Safe is a leading provider of multi-signature wallets and a digital asset management platform. Its smart contract wallets enable businesses to manage funds through predefined access-control schemes with multiple private keys (multisig) and other access modules.
Odaily News: The U.S. Securities and Exchange Commission (SEC) has proposed rules related to crypto assets, aiming to establish a clear framework for eligible investment contracts and provide a targeted securities offering regime for token issuances, enabling related entities to raise funds while retaining investor protection measures. The proposed rules would allow crypto companies to issue up to $5 million in tokens over four years, or up to $75 million in tokens within 12 months, and provide a safe harbor to prevent cryptocurrencies from being deemed "investment contracts." Issuers would be required to disclose financial statements and provide ongoing reporting. The SEC did not include the previously anticipated "innovation exemption" for crypto stocks. The proposal comes just days after the U.S. Senate failed to advance the Digital Asset Market Clarity (CLARITY) Act; the public will have 60 days to submit comments after the proposal is published in the Federal Register. SEC Chair Paul Atkins stated that congressional legislation remains essential for establishing rules that can be applied over the long term, and the SEC will continue to support Congress in advancing the CLARITY Act to President Trump. The Commodity Futures Trading Commission (CFTC) plans to discuss cryptocurrency, AI, and prediction market regulation on Thursday. (Cointelegraph)
Humanity released a post-mortem report on the H token security incident that occurred between June 8 and 9, stating that the incident was not caused by a smart contract vulnerability, but rather by a malware intrusion into a developer's device, which led to the leakage of private keys. Humanity stated that the attacker still holds the ProxyAdmin permissions for the ETH bridge and the BNB Chain token. Preliminary investigations confirmed that a colleague's device was infected with malware, which the attacker used to obtain the hot wallet private key of the administrator and the private keys for signing on 6 Gnosis Safe wallets. The team has hired an external security agency to conduct a forensic investigation and stated that they are formulating a recovery plan for affected users.
Humanity released an incident update stating that its H token was subject to a coordinated attack on Ethereum and BSC on the evening of June 8, resulting in approximately $36 million worth of tokens stolen and dumped across both chains. The project disclosed that the attack originated from a compromised employee laptop, which led to the leakage of multiple owner keys for the Gnosis Safe controlling the Hyperlane bridge ProxyAdmin. On Ethereum, the attacker seized ownership of the ProxyAdmin and upgraded the contract to a malicious implementation, transferring approximately 141.2 million H tokens in a single transaction. On BSC, after similarly gaining control of the ProxyAdmin, the attacker deployed a malicious implementation with infinite minting capabilities, minting 200 million H tokens in two transactions and continuously dumping them. Humanity has suspended deposits and withdrawals on the affected cross-chain bridge and is cooperating with exchanges and law enforcement to investigate the incident and seek partial recovery of the stolen funds.
Humility Protocol released a security incident update on the X platform, stating that its H token suffered a coordinated attack on the Ethereum and BSC chains yesterday, with confirmed losses exceeding $36 million in stolen and dumped assets.Preliminary investigations indicate the incident originated from a compromised employee computer, which led to the leakage of private keys for the multi-signature wallet controlling the Hyperlane Bridge ProxyAdmin. Specifically, the attacker obtained 3 out of 6 private keys of the Gnosis Safe wallet on the Ethereum chain, transferred ownership of the ProxyAdmin to a wallet under their control, upgraded the bridge contract to a malicious implementation, and subsequently transferred approximately 141.2 million H tokens in a single transaction.Simultaneously, the attacker also gained control of 3 out of 5 private keys of the Safe wallet on the BSC chain, took over the ProxyAdmin using the same method, deployed a malicious contract with unlimited minting functionality, and minted 200 million H tokens in two separate transactions to their own wallet.Humility stated that it has suspended all deposit and withdrawal operations on the affected bridge services and is collaborating with partners such as exchanges to mitigate losses. Meanwhile, it is cooperating with the police investigation and attempting to recover part of the stolen funds.
SUPERFORTUNE AI released a 24-hour investigation update stating that the May 27 GUA security incident was not, as previously suspected, address poisoning—but rather resulted from the leakage of private keys belonging to multi-signature signers. The attacker then forged valid signatures pointing to a malicious address and exploited the “premium address” feature—where the malicious address shared the same first four and last four characters as the legitimate address—to mislead the remaining signers into completing the signing process via the Safe interface.
