News linked to both this project and an event.
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
Blockaid stated that its vulnerability detection system identified that a Safe wallet belonging to an unidentified user on Ethereum was compromised, resulting in confirmed losses of approximately $7.73 million in rsETH. The attacker leveraged a public keeper's multi-call to route the custom Uni V4 LP Safe module to a hook-enabled liquidity pool they created, causing the associated hook to unwrap aEthrsETH into rsETH. The exploit was extracted via MEV within the block.
according to Lookonchain monitoring, the Lazarus Group hacker (0x0EBA...C22C) sold at an average price of $2,499 over the past 2 hours.
Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)
SlowMist issued a security alert stating that it had previously privately contacted the ether.fi team to disclose the relevant issues. This incident resulted in a loss of approximately 15.45 ETH. The root cause was that AtomicQueue.solve() lacked access control for the solver provided by the caller, failing to verify solver == msg.sender, and did not perform signature, registration, or consent verification.
According to Cryptopolitan, over 100 researchers used AI coding agents to reduce the quantum attack resource score for Bitcoin's secp256k1 elliptic curve point addition subroutine by 86.1% (from 10.75 billion to 1.496 billion). This optimization only targeted a single step within Shor's algorithm and did not crack any private keys or transfer funds; a full-scale attack still requires fault-tolerant quantum hardware that does not yet exist. However, each efficiency gain is compressing the time window for blockchains to complete their post-quantum migration. According to Glassnode data, approximately 6.04 million BTC (30.2% of the circulating supply) currently faces potential quantum risk due to publicly exposed on-chain public keys. Ethereum plans to achieve full quantum resistance before December 2029, while the Bitcoin community faces greater governance challenges, including how to handle approximately 1.7 million dormant coins held in P2PK addresses suspected to belong to Satoshi, which remains unresolved.
According to reporting from Christine D. Kim (@christine_dkim), Ethereum developers confirmed at the ACDC #186 conference that the Glamsterdam upgrade will be activated on the Sepolia testnet on October 6 at 13:53 UTC. However, there is significant uncertainty surrounding this upgrade—the current latest private testnet, Glamsterdam-Devnet-9, has not yet stabilized. A severe vulnerability in the consensus layer could halt block production across the network, and a bug in the execution layer's EIP-8037 also requires fixing. Developers will release Devnet-10 in the coming weeks; if Devnet-10 remains unstable, the Sepolia upgrade date may be pushed back. Activation timelines for the Hoodi testnet and the mainnet have not yet been determined, and it remains uncertain whether the goal of launching on the mainnet before the end of the year will be met.
Odaily News: Researchers from institutions including the Ethereum Foundation, Theta Labs, and StarkWare have jointly published a paper, using AI coding agents to deeply optimize the core operations of Shor's algorithm. The computing resources required for a potential quantum attack on Bitcoin and Ethereum (secp256k1 cryptographic system) have been reduced by more than 50% compared to Google's benchmark in March of this year. The number of logical qubits required for the circuit has been compressed to 1,151, and later versions have even been reduced to 813. Although current quantum hardware still cannot directly break public chains, the research shows that pure algorithmic optimization is significantly narrowing the time window for the quantum threat. The researchers emphasize that quantum-resistant upgrades take a long time and cannot be applied retroactively, and the industry needs to prepare defenses in advance. (Coindesk)
The Sandbox stated that it will provide full compensation to affected users for the SAND vulnerability incident on Base and BNB Smart Chain that occurred on August 22. Any wallet that legitimately held cross-chain SAND at the time of the snapshot prior to the incident will receive SAND compensation on the Ethereum network at a 1:1 ratio.
Odaily News On-chain analyst SomaXBT stated on the X platform that suspected Lootbot users have experienced a collective wallet theft incident, with losses now exceeding $600,000 (approximately 245 ETH). Preliminary information shows that about 50% of the victims are Lootbot subscribers.It is worth noting that Lootbot is one of the projects founded by dexter, the founder of gm.ai, a project previously involved in a soft rug pull. Lootbot was originally a trading bot platform within the Telegram ecosystem.
According to the post-incident report released by Tectonic, the Cronos blockchain lending protocol Tectonic suffered an oracle manipulation attack at 12:49 UTC on August 30, 2026. By repeatedly borrowing and re-collateralizing TONIC tokens 98 times within a single transaction, the attacker drove up the TONIC collateral price by approximately 195 times. Leveraging this artificially inflated value, they subsequently extracted assets with a nominal value of $120.4 million from nine lending markets, spanning USDC, USDT, WBTC, WETH, and other assets. The attacker then bridged the stablecoins to Ethereum and converted them to ETH, while selling the remaining assets for CRO on the Cronos chain before withdrawing them. Approximately $9.19 million in total successfully escaped before the network halt. At 14:32 UTC, Cronos validators emergency-paused the network, rolling back the on-chain state to pre-attack conditions and restoring assets still held on Cronos. Currently, Tectonic's supply and borrowing functions remain suspended, while withdrawal and repayment capabilities continue normally. Tracing efforts for the stolen funds are being coordinated by blockchain forensics firms, law enforcement agencies, and stablecoin issuers, with freeze requests already filed with the relevant issuers.
