News linked to both this project and an event.
According to Blockaid monitoring, Crypto DAO's Pro token was attacked. As of 00:23 early this morning, the attacker and related profit addresses currently hold a combined total of approximately 8.2 million USDT.
According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.
on-chain security analyst Specter has detected that a long-dormant PancakeSwap liquidity provider (LP) suffered a loss of approximately $2.96 million after signing a malicious EIP-7702 authorization. It is reported that the attacker removed approximately $1.48 million in BSC-USD and $1.48 million in BUSD liquidity provided by the victim, subsequently swapping the BUSD for ETH. Currently, the attacker has deposited approximately $1.46 million into Tornado Cash, while the remaining $1.48 million in USDT remains in the attacker's address.
Odaily reports, according to monitoring by Onchain Lens, Allbridge Core has been exploited on Solana. The attacker borrowed $1.12 million USDC via a Kamino flash loan, then rapidly executed a USDC/USDT swap, distorting the stablecoin pool ratio of Allbridge. They withdrew liquidity at the manipulated exchange rate and repaid the flash loan within the same transaction, extracting approximately $1.1 million in funds. The funds were subsequently mixed through a privacy protocol. The maximum single withdrawal from Allbridge was $2.24 million USDC. Further analysis of the vulnerability exploit and the affected pools is ongoing.
The U.S. government has just transferred seized funds related to the Bitfinex hack case, with 296,710 USDT moved to Coinbase Prime, possibly for OTC sale.
according to CertiK's monitoring, CodexField's X account and website have been taken offline. Earlier, on-chain analyst Specter had warned that the project might be a scam and exit scam, and tracked abnormal cross-chain fund transfers totaling over 17.3 million USDT.
Gate issued an announcement regarding the recent "user asset theft incident," sharing internal comprehensive verification results, analysis of the incident's cause, and progress on subsequent handling. Regarding the verification process and key facts, the announcement stated that after comprehensive verification, materials submitted by the applicant at the time, including account information, real-name information, transaction records, Alipay screen recordings, etc., matched the account completely. According to analysis by the technical team, Alipay screen recordings can only be made by the customer themselves or someone with access to the customer's Alipay account. Alipay possesses an extremely strict real-time risk control system; logging into Alipay on a different device will mandate multi-factor authentication. This indicates a situation involving serious leakage of customer information or device compromise. Regarding the Gate platform audit mechanism, the announcement stated that the Company's security unbinding audit mechanism strictly executes the four-fold verification process of "Multi-channel advance notification + System risk control preliminary screening + Manual multi-layer review + Time protection," and never has nor will it approve any security item change application based on a single material alone. Gate always takes information security and customer data protection as the Company's core management requirements. The issue of internal information leakage mentioned by some parties does not exist. Regarding fund recovery and subsequent handling, the announcement stated that Gate processed the matter with the highest priority immediately after the incident occurred, coordinating security, compliance, legal, business, and other teams to carry out on-chain analysis and asset tracking and freezing. It continues to coordinate with third-party institutions such as Tether to advance fund freezing. Subsequently, it will also actively cooperate with judicial authorities in investigations and data collection. Any substantive progress will be communicated immediately.
Gate 华语官方 X 账号发文披露,针对网传"Gate 被盗 170 万美元"事件,Gate 官方对完整操作时间线进行了还原。7月 4 日至 6 日期间,涉事账户通过活体人脸验证、历史交易记录核验等多重身份验证,完成了手机解绑、谷歌验证码重置、登录密码及资金密码修改等操作;7月 7 日,该账户在一台历史老设备上通过旧 Passkey 登录,随后经全面身份验证完成 5 笔提现,共涉及约 49.96 ETH、746,475 枚 HSK 及 1,565,982 枚 USDT;7月 8 日,用户方才向客服反馈资产被盗。Gate 强调,所有操作轨迹均来源于平台后台完整留存数据,可溯源核验,目前全站用户资产及账户安全。
According to official social media announcements, the HTX Genesis Hackathon, hosted by HTX DAO and B.AI and co-organized by OpenCSG, TinTinLand, and OpenCity, has entered the initial screening phase. Over 100 developer teams have registered to participate, including teams from more than 30 top universities across 22 cities globally, such as Tsinghua University, Fudan University, National University of Singapore, the University of Edinburgh, and others. Reportedly, the total prize pool for this event reaches 20,000 USDT, with over $100,000 in computing power support provided. Participating teams will innovate in areas including $HTX application scenarios, B.AI ecosystem applications and computing power services, AI Agent finance, on-chain asset management, trading infrastructure, DAO tools, and intelligent financial operating systems. The HTX Genesis finals will be held offline on July 19 during the Shanghai WAIC World Artificial Intelligence Conference.
: According to official sources, OKX has announced the official launch of the OKX.AI Genesis Hackathon, recruiting the first batch of Agent Service Providers (ASP) from global AI developers. The total prize pool for this hackathon is $100,000, with the highest single prize being 10,000 USDT. From now until 8:00 on July 18 (UTC+8), participants can submit their projects through the OKX.AI official website and post introduction threads on the X platform.It is reported that OKX.AI is an economic system specifically designed for Agents, where users and Agents can discover and utilize professional services provided by ASPs.
