News linked to both this project and an event.
according to official sources, OKX, in collaboration with Elliptic, SlowMist, and OttoSec, has released the "H1 2026 Web3 Security and Risk Control Report." The report indicates that the focus of Web3 attacks is shifting from smart contract code to more complex scenarios such as signature processes, user devices, operational infrastructure, and AI Agents.Data shows that in the first half of 2026, OKX's risk control system intercepted over 5.7 million high-risk transactions, including approximately 2.41 million related to hacking and theft, about 1.48 million phishing-related transactions, and roughly 990,000 fraud-related transactions. OKX Web3's on-chain intelligence label library now boasts over 1.1 billion labels, covering more than 420 chains. It has also integrated capabilities such as address screening, transaction monitoring, and sanctioned address control into infrastructure like DEX and Exchange OS.Furthermore, in terms of user protection, OKX has intercepted over 7 million risky website visits, completed more than 200,000 device risk detections, identified over 60,000 high-risk Apps, and blocked or alerted on over 4 million high-risk signature operations. The report also introduces the "proactive risk control" design in scenarios such as Exchange OS, Outcomes, RWA, and Agentic Wallet.
Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.
Odaily Odaily A new study by the Cambridge Centre for Alternative Finance reveals that approximately 31% of Ethereum node activity is located in the United States, with another 39% distributed across EU countries excluding the UK, indicating that the geographic distribution of Ethereum nodes remains relatively concentrated in Western nations.Lead researcher Alexander Neumuller stated that while node distribution is not currently concentrated in any single country, it is heavily reliant on a few major cloud service providers, including Hetzner, Amazon AWS, and OVH. Notably, the Ethereum network does not require half of its validators to fail for problems to arise. If more than one-third of validators go offline simultaneously, the network may be unable to finalize block checkpoints (finalization). Neumuller pointed out that nodes and validators do not have a one-to-one correspondence; a single node may run multiple validators. Therefore, it is currently impossible to precisely assess the actual impact on the validator network from the failure of a specific node or service provider.Furthermore, the study reassessed the energy consumption of Ethereum following The Merge. Data shows that Ethereum's current annual energy consumption is approximately 7.9 GWh, equivalent to a continuous power draw of about 1 MW. This represents only about 0.02% of pre-merge levels, a reduction of approximately 99.98%. Currently, over 56% of the energy used by the Ethereum network comes from sustainable sources, exceeding the global average.The study also noted that client software diversity is another potential risk. If a dominant client software has a vulnerability, it could affect a large number of network participants. The report was published by the Cambridge Centre for Alternative Finance and supported by the Ethereum Foundation. (The)
an Immunefi report shows that in the first half of 2026, crypto projects suffered cumulative losses of approximately $972 million from 207 hacker attacks. The number of attacks reached a record high, but total losses remained under $1 billion and were less than half the scale of losses in the first half of 2025. The report notes that DeFi attack losses have dropped by 74% from their peak of $2.62 billion in 2022, falling to approximately $680.3 million, with the median single-loss amount declining by 75% over the same period. Furthermore, the source of risk is shifting from purely smart contract vulnerabilities towards infrastructure failures, private key leaks, cross-chain configuration errors, and weaknesses in privileged access.
Odaily, Web3 security firm CertiK has released the "Hack3D: First Half of 2026 Report." The report shows that the Web3 ecosystem experienced 344 security incidents in the first half of 2026, with cumulative losses of approximately $1.32 billion. Although this figure represents a 46.8% decrease compared to the same period last year, excluding the impact of the $1.45 billion security incident involving Bybit, the scale of losses in the first half of this year actually increased by approximately 28% year-on-year, indicating that the overall security environment in the industry has not materially improved.The report points out that wallet theft has become the attack type causing the greatest financial loss, accounting for approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks fell by more than 50% year-on-year, the loss amount only decreased by approximately 10.8%, reflecting that attackers are shifting towards high-net-worth individuals and institutional targets, carrying out more targeted high-value attacks.Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running legacy smart contracts that lack re-audits. The report also shows that mega-attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents alone causing approximately $577 million in losses, accounting for 44% of the total losses in the first half of the year. Looking at the number of incidents, the impact of single attacks, and the changing attack patterns, the Web3 industry is facing more complex and continuously escalating security challenges.
: Cardano wallet service provider SecondFi has released an update on the security incident recovery progress, stating that EMURGO has established an asset recovery fund to return assets to users affected by the attack.SecondFi stated that emergency measures have been taken to protect and restore access to some assets. The team is currently discussing appropriate custody mechanisms with Intersect to ensure the safe return of assets to users.Furthermore, SecondFi is collaborating with a Cardano community-led working group to advance the on-chain recovery plan. Due to the recovery plan being more complex than initially expected, the overall recovery time may exceed the previously estimated two weeks.
