News linked to both this project and an event.
Zano disclosed a validation flaw in the Gateway Addresses introduced by Hard Fork 6. An attacker minted approximately 18.4 million ZANO in a single transaction on August 29, then minted an equal amount again on September 25, and minted fUSD in the same manner.The project team stated that the value of the illicit tokens involved exceeds $200 million, with potentially affected activity involving 117,941 outputs and 65,301 transactions. Zano has restored the chain state from block 3,833,000 and disabled Gateway Addresses. All affected balances will be fully restored, and the ZANO supply and issuance schedule will remain unchanged. (Bitcoin.com News)
Odaily News — According to monitoring by the Drift Foundation, the Drift Foundation has released an update on fund recovery progress related to the April 1 security incident: approximately $295 million in user assets were stolen. The foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct the investigation and trace the funds, with Mandiant identifying the attacker as the North Korean threat group UNC6862.The stolen funds were subsequently bridged to Ethereum, with approximately 130,300 ETH distributed across 4 wallets. Three of these wallets have seen no transfers to date, collectively holding 107,200 ETH; the other wallet transferred approximately 23,100 ETH to Tornado Cash on July 23.Currently, approximately $9.2 million in stolen funds has been frozen. The relevant funds had previously been transferred through Tornado Cash in August, and unfreezing and return still require cooperation with legal procedures. The Drift Foundation will transfer all assets recovered through freezing, bounties, or law enforcement channels into the DFX recovery pool, and is evaluating the subsequent path of the DRIFT token within the broader ecosystem. In addition, the foundation has partnered with Bybit to launch a public bounty program, offering a 10% bounty on successfully recovered funds.
Odaily News: Cosine disclosed the interim investigation reports by SlowMist and Google Cloud's Mandiant on the Bitget hot wallet breach. Both reports indicate that the attackers first compromised systems related to third-party security products, then moved laterally into Bitget's wallet business environment.SlowMist's investigation revealed that one of the third-party security product nodes had a zero-day vulnerability, with related malicious activity traced back to as early as August 31. On September 25, the attackers also used an internal employee identity to access the management platform of another third-party security product and used highly customized withdrawal tools to interact with the wallet system's withdrawal logic. Mandiant stated that after gaining persistent access through third-party security devices, the attackers moved laterally to production wallet task servers and deployed malicious programs.Mandiant also stated that no evidence of Bitget private key leakage has been found so far, and cold wallets were not affected. Both security teams are continuing to investigate the specific intrusion paths the attackers took between the relevant systems.
Odaily News: The U.S. Attorney's Office for the District of Massachusetts filed a civil forfeiture lawsuit on September 28, seeking the forfeiture of 110,300 USDT seized from a Binance account. The case involves phishing text messages impersonating Coinbase, which led to the theft of 33.7 bitcoins, worth approximately $900,000 at the time, from a beneficiary and their family trust held in the same Coinbase account.Investigators said that between June 5 and June 15, 2023, 11.2 of the stolen bitcoins were traced to the Binance account and were quickly converted into Monero. When the FBI requested the account be frozen, it held approximately 758.55 Monero; Binance transferred 110,300 USDT to a government-controlled wallet on August 3, 2026. (Bitcoin.com News)
Odaily reports: Privacy blockchain network Zano has disclosed that an inflation vulnerability involving Gateway Addresses has forced it to plan a rollback of approximately 24 hours of blockchain history, and has urged users to immediately cease all economic activity related to ZANO and Confidential Assets.Zano has promised to compensate for losses caused by the rollback, but has not yet announced the target block height for the rollback, the patched version, the compensation process, the mechanics of the vulnerability, or the amount of unauthorized assets created. Gateway Addresses went live on August 26 with Hard Fork 6. (Bitcoin.com News)
According to a Binance announcement, due to a security incident involving Zilliqa, the project team has announced the migration of ZIL from the Zilliqa mainnet to the ZILEVM network. Binance will discontinue support for the Zilliqa mainnet and will support ZIL deposits and withdrawals via the ZILEVM network. ZIL will be migrated from the Zilliqa mainnet to the ZILEVM network at a 1:1 ratio. Binance paused ZIL deposits and withdrawals on the Zilliqa mainnet at 9:00 on August 5, and will reopen deposits and withdrawals on the ZILEVM network upon completion of the migration without further notice. During the migration period, spot trading, leverage trading, contract trading, and Binance wealth management services remain unaffected.
Odaily reports: Bitcoin News posted on X that Core Lightning is urging node operators to immediately disable experimental features, as developers are investigating a vulnerability that could put channel funds at risk. This is Core Lightning's second warning within a few weeks, following an August patch and the release of the 26.06.7 upgrade after a series of AI-generated CVE reports. Core Lightning has not yet disclosed how the experimental feature could be exploited.
