News linked to both this project and an event.
Odaily News Rapid7, a cybersecurity firm, has disclosed a crypto phishing campaign named Operation Asterix that targets approximately 885,000 phone numbers across multiple countries, redirecting victims to fraudulent wallet service websites. A total of 5,576 phone numbers have been matched with Binance user accounts and placed on the attack queue.The attackers steal seed phrases through fake apps impersonating Ledger, Trezor, and Exodus, while also contacting victims via fraudulent customer support emails and phone calls. Rapid7 also found that among over 316,000 phone numbers in Germany, 43,066 were matched with crypto trading accounts, representing a hit rate of approximately 13.6%.The related attacks also include a bulk phone number verification tool targeting Kraken accounts, and the investigation revealed that AI tools are being widely used in phishing operations. According to data from blockchain security firm Hacken, phishing attacks and social engineering scams caused $306 million in losses in the first quarter of this year, accounting for the majority of the $482 million total losses in the crypto industry. (Cointelegraph)
The Binance Security Team recently independently discovered a malicious governance proposal targeting a project's Decentralized Autonomous Organization, which could put approximately $1.2 million worth of treasury tokens at risk. Binance notified the project team to vote against the proposal less than 48 hours before its execution and coordinated with relevant centralized exchanges to suspend deposits of the affected tokens to reduce the risk of potential fund transfers. Ultimately, the malicious proposal was rejected, the attack was not executed, and no funds were lost.
Odaily News: CZ posted a SafePal security incident alert on platform X, reminding the community to beware of phishing attacks. He also disclosed that SafePal is one of YZi Labs' (formerly Binance Labs) portfolio companies, and YZi Labs is currently a minority shareholder of SafePal.
Odaily News: BNB Smart Chain (BSC) has announced that the Pasteur hard fork will officially go live on the mainnet at 10:30 AM Beijing time on August 25 (02:30 UTC on August 25). Node operators are required to upgrade their clients to v1.7.7 in advance.This upgrade includes three improvements—BEP-682, BEP-695, and BEP-675—focusing on enhancing cross-chain security, validator governance mechanisms, and network throughput. Among them, BEP-682 will strengthen the BNB Chain cross-chain bridge verification mechanism, preventing permission bypass risks caused by duplicate signature counting by validators, thereby improving the security of cross-chain asset transfers. BEP-695 optimizes the validator key rotation mechanism, ensuring that old keys no longer retain management privileges after exit, while also fixing potential vulnerabilities related to slashing and governance voting.In terms of performance, BEP-675 reduces the time consumption caused by validators repeatedly executing transactions by optimizing the block construction process. In BNB Chain's internal QANet test environment, this solution increased throughput from 1,237 TPS to 2,324 TPS. While maintaining the 450-millisecond block time and the 100 million Gas block limit unchanged, the average Gas usage per block rose from 46.35 million to 84.15 million.BNB Chain stated that this upgrade is primarily aimed at validators and block builders, designed to provide greater capacity during network peak periods and advance the throughput expansion goals outlined in BNB Chain's roadmap for the second half of 2026.
Odaily News - A study published at USENIX Security '26 reveals that researchers identified 65,340 high-risk cryptocurrency addresses involved in abuse on Ethereum and BNB Chain, with associated native token losses reaching 126,982.94 ETH and 17,726.7 BNB. The study estimates that total losses linked to these addresses exceed $574.8 million, of which two newly described active attack vectors directly caused approximately $15.7 million in losses (2.7% of the total). The first category involves contract account misuse and exploitation of deterministic contract addresses; the second leverages EIP-7702 to delegate accounts with exposed keys to malicious code that directly transfers deposits. The research team extracted over 16.3 million unique private keys by mining 63,004 GitHub repositories from January 2015 to May 2025, achieving an overall accuracy rate of 99.11% in detection results. (Cryptoslate)
According to Bifrost's monitoring, at 19:47 Beijing time on August 8, hackers exploited a vulnerability in the liquidity pool, stealing approximately $720,000 worth of assets from the vDOT single-asset pool and the vASTR/ASTR and vMANTA/MANTA pools. The stolen assets were subsequently deposited into HitBTC and eventually flowed into Binance. Bifrost has contacted Binance's security department to submit a fund freeze request and has filed a report along with a chain of custody evidence package, including transaction tracking, wallet addresses, and timestamps, with law enforcement authorities. Currently, Bifrost has halted all liquidity mining rewards and is conducting a comprehensive security review.
BNB Chain announces the "Build the Era" Hackathon, soliciting proposals to build the best AI Agent trading platform on BNB Chain. The hackathon offers over $40,000 in prizes jointly provided by BNB Chain, @TermiX_AI, @PancakeSwap, @alt_layer, @binance Pay, and @AltanaNetwork. Both individuals and teams can register to participate.
Binance founder Changpeng Zhao stated that from a statistical perspective, storing crypto assets on exchanges may be safer than self-custody, but provided that the relevant data is accurate. He pointed out that data regarding exchanges being hacked is easier to collect and publicize, while theft or loss incidents in self-custody scenarios are often not fully disclosed, therefore statistical results may be biased.
