GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Ostium OLP Vault Attacked, Approximately $24 Million USDC Stolen and Transferred to Tornado Cash

According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), the public OLP vault of decentralized perpetual contract protocol Ostium (@Ostium) was attacked, with approximately 24 million USDC stolen. The attacker subsequently swapped the stolen funds for 12,080 ETH and has transferred 10,540 ETH into the mixer Tornado Cash to obscure the fund flow. On-chain tracing shows that the attacker's initial funds originated from ChangeNow and Bybit, with 1 ETH transferred from each to the attacker's wallet (0x321D...8bfD9).

Ostium suffers oracle attack, losing 18 million USDC; approximately one-third of liquidity drained

Ostium, a decentralized perpetual exchange, suffered an oracle attack on Wednesday, resulting in losses of approximately 18 million USDC. The attacker submitted false price reports for future dates using compromised oracle signing keys, generating fictitious trading profits and receiving payouts from the Ostium liquidity vault. Ostium stated that it has identified the issue with the OLP vault, has suspended all trading, and the team is currently investigating. Deployed on Arbitrum, Ostium offers perpetual futures trading for real-world assets including stocks, commodities, forex markets, and indices. At the time of the attack, the total value locked (TVL) in the Ostium protocol was approximately $63 million. The attack drained nearly one-third of this liquidity. In the first five months of 2026, DeFi protocols have lost over $840 million to exploits, including $292 million from KelpDAO and $285 million from Drift Protocol.

DeBank user musti_akrep exploits Ostium vulnerability to profit 23.75 million USDC and exchange for 12,085 ETH

according to on-chain analyst Yujin's monitoring, half an hour ago, an address (0x321...bfd9) with the DeBank username musti_akrep profited 23.75 million USDC by exploiting a vulnerability on Perp DEX Ostium and withdrew it. The 23.75 million USDC was withdrawn to the Arbitrum chain and immediately exchanged for 12,085 ETH at a price of $1,965. Currently, these 12,085 ETH remain on the Arbitrum chain.

Ostium Attacked, Losses Approximately $18 Million

Blockaid stated that it detected a vault exploit incident involving Ostium on Arbitrum. The attacker fabricated false trading profits through registered PriceUpKeep Forwarders and authorized oracle reports with future timestamps, triggering a payout of approximately 18 million USDC from the vault.

LayerZero_Core Executor wallet allegedly hacked, multi-chain losses of $2.1 million

according to on-chain detective Specter's monitoring, the LayerZero_Core Executor wallet may have been compromised, resulting in a total multi-chain loss of $2.1 million. The attacker bridged the stolen funds to Ethereum via Stargate and Relay, and is currently holding 955 ETH (worth $1.78 million) and 322,000 USDC. CyversAlerts first identified this suspicious activity.

BarnBridge governance attack reportedly causes approximately $776,000 in losses

According to BlockSec monitoring, the BarnBridge SMART Yield cUSDC protocol was attacked on Ethereum, resulting in losses of approximately $776,000, suspected to be a governance attack. The attacker first gained DAO governance rights, then upgraded the SmartYield/controller proxy to a malicious implementation contract. This contract called the _takeUnderlying privileged function of CompoundProvider, utilizing pre-existing USDC approvals from 50 user accounts, and via transferFees, moved the aggregated funds to the attacker.

Loss of approximately $9 million: Hedera ecosystem lending protocol Bonzo Finance suffers oracle attack

Bonzo Finance, a lending protocol based on Hedera, suffered an oracle attack, resulting in a loss of approximately $9 million. The attacker exploited collateral whose SAUCE token price had been artificially inflated to borrow assets far exceeding their actual value from the protocol. According to a preliminary incident report released by Bonzo Finance, the attacker deposited only 250 SAUCE tokens, then submitted a single price update that artificially inflated the token's price by approximately 12 orders of magnitude. Subsequently, the address borrowed 6.63 million USDC and 34.5 million wrapped HBAR from the lending pool.This attack was not due to a vulnerability in Bonzo Finance's smart contracts or the underlying Hedera network itself, but rather stemmed from a flaw in the on-chain oracle verifier of the oracle service provider Supra. It erroneously accepted a SAUCE price data point where the signature had been zeroed out. Supra has since confirmed the issue and completed a fix.

