News linked to both this project and an event.
A crypto asset vault on Base had approximately 1,783 wstETH transferred out on October 4, resulting in losses exceeding $6 million. On-chain records show that the vault is controlled by a 3-of-7 Safe, and the identities of the seven signers have not yet been made public.Security firms stated that the attacker borrowed aBaswstETH from the vault and swapped it for wstETH through Aave. Neither the Base chain itself nor Aave's core contracts have been identified as being exploited, and the specific authorization vulnerability remains unconfirmed. (Bitcoin.com News)
According to Spot On Chain monitoring, a vault on the Base chain was attacked, with losses expanding to approximately $6 million, involving around 1,783 wstETH. The attacker added a new contract to the vault's whitelist, borrowed aBaswstETH, and transferred it to an attacker-controlled contract.
According to Spot On Chain monitoring, the losses from the vault attack on Base chain have expanded to approximately $6 million, involving about 1,783 wstETH. The attacker added a new contract to the vault's whitelist, borrowed aBaswstETH from the vault, and transferred it to the attacker's contract. The attacker's address is a certain address. Spot On Chain stated that systemic risk is currently limited, but caution is needed regarding the potential short-term pressure on the peg of liquid staking tokens caused by the attacker selling off wstETH.
According to Blockaid monitoring, a vault on the Base chain is currently under attack. The attacker added a brand-new contract to the vault's whitelist, then borrowed aBaswstETH and transferred it to the attacker's contract. The attack is still ongoing, and approximately 4 transactions have resulted in about $2.02 million in assets being stolen.
Odaily reports: Xie Jiaxin posted on X stating that this Bitget security incident involved multiple non-EVM chains and 10 tokens, and due to the different method of asset theft, different approaches to handling and restoring withdrawals were taken compared to last year's Bybit security incident in order to thoroughly eliminate potential risks.Additionally, Xie Jiaxin stated that he and Bitget CEO Gracy Chen will host a community livestream 30 minutes before withdrawals resume on Monday to discuss this security incident and answer community questions.Bitget announced on X that it will restore withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate normally, and users do not need to take any action in advance.
Odaily News: Bitget posted on X platform that the vulnerability involved in the September 24 security incident has been identified and fixed. The team is conducting additional verification and security checks on the withdrawal infrastructure, with Mandiant and SlowMist continuing to assist with the investigation. The temporary suspension of withdrawals is a security measure and is unrelated to the availability of user assets; user account balances have not been affected, and the Bitget Protection Fund will cover the financial impact of this platform-wide incident.Bitget plans to resume withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on the Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on the Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate, and users do not need to take any action in advance.
Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.
Magic Eden clarified on the X platform that Payment Processor V2, an NFT trading protocol under Limit Break, was recently exploited. Magic Eden stopped using this protocol in October 2024 and will completely shut down its EVM marketplace in Q1 2026, so this exploit did not affect existing Magic Eden listings. However, NFTs listed on the Magic Eden EVM marketplace from February to October 2024 may have been impacted, and users should revoke the "Approve for All" authorization for the contract on Ethereum, Polygon, and Base. Additionally, Magic Eden stated it is collaborating with Limit Break to investigate and seek further mitigation measures.
Bitget CEO Gracy Chen posted a 12-hour progress report on the security incident on X, including:1. Affected assets include ETH, XRP (largest single-chain loss), BNB, AVAX, USDT, USDC, and other tokens. Affected chains include: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. All on-chain cold wallets have been confirmed secure and unaffected.2. All foundations of the affected chains have been contacted, and some foundations have confirmed the freezing of the hacker's wallet addresses.3. Based on IP behavioral characteristics and on-chain analysis, the attack methodology is highly consistent with known patterns of North Korean hacker groups. Relevant authorities have been notified, and full cooperation is being provided for a global investigation.4. Bitget Wallet (decentralized wallet) operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it. Bitget Wallet assets are completely safe.5. Transparent disclosure regarding the platform's financial status: In addition to over $464 million in protection funds (all held in publicly verifiable wallet addresses), Bitget's own assets exceed $1 billion. User funds are covered at a 1:1 ratio, and all data can be verified on-chain.6. Regarding withdrawal recovery timing: The goal is to achieve full recovery as soon as possible. Once a specific time window is confirmed, an announcement will be made immediately. No commitment will be made to timelines that cannot be fulfilled.
The Sandbox stated that it will provide full compensation to affected users for the SAND vulnerability incident on Base and BNB Smart Chain that occurred on August 22. Any wallet that legitimately held cross-chain SAND at the time of the snapshot prior to the incident will receive SAND compensation on the Ethereum network at a 1:1 ratio.
According to disclosures from the Phoenix Veritas Foundation, the Hunter Biden laptop-themed cultural token, LAPTOP, has been issued on the Base chain with a total supply of 1 billion tokens and an initial circulating supply of 350 million tokens (35%) at TGE. Token allocation consists of 30% for founders (including Hunter Biden), 30% for the prediction mechanism, 20% for the community airdrop, 10% for liquidity, 10% for the foundation treasury, and 5% for charity. Founder tokens are subject to a six-month lock-up period followed by linear unlocking over 24 months. LAPTOP provides no utility, positioned strictly as a cultural digital collectible with its value driven entirely by community sentiment. The token contract underwent a security audit by Hacken in April 2026, revealing no major vulnerabilities. Regarding market maker arrangements, the foundation has entered into a lending agreement with G20 and GSR totaling 20.5 million tokens.
