News linked to both this project and an event.
Odaily reports: Italian cybercrime police are investigating a government email security incident linked to a Revolut customer data breach, involving suspected unauthorized access to computer systems and computer fraud.The accounts involved are said to belong to Italy's Certified Email System (PEC). Revolut did not confirm which government agency the compromised accounts belonged to, but said it has reported the incident to Italian authorities and that its systems, databases, and customer funds were not affected.Italy's CERT-AGID cybersecurity agency warned in June that PEC only certifies email delivery and does not guarantee the security of email contents. The agency said it has handled over 650 cases of abused or illegal PEC accounts since the beginning of 2026. (Cointelegraph)
Empowa, a Cardano ecosystem project, disclosed two interrelated unauthorized asset transfer incidents across its three project wallets. Between November 2025 and June 2026, approximately 143,710 ADA were transferred out of one project treasury wallet in 18 transactions. The corresponding Midnight airdrop for this wallet was also registered and claimed by an unknown party using the private key, with approximately 36,000 NIGHT already transferred away. From June 2026 to August 2026, a cumulative total of approximately 4.24 million EMP tokens were transferred out of the other two project wallets, with portions sold via platforms such as Minswap and VyFi. Empowa stated that the funds from both incidents ultimately flowed into the same intermediate wallet, indicating they are controlled by the same party, although the identity of the individuals operating these private keys cannot currently be confirmed. The team has hired a professional blockchain investigation firm and plans to seek KYC information from the centralized exchange where the related funds ultimately entered.
Odaily News: The sandwich attack bot operated by JaredfromSubway.eth has extracted a cumulative total of 117,007 ETH since March 2023, worth approximately $295 million at current prices. In June 2026, an anonymous attacker deployed 66 counterfeit token contracts, exploiting the bot's automated trading logic to steal at least $7.5 million in ETH and stablecoins, and funneled the funds into Tornado Cash. The stolen assets have not yet been recovered.Sandwich attacks are a form of Maximal Extractable Value (MEV): the bot monitors large transactions in Ethereum's public mempool, buys ahead of the target transaction, and sells after the transaction pushes the price up, capturing profits from the spread. The bot's primary contract had received a cumulative total of 117,007 ETH as of August 28.MEV-Boost block construction is centralized among a small group of participants, with relay.ultrasound.money, Titan Relay, and bloXroute regulated relays collectively forwarding approximately 85% to 88% of related blocks within a 24-hour window; Titan's builder independently assembled 50.3% of the blocks. Monthly sandwich attack extraction amounts have declined from approximately $10 million in late 2024 to roughly $2.5 million in October 2025. (Bitcoin.com News)
1inch and HackenProof have jointly released the first-half 2026 Bug Bounty Report. The report shows that from January to June 2026, 1inch received a total of 1,055 submissions from security researchers across its 6 core bug bounty programs on HackenProof, of which 32 were rewarded.
Odaily News - Digital asset manager Grayscale's Zcash ETF began trading on NYSE Arca on Tuesday under the ticker ZCSH. The product is the world's first exchange-traded product offering spot exposure to Zcash, allowing investors to track ZEC prices through securities accounts without needing to directly purchase or store the token.ZCSH was formerly known as the Grayscale Zcash Trust, established in October 2017 through a private placement. Grayscale filed an application with the U.S. Securities and Exchange Commission in November 2025 to convert the trust into an ETF, with shareholders holding shares that track the fund's ZEC holdings rather than holding ZEC directly.In May of this year, security researcher Taylor Hornby, using Anthropic's Claude Opus 4.8, discovered a vulnerability in Zcash's Orchard shielded pool that had existed for four years, which could potentially allow attackers to mint counterfeit ZEC. Developers deployed an emergency patch on June 1, but due to privacy mechanisms, it was not possible to cryptographically confirm whether the vulnerability had been exploited.Zcash activated the Ironwood upgrade in July, replacing Orchard with a new shielded pool and introducing accounting rules that limit the amount of ZEC exiting the old shielded pool to no more than the amount entering. Grayscale stated it will monitor the adoption of the Ironwood upgrade, network security, exchange support, and regulatory conditions for privacy assets. (Decrypt)
According to a post by ZachXBT, after reviewing relevant evidence, he stated that two U.S. investment platforms, BitcoinIRA and iTrustCapital, are suspected of having suffered data breaches this year, though neither appears to have publicly disclosed the incidents to date. The compromised data reportedly includes user profiles, portfolio holdings, banking information, custodian details, and verification statuses. ZachXBT noted that in June 2026, an attacker leveraged information from the relevant database to target a BitcoinIRA user, stealing more than $1.2 million in assets.
According to Cryptopolitan, cybersecurity firm Adversa AI has disclosed that xAI's AI assistant Grok contains a security vulnerability known as "Encrypted Context Injection." Attackers can embed encrypted commands within standard web pages. When a user requests Grok to summarize such a page, Grok automatically decrypts and executes the hidden command, forwarding the user's name, geographic location, subscription tier, and complete chat history to the attacker's server. The vulnerability was reported to xAI through the HackerOne platform on June 3, 2026. Researcher Rony Utevsky followed up on August 4 and August 10, respectively. However, as of August 19, the vulnerability remains unpatched on Grok.com, and xAI has not provided a timeline for a fix.
