RAILGUN is a privacy system built directly, enabling users to interact directly with DEXs and other DeFi applications. Individuals can engage in cryptocurrency and DeFi-based activities, ensuring financial freedom without worrying about being spied on by anyone.
L2BEAT researcher @sergeyshemyakov posted on X platform, stating that a suspicious DAO proposal appeared on Tornado Cash on June 25, and the target contract of the proposal has not been verified.The address of the proposal creator obtained funds through Railgun 4 days ago. If the proposal passes and is executed, the governance contract will make a delegatecall to this target contract. The Tornado Cash fund pool itself is secure, but this proposal may directly target the Tornado Cash DAO for an attack. The DAO currently holds TORN tokens worth approximately $23 million.
mySwap, an automated market maker in the Starknet ecosystem, has issued a security alert stating that its concentrated liquidity protocol was exploited today, nearly draining all remaining liquidity from the protocol. As its frontend interface has not accepted new liquidity deposits for over six months, the affected funds primarily consist of residual liquidity scattered across more than 100,000 LP positions. After completing the theft, the attacker transferred the stolen funds across chains and obfuscated the transaction trail using the privacy protocol Railgun to conceal the asset flow. An investigation into the vulnerability details is ongoing, and potential remediation measures are being assessed.
According to PeckShield’s monitoring, the WUSD/GLOVE pool on Ethereum was attacked, resulting in losses of approximately $207,000. The attacker has swapped the stolen assets for roughly 98 ETH and deposited them into Railgun.
According to on-chain analyst PeckShield (@PeckShieldAlert), the TrustedVolumes attacker has laundered approximately $278,000 of stolen funds to date, including depositing 10.2 ETH (approx. $23,600) into Tornado Cash and swapping 110 ETH (approx. $250,000) for BTC via THORChain. Additionally, the attacker attempted to deposit 0.5 ETH into Railgun but subsequently withdrew it. TrustedVolumes was attacked on May 7, resulting in losses of approximately $6.7 million.
mySwap, an automated market maker in the Starknet ecosystem, has issued a security alert stating that its concentrated liquidity protocol was exploited today, nearly draining all remaining liquidity from the protocol. As its frontend interface has not accepted new liquidity deposits for over six months, the affected funds primarily consist of residual liquidity scattered across more than 100,000 LP positions. After completing the theft, the attacker transferred the stolen funds across chains and obfuscated the transaction trail using the privacy protocol Railgun to conceal the asset flow. An investigation into the vulnerability details is ongoing, and potential remediation measures are being assessed.
According to The Defiant, the Ethereum Foundation’s Kohaku Initiative has released an SDK for integrating privacy protocols into Ethereum wallets. A functional 4337 mempool relay supporting private transactions is now available in version v0.0.1-alpha.21 of the kohaku-eth/railgun integration. This SDK aims to integrate shielded-pool protocols—such as Railgun, Tornado Cash, and Privacy Pools—directly into wallet interfaces, reducing reliance on centralized relay infrastructure. Kohaku has also demonstrated a CLI-based wallet and is advancing integration with production-grade wallets like Ambire, while simultaneously developing post-quantum accounts, multisig support, and hardware wallet compatibility.
L2BEAT researcher @sergeyshemyakov posted on X platform, stating that a suspicious DAO proposal appeared on Tornado Cash on June 25, and the target contract of the proposal has not been verified.The address of the proposal creator obtained funds through Railgun 4 days ago. If the proposal passes and is executed, the governance contract will make a delegatecall to this target contract. The Tornado Cash fund pool itself is secure, but this proposal may directly target the Tornado Cash DAO for an attack. The DAO currently holds TORN tokens worth approximately $23 million.
mySwap, an automated market maker in the Starknet ecosystem, has issued a security alert stating that its concentrated liquidity protocol was exploited today, nearly draining all remaining liquidity from the protocol. As its frontend interface has not accepted new liquidity deposits for over six months, the affected funds primarily consist of residual liquidity scattered across more than 100,000 LP positions. After completing the theft, the attacker transferred the stolen funds across chains and obfuscated the transaction trail using the privacy protocol Railgun to conceal the asset flow. An investigation into the vulnerability details is ongoing, and potential remediation measures are being assessed.
According to The Defiant, the Ethereum Foundation’s Kohaku Initiative has released an SDK for integrating privacy protocols into Ethereum wallets. A functional 4337 mempool relay supporting private transactions is now available in version v0.0.1-alpha.21 of the kohaku-eth/railgun integration. This SDK aims to integrate shielded-pool protocols—such as Railgun, Tornado Cash, and Privacy Pools—directly into wallet interfaces, reducing reliance on centralized relay infrastructure. Kohaku has also demonstrated a CLI-based wallet and is advancing integration with production-grade wallets like Ambire, while simultaneously developing post-quantum accounts, multisig support, and hardware wallet compatibility.
According to PeckShield’s monitoring, the WUSD/GLOVE pool on Ethereum was attacked, resulting in losses of approximately $207,000. The attacker has swapped the stolen assets for roughly 98 ETH and deposited them into Railgun.
According to on-chain analyst PeckShield (@PeckShieldAlert), the TrustedVolumes attacker has laundered approximately $278,000 of stolen funds to date, including depositing 10.2 ETH (approx. $23,600) into Tornado Cash and swapping 110 ETH (approx. $250,000) for BTC via THORChain. Additionally, the attacker attempted to deposit 0.5 ETH into Railgun but subsequently withdrew it. TrustedVolumes was attacked on May 7, resulting in losses of approximately $6.7 million.