According to an official announcement, Consensys submitted a comment letter to the U.S. Securities and Exchange Commission (SEC) on May 11, stating that the SEC’s latest interpretive framework for digital assets may leave regulatory gaps, creating compliance uncertainty for self-custodial wallet providers such as MetaMask. Consensys requested that the SEC clarify—through a targeted safe harbor or other exemption—that self-custodial, user-directed interfaces need not register as broker-dealers solely because they facilitate transactions involving non-security digital assets that may be associated with investment contracts. Consensys stated that this measure aims to ensure U.S. users can continue using open, neutral peer-to-peer blockchain tools.
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
On-chain analyst Ai Yi (@ai_9684xtpa) monitored that two addresses each claimed 4,276 $LAPTOP tokens from the Hunter Biden Substack subscriber airdrop contract, subsequently selling them for profits of $404,000 and $243,000 respectively, totaling over $647,000. The two addresses exhibit overlapping ETH transactions, and address 0x8DA…4A18d has transferred the earned USDC to @FloB_Safe (Safe architect)'s publicly tagged address, indicating a suspected insider connection.
According to CoinDesk, as the yield on the U.S. 10-year Treasury note climbed 58 basis points year-to-date to 4.81%, the U.S. Dollar Index rose merely 0.9% to 99.22, signaling the breakdown of the traditional "higher yields drive a stronger dollar" logic. Japan's government bond yields surged 90 basis points this year, yet the yen fell to a 40-year low, and Germany's 10-year yield rose 45 basis points concurrently without the euro showing significant strength. Analysts note that markets may have begun interpreting rising yields as a signal of fiscal strain rather than fiscal robustness. This logical shift poses a potential tailwind for Bitcoin — amidst expectations of government debt monetization and currency devaluation, hard assets with inelastic supply, such as Bitcoin and gold, may attract safe-haven capital inflows.
According to Onchain Lens monitoring, a wallet suspected to be associated with the Ethena team deposited 170 million ENA into FalconX 1 hour ago, valued at approximately $14.09 million, possibly for an OTC sale. This wallet previously received ENA from Ethena's Gnosis Safe last year.
据 The Data Nerd 监测,数小时前,某钱包将 289,760 枚 LINK(约合 274 万美元)转入其自有 Gnosis Safe 多签地址。此前一个月,该钱包持续从 Binance 提取 LINK。The Data Nerd 表示,转入自有多签地址或表明其有长期持有意图,预计其建仓成本约在 8.5 至 9 美元区间。
According to on-chain analyst Onchain Lens (@OnchainLens), a wallet address 0x988...1cfc transferred 289,760 LINK (approximately $2.74 million) to its Gnosis Safe multisig wallet for self-custody two hours ago.
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
Blockaid stated that its vulnerability detection system identified that a Safe wallet belonging to an unidentified user on Ethereum was compromised, resulting in confirmed losses of approximately $7.73 million in rsETH. The attacker leveraged a public keeper's multi-call to route the custom Uni V4 LP Safe module to a hook-enabled liquidity pool they created, causing the associated hook to unwrap aEthrsETH into rsETH. The exploit was extracted via MEV within the block.
: Blockchain technology company Starkware stated that on August 26, a transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) scheme was mined on the Bitcoin mainnet, without requiring a soft fork, hard fork, or modification of consensus rules.The transaction consumed 10,000 sats and was processed through MARA Foundation's Slipstream service, as the non-standard format typically cannot propagate through Bitcoin's public mempool. The test consumed several hours of GPU computation, costing approximately $150 to $200.QSB employs hash-based quantum-resistant spending conditions and reduces quantum attack risks through signature trial mining, but still requires users to proactively migrate funds and cannot protect assets whose public keys have already been exposed. Starkware CEO Eli Ben-Sasson still supports introducing a protocol-level solution via a soft fork. (Bitcoin.com News)
Odaily News: Kostas Chalkias, co-founder and chief cryptographer of Mysten Labs, the development company behind the Sui blockchain, stated that he has leased a dedicated factory at a secret location and plans to scale up production of quantum-safe hardware wallet cards for Sui. The project aims to keep the cost of a single quantum card key under $10, with NFC quantum signing expected to take 1 to 2 seconds. Chalkias noted that the project is being advanced in his personal time outside of work and may include funding to provide cards for users who cannot afford them. The initiative is partly driven by a recent incident involving Coldcard hardware wallets, though the vulnerability was not a quantum attack. Coldcard manufacturer Coinkite disclosed that a firmware vulnerability in Coldcard, traceable to a 2021 update, bypassed the hardware random number chip and generated keys using a predictable software process linked to device serial numbers. Attackers have been moving funds since July 30, with losses climbing to approximately 2,055 BTC, affecting over 7,700 addresses and nearing a value of $130 million. At the protocol level, Sui plans to integrate two quantum-resistant signature schemes approved by the U.S. National Institute of Standards and Technology (NIST), designed for everyday accounts and high-value Move vaults, respectively. Existing accounts can be rotated to quantum-safe keys based on their original recovery phrases, without needing to migrate to new wallets. (Bitcoin.com News)
According to Cointelegraph, Bitcoin Lightning Network self-custodial wallet Zeus Wallet voluntarily took its infrastructure offline following a cybersecurity attack on Wednesday and is currently conducting a comprehensive audit of the system, with services to be restored upon completion. Zeus founder Evan Kaloudis stated that the attack was contained within hours, no customer fund losses were found, and there was no evidence that the Lightning node software was affected; the scope of the incident was limited to Zeus's own infrastructure. For users forced to close LSP channels during this incident, Zeus promised to provide replacement channels after services are restored. The company has not yet disclosed the specific nature of the attack or a timeline for resuming operations. Zeus stated that this incident will further drive its security development on Trusted Execution Environment (TEE) and Validating Lightning Signer (VLS) projects.