Odaily Odaily News Blockchain analyst Vadim noted that Base experienced a network outage today due to a consensus bug triggered by a single invalid block. All block generation after height 47806542 ceased, halting the network for nearly two hours. Since Base utilizes a single sequencer architecture, when that node encountered an error, the entire network stopped running, with no backup block producer or other validator nodes available to bypass the fault and maintain on-chain activity. During the outage, users were unable to conduct transactions, perform liquidations, or process withdrawals.Furthermore, the network recovery process was not automated; node operators within the ecosystem had to manually restart for block synchronization to gradually resume. This is not the first such incident for Base. In August of last year, the network also experienced a freeze lasting approximately 33 minutes due to a sequencer switching failure. The single sequencer model exposes the centralization risks in some current L2 networks: while offering higher speed, the entire chain can come to a halt due to a single point of failure when the core component malfunctions.
Ethereum Layer 2 project Taiko has released the latest update on a security incident, stating that this incident will not result in any user fund losses. Currently, bridged assets are under-collateralized, and the team will complete supplementary collateral for all assets before reopening the bridge, ensuring that each user's balance is supported on a 1:1 basis, identical to the state before the incident. Since the security incident occurred, cautious measures have been taken, including controlling the scope of impact, determining the root cause, and collaborating with the board to develop a plan to protect user assets.Furthermore, the CEO of Taiko has submitted a formal report to relevant authorities in Singapore, and the team will fully cooperate in tracing the responsible parties. Users are currently not required to take any action. The completed fix is now being tested, and Taiko will reopen the chain and bridge services as soon as it is deemed safe. Meanwhile, users are reminded to be vigilant against scams. The Taiko team will not proactively message users, and there are no claim or refund websites. Any links offering such services are fraudulent.
: Cross-chain protocol Axelar Network has issued a statement regarding the recent security incident related to Secret Network, clarifying that there is a misunderstanding within the community. Neither Axelar nor the Inter-Blockchain Communication Protocol (IBC) was attacked or compromised. The affected token smart contract was not developed, deployed, or maintained by Axelar. Furthermore, Axelar's firewall mechanism prevented the impact from spreading to other chains.It is reported that the exploited contract was a fork based on the CW20-ICS20 implementation, but the developers removed two core security checks, leading to an "infinite mint" vulnerability. By deleting the verification mechanisms originally designed to prevent such issues, this fork altered the contract's original trust model and was not subjected to a new security audit.Axelar Network explained that anyone can deploy contracts via IBC for wrapping cross-chain assets, and similar contracts are used to wrap tokens from other chains onto Secret Network. However, the specific fork on the Secret side in this incident contained a vulnerability due to the removal of critical security checks. This incident was not caused by an inherent logic flaw or an issue with the IBC protocol itself, but rather a security risk introduced by modifications made to the third-party contract.
SUPERFORTUNE AI posted on X platform, stating that the team is investigating a GUA security incident that occurred on May 27. The incident led to drastic price fluctuations in the token. Preliminary investigations suggest the incident may involve address tampering during a multi-signature transaction.The announcement states that the original plan was to send additionally unlocked tokens to the airdrop claim contract address. However, during execution, the funds were mistakenly sent to a different hacker address. The team noted that this hacker address had never interacted with any SUPERFORTUNE-related addresses before, making an "address poisoning attack" less likely as the attack vector.Furthermore, SUPERFORTUNE stated that its internal processes include a multi-layered address verification mechanism. The team is continuing its investigation into the incident and will update the community on the latest developments subsequently.
Syndicate, a DAO infrastructure service provider, has announced it will gradually cease operations. It stated that after five years of continuously building on-chain developer infrastructure, the Rollup market has undergone fundamental changes. Currently, the Rollup market has significantly shrunk, some Rollup projects are gradually shutting down, and the market has shifted from EVM Rollups to custom chains built from scratch by consulting teams, leading to a notable decline in reusable technology and network value.Syndicate stated that its system consists of two parts: Syndicate Labs, responsible for development, will be closed, while the independent entity Syndicate Network Collective (Wyoming DUNA), which holds SYND tokens and has governance rights, will continue to exist. SYND governance will not be affected in the short term.Furthermore, Syndicate emphasized that this decision to cease operations is unrelated to recent cross-chain security incidents. Affected users and SYND holders have been fully compensated through the treasury reserves, and team and investor tokens are currently still in a lock-up period.
