News linked to both this project and an event.
According to an official post from Midnight Foundation (@midnightfdn), the Wanchain Cardano<>BNB cross-chain bridge suffered a security attack. Currently, multiple major exchanges including KuCoin, Kraken, Binance, Bybit, OKX, and MEXC have responded rapidly, taking preventive measures to restrict the flow of stolen assets, including freezing relevant accounts and addresses, blacklisting the attacker's wallets, and suspending NIGHT token deposit and withdrawal services. The exchanges confirmed that this incident is an isolated third-party bridge vulnerability and is unrelated to the Midnight Network mainnet and the NIGHT asset itself.
the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.
Odaily Odaily A new study by the Cambridge Centre for Alternative Finance reveals that approximately 31% of Ethereum node activity is located in the United States, with another 39% distributed across EU countries excluding the UK, indicating that the geographic distribution of Ethereum nodes remains relatively concentrated in Western nations.Lead researcher Alexander Neumuller stated that while node distribution is not currently concentrated in any single country, it is heavily reliant on a few major cloud service providers, including Hetzner, Amazon AWS, and OVH. Notably, the Ethereum network does not require half of its validators to fail for problems to arise. If more than one-third of validators go offline simultaneously, the network may be unable to finalize block checkpoints (finalization). Neumuller pointed out that nodes and validators do not have a one-to-one correspondence; a single node may run multiple validators. Therefore, it is currently impossible to precisely assess the actual impact on the validator network from the failure of a specific node or service provider.Furthermore, the study reassessed the energy consumption of Ethereum following The Merge. Data shows that Ethereum's current annual energy consumption is approximately 7.9 GWh, equivalent to a continuous power draw of about 1 MW. This represents only about 0.02% of pre-merge levels, a reduction of approximately 99.98%. Currently, over 56% of the energy used by the Ethereum network comes from sustainable sources, exceeding the global average.The study also noted that client software diversity is another potential risk. If a dominant client software has a vulnerability, it could affect a large number of network participants. The report was published by the Cambridge Centre for Alternative Finance and supported by the Ethereum Foundation. (The)
According to CoinDesk, the Ethereum Foundation recently disclosed that its security team used AI agents to test the software running on Ethereum validator nodes and successfully discovered a vulnerability that could be triggered remotely, causing node crashes. However, researchers emphasized that amidst the large volume of security reports generated by AI, manual review remains a key step in distinguishing real vulnerabilities from false positives. Reportedly, the vulnerability discovered resides in the Ethereum network message propagation protocol gossipsub, where attackers can remotely trigger the node software into an abnormal computation state, causing the program to crash and shut down, taking the validator node offline until the operator manually restarts it. The vulnerability has been fixed and registered under the number "CVE-2026-34219". Nikos Baxevanis, a member of the Ethereum Foundation Protocol Security Team, stated that the truly surprising aspect of this incident was not the AI's ability to discover vulnerabilities, but the significant amount of time the team spent distinguishing which vulnerabilities were real and which were merely plausible "hallucinations".
researchers from the Ethereum Foundation Protocol Security team said in a blog post on Thursday that they have deployed a series of AI agents to test the software relied upon by Ethereum, searching for vulnerabilities in encryption systems, protocol code, and smart contracts. The vulnerabilities discovered by the AI agents include a remotely triggerable panic issue in the libp2p gossipsub peer-to-peer layer used by Ethereum consensus clients. The issue has been fixed and disclosed on Github as CVE-2026-34219. Researchers stated that the AI agents are organized into specialized roles such as reconnaissance, search, patching, and verification, used to find potential attack paths, reproduce faults, and verify their applicability to production code. The Ethereum Foundation stated that AI has not replaced security researchers but has changed the way they work, enabling the team to cover far more scope than manual review. However, it requires researchers to exercise more careful judgment when evaluating a large number of seemingly credible conclusions. (Decrypt)
US President Trump signed two executive orders on Monday aimed at accelerating the nation's quantum computing capabilities and advancing the migration of government systems to post-quantum cryptography. While the orders do not directly mention Bitcoin, industry insiders believe this could benefit blockchain post-quantum security research and development.The two executive orders focus on defending against advanced cryptographic attacks and driving the frontier of quantum innovation. This includes a clear timeline: advancing quantum sensor construction by September 2028, and requiring federal high-value assets and high-impact systems to complete their post-quantum cryptography migration by the end of 2031.Alex Pruden, CEO of Project Eleven, stated that this means the US government will allocate funds and time to achieve post-quantum security goals. It may also extend these requirements to the entire federal contractor system, not just government agencies, thereby accelerating the practical application of post-quantum cryptographic technology.This policy comes amid growing attention within the blockchain industry to quantum threats. The Ethereum Foundation, Solana Foundation, and others have already begun advancing post-quantum security R&D, while the Bitcoin community is also discussing potential risks. Some Bitcoin held in publicly exposed addresses is considered vulnerable to private key derivation attacks once sufficiently powerful quantum computers emerge.Pruden noted that this executive order sets a clear deadline of 2031 for the adoption of post-quantum cryptography, which is more enforceable than the previous US government guidance which only proposed phasing out traditional cryptographic systems by 2035. For Bitcoin and the broader crypto industry, government-level investment in post-quantum security could accelerate the maturation of related tools, standards, and migration pathways.
