Privacy-oriented cryptocurrency
Monero is an open-source, privacy-oriented cryptocurrency that was launched in 2014. Its blockchain is intentionally configured to be opaque, making transaction details such as the identity of senders and recipients and the amount of each transaction anonymous by disguising the addresses used by participants.
According to Odaily, an investigation into the security vulnerability exploit of the Cosmos EVM module reveals that the primary attacker (0x9AE7) purchased $250,000 worth of NES and bridged it to Nesa Chain, exploiting a balance vulnerability to inflate holdings to 200 times their original size, then bridged approximately $50 million worth of NES back to Ethereum. The attacker's initial funding for the wallet originated from Monero. Through multiple wallets, the attacker exchanged NES for ETH on DEXs and deposited the proceeds into centralized exchanges. Due to rapid liquidity withdrawal, most exchanges suffered extreme slippage, and the attacker ultimately sold for only $315,000, netting a profit of approximately $60,000 after deducting costs.
Odaily, the decentralized cross-chain liquidity protocol THORChain has resumed trading after being down for over five weeks following a May attack. Signing, swapping, liquidity provider operations, and redemptions have all been restored.On May 15, blockchain investigator ZachXBT and security firm PeckShield identified that the protocol had likely been exploited, prompting THORChain to halt trading. The vulnerability resulted in a loss of approximately $10.7 million from one of its six Asgard vaults, while the other five vaults were unaffected.THORChain stated that each vault has now been verified, and every key share has been cross-checked. Native Monero swaps are currently undergoing end-to-end testing and will be launched subsequently. (The Block)
According to Fortune, Foundry, a leading Bitcoin mining pool, officially launched a new mining pool for the privacy coin Zcash on April 13. Mike Colyer, CEO of Foundry, stated that this move aims to address growing institutional demand for privacy coins. The pool has already attracted several institutional miners, and its output now accounts for nearly one-third of all newly minted Zcash globally. Zcash implements transaction privacy via zero-knowledge proof technology while supporting selective disclosure to meet regulatory compliance requirements—making it more appealing to institutions than its competitor Monero. Fueled by this news, Zcash’s price has surged over 75% in the past 30 days, with its current market capitalization standing at approximately $6.3 billion. Foundry currently controls about 31% of the global Bitcoin hash rate, making it the world’s largest Bitcoin mining pool operator.
Odaily News According to on-chain analyst Ai Yi's monitoring, the top holder on the Monero native network has accumulated profits exceeding $3.15 million in just 23 days by betting on XMR's price increase. The position was opened on August 9, reaching a peak of 34,000 XMR, valued at approximately $16.72 million. Last night, the holder closed half of the position, banking $1.637 million in profits, and currently retains a 4x leveraged position of 16,000 XMR, with unrealized gains exceeding $1.53 million.
According to on-chain analysis platform Lookonchain (@lookonchain), a newly created wallet deposited 3.56 million USDC into Hyperliquid, opened a long position on 36,000 XMR with 4x leverage valued at approximately $14.33 million, and set take-profit orders in the $475 to $516 range; the current XMR price is approximately $397.
According to Specter monitoring, over $7.9 million was stolen from wallets associated with Coinsbuy on Ethereum and TRON, and the attackers subsequently laundered the funds into XMR through exchanges. Coinsbuy stated that, with the support of ChangeNOW, it has successfully frozen stolen funds amounting to up to six figures. Following the incident, Coinsbuy temporarily suspended deposit and withdrawal services, which have now resumed.
Odaily News: According to on-chain analyst Ai Yi’s monitoring, an address transferred 2 million USDC as margin and then opened a 4x long position of 10,962.78 XMR, valued at $4.18 million, with an entry price of $383.23. This has become the second-largest XMR position on Hyperliquid. The address has also placed a limit buy order worth $1.082 million between $378.2 and $381.4, indicating plans to add to the position if the price drops further.
