News linked to both this project and an event.
According to PeckShieldAlert citing Specter's monitoring, Notional Finance's custody contract may have been exploited, resulting in approximately $1.7 million in DAI and USDC losses. The attacker has converted the stolen funds into 689.2 ETH and deposited them into Tornado Cash.
Decentralized lending protocol Ajna tweeted that Ajna v2 was exploited and is investigating abnormal fund flows, advising users to withdraw all funds, repay loans, and pause interactions with the protocol. The incident caused approximately $775,000 in losses across pools including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI, attributed to a liquidation accounting manipulation attack.
Odaily News, Avici announced that its card partner Rain discovered today a vulnerability in an old Solana card contract used by Avici and a few other projects. The relevant contract has now been upgraded across all projects, and no further unauthorized activity has been detected. This incident only affected the standalone Solana contract used to hold post-deposit card balances; users' Avici wallets and card balances are isolated from each other, and funds in Solana and EVM self-custody wallets are safe and unaffected. Upon review, a total of 1,685 users were affected, with combined card balances of approximately $500,900. Avici has committed to fully refunding card balances to all affected users and has filed a report with the FBI's Internet Crime Complaint Center (IC3). Previously reported, Avici, a crypto banking project, saw its native token AVICI allegedly suffer a hacker attack, with losses of approximately $1.02 million. The attacker transferred 10,000 SOL stolen from the project to another wallet, converted it into approximately $1.02 million USDC, and then swapped the funds into approximately 418 ETH via cross-chain operations.
Odaily News, according to Onchain Lens monitoring, AVICI has been attacked, with losses of approximately $1.02 million. An address transferred 10,000 SOL to another wallet, exchanged it for approximately $1.02 million USDC, and then bridged the funds across chains to exchange for about 418 ETH.
according to D2 Finance monitoring, derivatives strategy protocol D2 Finance has raised five public questions regarding Tori Finance's operations to cover the shortfall after the Term Finance incident. These include: why 250,500 trUSD tokens were minted in advance instead of directly using existing USDC reserves; the source of the collateral used for minting; the other half of the funds coming from Kraken's hot wallet; the transparency page showing a buffer range of only approximately $17,600, or roughly 3 basis points, far below the scale of the incident's impact; as well as Delta Neutrality verification, high-yield money market positions, and hedging methods. Previously, the Term Finance governance vulnerability incident affected RockawayX Tori USDC Vault, resulting in a loss of approximately 454,000 USDC. RockawayX and Tori Finance subsequently stated that the loss has been fully covered by both parties.
Odaily News, SlowMist Security Team disclosed that the cross-chain bridge project Allbridge suffered an attack on August 19, 2026, with losses of approximately $190,000. Notably, this attack was not executed instantaneously—the attacker began laying the groundwork nearly a month in advance, bypassing the verification mechanism through forged cross-chain messages.According to SlowMist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as CCTP-style, claiming a transfer of 1 million USDC, despite no actual USDC burn operation occurring. Subsequently, Circle generated a valid attestation for this complete message following standard procedures.Approximately 24 days later, on August 19, the attacker waited for the Base Router to receive a genuine CCTP deposit, bringing its balance to approximately 191,000 USDC, then launched the attack just 6 seconds later. Using the previously forged message and attestation, the attacker called Allbridge's receiveCctpMessage function. Due to the project's lack of critical validation, the system mistook the fraudulent cross-chain message for a genuine deposit and recorded a 1 million USDC credit.Subsequently, the attacker borrowed approximately 809,000 USDC temporarily via an Aave flash loan to match the Router's balance with the forged amount, then utilized the internal credit record to call the transfer function, ultimately moving out approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800 in profit. The root cause of this vulnerability lies in Allbridge's failure to verify the identity of the cross-chain message sender and receiver, as well as its failure to confirm whether USDC was genuinely minted or whether the balance actually increased—instead directly trusting the amount and message hash data constructed by the attacker.SlowMist emphasized that on-chain message verification does not equate to actual asset arrival. Cross-chain protocols must not only verify message authenticity but also ensure the message source is trustworthy, confirm the receiver is Circle's official TokenMessengerV2, and only record assets after confirming actual minting and balance changes. This incident once again highlights the security risks in cross-chain bridges' message verification and asset settlement processes.
According to monitoring by PeckShield, an address labeled Bofur Capital was targeted by an address poisoning attack after withdrawing from Compound, resulting in losses of approximately $2 million. The attacker had previously sent 0.0002 USDC via a similar-looking address. Subsequently, due to mistakenly copying the wrong address, the controller of the Bofur Capital address transferred assets worth roughly $2 million to the attacker's address. The stolen funds have since been swapped for approximately 2 million DAI and are now held in a wallet beginning with 0xe2eB.
Odaily News: On-chain security firm PeckShield (@PeckShieldAlert) monitoring shows that an attacker, through controlling address 0x920d…9708, stole approximately 500,000 USDC from a victim wallet 0x3a53…0B5c on the Base chain. However, when the attacker subsequently attempted to swap the USDC into ETH, insufficient slippage protection parameters were set, causing the transaction to be sandwiched and arbitraged by MEV bots. In the end, the attacker only received approximately 67 WETH, valued at around $129,000, meaning the stolen funds suffered a loss rate exceeding 75%.
According to CoinDesk, the S&P 500 index has risen 3.12% this month, adding approximately $2.1 trillion in market value (equivalent to the total market cap of the entire crypto market), reaching a record high total market cap of $70.5 trillion, but Bitcoin has only risen about 2% this month, hovering near $64,600. Analysts point out that this round of stock market rise is mainly driven by AI and semiconductor individual stock narratives, rather than a broad-based recovery in risk appetite at the macro level, and Bitcoin lacks direct beneficial exposure to this. Meanwhile, the crypto market also faces multiple internal pressures: the Coldcard platform suffered a $120 million exploit, the prospects of the "Clarity Act" remain uncertain, MicroStrategy has reduced its BTC holdings for three consecutive months, and stablecoin supply continues to shrink—USDT's market cap dropped from $190 billion in April to $183 billion, and USDC's dropped from $79.5 billion to $72 billion.