According to Galaxy Research, in the Coldcard wallet attack incident, the Wave 3 attacker has transferred approximately 45% of the stolen Bitcoin, with the related funds routed to Ethereum via THORChain or entering CoinJoin transactions to increase tracking difficulty. Galaxy stated that the attacker previously created 293 2-of-2 multisig vaults to hold victim funds, draining them from largest to smallest amount, and the funds in the 11 largest vaults have now been fully transferred out.
Odaily News: The decentralized lending protocol Secured Finance's lending market was attacked on September 5, resulting in a loss of approximately $104,000. The root cause was that collateral was priced based on the average execution price of the order book for the current block, allowing attackers to influence the price through self-trading, causing fraudulent lending positions to be counted as valid collateral. The attacker initially deployed the contract but did not execute immediately, then used flash loans and self-trading to inflate the price and withdraw USDC. The original attacking wallet was rolled back due to insufficient gas fees; approximately 48 seconds later, the general-purpose sandwich bot coffeebabe took about 0.9 WBTC, worth approximately $72,000, and transferred about 28.8 ETH of it to the ultra sound money builder, keeping only about $29 for itself. Subsequently, another bot took part of the USDC.
Odaily News Silicon Valley angel investor Liron Shapira (@liron) posted on X this morning: "I predict (with 50% confidence): due to AI shaking the security and stability guarantees people once believed Bitcoin possessed, BTC's price will plummet more than 50% within the next two years."Ethereum co-founder Vitalik Buterin rebutted this, stating: "I hold the exact opposite view. My basic reasoning is that, in the long run, I am quite optimistic about network security. I believe the main challenge lies in smoothly navigating the transition period. Moreover, I think BTC can at least properly handle all problems that do not require social consensus (such as upgrading clients, mining pools, etc., to counter network-level attacks — these fall into this category). Additionally, I believe the probability of hash algorithms or proof-of-work mechanisms being genuinely broken is extremely slim. I would have wanted to bet with you, but considering my current asset allocation (I guess you hold the same view regarding Ethereum ETH), I have already staked about 90% of my net worth on this bet."
Odaily News: The attacker behind the Coldcard "Wave 3" exploit continues to move stolen funds. In this phase, the attacker created 293 separate 2-of-2 multisig vaults for each victim's assets. On September 2, the first batch of funds was bridged to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attacker is processing the largest holdings in descending order by stolen amount, having already transferred vaults ranked 1 through 11 in sequence. The next 10 vaults yet to be transferred collectively hold 30.81 BTC, while vaults ranked 61 through 293 collectively hold 33.77 BTC.To date, the attacker has moved approximately 45% of the assets stolen in this exploit, with funds either flowing to Ethereum or entering CoinJoin mixing transactions. This latest transfer activity has also revealed a previously unknown vault: 58 addresses jointly spent funds via a 2-of-2 multisig setup in the same format as Wave 3, with the Wave 3 attacker subsequently routing them to a jump address that funds CoinJoin transactions.This vault is currently marked with "cause = open," but it is highly likely to belong to Coldcard victims as well, which could bring the total number of vaults involved in Wave 3 to 294 and push the previously disclosed total stolen in the Coldcard exploit to approximately 1,806 BTC. At present, roughly 82% of the stolen BTC remains in addresses initially controlled by the attacker, while approximately 18% has been moved, with fund flows suggesting it may be undergoing laundering.
: The G7 cybersecurity working group stated in its latest report that quantum computing poses both a security threat and an economic threat to public and private institutions, and related organizations should immediately begin migrating to post-quantum cryptography (PQC).The working group noted that the migration process could take several years, as attackers can already collect and store encrypted data today and decrypt it once sufficiently powerful quantum computers emerge. Quantum computing could also break digital signatures, leading to identity theft and exposing companies and their supply chains.The report did not mention cryptocurrencies, but similar public-key cryptography is used for blockchain wallets and transaction authorization. Current quantum computers are not yet capable of breaking Bitcoin's cryptography, but developers are considering post-quantum solutions such as BIP-360.Ethereum researchers plan to replace multiple cryptographic components used by accounts, validators, and applications. The Solana Foundation has tested post-quantum signatures on its testnet and launched an optional hash-based vault. The G7 working group also urged governments to support related research, public-private cooperation, and national PQC strategies. (Decrypt)
Odaily News – According to Bitcoin News monitoring, hackers linked to the third wave of Coldcard wallet thefts have begun moving stolen funds for the first time, converting Bitcoin into ETH via THORChain. Galaxy Research's Alex Thorn stated that approximately 10% of the stolen BTC has been moved, while the remaining 90% remains untouched. The attacker reportedly encountered difficulties during the fund conversion, with multiple THORChain transactions being returned and retried. Researchers have traced the related swap activity to a new Ethereum address, which Alex Thorn noted has been shared with relevant authorities and cryptocurrency companies. Galaxy Research indicated that the broader Coldcard exploit has resulted in losses of at least 1,789 BTC across 8,865 addresses, valued at approximately $115 million based on prices at the time of the theft.
Odaily News: Term Labs hacker deposited 400 ETH into Tornado Cash, bringing the cumulative total to 960 ETH.
According to PeckShieldAlert citing Specter's monitoring, Notional Finance's custody contract may have been exploited, resulting in approximately $1.7 million in DAI and USDC losses. The attacker has converted the stolen funds into 689.2 ETH and deposited them into Tornado Cash.
PeckShieldAlert monitoring shows that an address flagged as the TectonicFi attacker has deposited 2,658.9 ETH into Tornado Cash, valued at approximately $6.65 million.