News linked to both this project and an event.
Odaily News: According to Bitcoin News monitoring, a wallet tagged as the United States transferred 833.6 BTC, valued at $71.6 million, to a Coinbase Prime deposit address. Arkham data shows that 568.7 BTC of this is related to assets forfeited from HashFlare, and 264.9 BTC is related to funds from the Bitfinex hack. Transfers to a Prime deposit address do not necessarily indicate a confirmed sale; Coinbase also provides custody services for cryptocurrency held by the government, and a similar $288 million transfer occurred in July.
Odaily News: As the crypto industry discusses whether users need to enter "bunker mode" before AI or quantum computing technologies expose wallet private keys, custody institutions face a more complex challenge: how to upgrade key management, approval, and audit systems before an emergency migration occurs.Project Eleven CEO Alex Pruden stated that institutions have already begun preparing for post-quantum migration outside of blockchain, and different blockchains may adopt different quantum-resistant signature schemes and migration paths in the future. Institutions holding multiple types of assets will face the challenge of simultaneously adapting to multiple cryptographic systems.Quantus co-founder and CEO Christopher Smith stated that AI is accelerating the development of quantum hardware and software, and the tail risk of quantum attacks should be incorporated into portfolio decisions — this is an institutional fiduciary duty.Currently, the timeline for quantum computers to crack Bitcoin and Ethereum's existing public-key cryptographic systems remains uncertain, but the industry is gradually viewing the coming years as a window for establishing migration plans, rather than waiting for an attack to occur before responding reactively. (CoinDesk)
Odaily reports: Second, a project built on Ark Protocol, disclosed that its server was exploited in an attack on Monday, resulting in the loss of 0.75 BTC of its own funds, worth approximately $62,300. The team stated that user funds were not affected and that the issue was fixed within hours.The attacker subsequently continued attempting to withdraw more funds from the project and launched a denial-of-service attack. On Tuesday, Second said the attack may have degraded the ability of Bark-based wallets to receive Lightning Network transfers.Second stated that the vulnerability was in the Ark server's boarding process, where an attacker could register and exit the relevant boards using only their own signature, while simultaneously spending the same batch of VTXOs in the node via the Lightning Network. The attacker also attempted to use bitcoin linked to the Blink Wallet security breach on September 19, but was unsuccessful. (Bitcoin.com News)
HM Revenue & Customs (HMRC) is pushing to expand its investigation powers over crypto asset information, proposing to allow tax authorities to directly obtain customer data from crypto asset service providers and to update rules for inspecting software and electronic records. UK crypto tax software company Recap has warned that the proposed regulations' definition of service providers is too broad and could encompass non-custodial wallet software, blockchain explorers, hardware wallet manufacturers, and tax software providers. Since Bitcoin transaction records are publicly transparent, once investors' names, addresses, and tax identities are linked to on-chain wallet addresses, their long-term asset activity records could be exposed, increasing the risk of data leaks, extortion, and physical attacks.
Odaily News: Galaxy Research on-chain tracking shows that the US government transferred approximately 9,261 BTC, worth about $770 million, to Coinbase Prime over two days. Since the deposit address was first activated in December 2025, it has cumulatively received 11,567 BTC, of which 6,406 came from wallets already labeled as belonging to the US government, and 5,160 came from previously unlabeled wallets.Of the 9,261 BTC transferred this time, nearly half can be traced back to Bitfinex hacker funds recovered by the US government, with some coming from previously known Binance-related seized assets; among them, 2,456 BTC previously had no clear government attribution label, but because they entered this address through the same path as government funds, they are currently regarded as US government seized assets. The US government currently holds approximately 319,100 BTC, of which about 71% comes from LuBian-related BTC and Bitfinex recovered funds.In January 2025, a US federal court approved the return in kind of seized Bitfinex hacker funds to Bitfinex, and the main address holding approximately 94,600 BTC has still not moved. In October 2025, the US Department of Justice filed a civil forfeiture lawsuit against Chen Zhi and related assets, involving approximately 127,300 BTC; this batch of LuBian BTC entered addresses attributed to the US government between June and July 2024. Since 2013, US government-related addresses have received a total of approximately 555,300 BTC, worth about $16.1 billion at prices at the time; during the same period, approximately 236,200 BTC flowed out, worth about $3.8 billion at prices at the time. After excluding internal transfers between the government's own addresses, this transfer, based on labeled government addresses, ranks 9th among the largest single-day BTC outflows in US government history, and is also the largest since December 2, 2024. BTC being transferred to Coinbase Prime does not mean the US government has already sold it, and on-chain transfers alone cannot confirm the specific purpose of the funds.