According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.
According to SlowMist monitoring, the decentralized finance protocol Lien Finance suffered an attack. The attacker exploited a smart contract vulnerability to mint unbacked bond tokens and stole approximately $542,000 worth of USDC. Leveraging this vulnerability, the attacker successfully minted new, non-anomalous BondTokens without burning the corresponding input bonds. Subsequently, the attacker exchanged the tokens for USDC via a pre-authorized address, ultimately transferring approximately 542,144.63 USDC from the victim's address. Analysis indicates that the incident was essentially caused by a verification flaw in the bond token exchange logic, which allowed the attacker to bypass asset collateral constraints and mint unsupported assets.
据 Blockaid 监测,Arbitrum 生态协议 AFX 于北京时间 7月 23日 5:30 遭攻击。此次攻击针对 AFX 运营的跨链桥,迄今已导致协议约 2415 万枚 USDC 被转移。Blockaid 称,正与 Arbitrum 团队协作响应事件,并协助相关协议控制被盗资金风险。
GoPlus Security issued a security alert stating that a user signed a malicious Permit transaction 183 days ago, resulting in approximately $1,625 worth of USDC being transferred by phishing attackers. Since the user did not revoke the relevant authorization thereafter, attackers exploited this authorization again to transfer approximately $75,780 worth of USDC.
the cross-chain protocol Allbridge has issued an official statement confirming that an attacker has withdrawn approximately $1.65 million in assets from the Allbridge Core liquidity pool. A detailed analysis of the incident is currently being compiled, and the full investigation results will be published subsequently. The team emphasizes that there is no further risk to current user liquidity and that the Allbridge Next service is operating normally.In response to this incident, Allbridge plans to relaunch the Core version but will remove the liquidity pool design. Future cross-chain transfers will be facilitated via Circle CCTP and the LayerZero router to eliminate the risk of liquidity pool imbalance and the model vulnerabilities exploited in this attack. This incident has accelerated the previously initiated migration plan to fully transition to the more secure new infrastructure, Allbridge Next. According to the plan, Allbridge Core and Allbridge Classic will cease operations in their current form within the next three months, and users are advised to withdraw their relevant liquidity in advance.It is understood that this attack has exposed the risks inherent in the traditional cross-chain liquidity pool model and has further driven the protocol's transition towards a cross-chain architecture based on message passing and native asset transfer.
according to Hinkal monitoring, full refunds will be issued this week to users who have completed the recovery process, with completion expected by July 22. Users who have not yet completed the recovery can still submit applications. Previously, Hinkal suffered an attack resulting in a loss of approximately 797,000 USDC, which the attacker exchanged for about 454 ETH.
Odaily reports, according to monitoring by Onchain Lens, Allbridge Core has been exploited on Solana. The attacker borrowed $1.12 million USDC via a Kamino flash loan, then rapidly executed a USDC/USDT swap, distorting the stablecoin pool ratio of Allbridge. They withdrew liquidity at the manipulated exchange rate and repaid the flash loan within the same transaction, extracting approximately $1.1 million in funds. The funds were subsequently mixed through a privacy protocol. The maximum single withdrawal from Allbridge was $2.24 million USDC. Further analysis of the vulnerability exploit and the affected pools is ongoing.
Odaily News: Headline: "Loss of 23.75 Million USDC: Ostium Price Data Attacked". According to Ostium's monitoring, Ostium has released an update on the security incident. Its liquidity provider treasury was attacked on July 15, resulting in a loss of 23,752,746 USDC. Preliminary investigations indicate that the attacker compromised the off-chain infrastructure that supplies price data to the protocol, submitting disguised, fraudulent price reports. By rapidly opening and closing multiple large positions, the attacker extracted artificially generated profits from the treasury. Ostium stated that trader collateral is stored in separate, isolated smart contracts and was unaffected by this incident; all trading positions remain open. The team paused trading and froze all trading contracts within 60 minutes of the first attack transaction. Currently, Ostium is cooperating with Mandiant, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies, and is coordinating with trading platforms, bridge contracts, and stablecoin issuers to advance the investigation. The engineering team is repairing and strengthening the relevant infrastructure to support a safe resumption of trading. Ostium stated it will notify at least 24 hours in advance before thawing the trading contracts. Once trading resumes, existing positions will be marked at the price at the time of reopening, unaffected by price fluctuations during the suspension.
CertiK published an analysis stating that the Solana ecosystem protocol DeFiTuna was attacked on July 16, with losses of approximately 569,601 USDC. The attacker first created an extremely low-liquidity TUNA/USDC pool and swapped borrowed USDC into the pool via Jupiter routing. Since only a minimal amount of TUNA was ultimately obtained, the protocol experienced rounding down during the position asset value calculation, causing the total assets to be recorded as 0, thereby incorrectly passing the health and solvency checks.
Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.
Odaily Odaily News According to MAX monitoring, on July 16, the Cascade CLS treasury suspectedly experienced a security vulnerability, resulting in approximately $1.3 million in user fund losses. The platform has suspended all trading and withdrawals and has invited SEAL 911 and other third-party security teams to investigate and handle the incident. Cascade is a 24/7 multi-asset perpetual contract platform headquartered in New York, targeting the US market. It supports deposits via Arbitrum USDC or bank accounts and is currently still in an invitation-only private testing phase.