News linked to both this project and an event.
MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.
Odaily News: Today, THORChain officially posted on X platform stating, "We have noticed the recent Bitget hack and are deeply saddened by it. We can imagine this is a difficult time for everyone in the industry. (However,) THORChain is as decentralized and permissionless as Bitcoin, Ethereum, and BNB Chain. When dealing with known stolen funds, what responsibility should Bitcoin, Ethereum, and BNB Chain bear?" Subsequently, it called out OKX CEO Star and Bitget CEO Gracy.However, crypto community members in the comments pointed out that when THORChain previously suffered an attack, it once suspended services for 39 days, and they are deeply ashamed of the differentiated treatment between the two situations.
Odaily News: OKX Star posted on X in response to THORChain, stating that he does not believe THORChain's TSS + validator model represents true decentralization. THORChain's validators collectively control the underlying assets in the TSS vault, and funds can be moved once the signature threshold is reached. Therefore, from a custody perspective, it cannot be compared to the underlying consensus mechanisms of Bitcoin and Ethereum, but instead acts as an intermediary between users and native chains. "TSS distributes control among multiple participants, but decentralizing an intermediary does not eliminate the intermediary itself."Previously, discussions arose after some stolen Bitget funds were transferred through THORChain. THORChain responded that it is decentralized and permissionless, just like Bitcoin, Ethereum, and BNB Chain, and stated that if stolen funds were known to flow through Bitcoin, Ethereum, or BNB Chain, what responsibility should those networks bear?
According to Blockaid, Meter is facing ongoing attacks on BNB Chain. Attackers are exploiting Meter Passport to mint a large amount of wrapped MTRG and sell portions on PancakeSwap. Approximately $2.3 million in unbacked wrapped MTRG has been minted through around two issuance transactions so far, and the attack remains ongoing.
According to Blockaid monitoring, Meter is currently under a sustained attack on BNB Chain. The attacker exploited Meter Passport to mint a large amount of wrapped MTRG and sold some of the tokens on PancakeSwap. So far, approximately $2.3 million in unbacked wrapped MTRG has been minted through about 2 minting transactions, and the attack is still ongoing.
According to Odaily, as monitored by SlowMist, per the SlowMist TI security alert, a Router contract has been exploited due to security flaws in its Swap entry point and uniswapV3SwapCallback, resulting in losses of approximately 62.28 BNB. The Router fails to verify whether the caller is a legitimate V3 Pool, nor does it bind the payer in the callback to the original transaction context. The attacker forged a V3 Pool/adapter and injected a victim's address as the payer, exploiting users' existing ERC-20 approvals granted to the Router to execute transferFrom() and transfer assets. Users who have previously granted sufficient token approvals to this Router may see their approved assets transferred out, even without further interaction on their part.
blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)
GoPlus Security released a security alert stating that on August 25, realio[.]fund, a project under Realio Network, was attacked. The attacker took control of the platform's signing system and moved treasury and custody wallet assets across Ethereum, BNB Chain, Algorand, Stellar, and the Realio native chain. A total of approximately 127.9 million RIO tokens worth around $6.2 million were affected, with the attacker having cashed out approximately $317,000 so far.
BounceBit Chain 已于 8 月 20 日 02:36:37(UTC)在区块高度 20,702,857 停止出块。团队决定永久停止 BounceBit Chain,不再进行网络升级,并将在 BNB Chain 上以 BEP-20 代币形式重新发行 BB。新 BB 余额将依据 8 月 19 日 21:02:35(UTC)区块高度 20,697,260 的快照确定,攻击期间被转移的 286,543,148 枚 BB 不会计入重新发行代币。
Odaily News: BNB Smart Chain (BSC) has announced that the Pasteur hard fork will officially go live on the mainnet at 10:30 AM Beijing time on August 25 (02:30 UTC on August 25). Node operators are required to upgrade their clients to v1.7.7 in advance.This upgrade includes three improvements—BEP-682, BEP-695, and BEP-675—focusing on enhancing cross-chain security, validator governance mechanisms, and network throughput. Among them, BEP-682 will strengthen the BNB Chain cross-chain bridge verification mechanism, preventing permission bypass risks caused by duplicate signature counting by validators, thereby improving the security of cross-chain asset transfers. BEP-695 optimizes the validator key rotation mechanism, ensuring that old keys no longer retain management privileges after exit, while also fixing potential vulnerabilities related to slashing and governance voting.In terms of performance, BEP-675 reduces the time consumption caused by validators repeatedly executing transactions by optimizing the block construction process. In BNB Chain's internal QANet test environment, this solution increased throughput from 1,237 TPS to 2,324 TPS. While maintaining the 450-millisecond block time and the 100 million Gas block limit unchanged, the average Gas usage per block rose from 46.35 million to 84.15 million.BNB Chain stated that this upgrade is primarily aimed at validators and block builders, designed to provide greater capacity during network peak periods and advance the throughput expansion goals outlined in BNB Chain's roadmap for the second half of 2026.
Odaily News - A study published at USENIX Security '26 reveals that researchers identified 65,340 high-risk cryptocurrency addresses involved in abuse on Ethereum and BNB Chain, with associated native token losses reaching 126,982.94 ETH and 17,726.7 BNB. The study estimates that total losses linked to these addresses exceed $574.8 million, of which two newly described active attack vectors directly caused approximately $15.7 million in losses (2.7% of the total). The first category involves contract account misuse and exploitation of deterministic contract addresses; the second leverages EIP-7702 to delegate accounts with exposed keys to malicious code that directly transfers deposits. The research team extracted over 16.3 million unique private keys by mining 63,004 GitHub repositories from January 2015 to May 2025, achieving an overall accuracy rate of 99.11% in detection results. (Cryptoslate)
BNB Chain announces the "Build the Era" Hackathon, soliciting proposals to build the best AI Agent trading platform on BNB Chain. The hackathon offers over $40,000 in prizes jointly provided by BNB Chain, @TermiX_AI, @PancakeSwap, @alt_layer, @binance Pay, and @AltanaNetwork. Both individuals and teams can register to participate.
