News linked to this event type.
NEAR Intents stated that the vulnerability involved flaws in the Omni deposit and withdrawal infrastructure and smart contract interactions. The issue has been fixed, and the team has committed to full compensation.
MetaMask announced it is exiting the affected validator nodes in its non-custodial staking service, and there are currently no signs that wallets or customer funds have been compromised.
Attackers exploited a voting power calculation vulnerability to submit two malicious proposals attempting to replace the voting mechanism and transfer funds from the DAO treasury, but neither proposal passed, and no funds were transferred.
Zcash founder Zooko Wilcox stated that Zcash recently distributed over $8 million in retroactive funding to contributors, with several million dollars allocated to reward those who volunteered to protect users during this year's AI vulnerability crisis.
Ethena founder Guy Young stated that USDe backing assets currently have no direct exposure to stETH or other liquid staking tokens, and he expects this incident will not impact Ethena.
ether.fi stated that it is aware of the security incident involving Ethereum node operators that occurred previously. Currently, weETH is unaffected and has no related exposure, and all user funds remain secure.
Aave founder Stani stated on X that the team is tracking the developments of the MetaMask staking infrastructure security incident in collaboration with Lido. Stani noted that so far, the Aave market has not been affected by the incident, and all operations remain fully operational.
MetaMask stated that some infrastructure was affected by a security incident, but no direct threat to MetaMask wallets has been identified to date, and it has voluntarily exited the affected validator nodes.
Bitget announced it will gradually resume normal operations following a fund loss incident of approximately $388 million. Its protected Operations Protection Fund absorbed the financial impact of the loss, though the cause of the attack has not yet been fully determined.
former UK National Crime Agency (NCA) officer Paul Chowles has been ordered by a court to forfeit £1,810,700, approximately $2.4 million, for stealing 50 bitcoins from a wallet seized during the Silk Road 2.0 investigation. The bitcoins were worth about $77,000 at the time of the theft in 2017.Of those, 30 bitcoins have been recovered, and the forfeiture order accounted for their current total value. Paul Chowles pleaded guilty in 2025 to theft, transfer, and concealment of criminal property, was sentenced to 5 years and 6 months in prison, and was dismissed by the NCA in July of the same year. (Decrypt)
Odaily — Ostium has released an update on the July 15 exploit and a recovery plan for OLP holders. Ostium stated that the attack resulted in approximately $23.75 million being withdrawn from the Ostium Liquidity Pool (OLP), and available evidence suggests the attack may have been carried out by a nation-state actor. As of now, 649,967 USDC has been recovered, and the remaining vault assets currently held by affected users are worth approximately 30% of their pre-incident OLP positions.Ostium launched its recovery portal today and took a snapshot of OLP balances at the time of the incident, identifying a total of 3,666 affected wallets. Of these, 3,321 wallets — or 90.59% — are eligible for full compensation of verified losses through the Phase 1 plan. Users with losses of 1,000 USDC or less can directly claim an equivalent amount in USDC; users with losses exceeding 1,000 USDC may choose to claim 1,000 USDC and forfeit the remaining recovery allocation, or participate in the Phase 2 proportional recovery plan.Phase 2 funding will primarily come from subsequent recovery of attacker funds and a share of Ostium protocol revenue, with the specific revenue share ratio and related arrangements to be announced by October 30.As previously reported, Ostium's off-chain infrastructure was hacked on July 15, resulting in approximately 23.75 million USDC being withdrawn from the OLP vault.
Odaily News — According to monitoring by the Drift Foundation, the Drift Foundation has released an update on fund recovery progress related to the April 1 security incident: approximately $295 million in user assets were stolen. The foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct the investigation and trace the funds, with Mandiant identifying the attacker as the North Korean threat group UNC6862.The stolen funds were subsequently bridged to Ethereum, with approximately 130,300 ETH distributed across 4 wallets. Three of these wallets have seen no transfers to date, collectively holding 107,200 ETH; the other wallet transferred approximately 23,100 ETH to Tornado Cash on July 23.Currently, approximately $9.2 million in stolen funds has been frozen. The relevant funds had previously been transferred through Tornado Cash in August, and unfreezing and return still require cooperation with legal procedures. The Drift Foundation will transfer all assets recovered through freezing, bounties, or law enforcement channels into the DFX recovery pool, and is evaluating the subsequent path of the DRIFT token within the broader ecosystem. In addition, the foundation has partnered with Bybit to launch a public bounty program, offering a 10% bounty on successfully recovered funds.