Odaily News: Bitcoin fork project Bitcoin BLAKE2b developers plan to restrict miners from unlocking newly mined tokens, with a waiting period set at 45 days. The related change is proposed to be executed at block height 973440. The chain forked from Bitcoin on August 8.Its native token BTCB2 is also labeled by some trading platforms as Bitcoin BLAKE2b, Bitcoin BIP-110, or XBT. BTCB2 has fallen 84% from its September high of $1,799, trading at approximately $270 to $315 in recent hours.Developer Luke Dashjr stated that some BLAKE2b mining pools are "attacking" the network. After forking, the chain inherited Bitcoin's difficulty, mining only about 8 blocks in the first 22 days, before resuming operation by enabling BLAKE2b hashing and adjusting difficulty.Currently, the chain is not listed by most trading platforms or CoinGecko and CoinMarketCap. Trading platform Neoxa has stated it supports the upcoming soft fork. (Bitcoin.com News)
Odaily reports: Owen Simonin, founder and CEO of French crypto platform Meria, stated that following several recent data breach incidents in France, there has been an increase in scam calls impersonating customer service representatives from legitimate platforms such as Binance and Meria.Scammers falsely claim that users' accounts or funds are at risk, inducing them to urgently transfer their crypto assets to designated addresses. Simonin emphasized that platforms will not ask users to initiate transactions or provide personal information when users have not proactively contacted them.In August, the French General Directorate of Public Finances (DGFiP) disclosed that a data breach incident allowed hackers to obtain the data of 678,000 taxpayers. (Bitcoin.com News)
Odaily News: Trader loshmi stated that he closed all positions on September 13, realizing $327,400 in profits from 30 days of public trading. He said he began buying when STONK had a market cap of approximately $1 million over a month ago and continued to add to his position as the price declined.Stonkfun is a Solana token launch platform that went live on August 3, allowing creators to pair new tokens with tokenized stocks. STONK is the platform's native token.loshmi disclosed that his portfolio once rose from $5,000 to over $25,000 before falling back to $4,000; during this period, he also lost over $6,000 due to a hack. He cited fatigue from intensifying competition in recent market trading as the reason for closing his positions. (Bitcoin.com News)
Empowa, a Cardano ecosystem project, disclosed two interrelated unauthorized asset transfer incidents across its three project wallets. Between November 2025 and June 2026, approximately 143,710 ADA were transferred out of one project treasury wallet in 18 transactions. The corresponding Midnight airdrop for this wallet was also registered and claimed by an unknown party using the private key, with approximately 36,000 NIGHT already transferred away. From June 2026 to August 2026, a cumulative total of approximately 4.24 million EMP tokens were transferred out of the other two project wallets, with portions sold via platforms such as Minswap and VyFi. Empowa stated that the funds from both incidents ultimately flowed into the same intermediate wallet, indicating they are controlled by the same party, although the identity of the individuals operating these private keys cannot currently be confirmed. The team has hired a professional blockchain investigation firm and plans to seek KYC information from the centralized exchange where the related funds ultimately entered.
Binance Wallet announced that following a security incident involving the Nesa (NES) token contract, Binance Alpha 2.0 will support NES contract swaps on BNB Smart Chain (BEP20) and provide compensation arrangements for eligible users: first, balances held by users as of 14:51 UTC on August 24, 2026, and maintained through to 04:00 UTC on September 5, 2026, will be swapped to the new contract at a 1:1 ratio; subsequent purchases will not be eligible for the swap and will be refunded separately. Second, users with net purchases of NES between 14:51 UTC on August 24, 2026, and 04:00 UTC on September 5, 2026, will receive an email detailing the specific refund plan within seven working days. Trading of NES on Binance Alpha 2.0 is expected to resume on September 10, 2026, at 08:00 UTC.
The Sandbox stated that it will provide full compensation to affected users for the SAND vulnerability incident on Base and BNB Smart Chain that occurred on August 22. Any wallet that legitimately held cross-chain SAND at the time of the snapshot prior to the incident will receive SAND compensation on the Ethereum network at a 1:1 ratio.
According to the post-incident report released by Tectonic, the Cronos blockchain lending protocol Tectonic suffered an oracle manipulation attack at 12:49 UTC on August 30, 2026. By repeatedly borrowing and re-collateralizing TONIC tokens 98 times within a single transaction, the attacker drove up the TONIC collateral price by approximately 195 times. Leveraging this artificially inflated value, they subsequently extracted assets with a nominal value of $120.4 million from nine lending markets, spanning USDC, USDT, WBTC, WETH, and other assets. The attacker then bridged the stablecoins to Ethereum and converted them to ETH, while selling the remaining assets for CRO on the Cronos chain before withdrawing them. Approximately $9.19 million in total successfully escaped before the network halt. At 14:32 UTC, Cronos validators emergency-paused the network, rolling back the on-chain state to pre-attack conditions and restoring assets still held on Cronos. Currently, Tectonic's supply and borrowing functions remain suspended, while withdrawal and repayment capabilities continue normally. Tracing efforts for the stolen funds are being coordinated by blockchain forensics firms, law enforcement agencies, and stablecoin issuers, with freeze requests already filed with the relevant issuers.