: According to on-chain detective Specter’s monitoring, B² Network may have suffered a vulnerability exploit on BNB Chain. The attacker transferred 8.591 million B2, worth $3.86 million, and exchanged them for 5,409 WBNB, worth $3.11 million. The funds were then bridged to Ethereum, and are currently being transferred to Zcash via NEAR Intents. The addresses used for the theft are 0xEc443f7D79835B464FBEAC798d3f92B62d6Ff433 and 0xf977427Ec8e583C55D413061FC205BCD57e8Bf6D.
According to on-chain analyst Specter, B² Network on BNB Chain suffered a hack, resulting in a loss of approximately 8.591 million B2 tokens (approximately $3.86 million). The attacker swapped them for 5409 WBNB (approximately $3.11 million) and bridged to Ethereum, and is currently transferring the funds to Zcash via NEAR Intents.
: BNB Chain Agent commercial clearing layer TermiX announced that Web3 security infrastructure GoPlus and smart contract security auditing firm Salus have officially become Provider Agents on the Agent.family platform. They have launched two production-grade security audit services, promoting the autonomous invocation and settlement of "security capability as a service" for AI Agents in on-chain commercial scenarios.GoPlus has packaged its verified token contract deep scanning capability as a standard Provider Agent service. DeepScan conducts comprehensive security checks on token contracts, identifying risk patterns such as Rug Pulls, honeypot scams, contract permission abuse, and trading restrictions, and generates structured audit reports.Salus has launched smart contract auditing and penetration testing services, encompassing formal verification, fuzz testing, machine learning-based vulnerability detection, and manual expert auditing. It covers high-risk vulnerability categories such as reentrancy attacks, access control issues, integer overflows, and DoS attacks. Salus, a seed-stage investment from Binance Labs, is a core security partner within the BNB Chain ecosystem.
Odaily Planet Daily reported that the algorithmic stablecoin Balance Coin dropped from $0.9954 to $0.001358, a decline of over 99%. The stablecoin is the native algorithmic stablecoin of the Balance Protocol, designed to maintain a peg to the US dollar. Blockchain security firm PeckShield stated that the depegging occurred following an exploit of the decentralized autonomous organization 42DAO, which governs the Balance Protocol and its BLC token, resulting in a $915,000 loss. TenArmor reported detecting suspicious attacks involving GemJoin and 42DAO on the BNB Chain.
Michael, Chief Business Officer of Token Pocket, stated on platform X that Robinhood founder's seed phrase was leaked during a live stream. After gaining control of the address, the hacker used it and associated addresses to heavily purchase the Meme token $1, prompting thousands of investors to follow suit. In a short time, the token's market cap quickly surged from approximately $500,000 to $14 million.Subsequently, the price of the $1 token dropped sharply, with two-hour trading volume reaching around $20 million. After the address was frozen, the hacker quickly moved to the BNB Chain, using the address and its associated addresses to issue a new token. They created trading activity through tactics like wash trading, ultimately dumping the tokens for profit.Currently, Robinhood's RPC has frozen the address, and the node does not allow transactions originating from this address to be packaged, making transfers, purchases, or sales impossible.
According to The Block, BNB Chain is building a new Layer 1 blockchain designed specifically for agent trading, targeting transaction pre-confirmation in under 50 milliseconds, and suppressing MEV behaviors such as sandwich attacks by eliminating the public mempool (adopting the TxStream mechanism). The new chain will also reserve block space for oracles, liquidations, and cross-chain bridges via PriorityLane, with a designed throughput target exceeding 100,000 TPS, and supporting sub-second block finality. This chain will become the fourth chain in the BNB Chain ecosystem, connected to BNB Smart Chain via a native bridge, with BSC serving as the settlement hub. The testnet is planned to launch at the end of 2026, and the mainnet is expected to deploy in early 2027.
BNB Chain is developing a new Layer 1 blockchain designed for Agentic Trading, releasing the first detailed architectural information after months of research and development. According to BNB Chain's disclosed technical roadmap for the second half of 2026, the new chain will run in parallel with the existing BNB Chain ecosystem, targeting transaction preconfirmation times of less than 50 milliseconds. The goal is to deliver an execution experience close to that of centralized exchanges (CEX) while retaining the advantages of on-chain self-custody and transparency.In terms of technical architecture, the new chain will remove the traditional public mempool and introduce a transaction transmission mechanism called "TxStream," which directly sends transactions to block producers to reduce latency and minimize MEV extraction behaviors such as sandwich attacks. (The Block)
Odaily news, Slow Mist founder Cosine published an analysis stating that the approximately $1.1 million loss incident in the OLPC / LABUBU liquidity pool on BNB Chain is suspicious. The loss occurred due to a severe imbalance in the OLPC/LABUBU trading pair, caused by a "vulnerability" in OLPC being exploited. Under certain conditions in _update, it is possible to burn OLPC tokens amounting to value * decimalsValue. Normally, decimalsValue is 1, but approximately 46 days before the attack, it was changed by the owner to an extremely large value of 7,326,680,472,586,200,649. A few days later, the OLPC owner renounced ownership, setting it to the zero address.Today, the attacker exploited this extremely large decimalsValue to trigger the Pair reserve burn, allowing a small amount of OLPC to extract a large amount of LABUBU. The attacker ultimately swapped 1.115 million USDT at a low cost. The suspicious point lies in the setting of decimalsValue—why did the OLPC owner set such an abnormally large value?