Humanity released a post-mortem report on the H token security incident that occurred between June 8 and 9, stating that the incident was not caused by a smart contract vulnerability, but rather by a malware intrusion into a developer's device, which led to the leakage of private keys. Humanity stated that the attacker still holds the ProxyAdmin permissions for the ETH bridge and the BNB Chain token. Preliminary investigations confirmed that a colleague's device was infected with malware, which the attacker used to obtain the hot wallet private key of the administrator and the private keys for signing on 6 Gnosis Safe wallets. The team has hired an external security agency to conduct a forensic investigation and stated that they are formulating a recovery plan for affected users.
Odaily News, Vitalik posted on the X platform, expressing his hope to include the recursive STARK memory pool proposal EIP-8288 in the Ethereum I-star upgrade, stating that it can be seen as the next step after Frames. This solution can place quantum-safe signature data off-chain, reducing signature costs; the fuel cost of quantum-safe privacy transactions is also expected to drop from approximately 10 million to tens of thousands. The solution aggregates transaction dependencies through frames and recursive STARKs, with nodes sending one STARK of about 100 to 300KB per time cycle; the on-chain overhead is one STARK and 96 bytes per statement to be proven.
: Blockchain technology company Starkware stated that on August 26, a transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) scheme was mined on the Bitcoin mainnet, without requiring a soft fork, hard fork, or modification of consensus rules.The transaction consumed 10,000 sats and was processed through MARA Foundation's Slipstream service, as the non-standard format typically cannot propagate through Bitcoin's public mempool. The test consumed several hours of GPU computation, costing approximately $150 to $200.QSB employs hash-based quantum-resistant spending conditions and reduces quantum attack risks through signature trial mining, but still requires users to proactively migrate funds and cannot protect assets whose public keys have already been exposed. Starkware CEO Eli Ben-Sasson still supports introducing a protocol-level solution via a soft fork. (Bitcoin.com News)
Odaily News: The U.S. Securities and Exchange Commission (SEC) has proposed rules related to crypto assets, aiming to establish a clear framework for eligible investment contracts and provide a targeted securities offering regime for token issuances, enabling related entities to raise funds while retaining investor protection measures. The proposed rules would allow crypto companies to issue up to $5 million in tokens over four years, or up to $75 million in tokens within 12 months, and provide a safe harbor to prevent cryptocurrencies from being deemed "investment contracts." Issuers would be required to disclose financial statements and provide ongoing reporting. The SEC did not include the previously anticipated "innovation exemption" for crypto stocks. The proposal comes just days after the U.S. Senate failed to advance the Digital Asset Market Clarity (CLARITY) Act; the public will have 60 days to submit comments after the proposal is published in the Federal Register. SEC Chair Paul Atkins stated that congressional legislation remains essential for establishing rules that can be applied over the long term, and the SEC will continue to support Congress in advancing the CLARITY Act to President Trump. The Commodity Futures Trading Commission (CFTC) plans to discuss cryptocurrency, AI, and prediction market regulation on Thursday. (Cointelegraph)
Odaily News: Kostas Chalkias, co-founder and chief cryptographer of Mysten Labs, the development company behind the Sui blockchain, stated that he has leased a dedicated factory at a secret location and plans to scale up production of quantum-safe hardware wallet cards for Sui. The project aims to keep the cost of a single quantum card key under $10, with NFC quantum signing expected to take 1 to 2 seconds. Chalkias noted that the project is being advanced in his personal time outside of work and may include funding to provide cards for users who cannot afford them. The initiative is partly driven by a recent incident involving Coldcard hardware wallets, though the vulnerability was not a quantum attack. Coldcard manufacturer Coinkite disclosed that a firmware vulnerability in Coldcard, traceable to a 2021 update, bypassed the hardware random number chip and generated keys using a predictable software process linked to device serial numbers. Attackers have been moving funds since July 30, with losses climbing to approximately 2,055 BTC, affecting over 7,700 addresses and nearing a value of $130 million. At the protocol level, Sui plans to integrate two quantum-resistant signature schemes approved by the U.S. National Institute of Standards and Technology (NIST), designed for everyday accounts and high-value Move vaults, respectively. Existing accounts can be rotated to quantum-safe keys based on their original recovery phrases, without needing to migrate to new wallets. (Bitcoin.com News)
Humanity released a post-mortem report on the H token security incident that occurred between June 8 and 9, stating that the incident was not caused by a smart contract vulnerability, but rather by a malware intrusion into a developer's device, which led to the leakage of private keys. Humanity stated that the attacker still holds the ProxyAdmin permissions for the ETH bridge and the BNB Chain token. Preliminary investigations confirmed that a colleague's device was infected with malware, which the attacker used to obtain the hot wallet private key of the administrator and the private keys for signing on 6 Gnosis Safe wallets. The team has hired an external security agency to conduct a forensic investigation and stated that they are formulating a recovery plan for affected users.