According to Odaily, a Satoshi-era address moved 100.02 BTC worth $8.55 million after 16 years of dormancy. Bankless co-founder David Hoffman suggested that the transfer may be intended as preparation against quantum attacks.
Odaily News: According to Bitcoin News monitoring, Arkham reports that US government-linked wallets transferred approximately 4,695 BTC, along with WBTC and USDT, through a series of transactions today, involving total assets worth approximately $470 million. On-chain analyst @TimechainIndex independently flagged the same batch of approximately 4,695 BTC, distributed across 4 transactions. The assets are related to seizures tied to the Bitfinex hack and FTX/Alameda, with some assets already sent to Coinbase Prime deposit addresses. This transfer follows the US government's additional transfer to Coinbase Prime yesterday.
According to Decrypt, Europol released a report on Wednesday stating that cryptocurrency wallets are the primary exposure points for quantum computing threats. Attackers can derive private keys from publicly exposed on-chain public keys and transfer assets, while underlying hash functions are largely quantum-resistant. The report notes that approximately 30.2% of BTC (6.04 million coins) public keys have already been exposed on-chain, recommending a phased industry transition to post-quantum cryptography, and calling for proactive preventive migration of related assets prior to an attack.
Odaily reports: Europol released two reports on Wednesday, urging organizations, policymakers, and the cryptocurrency industry to immediately prepare for the threat of quantum computing. Its European Cybercrime Centre noted that cryptocurrency wallet keys are the primary exposure point for quantum attacks, while the hash functions used to secure blockchains currently remain largely quantum-resistant.The reports state that a sufficiently capable quantum computer could derive private keys from exposed public keys, enabling attackers to transfer assets without authorization. Wallets whose public keys have already been exposed on-chain cannot be protected retroactively; holders need to migrate their assets to new wallets before an attack occurs.Glassnode estimated in May that 6.04 million BTC, representing 30.2% of the issued supply, have exposed public keys. The reports note that NIST-standardized post-quantum signatures are 10 to 120 times larger than the ECDSA signatures currently used by Bitcoin, and migrating all Bitcoin unspent transaction outputs would require at least 76 cumulative days of downtime.A second report published by Europol points out that commonly used protocols such as TLS, SSH, and OpenPGP face "harvest now, decrypt later" risks, but there is currently no clear evidence that this approach has been exploited at scale. The report argues that for payments, immediate interception within the brief window before transaction confirmation poses a more direct quantum risk than post-hoc decryption. (Decrypt)
According to on-chain monitoring, the U.S. government has just transferred funds seized in the Bitfinex hacker case, with approximately 264.863 BTC (worth around $22.87 million) moved to a new address.
