News linked to both this project and an event.
Odaily reports: Cross-chain protocol Chainflip has disclosed that an attack targeting Tron USDT occurred yesterday. It has been confirmed that 736,442.17 USDT was stolen through 6 unauthorized payments, while another 115,654.41 USDT in user swaps remained in the vault due to failed payments. All other funds were unaffected.Chainflip stated that the attacker exploited a vulnerability in the Tron transaction memo mechanism by attaching custom memos to transactions already signed by validators, causing the system to identify the same deposit as separate swaps and issue refunds again, ultimately resulting in duplicate payments. The attacker carried out 8 operations over approximately 90 minutes, gradually increasing the amounts. Chainflip said it has completed a fix and has flagged the stolen funds to relevant authorities in an attempt to recover them. The protocol is expected to resume operations as early as Monday and will be responsible for compensating affected users for their losses.
according to Bitcoin News monitoring, Samson Mow has warned the alleged white hat hacker behind the Liquid attack that they may have left behind more clues than they realize. Mow stated, "The net of justice is wide and inescapable; no one will be spared." Mow also questioned the attacker's demand to return Bitcoin in exchange for a bounty, asking whether it is wise to publicly admit to taking Bitcoin and demand a bounty in return. Mow pointed out that Liquid's approximately $5 billion in assets, including L-BTC, Tether, and real-world assets, all belong to their respective issuers and holders, and cannot be used as a basis for calculating a bounty. Regardless of how other matters are negotiated, all user assets must be fully returned.
According to Decrypt, the UK National Economic Crime Centre (NECC) stated in its annual report that criminals are "innovatively" leveraging crypto asset products to evade detection and transfer illicit funds at scale, while also highlighting AI alongside cryptocurrencies as an emerging threat method. Crypto assets have been ranked third among the nine priority economic crime areas jointly designated by NECC, the FCA, and the Treasury. NECC stated it will build more proactive, intelligence-driven crypto capabilities to actively identify targets for enforcement action. Previously, the NCA, in collaboration with the US Secret Service, Coinbase, Binance, Kraken, and Tether, conducted "Operation Atlantic," which identified 20,000 phishing attack victims and resulted in the freezing of $12 million in assets this March.
Liquid Network's official security incident report: On September 6, a vulnerability related to the range proof verification method in Liquid node caching within the open-source software Elements was exploited, resulting in the creation of approximately 4,000 LBTC tokens not backed by bitcoin reserves. The exploiter subsequently exchanged them for approximately 4,000 BTC via SideSwap and the Liquid standard Peg-out mechanism. Prior to the incident, Liquid's reserves stood at approximately 4,205 BTC. After the relevant Peg-out and other withdrawals completed before the network halt, reserves fell to 197 BTC.According to the official statement, the incident did not involve the compromise of Functionary nodes or private keys, and other issued assets on Liquid such as USDT were also unaffected by the vulnerability. The exploiter claimed to be a white hat security researcher and returned 3,400 BTC to the Liquid Federation Peg wallet on September 7. Approximately 598.5 BTC (about 15% of the funds involved) remain unrecovered, and Blockstream is in communication to recover the remaining assets.At present, the top priority is to recover the remaining funds and restore Liquid Network to normal operation as quickly and safely as possible. A fix for the vulnerability has been developed and is currently undergoing multiple rounds of internal and external review. Blockstream is preparing to urgently release Elements v23.3.4, which is expected to be rolled out as soon as preparations are complete, with a target launch within approximately 48 hours. Following the software update, Liquid Network Functionary operators will make further adjustments to restore full network functionality and resume a corrected network state, including rejecting previously invalid Peg-outs.
According to the post-incident report released by Tectonic, the Cronos blockchain lending protocol Tectonic suffered an oracle manipulation attack at 12:49 UTC on August 30, 2026. By repeatedly borrowing and re-collateralizing TONIC tokens 98 times within a single transaction, the attacker drove up the TONIC collateral price by approximately 195 times. Leveraging this artificially inflated value, they subsequently extracted assets with a nominal value of $120.4 million from nine lending markets, spanning USDC, USDT, WBTC, WETH, and other assets. The attacker then bridged the stablecoins to Ethereum and converted them to ETH, while selling the remaining assets for CRO on the Cronos chain before withdrawing them. Approximately $9.19 million in total successfully escaped before the network halt. At 14:32 UTC, Cronos validators emergency-paused the network, rolling back the on-chain state to pre-attack conditions and restoring assets still held on Cronos. Currently, Tectonic's supply and borrowing functions remain suspended, while withdrawal and repayment capabilities continue normally. Tracing efforts for the stolen funds are being coordinated by blockchain forensics firms, law enforcement agencies, and stablecoin issuers, with freeze requests already filed with the relevant issuers.