According to The Block, JPMorgan analysts noted in their latest report that ongoing DeFi security vulnerabilities and stagnant growth in total value locked (TVL) continue to constrain institutional enthusiasm for the DeFi sector. Recently, Kelp DAO’s cross-chain bridge suffered a major attack, during which the attacker minted $292 million worth of uncollateralized rsETH tokens and borrowed real ETH on Aave, resulting in approximately $230 million in bad debt. This caused DeFi TVL to evaporate by roughly $20 billion within several days. LayerZero and blockchain security researchers have attributed this attack to the North Korean hacker group Lazarus Group; some of the stolen funds have been frozen, while the rest remain in circulation. Analysts also pointed out that DeFi TVL denominated in ETH has remained range-bound for an extended period, raising market concerns about whether DeFi can achieve organic growth sufficient to support institutional adoption. Furthermore, following each security incident, users tend to shift funds into USDT as a safe-haven asset—yet this trend has not yet significantly driven USDT’s market capitalization growth.
Odaily News: The UK Financial Conduct Authority (FCA), in collaboration with HM Revenue & Customs and the South West Regional Organised Crime Unit, recently conducted raids on eight locations across the UK suspected of engaging in illegal P2P cryptocurrency trading. Officials issued prohibition orders on-site, requiring the operators to cease activities immediately and gathered relevant evidence. The UK FCA pointed out that currently, no P2P cryptocurrency traders or platforms are registered with the regulator in the UK. Furthermore, in the recent multi-agency Operation Atlantic, law enforcement agencies froze $12 million in assets linked to cryptocurrency scams and traced over $45 million in stolen cryptocurrency. The UK FCA has now launched a consultation on its guidelines for the cryptocurrency regulatory framework set to take effect in 2027.
Odaily News Cryptography engineer Filippo Valsorda wrote an article pointing out that the impact of quantum computing on current cryptographic systems is mainly concentrated on asymmetric algorithms (such as ECDSA, RSA, etc.), while its effect on symmetric encryption (like AES, SHA series) is limited. Grover's algorithm does not significantly weaken the security of 128-bit keys in practical scenarios.Although Grover's algorithm can theoretically accelerate brute-force attacks, it is difficult to parallelize, making the actual attack cost extremely high. Even under ideal quantum computing conditions, the resources required to break AES-128 are far greater than the cost of using Shor's algorithm to attack elliptic curve encryption.Furthermore, standards bodies including the National Institute of Standards and Technology (NIST) unanimously agree that AES-128 still meets post-quantum security requirements and does not need to be upgraded to 256-bit keys. Industry views suggest that focusing resources on replacing asymmetric encryption schemes vulnerable to quantum attacks is a more urgent task at present.
Odaily News Trader 0xSun posted stating that news-driven trading remains one of the more cost-effective strategies in the current crypto market, with its core lying in the directionality and volatility brought by events.Reviewing several recent events, including abnormal ETH transactions, Arc fee adjustments, TAO ecosystem changes, RAVE-related investigations, and the KelpDAO security incident, all triggered significant price fluctuations within a short period. He believes that participating in such opportunities relies on either the speed of information acquisition or the ability to judge the impact of events.Furthermore, he indicated that as the recent altcoin market has gradually cooled down, he has resumed the strategy of going long on BTC while hedging by shorting some altcoin assets. He believes that against the backdrop of relatively weak liquidity and the fading of certain narratives, the overall performance of altcoins may face relatively more pressure.
Odaily News: Sonic Labs co-founder and Flying Tulip founder Andre Cronje posted on platform X, stating that his team is continuing to investigate the L0/rsETH incident. Preliminary reports indicate that approximately $200 million worth of rsETH was stolen, possibly due to a private key leak or configuration error. The related assets were subsequently deposited into Aave as collateral to borrow ETH (due to insufficient rsETH liquidity).Andre Cronje pointed out that the affected positions are technically still overcollateralized. However, if bad debt occurs, Aave's token mechanism and Safety Module will serve as the first line of defense to absorb the risk. Nevertheless, Aave has no mechanism to subsidize user losses, as doing so could trigger a bank run. Currently, Aave holds approximately $7 billion in ETH with an outstanding borrowing amount of around $100 million, so the overall impact of this incident is limited. Furthermore, prioritizing user liquidity, Flying Tulip has withdrawn all its ETH from Aave to its fund management wrapper contract. This action was taken because Aave's available liquidity had fallen below its set minimum threshold.