GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

PeckShield: A total of 40 major hacking incidents occurred in the crypto sector in June, with total losses of approximately $75.87 million.

According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), a total of 40 major hacking incidents occurred in the cryptocurrency sector in June 2026, with total losses of approximately $75.87 million, down 7.13% month-over-month from May ($81.7 million). The top three incidents with the largest losses this month were: $31 million stolen from Humanity Protocol, $10 million lost from Syscoin Bridge, and $7.5 million stolen from the JaredFromSubway.eth MEV bot.

Base Releases Block Production Outage Analysis Report: Sequencer Bug Causes Brief On-Chain Downtime, Protocol Stress Testing to Be Strengthened

Base has officially released an analysis report on the block production outage, disclosing that the Base mainnet experienced two block production interruptions on June 25 and 26, lasting 116 minutes and 20 minutes respectively. On-chain asset security was unaffected, and funds remained safe at all times. The root cause was a vulnerability in the sequencer's block construction logic: after a transaction execution failure, the old journal state was not properly cleared, causing subsequent legitimate transactions to encounter gas calculation errors during execution, thereby generating invalid state transition blocks and halting block production on the entire L2 chain.Base stated that the issue has been resolved through a patch, and will strengthen the protocol's fuzz testing and stress testing framework to identify potential malicious transaction paths, while optimizing monitoring and operational processes. Additionally, plans are in place to introduce a recovery mechanism to enhance rapid recovery capabilities in future similar events.

Bitget Collaborates with SlowMist to Release the “2026 Anti-Fraud Report”: Cross-Asset Users Account for Over 10%; AI-Integrated Fraud Accelerates Evolution

According to the “2026 Anti-Fraud Report” jointly released by Bitget and SlowMist, as digital finance continues expanding into equities, tokenized assets, and AI tools, cross-asset trading is gradually emerging as a key trend for user participation in markets. The proportion of users engaging in cross-asset portfolio allocation has risen from less than 1% in mid-2025 to over 10% by May 2026. The report notes that fraud techniques are evolving from single-point attacks toward sophisticated attack chains—integrating AI-generated content, deepfakes, voice cloning, and multi-channel social engineering. Between July 2025 and June 2026, Bitget’s security system intercepted over 150 million malicious requests, identified more than 13,000 high-risk malicious IPs, and assisted users in recovering approximately $32.3 million in funds linked to security incidents and fraudulent activities. Gracy Chen, CEO of Bitget, stated: “This year marks the third annual Anti-Fraud Month initiative. Bitget will continue rolling out security education content, risk identification guides, and industry collaboration programs to help users enhance their ability to detect and defend against AI-powered fraud, phishing attacks, and scams occurring across multi-asset scenarios.”

Tornado Cash suspicious DAO proposal emerges, potentially threatening $23 million in DAO funds

L2BEAT researcher @sergeyshemyakov posted on X platform, stating that a suspicious DAO proposal appeared on Tornado Cash on June 25, and the target contract of the proposal has not been verified.The address of the proposal creator obtained funds through Railgun 4 days ago. If the proposal passes and is executed, the governance contract will make a delegatecall to this target contract. The Tornado Cash fund pool itself is secure, but this proposal may directly target the Tornado Cash DAO for an attack. The DAO currently holds TORN tokens worth approximately $23 million.

Queenie, Founder of CoinUp: “All assets on the platform are secure; we will never exit scam.”

Queenie, founder of CoinUp, will host an X Space on June 25 at 20:00 (UTC+8) to publicly address recent rumors about the platform “running away,” its operational status, user asset security, CPX price volatility, and related personnel matters.

HashKey Chain Japan Hackathon Countdown Begins: $12,000 USDT Total Prize Pool Invites Global Developers

HashKey Chain will host the “HashKey Chain Horizon” hackathon in Japan from June 18 to July 14. Built upon the foundation of building a compliant and secure Web3 ecosystem, this hackathon is open to developers, innovators, and Web3 enthusiasts worldwide. It features two challenge tracks focused on key areas within the HashKey Chain ecosystem.