According to an announcement from the official Liquid Network X account (@Liquid_BTC), a suspected whitehat hacker withdrew approximately 4,000 BTC worth around $320 million from a Liquid Federation wallet using a SideSwap PAK (Peg-out Authorization Key). The official statement indicated that the key itself was not leaked, and the Blockstream team is attempting to contact the party through on-chain signed messages. Following the incident, exchanges have paused or are about to pause LBTC deposit and withdrawal services. Bridge nodes have been temporarily shut down, and the Liquid sidechain is currently suspended, unable to submit new transactions. Officials emphasized that other Liquid assets such as USDT, DePix, and RWA remain unaffected by this incident, while Federation members are actively working to resolve the issue to restore normal network operations as soon as possible.
Odaily News: Bitcoin fork asset BTCB2 hit an all-time high of $1,799 on September 5. Over the past 4 hours, its price has fluctuated between 750 and 1,000 USDC; the Neoxa USDC market recorded a 24-hour trading volume of approximately $1 million.BTCB2 originated from a chain split that occurred on August 8, 2026, at block height 961,632. The network subsequently changed its proof-of-work algorithm to Blake2 and reduced block size, and it can now be mined using Blake2-compatible ASIC miners.Neoxa Exchange and Nonkyc.io have listed BTCB2, with the former offering BTC, USDC, and USDT trading pairs, and the latter offering a USDT trading pair. Both platforms have limited liquidity, and CoinMarketCap and CoinGecko have not yet listed the asset.Based on a BTCB2 price of $1,000, its fully diluted valuation stands at approximately $20.9 billion. Since UTXOs need to be split from Bitcoin first, transactions may otherwise be vulnerable to replay attacks; the network's hash rate has risen by 30.41% over the past 7 days, reaching approximately 5.1 PH/s. (Bitcoin.com News)
According to CriptoNoticias, Argentina's Public Prosecutor's Office (MPF) conducted a specialized training course titled "Virtual Assets: Financial Analysis, Tracking, Detection and Confiscation" via Zoom on August 19 and September 2, 2026, for internal staff, officials, and judges. Led by anti-money laundering specialist Carmen Chena, the curriculum covered digital wallet asset analysis, domestic and international legal frameworks, the cryptocurrency ecosystem, and practical case studies on preservation measures. Previously, Argentina's judiciary had already accumulated extensive experience in cryptocurrency-related cases, including the freezing of 3 million USDT in December 2024 and the 2022 ruling ordering Binance to return stolen BTC.
Odaily News, September 3 — WEEX Exchange announced that the WEEX Hackathon Season 2, themed "AI Wars II: The Algorithm Era," is now officially live. Global AI developers, quantitative traders, Web3 builders, teams, and individuals are invited to join Team AI or Team Human to compete in five rounds of live market trading battles, vying for rankings and rewards based on PnL% performance. The total prize pool stands at 600,000 USDT, with multi-tiered incentives designed to accommodate different participation methods.The early registration phase runs from September 3 to 6, during which the first 2,000 registrants can share in the 100,000 USDT Early Bird prize pool. Additionally, users who register early can complete event tasks ahead of time to accumulate activity points for the upcoming competition.
Odaily News: Cryptocurrency exchange BitMEX has announced that it will fully shut down its platform at 4:00 (UTC) on September 23, 2026. BitMEX CEO Peter Wilkinson stated that the exchange has been operating for over 11 years and has never lost customer funds due to hacker attacks during that period. Peter Wilkinson noted that BitMEX failed to keep pace with its competitors, having long focused on derivatives business while failing to offer spot trading, yield products, custody, and stablecoin trading services in a timely manner. The exchange also entered the USDT market relatively late, in 2021. He stated that BitMEX once supported its founding team in pioneering perpetual swaps, a product that has since become one of the highest-trading-volume financial instruments in the crypto industry and is now widely used for leveraged cryptocurrency trading. (Bitcoin.com News)
据 Ai 姨 监测,Lazarus Group 于约 2 小时前将 262.2 枚比特币(BTC) 转移至新地址,价值约 1664 万美元,相关转移或用于后续资金清洗。当前该组织在链上仍持有超过 7306 万美元 的资产,主要包括 比特币(BTC)、泰达币(USDT) 和 以太坊(ETH)。
Odaily讯 According to Cyvers Alert monitoring, an Address Poisoning attack incident has been detected, resulting in the victim losing approximately $100,000 in USDT. The attacker carried out the "address poisoning" against the victim's wallet about 66 days ago by sending a transaction to create a malicious address record resembling an address the victim normally interacts with. Today, the victim failed to verify the full wallet address and mistakenly transferred funds to the attacker's address.Following the incident, in order to avoid potential freezing risks, the attacker has converted the stolen USDT into ETH, and the wallet currently holds approximately 52.8 ETH.Cyvers reminds users to always fully verify wallet addresses when making on-chain transfers, and to avoid relying solely on address records from transaction history. Meanwhile, security agencies recommend adopting AI-based on-chain security tools for real-time detection of abnormal transaction behavior, in order to reduce risks such as address poisoning and phishing attacks. Address poisoning attacks have become one of the common fraud methods in the crypto asset space in recent years. Attackers typically exploit users' habit of copying addresses from historical transactions by forging similar-looking addresses to trick users into transferring assets mistakenly.
