News linked to both this project and an event.
Odaily News: Metaverse gaming platform The Sandbox has confirmed a vulnerability in its cross-chain bridge, allowing attackers to mint unbacked SAND on Base and BNB Smart Chain. Blockchain security firm PeckShield detected on August 21 that two addresses had collectively minted approximately 14.9 billion SAND. The Sandbox subsequently shut down bridging functionality on both networks.The Sandbox stated that the affected assets are bridged assets on Base and BNB Smart Chain, while SAND on Ethereum and Polygon, user wallet assets, and the Ethereum-locked assets backing the token remain unaffected. The proportion of genuinely collateralized assets involved in this incident is less than 0.01% of the total SAND supply.The Sandbox is developing a compensation plan for affected liquidity providers and advises users not to trade SAND on Base or BNB Smart Chain until bridging is restored. Coinbase plans to delist 10 perpetual futures contracts, including SAND, on August 26, with open positions to be automatically settled at that time. (Bitcoin.com News)
According to monitoring by CertiK Alert, the DeFi lending protocol Term Labs has been targeted by a governance attack, resulting in approximately $8.5 million in asset losses. Currently, around 2,843 ETH and approximately $1.6 million worth of DAI have been transferred to address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Term Labs has confirmed that its Term Vaults fell victim to a governance exploit, stating that the team is continuing to investigate the incident and will release further details upon completion of the investigation. Official sources have yet to disclose the specific attack vectors or the scope of the impact.
The Sandbox has officially confirmed and fully secured the recent SAND cross-chain bridge vulnerability affecting the Base and BNB Smart Chain (BSC) networks. Attackers exploited the flaw to mint uncollateralized SAND tokens across both networks, but the impact remains limited, accounting for less than 0.01% of the total SAND supply. SAND on Ethereum and Polygon, along with user wallets, remain unaffected. The Sandbox has since disabled cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable and non-redeemable. The official team advises users to avoid buying, selling, or trading SAND on the aforementioned networks.
Odaily News: Ethereum co-founder Vitalik Buterin has published his latest article "Obfuscation (Part 3): Local Mixing," providing an in-depth introduction to an emerging cryptographic obfuscation approach — "Local Mixing" — and describing it as a potential new fundamental cryptographic tool following elliptic curves, RSA, and lattice-based cryptography.Vitalik noted that current mainstream obfuscation techniques primarily rely on complex mathematical assumptions but often incur extremely high computational costs. Local mixing, by contrast, takes a completely different approach. Rather than depending on elliptic curves, large integer factorization, or lattice cryptography, it draws on design principles from symmetric cryptography and hash functions, continuously shuffling, restructuring, and hiding circuit architecture to eliminate information leakage while preserving functionality.He explained that the local mixing technique mainly involves steps such as reversibility, hardening, mixing, splitting, crossing walk, and "gadgetization." By introducing random structures into circuits, rearranging logic gates, and employing nonlinear hiding mechanisms, it makes it difficult for attackers to recover the original computational logic.Vitalik pointed out that the technique remains in its early stages, with security not yet subject to long-term validation, and it still faces challenges such as random attacks and linear analysis. Nevertheless, he believes local mixing represents an entirely new path of cryptographic exploration aimed at building more efficient indistinguishability obfuscation (iO) schemes.He stated that if local mixing achieves a breakthrough, it could lead to new quantum-resistant public-key encryption schemes and advance the development of general-purpose obfuscation techniques. While the field still requires years of cryptanalysis and optimization validation, AI-assisted research could significantly accelerate this maturation process.Vitalik described obfuscation as the "final frontier" of cryptography, as theoretically all other cryptographic primitives can be constructed from obfuscation and one-way functions. Local mixing not only has the potential to reduce the cost of traditional obfuscation schemes but could also become an important direction for future cryptographic infrastructure.
According to reporter Kate Irwin (@kateirwin), GalaChain experienced an anomalous on-chain capital outflow this Tuesday. Approximately 1.99 billion GALA tokens (worth roughly $2.9 million), along with other tokens, were transferred from five major addresses to a newly created wallet, subsequently bridged out and swapped for ETH within approximately one hour. Of these, approximately 1.639 billion GALA (representing roughly 82%) originated from a wallet linked to Gala Games CEO and co-founder Eric Schiermeyer, which simultaneously transferred out other tokens valued at over $500,000. Within hours of the incident, the Gala development team urgently merged a fix commit on GitHub, classifying the event as resulting from a GalaChain EIP-712 unsigned field injection vulnerability. The Gala Ethereum cross-chain bridge has since been halted, with the Solana bridge concurrently deactivated. While officially cited as routine maintenance, users have been unable to access the cross-chain bridge services normally for several consecutive days.