2026 Q2 sees 83 crypto hacks, a new all-time high

according to DefiLlama data, Q2 2026 has become the most active quarter on record for crypto hacks, with 83 separate attack incidents, setting a new all-time high.Despite the increased frequency of attacks, the total losses for the quarter were approximately $755.3 million, still lower than the $3.56 billion lost in Q4 2020. Of this, the $293 million attack on KelpDAO and the $280 million attack on Drift Protocol accounted for more than three-quarters of the quarter's total losses. Cross-chain bridges were the largest source of losses, with related attacks leading to approximately $351 million being stolen. Earlier this month, Humanity Protocol lost $36 million, Aztec Connect experienced two attacks on passive smart contracts, each losing about $2.1 million, and decentralized exchange Raydium suffered a $1.3 million attack in June. (financefeeds)

Namada suffered an attack, with over 220,000 ATOM flowing into a Cosmos Hub address before being transferred out

According to Odaily, the privacy-focused public chain project Namada officially stated that the protocol encountered a vulnerability attack incident. The team is currently investigating and has contacted relevant parties to assist in handling the matter.Officials stated that if the operator behind this attack is a white hat hacker, they hope the individual will proactively contact the team to further understand the vulnerability and facilitate a resolution.On-chain data shows that some ATOM assets related to the incident were allegedly transferred to a Cosmos Hub network address via IBC (Inter-Blockchain Communication protocol). According to on-chain tracking information, this address received approximately 228,517 ATOM on June 18. The funds were subsequently drained within hours through IBC transfers and multiple outgoing transactions. Currently, only a small balance remains in this address.As of now, Namada has not disclosed the type of vulnerability, the attack method, or the specific scale of losses. The relevant investigation is still ongoing.

G7: Calls for Joint Action Against North Korean Cryptocurrency Theft and Cybercrime

leaders of the Group of Seven (G7) issued a statement at the G7 summit in Évian-les-Bains, France, once again calling for joint action to combat North Korean cryptocurrency theft and cybercrime. United Nations security researchers have linked North Korea's cryptocurrency theft to the funding of its weapons programs.Previously, attacks suspected to be linked to North Korean hackers included a $285 million attack on Drift Protocol in April and a $36 million breach on Humanity Protocol in June. According to Chainalysis data, North Korean hackers stole at least $2 billion in cryptocurrency in 2025, bringing their historical total theft amount to at least $6.75 billion. (Cointelegraph)

Aztec Labs: Attacked Product Discontinued Four Years Ago, No Control Over It

according to Aztec Labs monitoring, the team is investigating a potential vulnerability affecting an Aztec payments product that was discontinued in 2021. Approximately $2 million was transferred from an immutable smart contract. This discontinued product is an immutable Stage 2 Rollup version that was deactivated in 2022. Aztec Labs does not hold the admin keys or any control over the system, and thus cannot pause or upgrade it. This incident is separate from the attack on the Aztec Connect product on June 14. The Aztec Foundation stated that the product affected by this attack is not associated with any smart contracts of the current network or the AZTEC ERC20 token.

Zcash Founder Says Claude Mythos Audit Found No Critical Vulnerabilities

Odaily Zcash founder Zooko Wilcox posted on X stating that a security audit conducted by Anthropic's Claude Mythos AI model did not find any "more severe vulnerabilities" in the Zcash protocol. The audit was commissioned by Shielded Labs, a Swiss non-profit organization supporting Zcash development. On June 3, Zcash developers temporarily paused Orchard transactions after discovering a vulnerability in the shielded pool, restoring functionality through an emergency upgrade the same day. The issue stemmed from a four-year-old forging vulnerability in the Orchard shielded pool, identified by security researcher Taylor Hornby with the assistance of Anthropic's Claude Opus 4.8 model. The Zcash Foundation stated there is no evidence that the vulnerability was exploited, nor was any unauthorized value creation detected, and user privacy remained unaffected.Anthropic released the first public version of the Claude Mythos model, Fable 5, on Tuesday, and stated on Friday that it has suspended access to the Fable 5 and Mythos 5 AI models due to export control directives issued by the U.S. government citing national security concerns. (Cointelegraph)

Anthropic Mythos AI Audit of Zcash Finds No New Critical Vulnerabilities

According to Cointelegraph, Zcash founder Zooko Wilcox stated that a security audit of the Zcash protocol—commissioned by Shielded Labs and conducted using Anthropic’s Mythos AI model—did not uncover any new critical vulnerabilities. Previously, security researcher Taylor Hornby discovered, using Claude Opus 4.8, a four-year-old forgery vulnerability in the Orchard shielded pool, prompting developers to urgently suspend Orchard transactions on June 3 and complete the fix the same day. The Zcash Foundation confirmed there is no evidence the vulnerability was ever exploited, and user privacy remained unaffected.