According to Chainalysis, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) updated its sanctions list against ISIS-K (Islamic State Khorasan Branch) on July 1, adding 134 cryptocurrency wallet addresses, of which 131 are on the TRON chain and 3 are Monero addresses. On-chain data shows that the aforementioned TRON wallets have cumulatively received over $1.4 million since 2023 and transferred out over $880,000, with some funds flowing to Syrian crypto exchangers. Currently, Tether has frozen the balances of all 131 TRON addresses. Additionally, on the same day, OFAC also sanctioned two Brazilian individuals and four companies related to the Latin American criminal organization "Primeiro Comando da Capital" (PCC), accusing them of using cryptocurrency to transfer over $30 million in illegal proceeds across borders from the United States to Brazil.
According to on-chain investigator ZachXBT, on June 11, the TRON chain address TA6YHq...zCoQ received 120.2 million USDT and subsequently initiated multiple rapid transfers: over $12 million was sent to KuCoin’s deposit address; approximately $8 million was transferred to several instant-exchange platforms; and more than $8 million was bridged to the Bitcoin and Ethereum networks via the Near Intents cross-chain bridge. Additionally, this address placed a large number of Monero (XMR) buy orders, causing XMR’s price to spike briefly from $330 to $420. Minutes ago, Tether blacklisted and froze 72 million USDT in the address TBzrPE...Ak9W, which is directly linked to TA6YHq.
On-chain detective ZachXBT posted allegations accusing user "Mr Austin Fine" (handle "@xmrfine") of helping Malone Lam, the mastermind behind a $245 million crypto fraud case, exchange funds for luxury goods and launder a portion of the stolen cryptocurrency, while also raising suspicions that he acted as an informant. ZachXBT has already traced on-chain, revealing that a portion of the funds flowed through Monero to Los Angeles luxury car dealer TBTFW for vehicle purchases.
According to Odaily, an investigation into the security vulnerability exploit of the Cosmos EVM module reveals that the primary attacker (0x9AE7) purchased $250,000 worth of NES and bridged it to Nesa Chain, exploiting a balance vulnerability to inflate holdings to 200 times their original size, then bridged approximately $50 million worth of NES back to Ethereum. The attacker's initial funding for the wallet originated from Monero. Through multiple wallets, the attacker exchanged NES for ETH on DEXs and deposited the proceeds into centralized exchanges. Due to rapid liquidity withdrawal, most exchanges suffered extreme slippage, and the attacker ultimately sold for only $315,000, netting a profit of approximately $60,000 after deducting costs.
据 Decrypt 报道,荷兰国家网络安全中心(NCSC)发出警告,攻击者正在积极利用 macOS 屏幕共享功能中的一个身份验证漏洞(CVE-2026-65400,严重性评分 7.1),对将 5900 端口暴露于公网的 Mac 设备发起攻击,成功获取 root 权限后植入门罗币挖矿程序。
Odaily News: The Dutch National Cyber Security Centre (NCSC) has reported that attackers are exploiting a vulnerability in Apple's macOS Screen Sharing feature to take control of devices and install Monero mining programs. Multiple systems with port 5900 exposed to the internet have been compromised, with attackers gaining root access. The vulnerability, tracked as CVE-2026-65400, has a severity score of 7.1 out of 10. It stems from a state management error in the authentication process, allowing remote attackers to bypass login verification without valid credentials. Public proof-of-concept code has already been circulated. Apple has addressed the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The NCSC advises users to update their systems promptly and avoid exposing the Screen Sharing service directly to the internet. (Decrypt)
According to Specter monitoring, over $7.9 million was stolen from wallets associated with Coinsbuy on Ethereum and TRON, and the attackers subsequently laundered the funds into XMR through exchanges. Coinsbuy stated that, with the support of ChangeNOW, it has successfully frozen stolen funds amounting to up to six figures. Following the incident, Coinsbuy temporarily suspended deposit and withdrawal services, which have now resumed.
Odaily News, January 10 - A Bitcoin and Litecoin holder provided a 12-word recovery phrase to attackers impersonating Trezor support personnel, resulting in the theft of approximately $282 million in assets, including about $139 million in Bitcoin and $153 million in Litecoin. Blockchain forensics firm ZeroShadow stated that the incident stemmed from a social engineering attack, not a compromise of wallet software or private key infrastructure. The stolen funds were split via the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze approximately $700,000 in funds within 20 minutes. Under the BIP39 standard, a 12-word recovery phrase contains approximately 128 bits of entropy, while a 24-word phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of all mined Bitcoin is permanently inaccessible due to lost keys, involving millions of BTC, with causes including forgotten recovery phrases, damaged backups, and a lack of inheritance planning.
