News linked to this event type.
Huma Finance posted on X platform, stating that its old v1 contract deployed on Polygon was exploited today, resulting in the transfer of approximately 101,400 USDC. This incident did not compromise user funds, and the related PST system was also unaffected. Only the gradually phased-out v1 legacy pools were impacted. The Huma v2 system is a complete rewrite deployed on Solana and is not vulnerable to this exploit. The team was already in the process of retiring v1 liquidity pools, and following this incident, they have fully suspended the operation of v1 contracts and accelerated the completion of migration efforts.
Sky (formerly MakerDAO) announced on X that the cross-chain bridging of USDS OFT on the Solana network, which was suspended due to the security review of the rsETH vulnerability incident, has resumed operation.Sky emphasized that during the review, its USDS-related contracts and the protocol itself were not affected. USDS has always maintained a fully overcollateralized state as designed, which can be verified in real-time on-chain. The suspension was a precautionary security measure. Currently, the bridging function on the Solana side has been reopened, while the Avalanche-related bridging will resume after further review is completed.
According to The Block, Rob Nichols, CEO of the American Bankers Association (ABA), sent a letter to senior bank executives on Sunday evening urging them to contact U.S. Senators and call for further tightening of provisions related to stablecoin rewards ahead of the Senate Banking Committee’s markup vote scheduled for Thursday. Nichols warned that the current draft fails to effectively prevent crypto firms from offering users “interest-like rewards,” which could trigger massive outflows of bank deposits and threaten economic growth and financial stability. The current draft was negotiated by Senators Angela Alsobrooks and Thom Tillis. It prohibits paying users interest or returns for holding stablecoins but permits rewards tied to genuine activity or transactions—a provision supported by Coinbase. Banking industry groups contend that these exceptions contain loopholes that could be circumvented, and on May 8, they jointly wrote to Committee Chairman Tim Scott and Democrat Elizabeth Warren, requesting technical revisions to the language of the provision.
Binance has released its latest security report. In response to the current industry trend of rapidly proliferating AI-powered fraud, the platform has deployed over 24 AI security initiatives and equipped more than 100 AI models to build an intelligent defense system against various types of crypto fraud. Statistics show that from the beginning of 2025 to the first quarter of 2026, Binance has protected over 5.4 million users and intercepted potential fund losses amounting to $10.53 billion.In Q1 2026, the platform successfully intercepted 22.9 million scams and phishing attacks, protecting $1.98 billion in user funds. It pushed over 9,600 real-time risk alerts daily and blacklisted a total of 36,000 malicious on-chain addresses. The report points out that AI-powered social engineering attacks, including deepfakes, voice cloning, and phishing bots, have become mainstream fraud methods. In 2025, the overall scale of crypto fraud reached $17 billion, a 30% year-over-year increase.On the risk control front, Binance's AI systems handle 57% of fraud detection work, reducing card fraud rates to 60%-70% of the industry average. Upgraded AI-driven anti-forgery KYC verification has increased audit efficiency by up to 100 times. Its AI trading tool, Binance Ai Pro, adopts an isolated account architecture, granting only trading permissions while prohibiting withdrawals. The platform blocked 12% of high-risk third-party AI plugins. Additionally, in 2025, Binance assisted in recovering $12.8 million in defrauded funds, handled 48,000 cases, and worked with law enforcement agencies to freeze $131 million in illegal assets.
Trader A (@missoralways) posted that he had stored seven-figure assets in Sigma for a long time without encountering security issues in the past. However, two of his recent wallets have suffered asset theft, both occurring when wallet balances fell below $10,000.He also stated that another friend suffered the theft of approximately $200,000 in assets today, and mentioned Sigma in connection with the incident. The Sigma team has launched an investigation. The trader said he released this information for security reminder purposes and emphasized that he is not an affiliated promoter of any bot-related products.
According to SlowMist, its security monitoring system MistEye has detected a counterfeit TronLink Chrome MV3 extension targeting TRON wallet users with a two-layer phishing attack. The extension disguises itself as the official plugin using Unicode obfuscation and brand spoofing. Upon installation, it first loads a remote iframe-based pop-up page designed to trick users into entering their mnemonic phrases, private keys, keystore files, and passwords—then exfiltrates this sensitive data via same-origin APIs to a Telegram bot. The malicious infrastructure involved includes the domains tronfind-api[.]tronfindexplorer[.]com and trx-scan-explorer[.]org; the malicious extension ID is ekjidonhjmneoompmjbjofpjmhklpjdd. SlowMist advises users to immediately uninstall the extension. If sensitive information has already been submitted, users should promptly migrate their assets and discontinue use of the compromised wallet.
According to Blockaid’s monitoring, Ink Finance’s Workspace Treasury Proxy on Polygon was exploited minutes ago, involving approximately $140,000.
According to on-chain analyst PeckShield (@PeckShieldAlert), the TrustedVolumes attacker has laundered approximately $278,000 of stolen funds to date, including depositing 10.2 ETH (approx. $23,600) into Tornado Cash and swapping 110 ETH (approx. $250,000) for BTC via THORChain. Additionally, the attacker attempted to deposit 0.5 ETH into Railgun but subsequently withdrew it. TrustedVolumes was attacked on May 7, resulting in losses of approximately $6.7 million.
