News linked to this event type.
Odaily News: According to Defimon monitoring, YAM Finance has suffered a governance takeover attack. The attacker self-delegated approximately 504,000 YAM tokens, accounting for about 3.3% of the total supply, slightly above the legal voting threshold, and subsequently submitted proposal #45 to YamGovernorAlpha. The proposal description is empty and only contains an operation to call the setPendingAdmin method of the YAM Timelock contract, redirecting permissions to the attacker's address. If the proposal passes and is executed, the attacker will become pendingAdmin and can then fully control the Timelock through acceptAdmin, thereby gaining administrative access to all YAM protocol contracts and the DAO treasury, involving a risk amount of approximately $337,000. As the YAM protocol is currently in a dormant state, Defimon Alerts reminds YAM holders to vote against this proposal before block height 25897343, with approximately 34 hours remaining until that block.
Odaily News: Blockchain project Core DAO has announced a coordinated emergency hard fork, caused by validators receiving CORE rewards exceeding the blockchain's originally scheduled issuance. Core DAO stated that the incident is under control, malicious validators can no longer continue to obtain excess rewards, and the upgrade will not roll back the network or revoke confirmed transactions.Core DAO previously stated that a small number of validators had accumulated rewards significantly higher than the protocol's set issuance, and that the incident only involved reward distribution, with user assets remaining secure. Coinbase, Bithumb, Coinone, Bitget, and LBank had restricted CORE deposits, withdrawals, or transfers.Core DAO has not yet disclosed the amount of excess CORE issued, the duration of the related activity, whether the extra tokens entered circulation, or the cause of the vulnerability, and stated that it will publish a technical post-mortem report. (Cointelegraph)
Odaily News: The Fogo mainnet has restarted and is operating normally. A total of 400 million FOGO tokens were stolen in this incident, of which 237 million have been recovered and permanently removed from the total supply. The team stated that they are cooperating with exchanges and law enforcement to continue recovering the remaining affected assets, and the investigation is still ongoing.
The Sui ecosystem DeFi protocol Full Sail stated that its protocol has been affected by the Switchboard oracle security incident and has decided to gradually wind down operations. Affected protocols include Virtue Money, which reported losses of approximately $455,000, with 45 users liquidated. Switchboard has issued a statement regarding the incident, but as of September 1, it has not provided the technical details requested by Full Sail, nor has it committed to compensation. Mysten Labs rejected Full Sail's request for financial support. Full Sail stated that all remaining liquidity from the protocols will be prioritized for distribution to users, with the team covering any shortfall to ensure community depositors receive priority compensation.
Clashes between the US and Iran erupted twice within three days, as Iran retaliated for the US strike. Trump warned that if Iran continues to counterattack, it will face a more intense assault, noting that a final strike is currently being prepared.
US-Iran military conflict escalates sharply as both sides exchange strikes on energy and military targets; a senior Federal Reserve governor warns of interest rate hikes, while Russia signals it will strike Ukrainian energy infrastructure.
Odaily News: Blockchain intelligence firm TRM Labs reports that 32 price manipulation attacks have been recorded in 2026, surpassing the total of any previous full year; 2025 saw 12 incidents throughout the year. Such attacks account for roughly one-eighth of hacker incidents, up from one-seventeenth in 2022.Attackers typically first inflate the price of low-liquidity tokens, then use them as collateral to borrow other assets from lending protocols. Subsequently, they cause the collateral price to plummet and abandon the collateral, potentially leading to bad debt in the lending pools.According to DeFiLlama data, the total value locked in crypto-collateralized lending protocols has grown by approximately 56% over the past two years, approaching $50 billion, with active loan volume nearing $29 billion. The sector currently hosts over 570 lending protocols.Recently, Tectonic suffered losses exceeding $70 million after the TONIC price was artificially inflated, with the attacker ultimately extracting approximately $6 million in assets after the Cronos chain was rolled back; Moonwell also previously incurred losses of around $8.7 million due to manipulation of the MAMO oracle price. (Bitcoin.com News)
The UK National Crime Agency announced the freezing of assets belonging to NFT platform Sorare, seizing approximately £1 million in funds. The case involves cryptocurrency fraud and money laundering using proceeds from the Binance hack.
US President Trump stated that the US military is striking Iranian targets near the Strait of Hormuz in response to Iran laying naval mines and firing eight missiles at bases in Jordan. He warned that if Iran retaliates, it will face even more intense and lethal follow-up strikes.
According to CoinDesk, several prominent figures in the cryptocurrency industry and CoinDesk employees received numerous unsolicited password reset emails via the X platform on Tuesday, with some users receiving up to 10 within a few hours. Crypto investor Nic Carter urged users to enable X's "password reset protection" feature as soon as possible. Currently, there is no evidence that the X system has been breached or that accounts were hijacked en masse, and X has not issued an official statement regarding the incident.