Odaily News: The French Finance Minister has confirmed that hackers breached the systems of the French Public Finance Directorate in late June and stole taxpayer data belonging to individuals and businesses. According to FrenchBreaches, a platform that tracks cyberattacks in France, this incident affects approximately 678,437 people, roughly 1% of France's population, though the exact number is still under investigation and has not been finalised.The compromised data reportedly includes sensitive information such as names, dates of birth, home addresses, phone numbers, email addresses, tax identification details, and income data. Among those affected, nearly 27,000 individuals had taxable income of at least €100,000, 386 exceeded €1 million, and another 8 surpassed €10 million.Reports indicate that the database has been listed for sale on dark web marketplaces for several thousand euros. The attacker, going by the name ZeroBytes, claims to have extracted the records using an internal search tool before being detected and having access cut off.The incident has raised concerns within the crypto industry, as France has seen a noticeable increase in "wrench attacks" targeting crypto holders in recent years. If high-income individuals' addresses and contact details are exposed, it could provide criminals with a more precise list of targets.
: Cardano ecosystem wallet project SecondFi has announced the launch of a wallet migration tool and revealed a recovery plan for assets affected by the June 2026 security incident. As the project will cease operations, users are required to migrate remaining assets still held in SecondFi wallets. The migration tool is expected to go live on August 13, supporting the transfer of eligible ADA, Cardano native tokens, and NFTs to new Cardano wallets created with service providers of the users' choosing. Currently, the tool only supports Cardano network assets; non-Cardano assets must be transferred separately through corresponding network and wallet processes. SecondFi stated that the migration tool has passed an independent security assessment by security firm Bitdefender. For affected assets, SecondFi plans to launch a recovery portal before September 10, where users can verify wallet ownership via zero-knowledge proofs (ZK Proof) and submit asset claims. SecondFi reminds users to only rely on information published through official channels, including @secondfiapp, @secondfi_jp, and the official support website, to guard against phishing sites and impersonating accounts.
: Israeli cybersecurity firm A Security has disclosed that researchers, using publicly available AI models and fewer than 20 prompts, discovered vulnerabilities in the annotation tool of the video conferencing platform Zoom and built a working exploit within 24 hours. The related vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. Attackers can join or host a meeting without requiring any victim action or visible prompts, then attack any participant and take over their device. The attack has been tested across Zoom applications on Windows, macOS, Linux, Android, and iOS. Once an attacker gains control of a device, they can steal personal data, activate the microphone or camera, or install additional malware. A Security reported the first vulnerability to Zoom on June 10, and Zoom issued fixes incrementally from June 22 to July 20. Because server-side protections in end-to-end encrypted meetings cannot filter malicious messages, users are still advised to update to the latest version. (Decrypt)
Odaily News On-chain security firm PeckShield (@PeckShieldAlert) monitoring shows that the Aztec private Rollup bridge attacker address has deposited 300 ETH, worth approximately $572,100, into Tornado Cash. As of now, the attacker has cumulatively deposited 500 ETH into Tornado Cash.Aztec suffered an attack in June 2026, with total crypto asset losses amounting to $2.165 million.
Odaily News: DefiLlama data shows that hackers stole $247 million in crypto assets in July, making it the second-highest month since 2026, trailing only April's $644 million; this figure represents a significant increase from June's $75 million and May's $60 million. Galaxy Digital stated that the Coldcard vulnerability was the largest attack event of the month, confirming three rounds of attacks involving 7,300 wallets, with at least $100 million in Bitcoin stolen; the firm also identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million. DefiLlama's hack tracker estimates losses related to this vulnerability at $115 million. Other attacks in July include a $9 million exploit on decentralized finance protocol Bonzo Lend, a $2.6 million theft from Cardano-based wallet SecondFi, a $24 million theft from Arbitrum-based perpetual trading platform AFX, and a $7.5 million theft from the Verus Ethereum Bridge.
Odaily News: Apple has limited the number of vulnerability reports a single researcher can submit at one time because its security team has received a large number of submissions generated by AI, many of which do not actually contain real flaws. Apple stated that researchers can request a higher limit at any time, and the company is also using AI internally to triage submissions.Bynario, a Milan-based cybersecurity startup, said it used OpenAI's ChatGPT to discover more than 50 vulnerabilities in the latest version of macOS within three weeks, including a privilege escalation chain that could give attackers full control of a Mac device.Bynario stated that it was unable to report this vulnerability because Apple had already rejected further submissions. Bynario CEO Alfredo Pesoli estimated the vulnerability's value on the criminal market at $100,000 to $200,000. Apple said it has reached out to the company and reviewed its work. In June, Apple added a submission cap and a 30-day cooldown period to its security portal. In a recent security update, Apple listed vulnerabilities discovered with the assistance of Anthropic and OpenAI software, with the number of fixes approximately five times that of a normal cycle. (Decrypt)
According to CoinDesk, the 30-day implied volatility index BVIV, which measures expected volatility in the Bitcoin options market, has continued to decline, now falling to 36%, the lowest level since May 31, significantly down from the high near 60% in early June. Recent influencing factors include the Coldcard wallet attack incident involving tens of millions of dollars, weak institutional demand, and uncertainty in the regulatory and macroeconomic environment, but there are no obvious signs of panic in the market. However, volatility has mean-reverting characteristics. When the indicator falls to historical lows, a rebound often follows. Currently, BVIV has approached levels that have previously formed support multiple times. If volatility rebounds quickly in the future, it may be accompanied by a significant directional move in Bitcoin; whether up or down, traders need to remain vigilant.
