News linked to both this project and an event.
L2BEAT researcher @sergeyshemyakov posted on X platform, stating that a suspicious DAO proposal appeared on Tornado Cash on June 25, and the target contract of the proposal has not been verified.The address of the proposal creator obtained funds through Railgun 4 days ago. If the proposal passes and is executed, the governance contract will make a delegatecall to this target contract. The Tornado Cash fund pool itself is secure, but this proposal may directly target the Tornado Cash DAO for an attack. The DAO currently holds TORN tokens worth approximately $23 million.
mySwap, an automated market maker in the Starknet ecosystem, has issued a security alert stating that its concentrated liquidity protocol was exploited today, nearly draining all remaining liquidity from the protocol. As its frontend interface has not accepted new liquidity deposits for over six months, the affected funds primarily consist of residual liquidity scattered across more than 100,000 LP positions. After completing the theft, the attacker transferred the stolen funds across chains and obfuscated the transaction trail using the privacy protocol Railgun to conceal the asset flow. An investigation into the vulnerability details is ongoing, and potential remediation measures are being assessed.
According to PeckShield’s monitoring, the WUSD/GLOVE pool on Ethereum was attacked, resulting in losses of approximately $207,000. The attacker has swapped the stolen assets for roughly 98 ETH and deposited them into Railgun.
According to on-chain analyst PeckShield (@PeckShieldAlert), the TrustedVolumes attacker has laundered approximately $278,000 of stolen funds to date, including depositing 10.2 ETH (approx. $23,600) into Tornado Cash and swapping 110 ETH (approx. $250,000) for BTC via THORChain. Additionally, the attacker attempted to deposit 0.5 ETH into Railgun but subsequently withdrew it. TrustedVolumes was attacked on May 7, resulting in losses of approximately $6.7 million.