South Korea’s Financial Security Institute announced three key initiatives focused on digital asset services: developing a smart contract verification tool, establishing a smart contract verification framework, and cultivating specialized talent in digital assets. The Institute will develop a dedicated security verification tool capable of automatically detecting major vulnerabilities—including reentrancy attacks, access control errors, and missed collateral checks—targeting use cases such as tokenized securities and stablecoins. Detection rules will be continuously updated to align with South Korea’s financial regulatory environment. Concurrently, the Institute will release the “Smart Contract Security Guidelines,” covering the full lifecycle of development, deployment, and operations, and will enhance financial institutions’ digital asset security capabilities through workshops, collaborative networks, and other means.
Syndicate announced on X platform that, regarding the latest developments in the Syndicate bridge security incident, all affected SYND holders on Commons Chain have been fully compensated, and have received an additional 15% payout on top of their total losses. The relevant funds have been sent directly to the affected users' Base chain wallets, with gas fees covered by Syndicate Labs. This compensation totals 12.901 million SYND, and no claim page operation is required.
Odaily News On the 10th local time, sources indicated the key points of Iran's response to the U.S., which include a demand for the U.S. Treasury Department's Office of Foreign Assets Control to lift sanctions related to Iran's oil sales within 30 days.The sources stated that the U.S. disclosure of Iran's response was inaccurate in some important aspects, particularly regarding nuclear issues. Iran's response emphasized the need to reach an agreement through political understanding, immediately end the war, ensure no further attacks against Iran, and that the U.S. must lift sanctions. Additionally, Iran's response also addressed changes in its control over the Strait of Hormuz if the U.S. fulfills certain commitments.The sources said that Iran stressed that after signing a preliminary understanding agreement, the U.S. must immediately lift the naval blockade on Iran and remove sanctions on Iran's oil sales within 30 days. Iran's response also included the U.S. unfreezing Iranian assets based on a preliminary understanding between the two sides, and the U.S. implementing certain measures within 30 days. (CCTV News)
According to CoinDesk, the floor price of Bored Ape Yacht Club (BAYC) NFTs has risen from approximately 5 ETH to over 10 ETH in the past month, while ApeCoin (APE) rebounded from below $0.10 to around $0.16 during the same period, with trading volume notably expanding. Meanwhile, repeated security vulnerabilities and persistently declining yields in the DeFi sector have driven some capital toward the NFT market. The financialization trend of NFTs is also intensifying: a recent $2.8 million loan collateralized by a CryptoPunk attracted widespread attention, with the lender expected to earn roughly $138,000 in interest over 90 days. Blue-chip collections such as Pudgy Penguins have also strengthened concurrently, and market expectations surrounding a potential token launch by OpenSea have further boosted sentiment.
following the Kelp security incident, Tether's asset interoperability protocol USDT0 has disclosed details of its protocol security architecture. It stated that the system currently utilizes a proprietary DVN (Decentralized Verification Network) with message veto authority, and requires 3 independent validators, operating on different codebases, to reach a 3/3 consensus before cross-chain messages can be settled. The current verification nodes include the USDT0 proprietary DVN, LayerZero, and Canary, with future plans to expand to 4/4 and 5/5 verification mechanisms.USDT0 also stated that all multi-signature transactions must undergo multiple reviews by internal teams, external security teams, and auditing firms before signatures are submitted. The relevant contracts have been audited by firms such as Guardian and OpenZeppelin, and a $6 million bug bounty program has been launched on Immunefi.
Wasabi Protocol released a security incident update, stating that the attacker exploited a Spring Boot Actuator configuration vulnerability in its AWS infrastructure to steal private keys controlling EVM smart contracts, and subsequently drained approximately $4.8 million in user funds and $900,000 from the protocol’s treasury—totaling roughly $5.7 million in losses. The attack chain originated from a public-facing analysis server whose Actuator heap dump was not properly password-protected, enabling the attacker to obtain credentials for another server and ultimately gain control of the smart contract private keys. This incident affected only EVM deployments—including certain treasuries on Ethereum, Base, Blast, and Berachain—while Solana deployments and the Prop AMM remained unaffected. No final user compensation plan has been announced yet; however, “ensuring all affected users are compensated” remains the team’s top priority. Updates on the investigation will be shared with the community via Discord.
