technology. The incident originated when a wallet address associated with the Overnight Finance hack deposited over $12.5 million USDC into Zama's cUSDC wrapper contract. Since the address was not on any sanctions list at the time of deposit and was not flagged by KYT (Know Your Transaction) tools, the funds were able to enter the protocol.Rand stated that law enforcement agencies recently issued asset restriction orders against several wallets linked to the hacker. At that time, the cUSDC wrapper contract held relatively small funds, with over 99% coming from the aforementioned hacker address. Consequently, the court ordered the freezing of the entire wrapper contract to restrict the movement of the related funds. Rand emphasized that this measure is not a sanction against Zama or privacy protocols, but a common judicial freezing measure in the DeFi space.To cooperate with the investigation, Zama has suspended the operation of the cUSDC, cUSDT, and cWETH contracts until the investigation is complete, all involved addresses are identified, and corresponding measures are taken. Rand reiterated that Zama adheres to the principle of "compliant confidentiality" and will not tolerate any illegal activities. He also indicated that a more detailed post-mortem of the incident and a plan for handling similar requests in the future will be released subsequently.
On-chain monitoring shows that the cross-chain bridge Gravity Bridge may have suffered a security incident due to a smart contract private key leak, affecting assets including USDC, WETH, and USDT, with total losses amounting to approximately $5.4 million.
The Resolv Foundation has announced its recovery plan following the protocol security incident. USR/wstUSR tokens held and snapshot-recorded prior to the incident will be redeemed for USDC at a 1:1 ratio, while USR/wstUSR acquired after the incident will be redeemed at a 1:0.5 ratio. RLP holdings will be restored at a core redemption rate of 0.71 USDC per token, with additional RESOLV token allocations based on a reference price of $0.03. The Foundation stated that eligible users may claim their recovery funds between May 26, 2026, and August 26, 2026.
Verus confirmed on Platform X that its Verus-Ethereum cross-chain bridge has been attacked, resulting in the theft of ETH, USDC, and tBTC from the contract on the Ethereum chain. Other bridged assets are currently unaffected. The Verus network is now suspended, with most block-producing nodes voluntarily going offline after experiencing the cascading effects of the attack. The development team is fully investigating the scope of the incident, the attack vector, and the subsequent remediation plan, and will provide updates once more information is confirmed. Verus stated that it is willing to cooperate with relevant law enforcement agencies to pursue legal accountability; however, if the attacker returns all stolen funds, the project team is willing to offer a bug bounty and will not pursue further legal action.Verus also reminds users that anyone claiming to be part of the Verus team or community in public channels, private messages, or other avenues, and offering "compensation" or "remediation plans," is a scammer. The official statement emphasizes not to interact with anyone claiming there are compensation projects or offering payouts, and to promptly report such accounts to Discord or Platform X.Previously, it was reported that the Verus-Ethereum cross-chain bridge was attacked, resulting in losses of approximately $11.58 million.
According to PeckShield monitoring, the Verus-Ethereum Bridge has been hacked, resulting in the loss of assets including 103.6 tBTC, 1,625 ETH, and 147,000 USDC. The hacker subsequently swapped the stolen assets for approximately 5,402.4 ETH. The attacker's address received an initial 1 ETH approximately 14 hours ago via the mixing protocol Tornado Cash.
Odaily Chainalysis posted on X platform, stating that prior to the THORChain theft, wallets suspected to be linked to the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several consecutive weeks. As early as late April, the attacker-associated wallets deposited funds into Hyperliquid positions via Hyperliquid and the Monero privacy bridge. These funds were subsequently converted to USDC and transferred to Arbitrum, then bridged to Ethereum. Some of the ETH was then moved to THORChain to stake as RUNE for a newly joined node, which is believed to be the source of the attack.Subsequently, the attacker bridged a portion of the RUNE back to Ethereum and split it into four chains. One chain went directly to the attacker, passing through intermediate wallets before transferring 8 ETH to the wallet that would ultimately receive the stolen funds, just 43 minutes before the attack. The funds from the other three chains flowed in reverse. Between May 14 and 15, these wallets bridged the ETH back to Arbitrum again, deposited it into Hyperliquid, and transferred it into Monero via the same privacy bridge, with the final transaction occurring less than 5 hours before the attack commenced. As of Friday afternoon, the stolen funds remain untouched, but the attacker has demonstrated sophisticated cross-chain money laundering capabilities. The Hyperliquid to Monero path may be the next move.
Euler Finance announced it will take over the maintenance and operation of the Euler contract stack known as Mewler under HypurrFi on the Hyperliquid EVM. The relevant infrastructure is undergoing a smooth transition, with Clearstar Labs continuing to serve as the risk manager for the Prime, Yield, and Earn vaults. HypurrFi Scale and Pooled Markets are scheduled to gradually wind down and undergo orderly liquidation over the coming weeks. However, all existing markets remain solvent and fully operational, with no security vulnerabilities or emergency parameter adjustments.During the migration process, new borrowing functionality for some Pooled assets has been frozen, but HYPE, USDC, and USDT0 can still be used for liquidity provision to allow borrowers to gradually unwind their positions. Euler emphasized that its isolated lending architecture on HyperEVM will continue to serve as core infrastructure, jointly maintained by Euler and Clearstar Labs.The HypurrFi team stated that user deposits, positions, and collateral assets remain fully secure. This adjustment is an active strategic migration, not a security incident or protocol failure. According to the plan, Euler Prime and Yield markets will become the primary entry points for lending and yield markets on HyperEVM moving forward. The HypurrFi brand will be gradually phased out, with related support services closing after May 28. Full market liquidation is expected to be completed by July 15, 2026.HypurrFi also reminded users to be aware of risks and fraudulent links during the migration process, to operate only through official channels, and to use the built-in migration tools to transfer Pooled positions to Euler Prime or Yield markets.