according to Aztec Labs monitoring, the team is investigating a potential vulnerability affecting an Aztec payments product that was discontinued in 2021. Approximately $2 million was transferred from an immutable smart contract. This discontinued product is an immutable Stage 2 Rollup version that was deactivated in 2022. Aztec Labs does not hold the admin keys or any control over the system, and thus cannot pause or upgrade it. This incident is separate from the attack on the Aztec Connect product on June 14. The Aztec Foundation stated that the product affected by this attack is not associated with any smart contracts of the current network or the AZTEC ERC20 token.
Odaily Zcash founder Zooko Wilcox posted on X stating that a security audit conducted by Anthropic's Claude Mythos AI model did not find any "more severe vulnerabilities" in the Zcash protocol. The audit was commissioned by Shielded Labs, a Swiss non-profit organization supporting Zcash development. On June 3, Zcash developers temporarily paused Orchard transactions after discovering a vulnerability in the shielded pool, restoring functionality through an emergency upgrade the same day. The issue stemmed from a four-year-old forging vulnerability in the Orchard shielded pool, identified by security researcher Taylor Hornby with the assistance of Anthropic's Claude Opus 4.8 model. The Zcash Foundation stated there is no evidence that the vulnerability was exploited, nor was any unauthorized value creation detected, and user privacy remained unaffected.Anthropic released the first public version of the Claude Mythos model, Fable 5, on Tuesday, and stated on Friday that it has suspended access to the Fable 5 and Mythos 5 AI models due to export control directives issued by the U.S. government citing national security concerns. (Cointelegraph)
According to Cointelegraph, Zcash founder Zooko Wilcox stated that a security audit of the Zcash protocol—commissioned by Shielded Labs and conducted using Anthropic’s Mythos AI model—did not uncover any new critical vulnerabilities. Previously, security researcher Taylor Hornby discovered, using Claude Opus 4.8, a four-year-old forgery vulnerability in the Orchard shielded pool, prompting developers to urgently suspend Orchard transactions on June 3 and complete the fix the same day. The Zcash Foundation confirmed there is no evidence the vulnerability was ever exploited, and user privacy remained unaffected.
A cryptography expert advisory committee led by Coinbase released a report stating that Bitcoin should immediately begin preparing for potential quantum computing attacks. However, the committee did not take a clear stance on whether to freeze the millions of bitcoins potentially vulnerable to quantum-computing theft in the future. The committee includes several leading experts, such as Justin Drake, a researcher at the Ethereum Foundation. They argue that the current debate is not about *how* to introduce quantum-resistant signature schemes, but rather *how to handle* bitcoins held in long-dormant addresses that fail to migrate. One camp advocates setting a final deadline after which Bitcoin’s existing ECDSA and Schnorr signature schemes would no longer be supported, and unmigrated funds would be frozen—thereby preventing future quantum attackers from seizing large amounts of BTC and destabilizing markets. The other camp contends that freezing funds would effectively amount to asset confiscation, violating Bitcoin’s core principles of immutability and full user control over assets—and could set a precedent for future regulatory-driven freezes. The Coinbase advisory committee notes that these approaches are not mutually exclusive and could be combined. Yet it declines to state a position on whether “legacy BTC” should be frozen, asserting that the ultimate decision rests with Bitcoin’s community governance. It emphasizes two key points: first, technical development of quantum-resistant signature migration must begin immediately—not wait for governance debates to conclude; second, users must receive clear, timely risk communication to prevent prolonged uncertainty from harming the Bitcoin ecosystem.
The Zcash Foundation released Zebra versions 4.5.3 and 5.0.0 to address a critical soundness vulnerability in the Orchard zero-knowledge proof circuit. Version 4.5.3 temporarily disables Orchard operations via an emergency soft fork, while version 5.0.0 activates NU 6.2, re-enables Orchard using the patched circuit, and permanently closes the vulnerability.
Odaily news: The Zcash Foundation has announced the release of Zebra 4.5.1 version update to fix a consensus-critical security vulnerability and strongly recommends that all node operators upgrade immediately. The vulnerability, identified as GHSA-2prc-cj5x-4443, involves a sigops (signature operation count) counting error in P2SH transactions, which could lead to potential consensus fork risks. This fix corrects an incomplete patch in the previously released 4.5.0 version, which was just released yesterday.The Zcash development team stated that the issue stems from discrepancies in sigop counting logic between different implementations, which could cause nodes to produce different results when verifying transactions, thereby affecting consensus consistency on the chain. The fix resolves this by reverting and adjusting the Rust implementation logic to ensure alignment with the expected protocol behavior.The Zcash Foundation emphasized that there is currently no workaround for this issue, and upgrading to 4.5.1 is the only method to ensure nodes remain on the correct chain and avoid potential fork risks.