: Harmony has released an update on the exchange reconciliation progress following the August 11 incident. It has verified on-chain deposits/withdrawals and cross-platform fund flows with Binance, Gate, KuCoin, MEXC, OKX, and Binance.US, prioritizing the coordination of restoring ONE deposits, withdrawals, and trading, with specific timelines to be announced separately by each exchange.Harmony stated that after matching 295 cross-exchange transfers totaling approximately 3.493 billion ONE and adjusting for circular transfers and returned funds, the preliminary shortage has been reduced from approximately 10.234 billion ONE to 6.581 billion ONE, a decrease of about 3.653 billion ONE. This change reflects an adjustment in reconciliation methodology and does not equate to newly recovered funds.Among these, Binance's data remains a preliminary upper-bound estimate, while some data from Gate and OKX are still pending final verification. Exchange teams have already frozen significant ONE balances and hacker proceeds. These efforts will be coordinated with the ONE migration and validator transition proposal, and validators may cease operations starting 22:00 Beijing time on September 10.
Odaily News: Bitcoin fork asset BTCB2 hit an all-time high of $1,799 on September 5. Over the past 4 hours, its price has fluctuated between 750 and 1,000 USDC; the Neoxa USDC market recorded a 24-hour trading volume of approximately $1 million.BTCB2 originated from a chain split that occurred on August 8, 2026, at block height 961,632. The network subsequently changed its proof-of-work algorithm to Blake2 and reduced block size, and it can now be mined using Blake2-compatible ASIC miners.Neoxa Exchange and Nonkyc.io have listed BTCB2, with the former offering BTC, USDC, and USDT trading pairs, and the latter offering a USDT trading pair. Both platforms have limited liquidity, and CoinMarketCap and CoinGecko have not yet listed the asset.Based on a BTCB2 price of $1,000, its fully diluted valuation stands at approximately $20.9 billion. Since UTXOs need to be split from Bitcoin first, transactions may otherwise be vulnerable to replay attacks; the network's hash rate has risen by 30.41% over the past 7 days, reaching approximately 5.1 PH/s. (Bitcoin.com News)
According to CriptoNoticias, Argentina's Public Prosecutor's Office (MPF) conducted a specialized training course titled "Virtual Assets: Financial Analysis, Tracking, Detection and Confiscation" via Zoom on August 19 and September 2, 2026, for internal staff, officials, and judges. Led by anti-money laundering specialist Carmen Chena, the curriculum covered digital wallet asset analysis, domestic and international legal frameworks, the cryptocurrency ecosystem, and practical case studies on preservation measures. Previously, Argentina's judiciary had already accumulated extensive experience in cryptocurrency-related cases, including the freezing of 3 million USDT in December 2024 and the 2022 ruling ordering Binance to return stolen BTC.
Odaily News: FUN LONGINUS, the first on-chain game launched by FUNVERSE, will officially go live on the Anubis Chain mainnet at 10:00 UTC on September 1, 2026 (18:00 UTC+8).Originating from a hackathon, FUN LONGINUS is an Eastern martial arts-themed on-chain game built for the Anubis GameFi ecosystem.The game adopts the 24 solar terms as its competitive structure. Each round brings together 24 different addresses, with each player using fLGNS to enter the arena. The execution of matches, determination of results, and final settlement are all handled by smart contracts, ultimately crowning one champion.On August 18, 2026, FUN LONGINUS completed its "Heroes Collective Mint." Based on market prices at the time of writing, the total value of this collective mint exceeded $1.4 million.This mainnet launch marks FUN LONGINUS's official transition from the hackathon prototype, public beta, and collective mint phases into the on-chain game operation stage.
According to PeckShieldAlert, the cryptocurrency industry saw 50 major attack incidents in August 2026, an increase of 67% over the 30 incidents in July. Total losses reached approximately $136.3 million, a 49.5% decrease from the $270 million in July. The Tectonic.cro incident caused approximately $74 million in losses, ranking as the fourth-largest crypto theft of the year, behind only attacks associated with Drift, KelpDAO/LayerZero, and COLDCARDwallet. The attacker managed to cross-chain only around $6 million to Ethereum before Cronos suspended its entire network, leaving the rest of the funds mostly stranded on Cronos. The attacker has since started laundering the illicit proceeds and bridging a portion to Bitcoin, amounting to roughly $200,000 to date. Other significant attack incidents in August involved Moonwell, Termlabs, Coinsbuy, TAC, Injective, MANTRA, BounceBit, Cosmos Labs, and aquifer.
According to an official tweet from Cronos Network, the Cronos network was previously affected by a vulnerability exploit targeting the Tectonic protocol. Validator consensus triggered an emergency halt to block production to protect user assets. The on-chain state has been rolled back to pre-exploit levels, and the network resumed block production at 07:49 Beijing Time on August 31, 2026, starting from block height 90,896,189. Node operators can now upgrade to Cronos v1.7.8 and use the latest mainnet snapshot to restart their nodes. The network remains under continuous monitoring, with select protocols, RPC providers, block explorers, and cross-chain bridges gradually recovering. A full post-mortem report will be released by the team in the near future.