Odaily reports: A wallet linked to the $387.5 million Bitget exploit transferred 2,746 ZEC into Zcash's Ironwood privacy pool on Wednesday across three transactions, worth approximately $3.9 million.The funds account for roughly 15% of the ZEC stolen on September 24. The Ironwood privacy pool can conceal the sender, recipient, and transfer amount, but investigators may still be able to trace the path of funds returning to public addresses through transaction timing and amounts. (CoinDesk)
链上侦探 ZachXBT 发文表示,Bitget 被盗事件中疑似朝鲜关联的攻击者已开始将约 2700 枚 ZEC(约 380 万美元)转入 Zcash 的 Ironwood 屏蔽池。Bitget 热钱包此前共被盗约 1.89 万枚 ZEC,价值约 2830 万美元。
Odaily News: Cosine disclosed the interim investigation reports by SlowMist and Google Cloud's Mandiant on the Bitget hot wallet breach. Both reports indicate that the attackers first compromised systems related to third-party security products, then moved laterally into Bitget's wallet business environment.SlowMist's investigation revealed that one of the third-party security product nodes had a zero-day vulnerability, with related malicious activity traced back to as early as August 31. On September 25, the attackers also used an internal employee identity to access the management platform of another third-party security product and used highly customized withdrawal tools to interact with the wallet system's withdrawal logic. Mandiant stated that after gaining persistent access through third-party security devices, the attackers moved laterally to production wallet task servers and deployed malicious programs.Mandiant also stated that no evidence of Bitget private key leakage has been found so far, and cold wallets were not affected. Both security teams are continuing to investigate the specific intrusion paths the attackers took between the relevant systems.
Odaily reports: Bitget stated on X platform that an investigation by Google Cloud's Mandiant into Bitget's September 24 security incident found that attackers gained unauthorized access to certain third-party security devices, then laterally moved into Bitget's exchange wallet environment and obtained access to both warm and hot wallets. The investigation findings are consistent with the attack path previously disclosed by Bitget.
Odaily News — SlowMist security team has disclosed preliminary investigation findings on the September 25 theft of assets from Bitget's hot wallet. The investigation found that the attack involved certain third-party security products and wallet application hosts, with a zero-day vulnerability present in one of the third-party products. The attacker also gained unauthorized access to a third-party product management platform by impersonating an internal employee.SlowMist stated that the team has obtained the custom withdrawal tool used by the attacker to interact with the wallet system's withdrawal logic. On-chain attack activity began at 2:31 on September 25, lasted approximately 2 hours and 52 minutes, and involved multiple blockchains. The attacker subsequently attempted to tamper with withdrawal records and trigger additional BTC withdrawals. The team is still investigating how the attacker moved laterally between the affected systems.
Voting results for the Zcash Q3 Token Holder Targeted Retroactive Funding Program indicate that both bounty proposals for Taylor Hornby, discoverer of the Orchard counterfeit coin vulnerability, have been approved. The awards include a $750,000 vulnerability bounty requested by himself, along with an additional $750,000 bonus nominated by community members, totaling $1.5 million. In accordance with regulations, recipients are required to complete subsequent steps including identity verification (KYC) and fund disbursement.
Odaily News — According to monitoring by SlowMist's Yu Xian, MistTrack_io's TrackAgent discovered that North Korean hackers used automated scripts to create orders on CoW Protocol and set the receiving address to pre-prepared Chainflip Deposit-related contract addresses. After the orders were filled, the relevant assets could complete cross-chain operations on Chainflip and be swapped into BTC. The operation involves stolen Bitget funds.
The Abracadabra community is voting on a proposal for the orderly shutdown of the protocol and its stablecoin MIM (Magic Internet Money). The proposal notes that, affected by factors such as multiple previous hacking attacks, the protocol currently holds approximately $21 million in bad debt. With the circulating MIM supply nearing $22 million and recoverable collateral valued at only around $900,000, the effective asset reserve ratio has fallen below 4%, leaving no viable path to restore the peg.