According to The Block, the Sui Foundation released an incident report on May 31, disclosing three consecutive outages on its mainnet from May 29 to 30—each traced back to two independent bugs introduced in the v1.72 upgrade. The first two outages were caused by a gas fee calculation error stemming from the newly launched “address balance” feature: funds were deducted even when transactions were canceled, resulting in negative account balances and subsequent validator node crashes. The third outage was triggered by a latent vulnerability in the random number generator during node restarts, preventing the network’s epoch from closing normally. The Sui Foundation stated that all known issues have now been resolved; user funds remained unaffected throughout the incidents, and no settled transactions were rolled back. The Foundation plans to further enhance its fault-tolerance mechanisms to ensure future similar bugs impact only individual transactions—not the entire network.
: The Zcash Foundation has released version 4.5.0 of its node client, Zebra. This update includes multiple security fixes, addressing a critical consensus vulnerability and several high-severity Denial of Service (DoS) issues. All node operators are strongly urged to upgrade immediately.Key fixes in this release include a sigop counting error in P2SH script parsing (which could cause a consensus fork with zcashd), a logic flaw in NU5 block validation caching, a crash risk related to transparent address balance overflow, along with multiple crash and resource exhaustion vulnerabilities in RPC interfaces and mempool processing. The Foundation stated that some vulnerabilities could be exploited by malicious nodes, leading to node stalls, restart loops, or even permanent stoppage.Additionally, this version adds support for ZIP-213 (enabling shielded coinbase outputs to Sapling) and optimizes network performance and security boundaries. This includes limiting resource allocation during the pre-handshake phase, fixing risks related to multi-threaded queue abuse, and enhancing the misbehavior scoring mechanism.The Zcash Foundation stated that this update addresses over 80 security reports from the ZCG Vulnerability Disclosure Program (spanning April to May 2026), covering multiple layers including consensus security, memory management, RPC processing, and the P2P network attack surface. Officials emphasized that there is no alternative to this upgrade; upgrading is the only way to ensure nodes do not experience a chain split and remain secure.
The Resolv Foundation has announced its recovery plan following the protocol security incident. USR/wstUSR tokens held and snapshot-recorded prior to the incident will be redeemed for USDC at a 1:1 ratio, while USR/wstUSR acquired after the incident will be redeemed at a 1:0.5 ratio. RLP holdings will be restored at a core redemption rate of 0.71 USDC per token, with additional RESOLV token allocations based on a reference price of $0.03. The Foundation stated that eligible users may claim their recovery funds between May 26, 2026, and August 26, 2026.
the Saturn Foundation officially posted on X, stating that it has blacklisted addresses related to the Squid hacker incident and frozen the stolen funds. Affected users can submit tickets on Saturn's official Discord server.None of Saturn's contracts or infrastructure were affected by this incident.
the Compound Foundation stated on X platform that, in coordination with the Kelp and Aave teams, and to avoid disrupting broader DeFi recovery efforts, the Comet markets for WETH and wstETH on Ethereum have resumed trading. It also noted that depending on the specific timing of Kelp's thawing of rsETH, temporary suspensions may still occur in relevant markets during the liquidation window for vulnerability-related positions. Specific arrangements have yet to be determined.
The Zcash Foundation officially announced the release of Zebra 4.4.0, which addresses multiple critical consensus-level security vulnerabilities. All node operators are strongly advised to upgrade immediately. The vulnerabilities include a denial-of-service (DoS) flaw that could permanently halt the discovery of new blocks; a signature operation (sigop) counting error in block validation that may cause consensus divergence; abnormal handling of transparent transaction signature hashes; and a memory allocation amplification attack risk. The Zcash Foundation stated that some of these vulnerabilities could cause Zebra nodes to accept blocks rejected by zcashd, potentially triggering a chain fork. Without timely upgrades, nodes risk interruption of block discovery, consensus forks, and amplified resource consumption. No alternative mitigations are currently available.
Odaily, Berachain Foundation issued a warning on the X platform, stating that the Wasabi Protocol experienced a cross-chain security incident due to a deployer's private key leak, which has impacted multiple blockchains including Berachain. To prevent the risk from spreading, Berachain has suspended and blacklisted all affected Wasabi Reward Vaults within its network, immediately halting the distribution of BGT staking rewards to the compromised contracts and blocking the flow of new BGT into the affected vaults.The official team requires all users who have previously interacted with Wasabi on Berachain to immediately revoke token approvals for the specified contracts to avoid the risk of asset theft. Berachain also emphasized that the BGT reward funds within the native Reward Vaults remain secure and users can claim them normally; this incident does not affect core ecosystem interests.
According to an official disclosure by Aftermath Finance, the protocol expects to complete full compensation to users within the next 48–72 hours. The team is currently working at full capacity to return funds and expresses its gratitude for users’ patience. Earlier reports indicated that the perpetual contract protocol Aftermath Finance was exploited via a vulnerability yesterday, resulting in losses of approximately $1.14 million. The Sui Foundation, in collaboration with Mysten Labs, stated it will actively assist Aftermath Finance in recovering user funds and is committed to ensuring the continued operation of the Aftermath protocol.