Odaily News: Margaret Garnett, a U.S. District Judge in Manhattan, has approved Aave's asset recovery proposal, allowing the transfer of approximately $71 million in ETH previously frozen on Arbitrum and linked to North Korean-linked attacks, to a wallet controlled by Aave LLC, while preserving the legal claims of terrorism victim plaintiffs over the funds. The ruling also amended the earlier freeze notice against the Arbitrum DAO, permitting the transfer to be executed through an on-chain governance vote and exempting those who propose, vote on, or participate in the transfer from liability under the freeze order. The transfer is still subject to an official vote by Arbitrum's on-chain governance. (CoinDesk)
According to BusinessMirror, the Bangko Sentral ng Pilipinas (BSP) issued a warning on May 8 urging the public—especially cryptocurrency users—not to transact with unauthorized Virtual Asset Service Providers (VASPs). The BSP noted that such activities carry operational risks including fraud, cyberattacks, and insolvency, as well as a lack of legal recourse. The BSP stated it will collaborate with regulatory bodies such as the Securities and Exchange Commission (SEC) and the National Telecommunications Commission (NTC) to strengthen market oversight, restrict Filipino access to unauthorized platforms, and call on consumers to protect their personal information, practice good cybersecurity hygiene, and transact only with licensed entities.
Odaily Odaily: Aave posted on the X platform stating that the second phase of the technical solution for the rsETH incident recovery has progressed. On May 6, eight positions of the hacker on Aave V3 were liquidated, and the recovered rsETH collateral has been transferred to the recovery guardian. The Arbitrum DAO has passed a proposal to return the previously recovered $71 million in ETH.Regarding the application for asset freezing filed by the plaintiff, the judge has approved Aave LLC's proposal, allowing the transfer of the $71 million in ETH to Aave LLC through an on-chain vote by the Arbitrum DAO. Subsequent plans include burning rsETH on Arbitrum and restoring the rsETH reserve. After the reserve is restored, withdrawals will be reopened, and the WETH Loan-to-Value (LTV) ratio on the Aave V3 Ethereum mainnet will be restored.
According to The Block, blockchain security firm CertiK released a report on May 8 stating that 34 confirmed “wrench attacks” (i.e., offline physical assaults and extortion targeting cryptocurrency holders) occurred globally in the first four months of 2026—an increase of 41% compared to the same period in 2025. Victims’ total losses amounted to approximately $101 million. If this trend continues, the annual number of incidents is projected to reach around 130, with losses potentially totaling hundreds of millions of dollars. Geographically, 28 of the 34 incidents (82%) occurred in Europe, with France standing out particularly: 24 cases were recorded there in the first four months of 2026 alone—exceeding the full-year total of 20 incidents in 2025. CertiK attributes this surge to France’s hosting of flagship crypto firms such as Ledger and Binance, frequent data breaches, and a community culture of conspicuous wealth display and proactive doxxing. In contrast, reported incidents in the U.S. dropped from nine in Q1 2025 to three in Q1 2026, while Asia saw a decline from 25 to two. Regarding attack patterns, CertiK notes that criminal groups have shifted toward a “data-driven targeting” model—purchasing victims’ names, addresses, and asset information from data brokers, thereby reducing the need for physical reconnaissance. Over half of this year’s incidents involved threats against or direct harm to victims’ family members (spouses, children, elderly parents) as a coercive tactic. Operationally, small gangs of three to five individuals typically carry out these attacks via
LayerZero’s official tweet: LayerZero Labs has formally apologized for the security incident that occurred over the past three weeks and for insufficient communication. Regarding the incident, an internal RPC of LayerZero Labs was compromised by the North Korean hacking group Lazarus Group, contaminating the data sources for its Decentralized Verifier Nodes (DVNs). Concurrently, external RPC providers also suffered DDoS attacks. This incident affected a single application—0.14% of all applications—and involved assets valued at approximately 0.36% of LayerZero’s total assets. The LayerZero protocol itself remained unaffected; over $9 billion in assets continued to flow across chains normally following the incident. LayerZero Labs acknowledged that it previously permitted its DVNs to operate under a “1/1” single-node configuration to secure high-value transactions—a setup inherently vulnerable to single-point failure. LayerZero Labs accepts managerial oversight responsibility for this decision. Additionally, LayerZero disclosed that, three and a half years ago, one of its multi-signature signers had mistakenly used a multi-sig hardware wallet for personal transactions. That signer has since been removed, and the associated wallet has been rotated. As corrective measures, LayerZero Labs announced: - It has discontinued support for “1/1” DVN configurations; - It is migrating all paths to a default 5/5 multi-signature configuration, with a minimum threshold of 3/3; - It has developed a second DVN client written in Rust to ensure client diversity.
LayerZero Labs posted on platform X, stating that the internal RPC used by LayerZero Labs had been attacked by the Lazarus Group over the past three weeks, compromising the true source of its DVN (Decentralized Verifier Network). Meanwhile, external RPC providers experienced DDoS attacks. The incident affected 0.14% of applications and approximately 0.36% of asset value. LayerZero Labs stated that assets are currently secure, and over $9 billion in funds have been bridged through the protocol since April 19.In response to the security risk, LayerZero Labs has ceased providing services for its DVN in a 1/1 configuration. Default configurations for all pathways will migrate to a multi-DVN model of at least 3/3 or 5/5 signatures. Additionally, regarding an incident from three years ago where a multi-sig holder mistakenly used a hardware wallet for personal transactions, LayerZero Labs has removed that signer and replaced the wallet, while developing a custom OneSig multi-sig system. LayerZero Labs advises developers to lock configurations to avoid reliance on default settings and plans to launch an asset management platform, Console, to enhance security monitoring.