11 national law enforcement agencies shut down AudiA6 crypto money laundering network

law enforcement agencies from 11 countries have jointly shut down the money laundering network AudiA6, which processed over 336 million euros in illicit funds between 2022 and 2025. On June 10, law enforcement arrested two administrators of Russian and Ukrainian nationality in Georgia, seized 25 domain names, over 30 servers, and 80 vehicles, and froze approximately 778,000 euros in cryptocurrency. Operating as a "mixer-as-a-service," AudiA6 provided services to cybercriminals involved in ransomware attacks, helping them cash out crypto assets and conceal the flow of funds, charging commissions of 3% to 10% and claiming to complete the "cleaning" process within about an hour.Since 2021, the AudiA6 wallet has received approximately 10,333 BTC, valued at around $389 million at the time of the transactions. The investigation also revealed that the money laundering network used thousands of fake accounts created with stolen or purchased identities, involving over 6,000 KYC records; many of these accounts were linked to Russian-speaking intermediaries and were used to transfer criminal proceeds through cryptocurrency exchanges. The clearnet and darknet domains of AudiA6 and Dark2Web have been replaced with seizure banners. (Cointelegraph)

Humanity Says It Is Formulating a Victim Recovery Plan

Humanity released a post-mortem report on the H token security incident that occurred between June 8 and 9, stating that the incident was not caused by a smart contract vulnerability, but rather by a malware intrusion into a developer's device, which led to the leakage of private keys. Humanity stated that the attacker still holds the ProxyAdmin permissions for the ETH bridge and the BNB Chain token. Preliminary investigations confirmed that a colleague's device was infected with malware, which the attacker used to obtain the hot wallet private key of the administrator and the private keys for signing on 6 Gnosis Safe wallets. The team has hired an external security agency to conduct a forensic investigation and stated that they are formulating a recovery plan for affected users.

Humanity releases incident update: affecting both Ethereum and BSC blockchains; stolen amount confirmed to exceed $36 million

Humanity released an incident update stating that its H token was subject to a coordinated attack on Ethereum and BSC on the evening of June 8, resulting in approximately $36 million worth of tokens stolen and dumped across both chains. The project disclosed that the attack originated from a compromised employee laptop, which led to the leakage of multiple owner keys for the Gnosis Safe controlling the Hyperlane bridge ProxyAdmin. On Ethereum, the attacker seized ownership of the ProxyAdmin and upgraded the contract to a malicious implementation, transferring approximately 141.2 million H tokens in a single transaction. On BSC, after similarly gaining control of the ProxyAdmin, the attacker deployed a malicious implementation with infinite minting capabilities, minting 200 million H tokens in two transactions and continuously dumping them. Humanity has suspended deposits and withdrawals on the affected cross-chain bridge and is cooperating with exchanges and law enforcement to investigate the incident and seek partial recovery of the stolen funds.

Arthur Hayes: Rising Oil Prices, AI-Related IPOs, and Trump's Anti-AI Rhetoric Could Pop the AI Bubble and Drag Down the Crypto Market

Odaily News, June 9th — BitMEX co-founder Arthur Hayes stated in his latest article "Reality Test" that if oil prices continue to rise due to the US-Iran conflict, it could trigger a collapse of the AI stock bubble and drag the entire crypto market down.Hayes said that if traffic restrictions in the Strait of Hormuz persist deep into the second quarter, spot prices for hydrocarbons and other key commodities could rise in the third quarter. If oil prices continue to climb and inflationary pressures impact the US midterm elections, Trump might pivot to a tough stance targeting data center construction, AI regulation, and taxation. Hayes believes the market could anticipate Trump limiting AI capital expenditure and taxing AI companies, thereby triggering the burst of the AI stock bubble.Hayes also noted that since November 2022, the scale of AI-related debt issuance has been approximately $1.5 trillion, and US M2 has increased by roughly the same amount during the same period. He believes the three factors that could pop the AI bubble include rising energy costs, the market's inability to absorb three major AI-related IPOs — namely SpaceX, Anthropic, and OpenAI — and Trump's shift to opposing AI. In terms of portfolio, Hayes stated that Maelstrom's stock portfolio holds significant positions in US-listed energy producers; he has sold AI-related stocks and offloaded non-core crypto assets, having dumped HYPE, NEAR, and WLD last week, as well as selling ZEC due to the Orchard Pool vulnerability. He still holds Bitcoin and ETH and will execute tactical short trades via derivatives.