Odaily News, Base co-founder Jesse Pollak issued a statement on the X platform clarifying that his account was compromised. The attacker published a fraudulent token ticker through a third-party application connected to the account. Jesse stated that the related posts have been deleted, all third-party app connections have been removed, and full control of the account has been restored. He reminded users to stay vigilant.According to screenshots of the deleted posts, the attacker, after gaining control of Jesse Pollak's account, launched a token named BASEMEME, describing it as the "first Meme coin with real utility," while attaching a trading link to o1.exchange and the contract address. The Meme coin's market cap currently stands at $257,000.
blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)
According to monitoring by Blockaid, its vulnerability detection system detected suspicious activity on Moonwell on Base. The attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market. To date, approximately 50.6 cbBTC (valued at over $4 million) have been observed being transferred. More details remain to be disclosed.
Odaily News, The Sandbox has released a post-mortem report on the August 22 vulnerability incident. The report shows that attackers exploited vulnerabilities in contracts related to cross-chain configurations on Base and BNB Smart Chain (BSC), stealing 14,742,341.84 SAND from the Ethereum treasury, accounting for approximately 0.5% of the maximum supply, with an estimated economic impact of approximately $1.4968 million, of which about $987,000 was actually retained by the attackers. The Ethereum mainnet and Polygon network were not affected. Until further notice, please do not purchase or send SAND on Base or BNB Smart Chain. Contracts deployed on Base and BNB Smart Chain have been permanently deactivated and will not be reopened. The Sandbox stated that the team has reported the attacker's wallet address to blockchain analysis firms TRM Labs and Chainalysis, and has communicated directly with relevant exchanges. The Sandbox also announced a compensation plan, which will compensate wallets that legitimately held cross-chain SAND on Base or BSC prior to the incident at a 1:1 ratio in Ethereum SAND. Compensation funds will come from The Sandbox treasury, with no new tokens issued. The claim process will open within the next two weeks and remain open for two weeks.
Odaily News, SlowMist Security Team disclosed that the cross-chain bridge project Allbridge suffered an attack on August 19, 2026, with losses of approximately $190,000. Notably, this attack was not executed instantaneously—the attacker began laying the groundwork nearly a month in advance, bypassing the verification mechanism through forged cross-chain messages.According to SlowMist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as CCTP-style, claiming a transfer of 1 million USDC, despite no actual USDC burn operation occurring. Subsequently, Circle generated a valid attestation for this complete message following standard procedures.Approximately 24 days later, on August 19, the attacker waited for the Base Router to receive a genuine CCTP deposit, bringing its balance to approximately 191,000 USDC, then launched the attack just 6 seconds later. Using the previously forged message and attestation, the attacker called Allbridge's receiveCctpMessage function. Due to the project's lack of critical validation, the system mistook the fraudulent cross-chain message for a genuine deposit and recorded a 1 million USDC credit.Subsequently, the attacker borrowed approximately 809,000 USDC temporarily via an Aave flash loan to match the Router's balance with the forged amount, then utilized the internal credit record to call the transfer function, ultimately moving out approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800 in profit. The root cause of this vulnerability lies in Allbridge's failure to verify the identity of the cross-chain message sender and receiver, as well as its failure to confirm whether USDC was genuinely minted or whether the balance actually increased—instead directly trusting the amount and message hash data constructed by the attacker.SlowMist emphasized that on-chain message verification does not equate to actual asset arrival. Cross-chain protocols must not only verify message authenticity but also ensure the message source is trustworthy, confirm the receiver is Circle's official TokenMessengerV2, and only record assets after confirming actual minting and balance changes. This incident once again highlights the security risks in cross-chain bridges' message verification and asset settlement processes.
Odaily News: Metaverse gaming platform The Sandbox has confirmed a vulnerability in its cross-chain bridge, allowing attackers to mint unbacked SAND on Base and BNB Smart Chain. Blockchain security firm PeckShield detected on August 21 that two addresses had collectively minted approximately 14.9 billion SAND. The Sandbox subsequently shut down bridging functionality on both networks.The Sandbox stated that the affected assets are bridged assets on Base and BNB Smart Chain, while SAND on Ethereum and Polygon, user wallet assets, and the Ethereum-locked assets backing the token remain unaffected. The proportion of genuinely collateralized assets involved in this incident is less than 0.01% of the total SAND supply.The Sandbox is developing a compensation plan for affected liquidity providers and advises users not to trade SAND on Base or BNB Smart Chain until bridging is restored. Coinbase plans to delist 10 perpetual futures contracts, including SAND, on August 26, with open positions to be automatically settled at that time. (Bitcoin.com News)
The Sandbox has officially confirmed and fully secured the recent SAND cross-chain bridge vulnerability affecting the Base and BNB Smart Chain (BSC) networks. Attackers exploited the flaw to mint uncollateralized SAND tokens across both networks, but the impact remains limited, accounting for less than 0.01% of the total SAND supply. SAND on Ethereum and Polygon, along with user wallets, remain unaffected. The Sandbox has since disabled cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable and non-redeemable. The official team advises users to avoid buying, selling, or trading SAND on the aforementioned networks.
According to earlier reports, the SAND contract for The Sandbox on the Base chain is suspected of anomalous minting, resulting in the issuance of over 500 million additional tokens.
Odaily News: Sheldon Lee, founder of cryptocurrency exchange BitMart, stated that a post on X claiming users were unable to withdraw funds and that some employees had not received their July salaries is a "fabricated rumor," adding that the exchange's Chinese-language account had been hacked. Critics, including users and on-chain investigator ZachXBT, have demanded that BitMart resume withdrawals or undergo an independent third-party audit. BitMart is gradually winding down operations, with the final trading day set for August 26. Troubled investment firm Echo Base said it had proposed a funded restructuring plan to BitMart but received no response. The firm warned that resolving a large volume of customer claims may require proceedings through the courts. (CoinDesk)