Odaily News: THORChain announced the launch of version 3.20, adding native cross-chain swap support for Monero (XMR) and Zcash (ZEC). Users can directly swap XMR and ZEC for Bitcoin, ETH, and stablecoins without wrapping assets, registering on centralized exchange accounts, or relinquishing asset custody. This upgrade also introduces Protocol-Owned Liquidity (POL) and Stable Reserve, and restores support for Solana, Base, and BNB. Among these, Stable Reserve supports zero-liquidity-fee swaps between stablecoins.
Odaily News: The Dutch National Cyber Security Centre (NCSC) has reported that attackers are exploiting a vulnerability in Apple's macOS Screen Sharing feature to take control of devices and install Monero mining programs. Multiple systems with port 5900 exposed to the internet have been compromised, with attackers gaining root access. The vulnerability, tracked as CVE-2026-65400, has a severity score of 7.1 out of 10. It stems from a state management error in the authentication process, allowing remote attackers to bypass login verification without valid credentials. Public proof-of-concept code has already been circulated. Apple has addressed the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The NCSC advises users to update their systems promptly and avoid exposing the Screen Sharing service directly to the internet. (Decrypt)
According to Specter monitoring, over $7.9 million was stolen from wallets associated with Coinsbuy on Ethereum and TRON, and the attackers subsequently laundered the funds into XMR through exchanges. Coinsbuy stated that, with the support of ChangeNOW, it has successfully frozen stolen funds amounting to up to six figures. Following the incident, Coinsbuy temporarily suspended deposit and withdrawal services, which have now resumed.
Odaily News, January 10 - A Bitcoin and Litecoin holder provided a 12-word recovery phrase to attackers impersonating Trezor support personnel, resulting in the theft of approximately $282 million in assets, including about $139 million in Bitcoin and $153 million in Litecoin. Blockchain forensics firm ZeroShadow stated that the incident stemmed from a social engineering attack, not a compromise of wallet software or private key infrastructure. The stolen funds were split via the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze approximately $700,000 in funds within 20 minutes. Under the BIP39 standard, a 12-word recovery phrase contains approximately 128 bits of entropy, while a 24-word phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of all mined Bitcoin is permanently inaccessible due to lost keys, involving millions of BTC, with causes including forgotten recovery phrases, damaged backups, and a lack of inheritance planning.
According to Chainalysis, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) updated its sanctions list against ISIS-K (Islamic State Khorasan Branch) on July 1, adding 134 cryptocurrency wallet addresses, of which 131 are on the TRON chain and 3 are Monero addresses. On-chain data shows that the aforementioned TRON wallets have cumulatively received over $1.4 million since 2023 and transferred out over $880,000, with some funds flowing to Syrian crypto exchangers. Currently, Tether has frozen the balances of all 131 TRON addresses. Additionally, on the same day, OFAC also sanctioned two Brazilian individuals and four companies related to the Latin American criminal organization "Primeiro Comando da Capital" (PCC), accusing them of using cryptocurrency to transfer over $30 million in illegal proceeds across borders from the United States to Brazil.