According to Cointelegraph, cybersecurity firm Morphisec has revealed that a counterfeit desktop application masquerading as Anthropic’s "Claude Opus 5 Free Desktop" is being leveraged to distribute the Windows malware RevStealer. The malicious program can exfiltrate data from over 50 cryptocurrency wallets, while simultaneously harvesting sensitive information including browser passwords, cookies, VPN configurations, message logs, and screenshots. RevStealer incorporates anti-detection measures, performing system environment checks on the target device prior to execution. If traces of debugging or virtualized environments are detected, it aborts its operation. Additionally, Russian cybersecurity company Kaspersky has disclosed OkoBot, a novel malware framework targeting crypto investors capable of harvesting wallet files, injecting malicious extensions, and capturing wallet application windows to siphon assets.
The official X account of Injective (@injective) issued a statement confirming that Injective recently completed an accelerated network upgrade. The upgrade process exceeded the expected timeline, resulting in some validators being temporarily jailed for failing to complete the update within the required window. Consequently, the network's staked amount experienced a brief decline, and several exchanges temporarily suspended deposits and withdrawals. This accelerated upgrade was initiated in response to a vulnerability exploit targeting a minority of ecosystem applications within the binary options market. The attack was confined to the respective application layers, leaving the Injective mainnet, underlying protocol, native assets, and consensus mechanism unaffected. The associated attack vectors have been successfully contained and remediated. Injective stressed that all user funds on-chain and staked INJ tokens remained fully secure, noting that external reports characterizing the event as the "blockchain being attacked or shut down" were inaccurate. Moving forward, Injective will implement enhanced invariant detection, real-time monitoring systems, and additional security safeguards, while maintaining continuous collaboration with ecosystem developers to raise overall security standards.
According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.
Odaily News: FUN LONGINUS, the first on-chain game launched by FUNVERSE, will officially go live on the Anubis Chain mainnet at 10:00 UTC on September 1, 2026 (18:00 UTC+8).Originating from a hackathon, FUN LONGINUS is an Eastern martial arts-themed on-chain game built for the Anubis GameFi ecosystem.The game adopts the 24 solar terms as its competitive structure. Each round brings together 24 different addresses, with each player using fLGNS to enter the arena. The execution of matches, determination of results, and final settlement are all handled by smart contracts, ultimately crowning one champion.On August 18, 2026, FUN LONGINUS completed its "Heroes Collective Mint." Based on market prices at the time of writing, the total value of this collective mint exceeded $1.4 million.This mainnet launch marks FUN LONGINUS's official transition from the hackathon prototype, public beta, and collective mint phases into the on-chain game operation stage.
Aquifer, an automated market maker within the Solana ecosystem, suffered losses of approximately $2.5 million after its wallet addresses were compromised. The incident appears to stem from leaked wallet credentials rather than a smart contract vulnerability. The attackers operated across multiple blockchains, including Ethereum and Solana, suggesting potential cross-chain fund transfers. As of now, the specific cause of the wallet access breach and the progress of asset recovery remain unclear.
According to PeckShieldAlert, the cryptocurrency industry saw 50 major attack incidents in August 2026, an increase of 67% over the 30 incidents in July. Total losses reached approximately $136.3 million, a 49.5% decrease from the $270 million in July. The Tectonic.cro incident caused approximately $74 million in losses, ranking as the fourth-largest crypto theft of the year, behind only attacks associated with Drift, KelpDAO/LayerZero, and COLDCARDwallet. The attacker managed to cross-chain only around $6 million to Ethereum before Cronos suspended its entire network, leaving the rest of the funds mostly stranded on Cronos. The attacker has since started laundering the illicit proceeds and bridging a portion to Bitcoin, amounting to roughly $200,000 to date. Other significant attack incidents in August involved Moonwell, Termlabs, Coinsbuy, TAC, Injective, MANTRA, BounceBit, Cosmos Labs, and aquifer.
According to a GoPlus Chinese community security alert, a user had approximately 97,000 SYN drained by a phisher after signing a malicious Permit transaction 922 days ago. Subsequently, due to failing to revoke the related approval, an additional $122,000 worth of SYN was stolen. GoPlus warns users to guard against phishing risks, avoiding clicking unfamiliar links, installing unverified software, signing unknown transactions, or transferring funds to unverified addresses.
Anthropic has released a new study titled "Training a Misaligned Reward Chaser," examining whether "reward hacking" during training compels models to pursue rewards at all costs. The research team trained an Opus-scale model across 80 known exploitable production environments. Simulated evaluations revealed that the model engaged in unauthorized network attacks, tampered with reward mechanisms, and attempted to evade security monitoring.
On September 1, tensions in the Middle East continued to escalate as Iran claimed to have shot down two US military MQ-9 drones in the Strait of Hormuz and attacked a UAE base. Tehran warned that it would respond with overwhelming retaliation if attacked, while also expressing willingness to resolve differences through negotiations.
Investigations reveal that North Korean hackers have moved tens of millions of dollars in funds on the decentralized exchange Hyperliquid; meanwhile, the Trump administration is pushing for the protocol to launch in the United States and seeking compliance.