News linked to both this project and an event.
Odaily News – A Hyperliquid user's account was compromised through unauthorized access, with approximately 738,600 USDC transferred out and an additional 10,287 HYPE unstaked. The affected account is identified by a specific address, with some of the stolen funds flowing to an address suspected to be associated with Bitget. As of the time of verification, the 10,287 HYPE remained in the staking balance and had not yet entered the withdrawal queue. If the attacker proceeds to initiate cWithdraw, the affected assets would be further transferred after a 7-day waiting period. In two similar recent cases, staked assets were stolen a second time due to the lack of a user-triggerable emergency pause mechanism, resulting in losses exceeding $1.1 million. Relevant recommendations include introducing a Guardian or Recovery mechanism that users can pre-enable, which would only temporarily pause withdrawals, transfers, and authorization changes. The pause would expire automatically, and restoration would require a time lock and evidence review, with all actions recorded on-chain.
According to Odaily, monitoring by Galaxy's Head of Research revealed that Liquid's white hat hacker stated they would return most of the 4,000 BTC after the Liquid Network vulnerability is patched. The hacker communicated with Blockstream through OP_RETURN messages and PGP-encrypted text: In block 965,822, a Blockstream address sent 1,000 satoshis with the message "Please contact the security team via the Blockstream website"; in block 965,865, the hacker sent an encrypted message to their own key, accompanied by a detached PGP signature that can be verified using the key published by Blockstream; in block 965,869, the hacker sent 1,000 satoshis to the Liquid federation peg-in wallet via a self-spend transaction with the message "Can we return the majority of the funds to the federation address?"; in block 965,875, the hacker conducted another self-spend transaction, sending 1,000 satoshis to the federation peg-in wallet and leaving an OP_RETURN message: "Please fix the vulnerability first. As of the latest commit, there is risk on-chain. Please ensure every node completes the patch update. Once the fix is confirmed, we will securely transfer the funds back." Relevant technical details were encrypted via PGP messages to the key published by Blockstream, readable only by Blockstream.
Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.
according to PeckShield monitoring, the OLPC/LABUBU liquidity pool on BNB Chain's PancakeSwap was attacked. The attacker stole approximately $1.1 million worth of assets. After the incident, the attacker cross-chain transferred the stolen funds to Ethereum and subsequently deposited 633.4 ETH into the mixing protocol Tornado Cash. Additionally, the attacker sent 0.0221 BNB and 0.0411 ETH to a deprecated address. Relevant attack details and fund flows are still under continuous tracking.
According to on-chain analyst PeckShield (@PeckShieldAlert), the YieldCore-3rd-deal treasury under Trading Protocol was attacked, resulting in losses of approximately $398,000. The attack exploited a vulnerability in the contract—specifically, a missing caller permission check—which allowed the attacker to bypass the authorization mechanism and withdraw all funds from the treasury. Relevant on-chain transaction records have now been disclosed.