Humanity released an incident update stating that its H token was subject to a coordinated attack on Ethereum and BSC on the evening of June 8, resulting in approximately $36 million worth of tokens stolen and dumped across both chains. The project disclosed that the attack originated from a compromised employee laptop, which led to the leakage of multiple owner keys for the Gnosis Safe controlling the Hyperlane bridge ProxyAdmin. On Ethereum, the attacker seized ownership of the ProxyAdmin and upgraded the contract to a malicious implementation, transferring approximately 141.2 million H tokens in a single transaction. On BSC, after similarly gaining control of the ProxyAdmin, the attacker deployed a malicious implementation with infinite minting capabilities, minting 200 million H tokens in two transactions and continuously dumping them. Humanity has suspended deposits and withdrawals on the affected cross-chain bridge and is cooperating with exchanges and law enforcement to investigate the incident and seek partial recovery of the stolen funds.
According to The Kobeissi Letter (@KobeissiLetter), government bond yields across major global economies have continued to rise, with the US returning to 2007 levels, the UK to 1998 levels, Germany and France to 2008 levels, and Japan to 1996 levels; among them, the UK 30-year government bond yield touched 5.95% today, its highest since March 1998 and 15 times the 2020 level, placing its borrowing costs at the top of the G7.
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
Blockaid stated that its vulnerability detection system identified that a Safe wallet belonging to an unidentified user on Ethereum was compromised, resulting in confirmed losses of approximately $7.73 million in rsETH. The attacker leveraged a public keeper's multi-call to route the custom Uni V4 LP Safe module to a hook-enabled liquidity pool they created, causing the associated hook to unwrap aEthrsETH into rsETH. The exploit was extracted via MEV within the block.
Odaily News, Vitalik posted on the X platform, expressing his hope to include the recursive STARK memory pool proposal EIP-8288 in the Ethereum I-star upgrade, stating that it can be seen as the next step after Frames. This solution can place quantum-safe signature data off-chain, reducing signature costs; the fuel cost of quantum-safe privacy transactions is also expected to drop from approximately 10 million to tens of thousands. The solution aggregates transaction dependencies through frames and recursive STARKs, with nodes sending one STARK of about 100 to 300KB per time cycle; the on-chain overhead is one STARK and 96 bytes per statement to be proven.
On-chain analyst Ai Yi (@ai_9684xtpa) monitored that two addresses each claimed 4,276 $LAPTOP tokens from the Hunter Biden Substack subscriber airdrop contract, subsequently selling them for profits of $404,000 and $243,000 respectively, totaling over $647,000. The two addresses exhibit overlapping ETH transactions, and address 0x8DA…4A18d has transferred the earned USDC to @FloB_Safe (Safe architect)'s publicly tagged address, indicating a suspected insider connection.
According to CoinDesk, as the yield on the U.S. 10-year Treasury note climbed 58 basis points year-to-date to 4.81%, the U.S. Dollar Index rose merely 0.9% to 99.22, signaling the breakdown of the traditional "higher yields drive a stronger dollar" logic. Japan's government bond yields surged 90 basis points this year, yet the yen fell to a 40-year low, and Germany's 10-year yield rose 45 basis points concurrently without the euro showing significant strength. Analysts note that markets may have begun interpreting rising yields as a signal of fiscal strain rather than fiscal robustness. This logical shift poses a potential tailwind for Bitcoin — amidst expectations of government debt monetization and currency devaluation, hard assets with inelastic supply, such as Bitcoin and gold, may attract safe-haven capital inflows.