News linked to both this project and an event.
According to Blockaid monitoring, Crypto DAO's Pro token was attacked. As of 00:23 early this morning, the attacker and related profit addresses currently hold a combined total of approximately 8.2 million USDT.
According to BlockSec monitoring, the BarnBridge SMART Yield cUSDC protocol was attacked on Ethereum, resulting in losses of approximately $776,000, suspected to be a governance attack. The attacker first gained DAO governance rights, then upgraded the SmartYield/controller proxy to a malicious implementation contract. This contract called the _takeUnderlying privileged function of CompoundProvider, utilizing pre-existing USDC approvals from 50 user accounts, and via transferFees, moved the aggregated funds to the attacker.
According to Fortune, DeFi asset management and risk analysis company Gauntlet completed a $125 million financing round, exclusively invested by Japanese financial group SBI Holdings. The financing was completed in June this year, and the specific valuation was not disclosed. This is Gauntlet's largest financing round since its establishment in 2018, far exceeding its $24 million Series B round in 2022 led by Ribbit Capital at a $1 billion valuation. Gauntlet was founded by former Wall Street quantitative trader Tarun Chitra. It initially focused on providing stress testing and vulnerability analysis services for DeFi protocols. Later, as the DAO governance model waned, it gradually transitioned to a "treasury curation" business—assessing yield strategy risks through quantitative analysis to help institutional investors manage digital asset allocation. Currently, its clients include asset management giant Apollo, Coinbase, and stablecoin issuer Circle.
Odaily, on-chain security firm Specter has released preliminary findings on the BONK DAO governance attack. After tracing on-chain fund flows, significant suspicions have emerged: the Realms founder, an address associated with Crypto Notte, shows signs of capital flow interaction with the suspected attacker's wallet.According to the review, the attacker published a malicious governance proposal on June 30. The proposal required 1% of the total BONK circulating supply in voting power to pass. Between July 4 and 5, the attacker acquired sufficient voting weight by purchasing tokens through exchanges and borrowing from Marginfi, totaling approximately $4 million, thereby pushing forward and executing the governance attack.
据官方消息,BonkDAO 表示,其 DAO 金库 因一项恶意治理提案遭攻击,约价值 2000 万美元的 BONK 代币被盗。调查显示,相关地址曾在提案发起前通过交易所钱包购买 BONK。BonkDAO 正与交易所、跨链桥及 Solana 基金会合作处理此事,执法部门已获通知,后续将继续推进资金追回及责任追查。
the official Bonk Inu X account announced that BonkDAO was attacked via a malicious governance proposal, resulting in the theft of approximately $20 million worth of BONK tokens from its DAO treasury.According to reports, the attacker exploited a suspicious governance proposal to transfer assets from the BonkDAO treasury. The stolen BONK subsequently began flowing to exchanges, putting downward pressure on the BONK price. Data from The Block shows that the BONK price has dropped over 9%.South Korean exchange Upbit subsequently issued a notice stating that it has temporarily suspended BONK deposits and withdrawals to address the incident and mitigate potential risks. (The Block)
Odaily, Web3 security firm CertiK has released the "Hack3D: First Half of 2026 Report." The report shows that the Web3 ecosystem experienced 344 security incidents in the first half of 2026, with cumulative losses of approximately $1.32 billion. Although this figure represents a 46.8% decrease compared to the same period last year, excluding the impact of the $1.45 billion security incident involving Bybit, the scale of losses in the first half of this year actually increased by approximately 28% year-on-year, indicating that the overall security environment in the industry has not materially improved.The report points out that wallet theft has become the attack type causing the greatest financial loss, accounting for approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks fell by more than 50% year-on-year, the loss amount only decreased by approximately 10.8%, reflecting that attackers are shifting towards high-net-worth individuals and institutional targets, carrying out more targeted high-value attacks.Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running legacy smart contracts that lack re-audits. The report also shows that mega-attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents alone causing approximately $577 million in losses, accounting for 44% of the total losses in the first half of the year. Looking at the number of incidents, the impact of single attacks, and the changing attack patterns, the Web3 industry is facing more complex and continuously escalating security challenges.
According to official social media announcements, the HTX Genesis Hackathon, hosted by HTX DAO and B.AI and co-organized by OpenCSG, TinTinLand, and OpenCity, has entered the initial screening phase. Over 100 developer teams have registered to participate, including teams from more than 30 top universities across 22 cities globally, such as Tsinghua University, Fudan University, National University of Singapore, the University of Edinburgh, and others. Reportedly, the total prize pool for this event reaches 20,000 USDT, with over $100,000 in computing power support provided. Participating teams will innovate in areas including $HTX application scenarios, B.AI ecosystem applications and computing power services, AI Agent finance, on-chain asset management, trading infrastructure, DAO tools, and intelligent financial operating systems. The HTX Genesis finals will be held offline on July 19 during the Shanghai WAIC World Artificial Intelligence Conference.