Odaily News: According to on-chain detective Specter's monitoring, the victim claimed that due to a Coldcard hack, funds were transferred from Bitcoin to Ethereum. However, on-chain data shows that the 73 BTC ($4.6 million) originally came from the Whirlpool coin mixer two weeks ago, with some of it bridged to Ethereum and subsequently deposited through a phishing Tornado Cash interface. Two coin mixers were used during the fund transfer process. The individual was also found to have appeared in Telegram groups involving private key searches and brute-force attacks. On-chain detective Specter stated that the victim may be a threat actor, and their funds may have been stolen by another threat actor.
According to monitoring by on-chain analyst Ember (@EmberCN), a hacker address associated with Tornado Cash bought 18,273 ETH at an average price of $2,109, spending 38.535 million DAI/USDS over the past 5 hours during today's strong ETH rebound. It is reported that the aforementioned stablecoins originated from 17,124 ETH the hacker received from Tornado Cash 9 months ago, which were all sold at an average price of approximately $3,308 at that time to be held as stablecoins, and were bought back to rebuild positions today taking advantage of the significant ETH rebound.
Odaily News According to on-chain analyst Yu Jian's monitoring, a hacker spent 38.535 million DAI/USDS to buy 18,273 ETH over the past 5 hours, at a purchase price of $2,109. The aforementioned stablecoins came from 17,124 ETH received from Tornado Cash 9 months ago. The hacker subsequently sold the ETH at an average price of approximately $3,308 and converted it into DAI and USDS for holding. Today, during the ETH rebound, the hacker repurchased ETH.
Odaily News: The KITE Foundation has provided an update on the handling of a token security incident. A new KITE ERC-20 contract has been deployed on the Ethereum mainnet, with the total token supply remaining unchanged. Old KITE tokens will be migrated to the new contract at a 1:1 ratio. Addresses confirmed to be controlled by the attacker will be excluded and will not receive new tokens.The migration snapshot is based on Ethereum mainnet block height 25,692,498. Regular self-custody wallet users will receive the new tokens directly without needing to redeem or authorize anything. Exchange users will have their migration coordinated between the exchange and the KITE team. Cross-chain channels will remain paused until migration and verification are complete.Previously, KITE detected abnormal transfers on August 6 and confirmed it had been attacked by hackers. The team stated that this incident did not result in any asset losses for users or the project, and the impact is currently under control.
According to monitoring by on-chain analyst Onchain Lens (@OnchainLens), the Pando Rings exploiters have become active again after two months of silence, swapping 3 million DAI for approximately 1,570 ETH (worth about $3 million) via CoW Protocol, and subsequently transferring 800 ETH (about $1.52 million) of them into the mixer Tornado Cash through eight transactions, suspected of laundering funds. Pando Rings previously suffered an oracle manipulation attack in November 2022, losing about $20 million.
Odaily News - A study published at USENIX Security '26 reveals that researchers identified 65,340 high-risk cryptocurrency addresses involved in abuse on Ethereum and BNB Chain, with associated native token losses reaching 126,982.94 ETH and 17,726.7 BNB. The study estimates that total losses linked to these addresses exceed $574.8 million, of which two newly described active attack vectors directly caused approximately $15.7 million in losses (2.7% of the total). The first category involves contract account misuse and exploitation of deterministic contract addresses; the second leverages EIP-7702 to delegate accounts with exposed keys to malicious code that directly transfers deposits. The research team extracted over 16.3 million unique private keys by mining 63,004 GitHub repositories from January 2015 to May 2025, achieving an overall accuracy rate of 99.11% in detection results. (Cryptoslate)
据 Ai 姨 监测,Lazarus Group 于约 2 小时前将 262.2 枚比特币(BTC) 转移至新地址,价值约 1664 万美元,相关转移或用于后续资金清洗。当前该组织在链上仍持有超过 7306 万美元 的资产,主要包括 比特币(BTC)、泰达币(USDT) 和 以太坊(ETH)。
Odaily News: According to on-chain detective Specter's monitoring, the attacker exchanged all assets, including WBTC, cbBTC, LDO, USDS, and CRV, for DAI and ETH. The same wallet had previously been compromised in September 2023 due to a malicious token approval, resulting in a loss of $24.23 million, with the attacker ultimately returning approximately 90% of the stolen funds. The attacker's address is 0x8fEB...F95Ae.