Developers on Reddit used Claude Code to scan the Coldcard open-source firmware for vulnerabilities, pinpointing the core issue within 8 minutes: When generating private keys, the firmware invoked a software pseudo-random number generator instead of a hardware true random number generator, and it was this vulnerability that led to the theft of approximately $70 million in BTC from 1,196 wallets. Meanwhile, community users also reported that using Zhipu GLM 5.2 (trained on June 16, offline) for an independent scan similarly discovered this vulnerability. This bug has existed in the open-source wallet code for over five years.
Odaily News: Ethereum Layer 2 network Taiko released a post-mortem of the June 21 security incident, stating that the attack resulted from an off-chain signature key leak and a verification process gap. The attacker exploited these to forge proofs and bypass the Prover whitelist, rather than breaking ZK cryptography or smart contracts. The attacker stole approximately $1.75 million from cross-chain bridges and Vaults, but over $11 million in assets were protected, and no user funds were lost. Taiko has fixed the vulnerability, restored the pre-attack state, and resumed operation on July 2; an OpenZeppelin audit confirmed the fixes with no high, medium, or low-risk vulnerabilities identified. The official statement also indicated that the Unzen upgrade, scheduled for August 6, will require ZK proofs for every block to further enhance network security.
According to Fortune, DeFi asset management and risk analysis company Gauntlet completed a $125 million financing round, exclusively invested by Japanese financial group SBI Holdings. The financing was completed in June this year, and the specific valuation was not disclosed. This is Gauntlet's largest financing round since its establishment in 2018, far exceeding its $24 million Series B round in 2022 led by Ribbit Capital at a $1 billion valuation. Gauntlet was founded by former Wall Street quantitative trader Tarun Chitra. It initially focused on providing stress testing and vulnerability analysis services for DeFi protocols. Later, as the DAO governance model waned, it gradually transitioned to a "treasury curation" business—assessing yield strategy risks through quantitative analysis to help institutional investors manage digital asset allocation. Currently, its clients include asset management giant Apollo, Coinbase, and stablecoin issuer Circle.
According to PPP Prediction Market Tool monitoring, the probability of "WTI crude oil rising to $80 by July 2026" on Polymarket has reached 47%, up 28% in 24 hours.Trump stated today that he may launch a large-scale attack on Iran. As the 60-day ceasefire agreement between the US and Iran becomes precarious, oil tanker traffic through the Strait of Hormuz has "basically come to a standstill." Kpler senior oil analyst Navin Das stated that since the US and Iran reached a 60-day ceasefire agreement on June 17, the average daily number of tankers passing through has been approximately 32. This figure is nearly three times the average daily traffic between the outbreak of the conflict (February) and the signing of the agreement on June 17, though still far below pre-war levels.Join the PPP Signal Push Community to stay ahead and seize the opportunity.
Odaily Zcash's native token ZEC rose over 12% on Tuesday after the team responsible for developing its privacy pool said it is nearing completion of a mathematical proof to confirm that there are no undetectable counterfeit minting vulnerabilities in the latest Zcash shielded pool.The verification work, driven by Project Tachyon, is aimed at Zcash's upcoming Ironwood shielded pool. Zcash founder Zooko Wilcox stated that the project is on the verge of producing a mathematical proof, with the goal of proving that the latest Zcash privacy pool has no undetectable minting vulnerabilities.This development follows the disclosure last month of a serious counterfeit vulnerability in the Zcash Orchard shielded pool. At the time, the flaw sparked market concerns about the potential for undiscoverable, hidden inflation risks within Zcash's privacy system, causing ZEC to drop by over 40% within two days.Developers say that with the help of AI-assisted formal verification, proof work that previously might have taken years has now been compressed to a few weeks. The news pushed ZEC back above $500, its highest level since early June. (The Block)
Odaily, on-chain security firm Specter has released preliminary findings on the BONK DAO governance attack. After tracing on-chain fund flows, significant suspicions have emerged: the Realms founder, an address associated with Crypto Notte, shows signs of capital flow interaction with the suspected attacker's wallet.According to the review, the attacker published a malicious governance proposal on June 30. The proposal required 1% of the total BONK circulating supply in voting power to pass. Between July 4 and 5, the attacker acquired sufficient voting weight by purchasing tokens through exchanges and borrowing from Marginfi, totaling approximately $4 million, thereby pushing forward and executing the governance attack.