News linked to both this project and an event.
US President Trump signed two executive orders on Monday aimed at accelerating the nation's quantum computing capabilities and advancing the migration of government systems to post-quantum cryptography. While the orders do not directly mention Bitcoin, industry insiders believe this could benefit blockchain post-quantum security research and development.The two executive orders focus on defending against advanced cryptographic attacks and driving the frontier of quantum innovation. This includes a clear timeline: advancing quantum sensor construction by September 2028, and requiring federal high-value assets and high-impact systems to complete their post-quantum cryptography migration by the end of 2031.Alex Pruden, CEO of Project Eleven, stated that this means the US government will allocate funds and time to achieve post-quantum security goals. It may also extend these requirements to the entire federal contractor system, not just government agencies, thereby accelerating the practical application of post-quantum cryptographic technology.This policy comes amid growing attention within the blockchain industry to quantum threats. The Ethereum Foundation, Solana Foundation, and others have already begun advancing post-quantum security R&D, while the Bitcoin community is also discussing potential risks. Some Bitcoin held in publicly exposed addresses is considered vulnerable to private key derivation attacks once sufficiently powerful quantum computers emerge.Pruden noted that this executive order sets a clear deadline of 2031 for the adoption of post-quantum cryptography, which is more enforceable than the previous US government guidance which only proposed phasing out traditional cryptographic systems by 2035. For Bitcoin and the broader crypto industry, government-level investment in post-quantum security could accelerate the maturation of related tools, standards, and migration pathways.
According to on-chain analyst Onchain Lens (@OnchainLens), the attacker behind the well-known MEV bot Jaredfromsubway laundered 2,000 ETH via Tornado Cash, worth approximately $3.44 million at current prices.
Ethereum Layer 2 blockchain Taiko has stated its chain state verification mechanism has been compromised, and the security assumptions of all bridges deployed on Taiko can no longer be relied upon. It urges users to immediately withdraw funds from the relevant bridges. Taiko says it is coordinating with partners to control the incident and has suspended the affected systems.Crypto security firm Blockaid stated that the root cause appears to be a flaw in the way Taiko's bridge validates source signals. Attackers can submit message proofs on Ethereum that lack legitimate proof from the Taiko chain, thereby registering and withdrawing fraudulent bridge messages. This leads to the unauthorized release of assets from the ERC20 treasury. Blockaid estimates at least $1 million was stolen, while Lookonchain and PeckShield believe the value of stolen assets could be as high as $1.7 million.PeckShield reported that the attacker has transferred approximately 1.99 million TAIKO tokens to MEXC, valued at around $189,000. Data from blockchain intelligence firm Arkham shows that the Taiko attacker's wallet holds approximately $1.5 million in assets, primarily in Ether. (Cointelegraph)
Odaily Odaily reports: Well-known MEV sniper ae13 has posted a white hat bounty on-chain: "Well done. If you return 2,150 ETH to this address within 48 hours, we are willing to pay a 50% white hat bounty; otherwise, we will pursue all available legal and enforcement measures to hold you accountable."According to previous reports, the long-active Ethereum MEV bot Jaredfromsubway.eth (ae13) was attacked by hackers exploiting vulnerabilities in its automated execution system, resulting in losses exceeding $7.5 million.Recommended reading: When the hunter becomes the hunted: the most profitable MEV Bot gets hacked.
Blockaid monitoring reported that Taiko’s ERC-20 treasury on Ethereum was attacked, resulting in losses exceeding $1 million. Preliminary analysis suggests the issue may stem from a vulnerability in Taiko’s cross-chain bridge proof verification, enabling the attacker to forge cross-chain messages and withdraw assets—causing unauthorized release of treasury funds.
According to on-chain analyst PeckShield (@PeckShieldAlert), the well-known MEV bot “JaredFromSubway” has reportedly been attacked, resulting in the theft of approximately $7.5 million worth of crypto assets—including 1,474.58 WETH, 2.87 million USDC, and 2 million USDT. The attacker has exchanged the stolen funds for 4,400 ETH and transferred 1,000 ETH to the mixer Tornado Cash to obfuscate the fund’s trail.
Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)
According to on-chain analyst Blockaid (@blockaid_), the well-known Ethereum MEV bot JaredFromSubway (@jaredsmev) has been attacked, resulting in losses of approximately $7.5 million. The attacker constructed a deceptive MEV arbitrage path to trick the bot into automatically approving token transfers. Leveraging these open approvals—before they were revoked—the attacker drained WETH, USDC, and USDT from the bot’s contract. The stolen funds ultimately flowed to the attacker’s wallet address. Blockaid noted that this attack was not a conventional phishing attempt or smart contract vulnerability, but rather a targeted exploitation of the bot’s automated execution mechanism.
according to PeckShield monitoring, the OLPC/LABUBU liquidity pool on BNB Chain's PancakeSwap was attacked. The attacker stole approximately $1.1 million worth of assets. After the incident, the attacker cross-chain transferred the stolen funds to Ethereum and subsequently deposited 633.4 ETH into the mixing protocol Tornado Cash. Additionally, the attacker sent 0.0221 BNB and 0.0411 ETH to a deprecated address. Relevant attack details and fund flows are still under continuous tracking.
on-chain security researcher Specter posted on X, stating that THORChain has not resumed normal operations for over a month after suspending all transactions due to a security vulnerability incident. The protocol previously did not choose to suspend transactions during other security incidents or suspicious fund flows; it even continued operating simple ETH-BTC paths. However, after becoming the affected party this time, it completely halted cross-chain transactions, sparking community discussion about the consistency of its risk management. Currently, THORChain on-chain trading remains completely stagnant, with almost no transactions on the entire chain. The recovery timeline remains unclear, and Specter reminds community users to "stay alert."