OdailyOdaily reports that the Prosecutor General's Office of Ukraine stated it has, for the first time, transferred approximately $8.3 million worth of USDT crypto assets into the national asset management system, marking the country's first official takeover of seized crypto assets. The funds originate from an investigation into an international hacking group, which is alleged to have laundered money through high-value real estate and other assets. The assets were received by the Asset Recovery and Management Agency (ARMA) of Ukraine, with the transfer completed pursuant to a court order.Officials stated that this operation marks a significant step for Ukraine in the regulation and management of crypto assets, and aligns with ongoing discussions regarding the establishment of a strategic crypto reserve. Previous data indicates that Ukraine ranked among the top in Europe in terms of crypto transaction volume between 2024 and 2025.However, the relevant assets are currently in a "custodial" state and have not been legally forfeited; subsequent judicial conviction procedures are still required. Analysts believe that the mechanism of this move is similar to the path of the United States using criminally forfeited crypto assets to build a potential strategic reserve. (CoinDesk)
According to an official social media announcement by HTX DAO, the HTX Genesis Hackathon—organized by HTX DAO and B.AI, and co-organized by OpenCSG, TinTinLand, and OpenCity—has attracted over 90 teams to register. The total prize pool for this event amounts to 20,000 USDT, with over $100,000 in computing power support provided. The hackathon aims to encourage developers to explore use cases centered around $HTX applications, B.AI ecosystem applications and computing services, AI Agent finance, on-chain asset management, trading infrastructure, DAO tools, and intelligent financial operating systems. Winning teams will receive cash prizes, computing resources, ecosystem support, introductions to investment firms, community exposure, and follow-up grant funding. Registration for HTX Genesis closes on July 5, and the final competition will be held offline during the World Artificial Intelligence Conference (WAIC) in Shanghai on July 17–18.
HashKey Chain will host the “HashKey Chain Horizon” hackathon in Japan from June 18 to July 14. Built upon the foundation of building a compliant and secure Web3 ecosystem, this hackathon is open to developers, innovators, and Web3 enthusiasts worldwide. It features two challenge tracks focused on key areas within the HashKey Chain ecosystem.
CoinUp has responded to the topic of "CPX price volatility and related personnel identity," stating that Zhu Pan is not a member of the CoinUp platform and has not participated in the platform's core operational management. His identity is merely the project party for a project listed on the CoinUp platform.Regarding the recent sharp short-term fluctuations in the CPX/USDT trading pair, CoinUp stated that its preliminary judgment indicates it was mainly caused by concentrated selling pressure in the market. The platform is further investigating and verifying the specific reasons.CoinUp also emphasized that the platform has not suffered any hacker attacks, data breaches, or exploitation of system vulnerabilities. The wallet system, account system, and asset custody services are all currently in a secure and controllable state.
According to on-chain analyst PeckShield (@PeckShieldAlert), the well-known MEV bot “JaredFromSubway” has reportedly been attacked, resulting in the theft of approximately $7.5 million worth of crypto assets—including 1,474.58 WETH, 2.87 million USDC, and 2 million USDT. The attacker has exchanged the stolen funds for 4,400 ETH and transferred 1,000 ETH to the mixer Tornado Cash to obfuscate the fund’s trail.
Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)
According to on-chain analyst Blockaid (@blockaid_), the well-known Ethereum MEV bot JaredFromSubway (@jaredsmev) has been attacked, resulting in losses of approximately $7.5 million. The attacker constructed a deceptive MEV arbitrage path to trick the bot into automatically approving token transfers. Leveraging these open approvals—before they were revoked—the attacker drained WETH, USDC, and USDT from the bot’s contract. The stolen funds ultimately flowed to the attacker’s wallet address. Blockaid noted that this attack was not a conventional phishing attempt or smart contract vulnerability, but rather a targeted exploitation of the bot’s automated execution mechanism.
Odaily news, Slow Mist founder Cosine published an analysis stating that the approximately $1.1 million loss incident in the OLPC / LABUBU liquidity pool on BNB Chain is suspicious. The loss occurred due to a severe imbalance in the OLPC/LABUBU trading pair, caused by a "vulnerability" in OLPC being exploited. Under certain conditions in _update, it is possible to burn OLPC tokens amounting to value * decimalsValue. Normally, decimalsValue is 1, but approximately 46 days before the attack, it was changed by the owner to an extremely large value of 7,326,680,472,586,200,649. A few days later, the OLPC owner renounced ownership, setting it to the zero address.Today, the attacker exploited this extremely large decimalsValue to trigger the Pair reserve burn, allowing a small amount of OLPC to extract a large amount of LABUBU. The attacker ultimately swapped 1.115 million USDT at a low cost. The suspicious point lies in the setting of decimalsValue—why did the OLPC owner set such an abnormally large value?
the U.S. Department of Justice has seized approximately $9 million in funds linked to a scam network, with the seized assets being the stablecoin Tether (USDT). Law enforcement officials stated that the case is related to long-term romance and investment scams commonly known as "pig butchering." The criminal organization gradually gained victims' trust by establishing fake romantic or social relationships, luring them into depositing funds on fraudulent crypto investment platforms before disappearing with the money.Investigations revealed that the network has affected over 70 victims within the United States, with illegally transferred funds totaling millions of dollars. The U.S. Department of Justice stated that this asset freeze and enforcement action aims to cut off the flow of scam funds and strengthen the ability to track and combat cross-border crypto scams. (Bloomberg)
According to on-chain analyst Yu Jin (@EmberCN), the attacker responsible for the March THE liquidation event on the Venus platform sold 1,912 ETH for $3.26 million one hour ago to repay part of their loan on Aave. That loan was originally taken out by collateralizing ETH and was used to manipulate the Venus liquidations. The attacker’s address still has $6.78 million in USDT outstanding on Aave.