News linked to both this project and an event.
据 Wanchain 官方 X 账号发文,2026 年 7 月 20 日,Wanchain Bridge Cardano 跨链桥遭到攻击,黑客盗取 NIGHT 代币。Wanchain 随即向攻击者发出公告,要求其在 8 月 6 日 UTC 12:00 前归还 90% 被盗 NIGHT 代币,可保留 10% 作为白帽赏金,并承诺不追究民事责任。 目前,有社区用户指出黑客已将 NIGHT 代币在 DEX 上完成兑换,NIGHT 代币价格下跌逾 30%,现报 0.0188 美元。
according to official sources, OKX, in collaboration with Elliptic, SlowMist, and OttoSec, has released the "H1 2026 Web3 Security and Risk Control Report." The report indicates that the focus of Web3 attacks is shifting from smart contract code to more complex scenarios such as signature processes, user devices, operational infrastructure, and AI Agents.Data shows that in the first half of 2026, OKX's risk control system intercepted over 5.7 million high-risk transactions, including approximately 2.41 million related to hacking and theft, about 1.48 million phishing-related transactions, and roughly 990,000 fraud-related transactions. OKX Web3's on-chain intelligence label library now boasts over 1.1 billion labels, covering more than 420 chains. It has also integrated capabilities such as address screening, transaction monitoring, and sanctioned address control into infrastructure like DEX and Exchange OS.Furthermore, in terms of user protection, OKX has intercepted over 7 million risky website visits, completed more than 200,000 device risk detections, identified over 60,000 high-risk Apps, and blocked or alerted on over 4 million high-risk signature operations. The report also introduces the "proactive risk control" design in scenarios such as Exchange OS, Outcomes, RWA, and Agentic Wallet.
DeFi infrastructure company Enso disclosed a type of malicious liquidity pool called "toxic pools" in a report on July 16th. These pools manipulate transaction simulations to return false optimal quotes to wallets and DEX aggregators, subsequently altering the logic during actual on-chain execution. Enso stated that the relevant malicious contracts can identify read-only simulation environments and return optimized prices, but when the transaction is broadcast on-chain, it is executed at a worse price or causes the transaction to fail. One manipulated Curve pool processed over 129,000 swaps, resulting in approximately $225,000 in inflated quotes. Additionally, over 37,000 transactions were reverted, consuming nearly $30,000 in gas fees. On Polygon, a malicious Uniswap v4 hook attracted routing systems with fake exchange rates, subsequently triggering a 99.1% transaction failure rate. Enso stated that it has updated its execution protection product, Enso Shield, to detect fake quotes in Ethereum and Polygon environments.
Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.
according to on-chain analyst Yujin's monitoring, half an hour ago, an address (0x321...bfd9) with the DeBank username musti_akrep profited 23.75 million USDC by exploiting a vulnerability on Perp DEX Ostium and withdrew it. The 23.75 million USDC was withdrawn to the Arbitrum chain and immediately exchanged for 12,085 ETH at a price of $1,965. Currently, these 12,085 ETH remain on the Arbitrum chain.
Odaily reports: In response to the "Humanity theft incident," on-chain detective ZachXBT has released a new post stating that this "incident" was very likely a staged event. He fundamentally does not believe the team's corresponding explanation, which he sees as nothing more than an excuse fabricated by those with ill intentions to escape blame.According to earlier news, ZachXBT stated that it has not been confirmed whether the Humanity theft was a security attack or a malicious sell-off by the project team. The sell-off of the H token originated from a DEX rather than a CEX.
in response to the "Humanity hack of over $31 million," on-chain detective ZachXBT stated, "It is uncertain whether this was a hacker's theft or a malicious act by the project team. Looking at the chart, given the concentration of supply, the H team was likely working with an active market maker. However, all H tokens were dumped on a decentralized exchange (on-chain), not on a centralized exchange."
stablecoin issuer StablR suffered a sustained attack, causing its euro stablecoin EURR and dollar stablecoin USDR to depeg.Blockchain security firm Blockaid stated that the attacker allegedly gained control by obtaining the private key of one of the owners of the minting multi-signature account. Exploiting the 1/3 signature threshold mechanism, the attacker replaced other administrators and minted an additional 8.35 million USDR and 4.5 million EURR.Subsequently, the attacker swapped tokens worth approximately $10.4 million for about 1,115 ETH on a DEX, yielding an actual profit of around $2.8 million. Following the incident, EURR fell to around $0.88, while USDR dropped to approximately $0.7.Blockaid noted that the incident was not caused by a smart contract vulnerability but rather by a failure in key management and governance mechanisms. (Cointelegraph)
According to CoinDesk, at the “Perp DEX Explosion: Bullish Volumes and Bear Market Resilience” panel at Consensus Miami, several industry insiders stated that institutional investors are still largely avoiding decentralized exchanges offering perpetual futures (Perp DEXs). Veteran trader Wizard of SoHo pointed out that Drift’s recent multi-million-dollar hack highlights security vulnerabilities in the DeFi ecosystem, making secure onboarding of institutional capital a core competitive focus for major Perp DEXs. Anderson of Canary Labs expressed concern about DeFi’s current security posture, noting that large institutions face significantly greater challenges adopting decentralized exchanges compared to centralized platforms. Additionally, the structural tension between DeFi’s permissionless, open design and institutions’ stringent KYC compliance requirements is seen as a key barrier to scaling adoption. Michaël van de Poppe, founder of MN Fund, shared his views on AI-powered trading tools, stating that AI agents represent an evolutionary extension of algorithmic trading—and that trading will increasingly become fully automated.
Litecoin disclosed on X platform that a recent zero-day vulnerability once led to a DoS attack, affecting the operation of major mining pools. Mining nodes that were not updated in time allowed an invalid MWEB (MimbleWimble Extension Block) transaction to be executed, enabling the relevant tokens to be withdrawn to a third-party DEX. The Litecoin network rolled back these invalid transactions through a 13-block reorganization (reorg), confirming they would not be included in the main chain. All valid transactions during this period were unaffected. The vulnerability has now been completely fixed, and the network has resumed normal operation.