Circle Refuses to Assist in Recovering Stolen USDC, Drawing Criticism from Wisconsin and New York Prosecutors

prosecutors from Wisconsin and New York have expressed dissatisfaction with stablecoin issuer Circle, as the company has repeatedly refused to cooperate with law enforcement agencies in recovering stolen funds.According to the report, multiple law enforcement agencies had requested Circle to help victims of fraud and hacking incidents recover their losses by burning and reissuing USDC. However, Circle declined these requests based on its own policy stance.Circle stated that modifying the blockchain ledger to reverse transactions would undermine the fundamental properties of the USDC stablecoin and could set a dangerous precedent for the entire crypto industry. This incident highlights the conflict between the immutability of blockchain and the need for law enforcement to recover assets. (Protos)

DeFi asset management and risk analysis company Gauntlet secures $125 million financing from Japanese financial giant SBI Holdings

According to Fortune, DeFi asset management and risk analysis company Gauntlet completed a $125 million financing round, exclusively invested by Japanese financial group SBI Holdings. The financing was completed in June this year, and the specific valuation was not disclosed. This is Gauntlet's largest financing round since its establishment in 2018, far exceeding its $24 million Series B round in 2022 led by Ribbit Capital at a $1 billion valuation. Gauntlet was founded by former Wall Street quantitative trader Tarun Chitra. It initially focused on providing stress testing and vulnerability analysis services for DeFi protocols. Later, as the DAO governance model waned, it gradually transitioned to a "treasury curation" business—assessing yield strategy risks through quantitative analysis to help institutional investors manage digital asset allocation. Currently, its clients include asset management giant Apollo, Coinbase, and stablecoin issuer Circle.

Summer.fi: Lazy Summer USDC Vault Suffers NAV Manipulation Attack, Losing Approximately 6.04 Million USD

According to official sources, Summer.fi released a post-mortem stating that on July 6, the attacker manipulated the share prices of two Lazy Summer USDC vaults by injecting overvalued Silo tokens into an offline Ark still included in the NAV, and extracted approximately $6.04 million in a single atomic transaction.

Serious Vulnerability Exposed on Aptos Blockchain, $70 Billion in Assets Once Faced Systemic Risk

According to CoinDesk, researchers at blockchain security company Hexens discovered an "expired cache" type confusion vulnerability in the Aptos blockchain Move virtual machine. Attackers require only about $3,000 in server costs to launch attacks in a simulated environment with a success rate of nearly 90%, without needing validator privileges or internal knowledge. Researchers ran approximately 20 attacks in simulated tests, succeeding 17-18 times, and verified the potential ability to control management permissions of cross-chain protocols such as LayerZero, Wormhole, and USDC CCTP. Hexens assessed that the vulnerability directly threatens protocols on the Aptos chain such as DeFi, stablecoins, and liquid staking, involving assets in the low single-digit billions of dollars; if spread through paths such as cross-chain bridges, stablecoin minting, and centralized exchanges, the systemic risk exposure could reach up to $70 billion. The Aptos team completed the fix and deployed it to the mainnet within hours after receiving the vulnerability report on February 25, and currently no user funds have been compromised.

hinkal will fully compensate user funds, confirming approximately 797,000 USDC was extracted by an attacker and swapped for 454 ETH

decentralized privacy protocol hinkal has released an update on a security incident, confirming that an attacker extracted approximately 797,000 USDC from its Ethereum contract through a series of transactions and exchanged it for about 454 ETH. Of this, roughly 410 ETH was subsequently transferred to Tornado Cash, while the remaining approximately 44.67 ETH was bridged to the Bitcoin network via THORChain. hinkal is currently collaborating with an external security team to trace the flow of funds.hinkal stated that the impact of this security incident is limited to the relevant fund pools on the Ethereum chain, and contracts on other chains remain unaffected. However, all contracts have been temporarily suspended for fixes and security verification. All affected users will be fully compensated at a 1:1 ratio, with specific compensation procedures and timelines to be announced in a subsequent update.

