News linked to this event type.
Investigations reveal that North Korean hackers have moved tens of millions of dollars in funds on the decentralized exchange Hyperliquid; meanwhile, the Trump administration is pushing for the protocol to launch in the United States and seeking compliance.
Odaily News: Yu Xian, founder of Slow Mist, posted on platform X that a recent group theft incident occurred, involving more than one hundred addresses and dozens of real users. The cause was private key leakage, resulting in hackers profiting approximately $200,000. The common factor was that all affected users had previously used the iToken wallet—a wallet that had been discovered in the past to collect users' private keys/mnemonic phrases, and related individuals from the group had been arrested before.
According to an official tweet from Cronos Network, the Cronos network was previously affected by a vulnerability exploit targeting the Tectonic protocol. Validator consensus triggered an emergency halt to block production to protect user assets. The on-chain state has been rolled back to pre-exploit levels, and the network resumed block production at 07:49 Beijing Time on August 31, 2026, starting from block height 90,896,189. Node operators can now upgrade to Cronos v1.7.8 and use the latest mainnet snapshot to restart their nodes. The network remains under continuous monitoring, with select protocols, RPC providers, block explorers, and cross-chain bridges gradually recovering. A full post-mortem report will be released by the team in the near future.
Odaily News: Balancer has announced that a vulnerability has been discovered in its legacy Balancer v1 contracts, which could potentially lead to LP funds being drained. The affected liquidity pools have been deprecated and cannot be paused, so users are advised to withdraw their liquidity as soon as possible. Other Balancer products are not impacted.
According to BeInCrypto, Elon Musk predicted that by the end of 2027, AI will reach superhuman levels across all digital tasks, with AI hacking capabilities surpassing human abilities being one of them. Previously, software company JFrog disclosed a critical vulnerability (CVE-2026-82329) in its code repository tool Artifactory, with a CVSS score as high as 9.8. It can be exploited without authentication, remains exposed with default configurations, and poses a risk of supply chain attacks. Notably, OpenAI models independently discovered nine zero-day vulnerabilities in Artifactory during tests in July of this year.
According to CNBC, Andrew Bailey, Governor of the Bank of England and Chairman of the Financial Stability Board (FSB), wrote to G20 finance ministers and central bank governors on August 31 to warn that frontier AI models are exhibiting increasingly sophisticated autonomy and threat capabilities, which could fundamentally alter the speed, scale, and economics of cyberattacks, potentially triggering disorderly adjustments across global financial markets. Bailey noted that highly concentrated third-party service providers will become critical nodes of systemic risk, emphasizing that most countries currently lack regulatory frameworks for the development and deployment of frontier AI. He also flagged vulnerabilities in sovereign debt markets, the growing trend of leverage in equity markets, and the overvaluation of AI-related assets, urging governments to accelerate the refinement of relevant safety mechanisms.
According to Digital Asset, South Korea's National Tax Service stated that it will introduce commercial blockchain tracking software used by domestic and international law enforcement agencies, including prosecutors, police, and the IRS, to track and analyze transfers between digital asset wallets in order to prevent tax loopholes arising from personal wallets. Meanwhile, regarding tax oversight of overseas exchanges, South Korea will address this through the Crypto-Asset Reporting Framework (CARF). Taking effect in 2028, CARF will cover transaction information from 2027, aligning with the timeline of the domestic digital asset income tax, which will be levied starting in 2027 with declarations due in May 2028, thereby achieving effective tax coverage of overseas holdings.
According to German newspaper DIE ZEIT, Berlin's administrative data network has been targeted by hackers for over two weeks. The hacker group Rhysida has threatened to make public a large volume of stolen sensitive data if Berlin refuses to pay a ransom of 30 bitcoins (approximately 2 million euros). The allegedly stolen data reportedly includes around 46,000 contracts, over 11,000 confidential documents, nearly 6,000 passwords, 16,000 emails, and 148 IBAN accounts. Citing "investigative strategy reasons," the Berlin state government has declined to disclose the ransom demands and details of the data breach. Governing Mayor Kai Wegner stated that Berlin will not succumb to extortion.
Odaily News: According to blockchain security firm Blockaid's monitoring, More Markets (More Labs) on Flow EVM has been exploited. The attacker leveraged Ankr's liquid staking tokens and the E-Mode mechanism to drain More Markets' WFLOW lending reserves, transferring approximately 15.5 million WFLOW from the mFlowWFLOW reserve. The detected impact amount is approximately $9.3 million, and the related attack transaction cluster also includes post-exploit fund transfer operations. At present, the specific losses and the destination of the attacker's funds are still under further confirmation.
Binance announced that due to a hack on BounceBit and the project team's decision to permanently shut down the chain, Binance will stop supporting the BounceBit (BB) mainnet. Binance has suspended deposits and withdrawals of BB on the BounceBit mainnet as of 10:00 (UTC+8) on August 20, 2026, and will reopen deposits and withdrawals via the BNB Smart Chain (BEP20) network starting at 15:00 on September 1, 2026. BB will be migrated from the original mainnet to the BNB Smart Chain at a 1:1 ratio. During the migration, spot, margin, futures, and Earn services will remain unaffected.
PeckShieldAlert monitoring indicates that Tectonic was attacked on the Cronos Network, resulting in total losses of approximately $74 million. Following the incident, Cronos has halted the entire chain. Prior to the halt, the attacker successfully bridged only about $6 million to Ethereum, while the remaining approximately $60 million remains stranded on Cronos, with an additional $8 million in funds held in Cronos addresses.