According to on-chain analyst PeckShield (@PeckShieldAlert), the Humanity attacker’s address has bridged 130 ETH (approximately $220,600) from Ethereum to BNB Chain (381 BNB).
Cosine, founder of SlowMist, posted on X stating that Aztec appears to have been hacked again. Aztec’s Private Rollup Bridge is suspected to have been exploited, resulting in the abnormal transfer of approximately 1,158 ETH, 150,000 DAI, and 0.46963295 renBTC, with a total value of roughly $2.15 million.
According to on-chain analyst PeckShield (@PeckShieldAlert), the address labeled as the UXLINK attacker has swapped approximately 14.6 million DAI for 8,298.6 ETH. Subsequently, this address deposited 8,340 ETH into Tornado Cash and bridged 2.64 ETH (approximately $4,630) from Ethereum to a Bitcoin address.
According to Lookonchain monitoring, over the past 30 minutes, the UXLINK attacker spent 6.5 million DAI to buy 3,686 ETH at an average price of $1,764, and laundered the funds through Tornado Cash.
Humanity has announced the $H incident recovery plan: The legacy version of H on Ethereum, BNB Smart Chain, and Humanity Mainnet has been deprecated. A new Ethereum ERC-20 version of H will be airdropped 1:1 to eligible holders based on a pre-attack snapshot. Attackers and associated addresses have been excluded.
According to PeckShield monitoring, structured products protocol ThetanutsFi has been attacked, resulting in a loss of approximately $2.1 million. Of this, roughly $2 million in option tokens have been recovered by a white hat address. The attacker has exchanged $105,000 USDC for approximately 60 ETH, and still holds USDC option tokens worth around $34,000.
in response to a suspected attack on the Aztec Router contract on the Ethereum chain, Aztec Labs has formally launched an investigation. At the same time, it clarified that Aztec Connect was deprecated three years ago, and that Aztec Labs does not hold any admin keys or control over the system, and cannot currently pause or upgrade it. Therefore, the community is advised to be wary of fake "support" accounts and direct messages.
According to on-chain analyst Yu Jin (@EmberCN), the attacker responsible for the March THE liquidation event on the Venus platform sold 1,912 ETH for $3.26 million one hour ago to repay part of their loan on Aave. That loan was originally taken out by collateralizing ETH and was used to manipulate the Venus liquidations. The attacker’s address still has $6.78 million in USDT outstanding on Aave.
A cryptography expert advisory committee led by Coinbase released a report stating that Bitcoin should immediately begin preparing for potential quantum computing attacks. However, the committee did not take a clear stance on whether to freeze the millions of bitcoins potentially vulnerable to quantum-computing theft in the future. The committee includes several leading experts, such as Justin Drake, a researcher at the Ethereum Foundation. They argue that the current debate is not about *how* to introduce quantum-resistant signature schemes, but rather *how to handle* bitcoins held in long-dormant addresses that fail to migrate. One camp advocates setting a final deadline after which Bitcoin’s existing ECDSA and Schnorr signature schemes would no longer be supported, and unmigrated funds would be frozen—thereby preventing future quantum attackers from seizing large amounts of BTC and destabilizing markets. The other camp contends that freezing funds would effectively amount to asset confiscation, violating Bitcoin’s core principles of immutability and full user control over assets—and could set a precedent for future regulatory-driven freezes. The Coinbase advisory committee notes that these approaches are not mutually exclusive and could be combined. Yet it declines to state a position on whether “legacy BTC” should be frozen, asserting that the ultimate decision rests with Bitcoin’s community governance. It emphasizes two key points: first, technical development of quantum-resistant signature migration must begin immediately—not wait for governance debates to conclude; second, users must receive clear, timely risk communication to prevent prolonged uncertainty from harming the Bitcoin ecosystem.
Odaily, Mitchell Amador, CEO of bug bounty platform Immunefi, stated at the WAIB Summit that new AI models such as Claude Opus 4.8 and ChatGPT 5.5 are shifting the balance of cybersecurity offense and defense in favor of attackers, leading to a resurgence in crypto hacks in 2026. Data from DefiLlama shows that in April 2026, illicit actors stole over $634 million from crypto platforms, the highest monthly total since the Bybit hack in February 2025 drove losses of approximately $1.4 billion.Amador stated that the crypto industry is in a critical survival period for the next three to four years until security teams leverage similar AI models to build codebases that attackers cannot breach; if the industry adopts more crowd-sourced security solutions, this timeline could be shortened to within two years. The latest Claude Mythos model, Fable 5, from AI company Anthropic, previously raised concerns about accelerating the ability to exploit crypto vulnerabilities.Anthropic stated that Fable 5 has safeguards in place that will redirect topics related to cybersecurity and similar fields to Claude Opus 4.8. On April 19, an attacker transferred approximately 116,500 restaked Ethereum (rsETH) from Kelp DAO's LayerZero-based rsETH bridge, valued at around $290 million to $293 million at the time. Cross-chain protocol LayerZero stated that the 1/1 decentralized verification network configuration of Kelp DAO relied on a single verification path for processing cross-chain messages, creating a single point of failure. (Cointelegraph)