CertiK: Hinkal Protocol Exploited, Approximately $800K USDC Stolen

according to CertiK's monitoring, suspicious transactions occurred in the Hinkal Protocol. An address (0xbB3...fc20) executed multiple "Transact" transactions after initiating a "Proofless Deposit," siphoning approximately $800,000 USDC from the Hinkal contract.

StarkWare Releases Starknet Quantum Resistance Roadmap

zero-knowledge scaling company StarkWare has released a Starknet quantum resistance roadmap, stating that the roadmap is divided into three phases to address the risk of future quantum computing attacks. StarkWare CEO Eli Ben-Sasson stated that Starknet can leverage its architectural advantages to achieve quantum resistance, as its underlying cryptography is based on zero-knowledge STARK proofs. According to reports, the first phase of the roadmap includes replacing part of the existing secure mathematical mechanism, Pedersen hash, with a quantum-resistant version, and adding quantum-resistant signatures; the second phase focuses on migration tools, upgrading existing smart contracts without requiring developers to manually rebuild applications; the third phase involves dependencies that Starknet cannot solve alone, primarily relying on Ethereum's quantum upgrade roadmap. Circle, Ethereum, Solana, Tezos, and Algorand have all proposed quantum resistance roadmaps. (Cointelegraph)

PeckShield: The JaredFromSubway attacker has converted the stolen funds into 4,400 ETH, with some of the proceeds flowing into Tornado Cash.

According to on-chain analyst PeckShield (@PeckShieldAlert), the well-known MEV bot “JaredFromSubway” has reportedly been attacked, resulting in the theft of approximately $7.5 million worth of crypto assets—including 1,474.58 WETH, 2.87 million USDC, and 2 million USDT. The attacker has exchanged the stolen funds for 4,400 ETH and transferred 1,000 ETH to the mixer Tornado Cash to obfuscate the fund’s trail.

Well-known MEV bot Jaredfromsubway.eth suffers reverse attack, losing over $7.5 million

Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)

JaredFromSubway’s MEV Bot Attacked, Suffers $7.5 Million Loss

According to on-chain analyst Blockaid (@blockaid_), the well-known Ethereum MEV bot JaredFromSubway (@jaredsmev) has been attacked, resulting in losses of approximately $7.5 million. The attacker constructed a deceptive MEV arbitrage path to trick the bot into automatically approving token transfers. Leveraging these open approvals—before they were revoked—the attacker drained WETH, USDC, and USDT from the bot’s contract. The stolen funds ultimately flowed to the attacker’s wallet address. Blockaid noted that this attack was not a conventional phishing attempt or smart contract vulnerability, but rather a targeted exploitation of the bot’s automated execution mechanism.

The Humanity Protocol attacker converted part of the stolen funds into USDC and deposited them into KuCoin.

According to Lookonchain, the Humanity Protocol attacker has converted part of the stolen funds into USDC and deposited them into KuCoin.

PeckShield: ThetanutsFi Suffers ~$2.1 Million Loss in Attack, Partially Recovered by White Hat Hacker

According to PeckShield monitoring, structured products protocol ThetanutsFi has been attacked, resulting in a loss of approximately $2.1 million. Of this, roughly $2 million in option tokens have been recovered by a white hat address. The attacker has exchanged $105,000 USDC for approximately 60 ETH, and still holds USDC option tokens worth around $34,000.

Raydium old liquidity pool suspected of being attacked, approximately $1.34 million in assets stolen

blockchain security analyst Specter posted on X platform, stating that an old liquidity pool of the Solana DeFi protocol Raydium is suspected of being attacked, with the attacker stealing approximately $1.34 million in assets, mainly including USDC, RAY, and wSOL. Currently, the hacker has transferred the stolen funds to Ethereum via a bridge and subsequently deposited them into Tornado Cash for mixing.