Odaily News: A 28-year-old Russian national identified as a core member of the globally notorious ransomware gang Qilin was arrested in Japan and lawfully extradited to Germany on October 2. Reports state that the man is suspected of illegally breaching a German logistics company's systems in September 2024, encrypting its data, and demanding and extorting approximately $165,000 (about 26 million yen) in Bitcoin. Investigations show that within the Qilin criminal network, he was responsible for building attack systems and received a proportional cut of the ransom payments collected by various affiliate execution teams.Japanese police took him into custody in late May of this year while he was traveling in Osaka, and he was subsequently handed over to German authorities after the Tokyo High Court ruled that the conditions for extradition were met. Qilin operates on a "ransomware-as-a-service" (RaaS) model and previously claimed responsibility in 2025 for a cyberattack on Japan's Asahi Group. (Nada News)
Odaily News: On-chain detective ZachXBT posted on X that he once posed as a client to infiltrate a criminal group suspected of laundering money for the North Korea-backed hacker organization Lazarus Group, and assisted in freezing funds related to the 2025 Bybit attack.ZachXBT stated that after Bybit suffered a $1.5 billion attack in February 2025, he discovered that more than 15 accounts in public Telegram and Discord groups were seeking help processing transactions related to the stolen funds. He subsequently contacted one of the Telegram users using the alias "Jimmy Green" and built trust through multiple transactions. According to his disclosure, on March 6, 2025, he transferred $3.497 million in USDC to an Ethereum address for a USDC-to-TRON-chain USDT exchange transaction with the counterparty. The source of gas funds for that address can be traced back to the Bybit attack funds and was publicly flagged as a Bybit attack blacklisted address.ZachXBT said that in subsequent communications, the counterparty revealed that their team had been involved in processing the stolen Bybit funds and disclosed in advance that the funds would be moved across chains including Solana. By matching transaction timing, amounts, and on-chain data, he identified a wallet cluster involving more than $12 million in Bybit attack funds, with fund paths spanning multiple networks including BTC→ETH→SOL→TRON. Approximately 442,000 USDT was frozen by Tether, and the group also attempted to launder money through Uniswap liquidity pools and low-liquidity tokens. Additionally, the counterparty disclosed having helped other clients process approximately $3 million in fraudulent proceeds, and ZachXBT traced the related funds to wallets associated with the sanctioned Huione Guarantee.ZachXBT revealed that in this investigation, he initially invested $3.497 million and bore a loss risk of approximately 5% per transaction. The intelligence ultimately obtained was provided to relevant investigative agencies and law enforcement authorities at the earliest opportunity. Since 2022, he has assisted in freezing over $75 million in funds related to North Korea-linked incidents.
victims of the Drift hack, a perpetual contract exchange on Solana, began filing claims on October 1. The recovery pool's initial funding stands at approximately $3.11 million against nearly $295.4 million in verified losses. Victims can redeem USDT through DFX tokens, with each $1 of loss converting to roughly 1.04 cents at launch, meaning a $1,000 loss corresponds to about $10.40.The total supply of DFX is fixed at 299,500,810.998 tokens, with each token corresponding to $1 of verified loss from the April incident, and no additional tokens will be minted. Holders can choose to burn DFX to redeem USDT, sell on secondary markets such as Raydium, or continue holding their claims. Completed redemptions are irreversible, and unclaimed tokens will expire after the claims window closes on January 1, 2028.Future funding for the recovery pool includes a portion of daily net protocol revenue from Velocity, the rebranded exchange rebuilt by Drift, up to $127.5 million in USDT committed by Tether, $20 million in USDT committed by strategic partners, and recovered stolen assets. On the first Friday after claims opened, approximately 216,480 DFX tokens were redeemed for about 2,250 USDT, with Velocity's first revenue transfer amounting to 31 USDT; approximately 13,025.9 ETH is spread across 4 Ethereum wallets, another approximately 2,309.4 ETH passed through Tornado Cash, and about $9.2 million in assets have been frozen at other addresses. (Bitcoin.com News)
A crypto asset vault on Base had approximately 1,783 wstETH transferred out on October 4, resulting in losses exceeding $6 million. On-chain records show that the vault is controlled by a 3-of-7 Safe, and the identities of the seven signers have not yet been made public.Security firms stated that the attacker borrowed aBaswstETH from the vault and swapped it for wstETH through Aave. Neither the Base chain itself nor Aave's core contracts have been identified as being exploited, and the specific authorization vulnerability remains unconfirmed. (Bitcoin.com News)