Polymarket launches "Zcash Orchard Privacy Pool Confirmed Vulnerable Exploit"

Odaily Seer monitoring shows that Polymarket has launched a new prediction event titled "Was Zcash's Orchard privacy pool confirmed to have been exploited?"On June 4, Zcash's core development team revealed that they had deployed an emergency network upgrade to fix a critical cryptographic vulnerability in the Orchard privacy pool. This flaw could have potentially allowed a malicious attacker to arbitrarily forge unlimited amounts of ZEC. Due to the vulnerability's characteristic that "it is impossible to cryptographically prove whether it was exploited in the past," independent support organization Shielded Labs subsequently proposed on June 5 to deploy a new privacy pool during the NU7 upgrade at the end of July. They also suggested implementing strict "Turnstile-accounting" audits for tokens exiting Orchard to investigate whether any forged tokens exist. According to the settlement rules for this prediction event, if before December 31, 2026, official sources or mainstream credible media confirm that the vulnerability was effectively exploited on the mainnet before being patched, the event will settle as YES.Odaily Seer continues to monitor prediction markets, seeing changes before pricing.

A rETH holder suffered a $4.5 million loss in a hacker attack, urgently transferring assets to secure $4.7 million

According to monitoring by Specter, 13 wallets belonging to a rETH holder were attacked on June 5, resulting in cumulative losses of approximately $4.5 million in assets. However, the victim detected the issue in time before the attacker could further transfer funds and successfully moved about $4.7 million in remaining assets. It is reported that these wallets had been inactive for years. The attacker has now begun laundering the stolen funds.

Zcash fixes vulnerability that could have allowed infinite ZEC minting, but privacy pool features prevent verifying if it was exploited

on May 29, 2026, Taylor Hornby discovered a critical counterfeiting vulnerability in Zcash's Orchard pool. Taylor Hornby reported the vulnerability to the Zcash Open Development Lab, and after coordinated efforts, a fix was completed on June 2. The vulnerability could have been exploited to secretly create an unlimited number of counterfeit ZEC within Zcash Orchard. Due to the privacy features of Orchard, it is cryptographically impossible to determine whether the vulnerability was exploited before the fix was deployed.The vulnerability had existed since Orchard's activation in May 2022 until an emergency fix was deployed on June 1, 2026. Taylor Hornby, with the assistance of AI tools, wrote a complete exploit program and generated an infinite, undetectable amount of counterfeit ZEC in a local test environment. Shielded Labs is currently collaborating with other Zcash developers to explore network upgrade proposals that would allow anyone to verify the integrity of Zcash's supply.

Drift Protocol Launches Full Rebuild After North Korean Hacker Attack, Enlists Top-Tier Security Team to Accelerate Platform Post-Mortem

According to Drift’s official announcement, the Drift Protocol released its latest recovery update on June 3, 2026. An independent forensic investigation conducted by cybersecurity firm Mandiant has confirmed that the prior attack against Drift was carried out by the North Korean threat group UNC6862, whose tactics closely align with those historically employed by North Korean state-sponsored hacking operations. On the rebuilding front, Drift announced the appointment of Noah Prince—former Engineering Lead of the Helium Protocol—as Protocol Lead, who will spearhead codebase hardening and platform security architecture redesign. Additionally, former members of the Gauntlet team have been brought on board to conduct margin engine reviews, optimize funding rates and market parameters, enhance liquidation mechanisms, and implement continuous risk monitoring. Drift plans to relaunch with “security-first” as its core principle, repositioning itself as Solana’s largest USDT-perpetuals exchange. With support from strategic partners including Tether, Drift will establish a dedicated recovery pool funded by platform revenues to compensate users for losses. Further details regarding the recovery mechanism and timeline will be disclosed progressively.