Odaily News: Brazil's crypto market has recorded $318.8 billion in on-chain transaction value over the past 12 months, ranking fifth globally in cryptocurrency adoption, with nearly one-third of Latin America's related activity conducted through Brazilian wallets and platforms. Blockchain security firm CertiK stated that virtual asset service providers must submit authorization applications to the Central Bank of Brazil (BCB) by October 30, 2026, accompanied by independent audit reports. On November 10, 2025, the Central Bank of Brazil issued three resolutions clarifying the licensing scope, minimum capital requirements, and foreign exchange rules for virtual asset service providers. Minimum capital requirements for different license categories range from approximately R$10.8 million to R$37.2 million. Among the current approximately 120 service providers, most have not yet obtained formal licenses, and overseas operators must relocate their operations to Brazil within 270 days. Approximately 80% of Brazil's declared cryptocurrency transaction volume is settled via dollar-pegged tokens, with USDT accounting for 88.7% of that share. Total stablecoin transaction volume from 2019 to 2025 reached R$1.13 trillion. CertiK statistics show that the crypto industry suffered losses of $1.32 billion due to hacker attacks and exploit incidents in the first half of 2026, involving 344 events. (Decrypt)
据 Cointelegraph 报道,区块链初创公司 Quantus 创始人 Christopher Smith 警告称,量子计算破解现代加密技术的首个信号,可能并非高调盗取中本聪比特币,而是一系列无迹可查的钱包资产异常转移——攻击者无需入侵设备或交易所系统,仅凭链上暴露的公钥即可推算出私钥。Smith 指出,若攻击发生,"唯一的法证证据就是没有任何入侵痕迹"。 在攻击目标方面,Smith 认为加密领域最具价值的目标或为 Tether 铸币密钥,量子攻击者可凭此凭空增发 USDT 并迅速抛售套利。Blockchain Capital 安全研究员 Sean Cheetham 则认为,攻击者更可能优先针对交易所热钱包,以避免引发广泛警觉。 在时间线方面,Smith 给出 2028 年前实现量子破密的概率为"五五开",Cheetham 认为 2030 年代初"几乎确定"会到来。Google 已于今年 3 月将后量子迁移时间表提前至 2029 年。
According to CoinDesk, the S&P 500 index has risen 3.12% this month, adding approximately $2.1 trillion in market value (equivalent to the total market cap of the entire crypto market), reaching a record high total market cap of $70.5 trillion, but Bitcoin has only risen about 2% this month, hovering near $64,600. Analysts point out that this round of stock market rise is mainly driven by AI and semiconductor individual stock narratives, rather than a broad-based recovery in risk appetite at the macro level, and Bitcoin lacks direct beneficial exposure to this. Meanwhile, the crypto market also faces multiple internal pressures: the Coldcard platform suffered a $120 million exploit, the prospects of the "Clarity Act" remain uncertain, MicroStrategy has reduced its BTC holdings for three consecutive months, and stablecoin supply continues to shrink—USDT's market cap dropped from $190 billion in April to $183 billion, and USDC's dropped from $79.5 billion to $72 billion.
According to reports from the Procuratorial Daily, an employee of a Shenzhen enterprise, under pressure from over 400,000 yuan in online loans, stole the company's core R&D data and disguised himself as an overseas hacker to demand a ransom of 0.88 Bitcoin and 90,000 USDT from the enterprise, and was ultimately sentenced to three years and three months for attempted extortion and fined 10,000 yuan.
Odaily News — According to official sources, OKX.AI has announced that registration for its inaugural trading hackathon is now open. Following the previous Genesis hackathon for Agent Service Providers (ASP), this hackathon focuses on AI Agent live trading capabilities. Participants are required to deploy their trading strategies as Trading ASPs and conduct live trading with no less than 300 USDT in equivalent funds. Rankings will be updated in real time based on yield (PnL %). The total prize pool is $20,000, with the champion receiving a $5,000 reward.It is reported that OKX.AI is an economic system built specifically for Agents, where users and Agents can discover and utilize professional services provided by ASPs. This event supports two development frameworks: Onchain OS and Agent Trade Kit. Registration runs from July 31 to August 11 at 12:00 (UTC+8), and the competition will take place from August 11 to August 25.
According to Blockaid monitoring, Crypto DAO's Pro token was attacked. As of 00:23 early this morning, the attacker and related profit addresses currently hold a combined total of approximately 8.2 million USDT.
According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.
on-chain security analyst Specter has detected that a long-dormant PancakeSwap liquidity provider (LP) suffered a loss of approximately $2.96 million after signing a malicious EIP-7702 authorization. It is reported that the attacker removed approximately $1.48 million in BSC-USD and $1.48 million in BUSD liquidity provided by the victim, subsequently swapping the BUSD for ETH. Currently, the attacker has deposited approximately $1.46 million into Tornado Cash, while the remaining $1.48 million in USDT remains in the attacker's address.