Odaily reports: Cross-chain swap service Near Intents announced that the $3.8 million in funds stolen in a previous exploit has been fully returned, and the team has closed its investigation. Near Intents General Manager Alex Shevchenko had previously issued a 48-hour return deadline to the attacker, providing Bitcoin, BNB, Ethereum, and Solana addresses.The attacker acknowledged wrongdoing in an on-chain message, stating that all funds had been returned and urging others to report issues through the bug bounty program. The incident stemmed from a vulnerability in the interaction between its Omni deposit and withdrawal layer and the main smart contract. Near Intents had suspended services and promised full compensation to users. (Decrypt)
Odaily News: According to Bitcoin News monitoring, Blink has released a full post-mortem of the September 19 attack: the attack resulted in the theft of a total of 6.61 BTC from 24 customer accounts. The company stated that the vulnerability had existed since October 2023, and any user with a free Blink account could potentially exploit it to gain customer-service-level privileges, take over customer accounts, and raise withdrawal limits. The attacker also obtained partial information from 3,817 accounts, including some phone numbers and email addresses; names, identity documents, addresses, passwords, and seed phrases were not leaked.None of the 24 stolen accounts had two-factor authentication enabled. The attacker attempted 18 withdrawals from 9 accounts protected by two-factor authentication, all of which failed. Blink shareholders have fully reimbursed all affected customers.About 5 of the stolen BTC were subsequently transferred through a cross-chain swap service. Blink is now offering a recovery bounty of up to approximately 3.3 BTC, with half of any successfully recovered funds to be distributed to those who provide valid leads and to the Bitcoin circular economy.
Odaily reports, according to Bitcoin News monitoring, Core Lightning stated that attackers are targeting nodes still running version 26.06.7 and earlier. The 26.06.8 patch released on September 22 fixes a channel closure issue that could jeopardize funds, as well as vulnerabilities that cause crashes and memory exhaustion. The project has not yet disclosed the name of the vulnerability used by attackers, nor has it reported any stolen funds. Node operators who have not yet upgraded are becoming attack targets.
the Core Lightning team, which develops the Bitcoin Lightning Network node software, is warning node operators running version 26.06.7 or earlier to upgrade to the latest version as soon as possible. The team said it has received reports of attackers targeting unpatched nodes, but did not disclose the vulnerability exploited by the attackers or the potential impact.Core Lightning said on September 16 that it was investigating an issue that could affect experimental features and user funds, and on September 22 released version 26.06.8 to fix the vulnerability and update the software. This announcement did not state whether the previously reported attacks were related to the vulnerability fixed in this version. (Cointelegraph)
According to Cointelegraph, Alex Shevchenko, General Manager of NEAR Intents, stated that the team has identified the hackers behind the previous security incident and given them a 48-hour deadline to return the stolen funds through a "responsible disclosure." NEAR Intents previously suspended its services due to a vulnerability in the interaction between the Omni deposit and withdrawal infrastructure and its smart contracts. Initial investigations revealed that approximately $3.8 million in user funds were stolen in the incident, and the team has committed to fully compensating affected users. On-chain detective ZachXBT stated that the stolen funds were subsequently transferred to KuCoin and cross-chain converted into Bitcoin.
Odaily News: NEAR Intents has stated that it has identified the attacker responsible for the loss of user funds and has demanded the return of $3.8 million within 48 hours through a "responsible disclosure" mechanism, after which the window will be closed.NEAR Intents suspended services on Thursday after discovering a vulnerability in the interaction between the Omni deposit and withdrawal infrastructure and its smart contracts. A preliminary investigation showed that the attack resulted in the theft of $3.8 million in user funds, and the platform has committed to fully compensating affected users.On-chain investigator ZachXBT disclosed that the related funds were transferred to the KuCoin exchange and subsequently bridged to Bitcoin. (Cointelegraph)