On-chain investigator ZachXBT stated that the stolen funds from the Humanity Protocol and Kelp DAO security incidents have been mixed and transferred, suggesting potential overlap among the attackers and further undermining the possibility of an insider attack on Humanity Protocol.
L2BEAT researcher @sergeyshemyakov posted on X platform, stating that a suspicious DAO proposal appeared on Tornado Cash on June 25, and the target contract of the proposal has not been verified.The address of the proposal creator obtained funds through Railgun 4 days ago. If the proposal passes and is executed, the governance contract will make a delegatecall to this target contract. The Tornado Cash fund pool itself is secure, but this proposal may directly target the Tornado Cash DAO for an attack. The DAO currently holds TORN tokens worth approximately $23 million.
Aave founder Stani Kulechov has responded to reports suggesting Kraken's parent company Payward is interested in acquiring a 15% stake in the Aave protocol, stating that AAVE is "not going to be sold at a 70% discount."Prior reports from CoinDesk indicated that Payward was in talks to acquire a 15% stake in Aave at a valuation of $385 million. If calculated at this valuation, it would represent only approximately 30% of AAVE's fully diluted valuation, significantly below the market valuation.In a post on X, Kulechov stated that the relevant reports were not entirely accurate. He did not completely deny the possibility of Aave Labs selling a portion of its held AAVE tokens, but noted that Aave Labs does have a certain allocation of AAVE, and that multiple market participants have discussed purchasing either directly or indirectly, or engaging in deeper collaboration centered around long-term partnerships.Aave is the largest decentralized lending protocol on the Ethereum ecosystem. Kulechov stated that Aave currently generates an annualized revenue of approximately $134 million, with the relevant revenue flowing to the Aave DAO. He has also previously proposed a governance plan to redirect revenue from Aave Labs, the protocol, and its products to the Aave DAO and token holders.These rumors emerge at a time when Aave is experiencing certain pressures. Following the Kelp DAO incident in April, Aave's TVL saw a significant decline. Although Aave itself was not directly attacked, the KelpDAO cross-chain bridge attacker utilized Aave to convert the stolen rsETH into other assets.
According to an official social media announcement by HTX DAO, the HTX Genesis Hackathon—organized by HTX DAO and B.AI, and co-organized by OpenCSG, TinTinLand, and OpenCity—has attracted over 90 teams to register. The total prize pool for this event amounts to 20,000 USDT, with over $100,000 in computing power support provided. The hackathon aims to encourage developers to explore use cases centered around $HTX applications, B.AI ecosystem applications and computing services, AI Agent finance, on-chain asset management, trading infrastructure, DAO tools, and intelligent financial operating systems. Winning teams will receive cash prizes, computing resources, ecosystem support, introductions to investment firms, community exposure, and follow-up grant funding. Registration for HTX Genesis closes on July 5, and the final competition will be held offline during the World Artificial Intelligence Conference (WAIC) in Shanghai on July 17–18.
Odaily, Mitchell Amador, CEO of bug bounty platform Immunefi, stated at the WAIB Summit that new AI models such as Claude Opus 4.8 and ChatGPT 5.5 are shifting the balance of cybersecurity offense and defense in favor of attackers, leading to a resurgence in crypto hacks in 2026. Data from DefiLlama shows that in April 2026, illicit actors stole over $634 million from crypto platforms, the highest monthly total since the Bybit hack in February 2025 drove losses of approximately $1.4 billion.Amador stated that the crypto industry is in a critical survival period for the next three to four years until security teams leverage similar AI models to build codebases that attackers cannot breach; if the industry adopts more crowd-sourced security solutions, this timeline could be shortened to within two years. The latest Claude Mythos model, Fable 5, from AI company Anthropic, previously raised concerns about accelerating the ability to exploit crypto vulnerabilities.Anthropic stated that Fable 5 has safeguards in place that will redirect topics related to cybersecurity and similar fields to Claude Opus 4.8. On April 19, an attacker transferred approximately 116,500 restaked Ethereum (rsETH) from Kelp DAO's LayerZero-based rsETH bridge, valued at around $290 million to $293 million at the time. Cross-chain protocol LayerZero stated that the 1/1 decentralized verification network configuration of Kelp DAO relied on a single verification path for processing cross-chain messages, creating a single point of failure. (Cointelegraph)
in April this year, KelpDAO's LayerZero bridge was exploited in a $292 million vulnerability attack, triggering an $8.45 billion deposit run on Aave within 48 hours, marking the largest capital outflow event in decentralized finance (DeFi) history. Aave founder Stani Kulechov stated that the design of Aave V3 withstood the market test, demonstrating the network's "resilience." However, independent data indicates that Aave's survival primarily relied on $300 million in emergency rescue, including a 25,000 ETH guarantee from the Aave DAO and a personal injection of 5,000 ETH (approximately $8.4 million) by Kulechov.Kulechov attributed the vulnerability to third-party infrastructure rather than core smart contracts. However, analysts pointed out that this incident exposed deficiencies in Aave's risk architecture and insurance mechanisms, leading the platform to incur significant bad debt (approximately $123.7 million in wETH). To prevent future bridge failures from triggering systemic bank runs, Aave V4 will adopt a modular "hub-and-spoke" architecture, enabling local risk auto-adjustment and collateral freezing. (CoinDesk)
According to The Block, the DeFi lending protocol Radiant Capital has announced it will officially cease operations. The protocol suffered a hack in October 2024, losing approximately $51 million; the attacker gained unauthorized access by deploying backdoor contracts on Arbitrum and BNB Chain. Earlier in 2024, the protocol had also been hit by a flash loan attack, resulting in a loss of roughly 1,900 ETH (approximately $4.5 million). After 18 months of recovery efforts, Radiant Capital stated that it has neither recovered a significant portion of the stolen funds nor secured new financing, declaring that “the DAO has no viable path forward.” The protocol will now enter a “maintenance mode”: its frontend and smart contracts remain accessible, allowing users to withdraw funds, repay loans, and manage positions. Any funds recovered in the future will be returned to affected users.