Odaily News: Bitcoin News posted on X platform that Blockstream stated Jade is not affected by the Coldcard random number generator vulnerability, and has released firmware 1.0.41 following a large number of AI-assisted security reviews.Jade stated that it has undergone dozens of automated AI scans and multiple manual reviews, focusing on sensitive areas such as random number generation and transaction signing.The new firmware strengthens stack protection, updates dependencies, audits sensitive memory cleanup processes, and upgrades the Jade runtime environment.Blockstream stated that Jade's random number generation mechanism uses multiple entropy sources, including hardware chip noise, timing data, sensor data, and camera noise, mixed via SHA-512 to prevent a single entropy source failure from affecting seed generation.The team stated that other lower-severity findings are still being addressed, and firmware 1.0.42 is expected to be released within a shorter development cycle.
Yi Lihua, founder of LD Capital, stated that over the past decade-plus, the crypto industry has gradually formed a "small world." However, in recent years, industry attention has increasingly been captured by negative content such as smear articles, traffic competition, personal attacks, and fabricated narratives, which has inevitably impacted the sector's reputation. He believes the industry should refocus its attention on innovation and opportunities themselves, stating that "a new bull market is approaching." On-chain finance, particularly on-chain stocks, is unlocking new avenues for imagination, with substantial meaningful developments and wealth-creation opportunities still ahead. Furthermore, compared to the crypto industry, the significantly larger AI sector is equally worth exploring.
The self-proclaimed "White-Haired Stock Guru" Serenity posted that he recently observed a disappointing pattern: first attempting to compete for the same audience, then quickly funneling traffic toward paid communities or high-priced services. After he refuses to join or promote paid groups, they switch to personal attacks, framing them as "fundamental viewpoint disagreements." When he first joined X, financial content was saturated with luxury watches, private jets, options trading, and promotions for "Wall Street Secrets" paid communities and technical analysis charts. Consequently, he has always aimed to take a different approach by publicly sharing his research and investment logic, making it freely accessible to everyone so they can form their own judgments. Serenity added that although some had previously claimed he would eventually raise the subscription price to $100, his rate has consistently remained at $1 for months and will continue to be kept at the lowest possible price. He also outlined his investment perspectives on stocks such as AXTI, NBIS, AEHR, MU, and INTC. Serenity noted that some investment themes may not be verifiable until 2027–2028, covering subjects related to Sivers, Foci, and Shunsin. Finally, Serenity emphasized that not every investment thesis needs to be right, as uncertainty is inherent to research. Rather than seeing information increasingly trapped behind a $100 paywall or diluted by engagement-bait content, he hopes X will cultivate a new culture centered on openly sharing investment logic, enabling everyone to learn from rigorous research.
Odaily News: The sandwich attack bot operated by JaredfromSubway.eth has extracted a cumulative total of 117,007 ETH since March 2023, worth approximately $295 million at current prices. In June 2026, an anonymous attacker deployed 66 counterfeit token contracts, exploiting the bot's automated trading logic to steal at least $7.5 million in ETH and stablecoins, and funneled the funds into Tornado Cash. The stolen assets have not yet been recovered.Sandwich attacks are a form of Maximal Extractable Value (MEV): the bot monitors large transactions in Ethereum's public mempool, buys ahead of the target transaction, and sells after the transaction pushes the price up, capturing profits from the spread. The bot's primary contract had received a cumulative total of 117,007 ETH as of August 28.MEV-Boost block construction is centralized among a small group of participants, with relay.ultrasound.money, Titan Relay, and bloXroute regulated relays collectively forwarding approximately 85% to 88% of related blocks within a 24-hour window; Titan's builder independently assembled 50.3% of the blocks. Monthly sandwich attack extraction amounts have declined from approximately $10 million in late 2024 to roughly $2.5 million in October 2025. (Bitcoin.com News)
SVM Layer 1 network Fogo stated that after detecting unauthorized activity, it has taken precautionary measures to temporarily halt the Fogo mainnet in order to prevent the continued transfer of affected assets. During the mainnet suspension, Fogo will upgrade the network and restrict addresses associated with the incident. The team stated that further updates will be released once more information is confirmed, and reminded users to obtain relevant information only through Fogo's official channels. At present, the cause of the incident, the scale of affected assets, and the timeline for mainnet restoration have not yet been disclosed. Previously, the Fogo Foundation was breached by an unknown attacker, with approximately 400 million FOGO tokens transferred to the attacker's address. The foundation stated that it had immediately notified relevant trading platforms and is in communication with law enforcement agencies and forensic experts.
Oracle protocol Switchboard issued a statement disclosing a report of a potential overnight attack. The Switchboard team has partnered with relevant projects and security agencies to take measures, suspending its network services on the Aptos, Sui, IOTA, and Movement chains. Currently, there are no similar reports indicating a comparable intrusion attack on the Solana chain. However, for security reasons, official channels recommend that users migrate to alternative oracle solutions as soon as possible, at least temporarily, during the investigation period. The team continues to investigate the incident and will release further details subsequently.
According to Cointelegraph, Polygon disclosed several previously undisclosed security vulnerabilities affecting its Bor and Heimdall clients, which could lead to denial of service (DoS), validator resource exhaustion, and anomalies in checkpoint and milestone processing. The relevant vulnerabilities have currently been patched through two hard forks: Austin and Kyoto.
A new bank in the Solana ecosystem, Avici, suffered a security breach, resulting in nearly $1 million being stolen from its crypto debit card vault. Following the news, the AVICI governance token experienced severe volatility, plummeting more than 40% in a single day.
Polygon disclosed multiple hidden security vulnerabilities affecting its PoS network and implemented preventive fixes through a recent fork, with no evidence of actual exploitation.