Odaily News: Binance co-founder CZ reposted user Rager's experience with a hardware wallet malfunction on the X platform. CZ stated that protecting wallet backup seed phrases is an extremely challenging task. The seed phrase must not be seen by others, or it could be copied or exploited, and it must also be protected from accidental damage caused by fires, floods, or other incidents, while also preventing hackers from gaining access. More importantly, users themselves must not lose the seed phrase.
Odaily News: In response to the persistent attacks on Coldcard wallets, Binance co-founder CZ reposted on X platform stating that for self-custody wallets, developers fixing vulnerabilities cannot resolve the risks associated with previously generated wallets, and developers are unable to directly contact users of air-gapped devices.CZ stated that users' wallets may still be exposed to attack risks before any action is taken. He emphasized that he still supports the self-custody model, but self-custody means users need to bear more security responsibilities.
Odaily News: Binance founder CZ reposted on X platform about a user's encounter with a Coldcard wallet attack and stated that software will always have vulnerabilities; the key lies in how the team behind it handles the problems.CZ added that Trust Wallet faced a similar issue years ago, when a non-truly random pseudo-random number generator led to losses of approximately $12 million, but the team ultimately covered the user losses.Previous report: A third wave of attacks suspected to target addresses generated by Coldcard has emerged, with the attacker transferring approximately 207.7294 BTC again. Data shows that the scale of Coldcard-related attacks observed so far has expanded to about 1,367.05 BTC, involving approximately 4,585 addresses, valued at around $88.6 million at current prices.
In response to the suspected vulnerability incident involving the Coldcard wallet, Binance founder CZ stated that even hardware wallets and long-standing wallets may have vulnerabilities, and no solution can be 100% secure.
According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.
: According to on-chain detective Specter’s monitoring, B² Network may have suffered a vulnerability exploit on BNB Chain. The attacker transferred 8.591 million B2, worth $3.86 million, and exchanged them for 5,409 WBNB, worth $3.11 million. The funds were then bridged to Ethereum, and are currently being transferred to Zcash via NEAR Intents. The addresses used for the theft are 0xEc443f7D79835B464FBEAC798d3f92B62d6Ff433 and 0xf977427Ec8e583C55D413061FC205BCD57e8Bf6D.
According to on-chain analyst Specter, B² Network on BNB Chain suffered a hack, resulting in a loss of approximately 8.591 million B2 tokens (approximately $3.86 million). The attacker swapped them for 5409 WBNB (approximately $3.11 million) and bridged to Ethereum, and is currently transferring the funds to Zcash via NEAR Intents.
: BNB Chain Agent commercial clearing layer TermiX announced that Web3 security infrastructure GoPlus and smart contract security auditing firm Salus have officially become Provider Agents on the Agent.family platform. They have launched two production-grade security audit services, promoting the autonomous invocation and settlement of "security capability as a service" for AI Agents in on-chain commercial scenarios.GoPlus has packaged its verified token contract deep scanning capability as a standard Provider Agent service. DeepScan conducts comprehensive security checks on token contracts, identifying risk patterns such as Rug Pulls, honeypot scams, contract permission abuse, and trading restrictions, and generates structured audit reports.Salus has launched smart contract auditing and penetration testing services, encompassing formal verification, fuzz testing, machine learning-based vulnerability detection, and manual expert auditing. It covers high-risk vulnerability categories such as reentrancy attacks, access control issues, integer overflows, and DoS attacks. Salus, a seed-stage investment from Binance Labs, is a core security partner within the BNB Chain ecosystem.
Odaily Planet Daily reported that the algorithmic stablecoin Balance Coin dropped from $0.9954 to $0.001358, a decline of over 99%. The stablecoin is the native algorithmic stablecoin of the Balance Protocol, designed to maintain a peg to the US dollar. Blockchain security firm PeckShield stated that the depegging occurred following an exploit of the decentralized autonomous organization 42DAO, which governs the Balance Protocol and its BLC token, resulting in a $915,000 loss. TenArmor reported detecting suspicious attacks involving GemJoin and 42DAO on the BNB Chain.
According to an official post from Midnight Foundation (@midnightfdn), the Wanchain Cardano<>BNB cross-chain bridge suffered a security attack. Currently, multiple major exchanges including KuCoin, Kraken, Binance, Bybit, OKX, and MEXC have responded rapidly, taking preventive measures to restrict the flow of stolen assets, including freezing relevant accounts and addresses, blacklisting the attacker's wallets, and suspending NIGHT token deposit and withdrawal services. The exchanges confirmed that this incident is an isolated third-party bridge vulnerability and is unrelated to the Midnight Network mainnet and the NIGHT asset itself.
the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.
According to monitoring by Yu Jin, the address that previously transferred BONK worth $21.2 million from the Bonk treasury through a governance proposal, after moving 1.186 trillion BONK (approximately $4.11 million) to Binance yesterday, has today transferred another 400 billion BONK (worth about $1.28 million) to Coinbase.Data shows that of the 4.426 trillion BONK removed from the Bonk treasury via the governance proposal by this address, 1.626 trillion BONK (approximately $5.58 million) have been moved to centralized exchanges. Additionally, in the 11 days since the address began withdrawing assets from the Bonk treasury, the price of BONK has fallen by approximately 36%, dropping from $0.0000047 to $0.000003.