DeFi protocol Radiant has announced that after 18 months of continuous effort following a hack attack in October 2024, the DAO no longer has a viable path to continue operations and will gradually enter a "sunsetting" phase.Radiant stated that there is currently no progress in fund recovery, no new capital injection, and a lack of funds and development space to maintain normal operations. Therefore, it cannot proceed with responsible long-term operation.According to the plan, Radiant will transition to maintenance mode: the frontend interface will continue to run, on-chain smart contracts will remain accessible, and users can still withdraw, repay, and manage positions. However, the project will halt all new feature development, upgrades, and expansions. At the same time, the borrowing cap will be set to zero, incentives for issuing the RDNT token will cease, and treasury funds will be used solely to maintain basic operations. The project's future focus will be entirely on user asset security, fund recovery, and an orderly liquidation process.Radiant stated that efforts to recover assets will continue, and the relevant recovery portal will remain open. Any future recovered funds will be returned to affected users, but the outcome of the recovery remains uncertain and may take a long time. Although operations are gradually ceasing, on-chain contracts will remain available, and users need to manage their own risks and gradually exit their positions.
Stake DAO posted a response on platform X regarding the security incident, stating that its team has taken note of the incident and that users should not interact with vsdCRV for the time being.In addition, contracts related to Stake DAO on Arbitrum exhibited abnormal behavior, resulting in the minting of 5.4 trillion vsdCRV tokens. Security teams have classified this as a suspected infinite minting exploit.
Syndicate, a DAO infrastructure service provider, has announced it will gradually cease operations. It stated that after five years of continuously building on-chain developer infrastructure, the Rollup market has undergone fundamental changes. Currently, the Rollup market has significantly shrunk, some Rollup projects are gradually shutting down, and the market has shifted from EVM Rollups to custom chains built from scratch by consulting teams, leading to a notable decline in reusable technology and network value.Syndicate stated that its system consists of two parts: Syndicate Labs, responsible for development, will be closed, while the independent entity Syndicate Network Collective (Wyoming DUNA), which holds SYND tokens and has governance rights, will continue to exist. SYND governance will not be affected in the short term.Furthermore, Syndicate emphasized that this decision to cease operations is unrelated to recent cross-chain security incidents. Affected users and SYND holders have been fully compensated through the treasury reserves, and team and investor tokens are currently still in a lock-up period.
following the $292 million exploit of Kelp DAO's LayerZero bridge, the security of cross-chain infrastructure has once again come under scrutiny. DeFi protocols Kelp DAO, Solv Protocol, Re, and crypto exchange Kraken have all taken similar migration measures, with the total value of this outflow reaching approximately $4 billion.Decentralized finance protocol Lombard has become the latest project to join the migration wave, announcing a gradual phase-out of LayerZero and the migration of over $1 billion in Bitcoin collateral assets to Chainlink's Cross-Chain Interoperability Protocol (CCIP). Bitcoin-related tokens issued by Lombard include LBTC and BTC.b. It is reported that Lombard's initial migration assets cover the Solana, Etherlink, Berachain, Corn, and TAC chains, while the use of LayerZero on Morph and Swell will also be terminated. As of now, LayerZero has not responded to requests for comment. (CoinDesk)
in April 2026, two major DeFi attacks on Drift Protocol and Kelp DAO resulted in losses of nearly $600 million, triggering approximately $9 billion in capital outflows from protocols like Aave. TRM Labs investigator Nick Carlsen stated that a hacker group suspected to be linked to North Korea has allegedly used AI to assist in target selection and attack path design. Failsafe CEO Aneirin Flynn said that AI has compressed the time for discovering blockchain vulnerabilities from months to days or even hours. The report noted that Anthropic has not fully opened its AI model Mythos due to cybersecurity risks, claiming the model has the capability to discover large-scale zero-day vulnerabilities. Its research indicates that over half of blockchain attacks in 2025 could theoretically be completed autonomously by AI. (Bloomberg)