Odaily, the decentralized cross-chain liquidity protocol THORChain has resumed trading after being down for over five weeks following a May attack. Signing, swapping, liquidity provider operations, and redemptions have all been restored.On May 15, blockchain investigator ZachXBT and security firm PeckShield identified that the protocol had likely been exploited, prompting THORChain to halt trading. The vulnerability resulted in a loss of approximately $10.7 million from one of its six Asgard vaults, while the other five vaults were unaffected.THORChain stated that each vault has now been verified, and every key share has been cross-checked. Native Monero swaps are currently undergoing end-to-end testing and will be launched subsequently. (The Block)
Odaily News: Research firm Galaxy Research recorded a reorganization event at Bitcoin block height 966500 on September 11, where mining pools Spiderpool and Antpool simultaneously discovered two valid blocks pointing to the same parent block, subsequently forming a brief competition. Ultimately, the Antpool block joined the chain with more cumulative work, and the Spiderpool block was discarded.Galaxy Research stated that this was the 3rd single-block reorganization in Bitcoin over the past 4 weeks, with the previous two occurring at block heights 962722 and 963853, respectively. Its node did not observe the block until the Antpool block completed confirmation and continued extending upon it.When a single-block reorganization occurs, the network will ultimately continue building along the chain with more cumulative work, while the other block is removed from the chain. Monero once experienced an 18-block reorganization, and Bitcoin SV experienced a 100-block reorganization in 2021; if a transaction is located in a replaced block, its confirmation count will disappear. (Bitcoin.com News)
On-chain detective ZachXBT posted allegations accusing user "Mr Austin Fine" (handle "@xmrfine") of helping Malone Lam, the mastermind behind a $245 million crypto fraud case, exchange funds for luxury goods and launder a portion of the stolen cryptocurrency, while also raising suspicions that he acted as an informant. ZachXBT has already traced on-chain, revealing that a portion of the funds flowed through Monero to Los Angeles luxury car dealer TBTFW for vehicle purchases.
Odaily News - glassnode stated on platform X that while Bitcoin remains 36% below its October 2025 high, most sectors in the crypto market are still at low levels. However, the privacy sector has become the only one outperforming its previous market peak, up 213% since October 6, 2025.Data shows that all top 10 sectors have posted gains over the past 30 days, with the privacy sector leading at 90%. Currently, the total market cap of privacy-focused crypto assets ranked in the top 200 has risen to approximately $33.6 billion, a significant increase from $7.1 billion a year ago, with nearly half of that growth coming in the last 30 days. Among them, Zcash (ZEC) has jumped from 82nd to 7th place in market cap rankings, accumulating a 2,496% gain over the past year; Monero (XMR) has also doubled in price over the same period.Although ZEC accounts for about 62% of the privacy sector's market cap and its strong performance has dominated sector gains, the privacy sector's rally is not driven by a single asset. All 8 privacy assets with at least one year of historical data have posted gains. Excluding ZEC, a weighted portfolio of privacy assets is still up 85% over the past year, and up 56% from Bitcoin's October 2025 high.Among the top 25 assets by market cap, only ZEC, HYPE, XMR, and WBT are currently above their October 6, 2025 levels, with two of those spots occupied by privacy assets. Data indicates that 91.5% of the top 200 crypto assets by market cap have risen over the past 30 days, but only 25 assets have gained over the past year—suggesting the recent rebound has broad market participation, while the strong performance over the past year has been highly concentrated in the privacy sector.
Odaily News According to on-chain analyst Ai Yi's monitoring, the top holder on the Monero native network has accumulated profits exceeding $3.15 million in just 23 days by betting on XMR's price increase. The position was opened on August 9, reaching a peak of 34,000 XMR, valued at approximately $16.72 million. Last night, the holder closed half of the position, banking $1.637 million in profits, and currently retains a 4x leveraged position of 16,000 XMR, with unrealized gains exceeding $1.53 million.
According to Odaily, an investigation into the security vulnerability exploit of the Cosmos EVM module reveals that the primary attacker (0x9AE7) purchased $250,000 worth of NES and bridged it to Nesa Chain, exploiting a balance vulnerability to inflate holdings to 200 times their original size, then bridged approximately $50 million worth of NES back to Ethereum. The attacker's initial funding for the wallet originated from Monero. Through multiple wallets, the attacker exchanged NES for ETH on DEXs and deposited the proceeds into centralized exchanges. Due to rapid liquidity withdrawal, most exchanges suffered extreme slippage, and the attacker ultimately sold for only $315,000, netting a profit of approximately $60,000 after deducting costs.
Odaily News: THORChain announced the launch of version 3.20, adding native cross-chain swap support for Monero (XMR) and Zcash (ZEC). Users can directly swap XMR and ZEC for Bitcoin, ETH, and stablecoins without wrapping assets, registering on centralized exchange accounts, or relinquishing asset custody. This upgrade also introduces Protocol-Owned Liquidity (POL) and Stable Reserve, and restores support for Solana, Base, and BNB. Among these, Stable Reserve supports zero-liquidity-fee swaps between stablecoins.