Odaily讯 According to Cyvers Alert monitoring, an Address Poisoning attack incident has been detected, resulting in the victim losing approximately $100,000 in USDT. The attacker carried out the "address poisoning" against the victim's wallet about 66 days ago by sending a transaction to create a malicious address record resembling an address the victim normally interacts with. Today, the victim failed to verify the full wallet address and mistakenly transferred funds to the attacker's address.Following the incident, in order to avoid potential freezing risks, the attacker has converted the stolen USDT into ETH, and the wallet currently holds approximately 52.8 ETH.Cyvers reminds users to always fully verify wallet addresses when making on-chain transfers, and to avoid relying solely on address records from transaction history. Meanwhile, security agencies recommend adopting AI-based on-chain security tools for real-time detection of abnormal transaction behavior, in order to reduce risks such as address poisoning and phishing attacks. Address poisoning attacks have become one of the common fraud methods in the crypto asset space in recent years. Attackers typically exploit users' habit of copying addresses from historical transactions by forging similar-looking addresses to trick users into transferring assets mistakenly.
Odaily News: According to Lookonchain monitoring, the Jaredfromsubway attacker bought back 2,063 ETH at $1,912 four days ago, worth $3.94 million; today they sold 2,167 ETH at $1,872, worth $4.05 million.
Odaily News: Standard Chartered initiated coverage on Monday of blockchain oracle project Chainlink, projecting LINK to reach $200 by the end of 2030 — roughly 25 times its current price of around $8. The bank's phased targets are $13 by the end of this year, followed by $41, $82, and $133. Standard Chartered estimates that the on-chain tokenized asset market will reach $4 trillion by the end of 2028, with DeFi-deployed assets hitting $2.7 trillion by 2030 — a 37-fold increase from current levels. The bank expects Chainlink fees to grow approximately 25-fold over the same period, assuming token prices track fee growth. Chainlink secures over $110 billion in total value, covering approximately 70% of the value that global DeFi relies on from oracles, with a share exceeding 80% on Ethereum; Aave V3 accounts for 44% of that. Swift, DTCC, Euroclear, JPMorgan, Mastercard, UBS, Fidelity, and S&P Global are all listed as institutions using its services. Chainlink still lags behind LayerZero in cross-chain interoperability. Following the $292 million attack in April, over $7 billion in token value has migrated to Chainlink CCIP, with second-quarter transaction volume reaching $4.9 billion — up 353% year-over-year. Risks include slowing institutional tokenization, pilots not converting to production processes, and technical failures impacting confidence. (Decrypt)
Odaily News: After a 9-month silence, the X account of renowned artist and Pepe creator Matt Furie became active again in early August, posting content and contract addresses related to HOODRAT, DORK, and BOYZ within a single week. Most of these posts were subsequently deleted. On August 9, the account posted a statement claiming it had been hacked, stating it does not endorse any altcoins, and adding that a relevant notice had previously appeared on its official website. On-chain analyst @StandartXBT noted that after the HOODRAT-related post was published, the token's market cap surged briefly before the price declined; following the DORK deployment, the deployer completed bundled purchases, removed liquidity, and sold off, extracting significant ETH profits from the initial raise. @StandartXBT discovered through web archives that Matt Furie's official website had not previously contained such a notice, and no prior trace was found on the X platform, casting doubt on the credibility of the statement.
According to Specter monitoring, over $7.9 million was stolen from wallets associated with Coinsbuy on Ethereum and TRON, and the attackers subsequently laundered the funds into XMR through exchanges. Coinsbuy stated that, with the support of ChangeNOW, it has successfully frozen stolen funds amounting to up to six figures. Following the incident, Coinsbuy temporarily suspended deposit and withdrawal services, which have now resumed.
Odaily News: According to Onchain Lens monitoring, addresses associated with the Solana OG attacker (0xd229...9D15, 0x501...f051) have transferred 2,290 ETH, worth $4.39 million, to Tornado Cash. This operation occurred nearly a month after the $14.2 million attack incident; the same cluster of addresses also used Tornado Cash two weeks ago.
On-chain data shows that the address labeled as the Aztec attacker has deposited another 300 ETH into Tornado Cash, worth approximately $572,000. To date, the address has transferred a total of 500 ETH to Tornado Cash.