News linked to both this project and an event.
According to Cointelegraph, Fidelity Digital Assets has rebutted concerns in a new research report that Bitcoin’s long-term security will deteriorate as mining rewards decline, asserting that the network’s economic incentives remain sufficient to secure the blockchain over the long term. Authored by Fidelity research analyst Daniel Gray, the report reiterates that Bitcoin’s security depends not only on block rewards but also on transaction fees and market-driven economic incentives, which will continue to motivate miners to protect the network—and render sustained attacks prohibitively costly. The report challenges a longstanding critique that Bitcoin’s security is weakened every four years by the halving event, which reduces new coin issuance. It notes that since April 20, 2024, Bitcoin miners have received a subsidy of 3.125 BTC per block—down from 6.25 BTC in the previous halving cycle—but this reduction in issuance has not translated into diminished miner incentives, as Bitcoin’s price appreciation has more than offset the decline in block rewards. Gray points out that average daily miner revenue has surged from approximately $26,300 during Bitcoin’s first halving cycle to over $40.2 million today. The report also notes that although Fidelity views the long-term incentive structure as sound, many publicly listed mining companies are currently facing financial pressure, with some diversifying into artificial intelligence and high-performance computing. VanEck recently
Ethereum Layer 2 blockchain Taiko has stated its chain state verification mechanism has been compromised, and the security assumptions of all bridges deployed on Taiko can no longer be relied upon. It urges users to immediately withdraw funds from the relevant bridges. Taiko says it is coordinating with partners to control the incident and has suspended the affected systems.Crypto security firm Blockaid stated that the root cause appears to be a flaw in the way Taiko's bridge validates source signals. Attackers can submit message proofs on Ethereum that lack legitimate proof from the Taiko chain, thereby registering and withdrawing fraudulent bridge messages. This leads to the unauthorized release of assets from the ERC20 treasury. Blockaid estimates at least $1 million was stolen, while Lookonchain and PeckShield believe the value of stolen assets could be as high as $1.7 million.PeckShield reported that the attacker has transferred approximately 1.99 million TAIKO tokens to MEXC, valued at around $189,000. Data from blockchain intelligence firm Arkham shows that the Taiko attacker's wallet holds approximately $1.5 million in assets, primarily in Ether. (Cointelegraph)
Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)
Odaily Aave, a DeFi lending protocol, successfully maintained operations after experiencing capital outflows totaling approximately $8.45 billion. However, the incident has simultaneously triggered renewed market discussion regarding its risk structure and the fragility of the DeFi system.This stress event originated from a vulnerability exploit on the KelpDAO rsETH cross-chain bridge in April 2026, resulting in the theft of approximately $292 million in assets. This triggered market concerns over the safety of rsETH collateral. As this asset was widely used as collateral on Aave, panic spread rapidly, leading to concentrated withdrawals by users.During the capital outflow process, liquidity in certain lending markets was quickly depleted, with utilization rates briefly approaching 100%. Aave managed the situation by adjusting risk parameters and activating emergency mechanisms, although localized withdrawal restrictions did occur.Nevertheless, Aave's core smart contracts were not compromised. Protocol founder Stani Kulechov stated that the event validated the system's stability and resilience under extreme stress conditions.However, analysts pointed out that this incident exposed structural risks within DeFi: high coupling of assets across protocols, reliance on external bridged assets for collateral, and the potential for liquidity to rapidly evaporate in extreme scenarios.Industry observers believe that while DeFi's "composability" enhances efficiency, it also accelerates risk transmission, potentially causing a single asset event to trigger systemic cascading effects. Although Aave successfully navigated this stress test, the outcome does not equate to the elimination of risk.Overall, this event is viewed as a genuine extreme stress test for the DeFi lending system: the system can function, but its stability remains highly dependent on the quality of external assets and the market liquidity environment. (Cointelegraph)
leaders of the Group of Seven (G7) issued a statement at the G7 summit in Évian-les-Bains, France, once again calling for joint action to combat North Korean cryptocurrency theft and cybercrime. United Nations security researchers have linked North Korea's cryptocurrency theft to the funding of its weapons programs.Previously, attacks suspected to be linked to North Korean hackers included a $285 million attack on Drift Protocol in April and a $36 million breach on Humanity Protocol in June. According to Chainalysis data, North Korean hackers stole at least $2 billion in cryptocurrency in 2025, bringing their historical total theft amount to at least $6.75 billion. (Cointelegraph)
According to Cointelegraph, cybersecurity leaders led by former Facebook Chief Security Officer Alex Stamos jointly penned a letter urging the Trump administration to lift restrictions on the use of Anthropic’s Mythos model. They argue that these restrictions harm defenders far more than attackers, hindering the overall development of the cybersecurity ecosystem.
Odaily Zcash founder Zooko Wilcox posted on X stating that a security audit conducted by Anthropic's Claude Mythos AI model did not find any "more severe vulnerabilities" in the Zcash protocol. The audit was commissioned by Shielded Labs, a Swiss non-profit organization supporting Zcash development. On June 3, Zcash developers temporarily paused Orchard transactions after discovering a vulnerability in the shielded pool, restoring functionality through an emergency upgrade the same day. The issue stemmed from a four-year-old forging vulnerability in the Orchard shielded pool, identified by security researcher Taylor Hornby with the assistance of Anthropic's Claude Opus 4.8 model. The Zcash Foundation stated there is no evidence that the vulnerability was exploited, nor was any unauthorized value creation detected, and user privacy remained unaffected.Anthropic released the first public version of the Claude Mythos model, Fable 5, on Tuesday, and stated on Friday that it has suspended access to the Fable 5 and Mythos 5 AI models due to export control directives issued by the U.S. government citing national security concerns. (Cointelegraph)
According to Cointelegraph, Zcash founder Zooko Wilcox stated that a security audit of the Zcash protocol—commissioned by Shielded Labs and conducted using Anthropic’s Mythos AI model—did not uncover any new critical vulnerabilities. Previously, security researcher Taylor Hornby discovered, using Claude Opus 4.8, a four-year-old forgery vulnerability in the Orchard shielded pool, prompting developers to urgently suspend Orchard transactions on June 3 and complete the fix the same day. The Zcash Foundation confirmed there is no evidence the vulnerability was ever exploited, and user privacy remained unaffected.
law enforcement agencies from 11 countries have jointly shut down the money laundering network AudiA6, which processed over 336 million euros in illicit funds between 2022 and 2025. On June 10, law enforcement arrested two administrators of Russian and Ukrainian nationality in Georgia, seized 25 domain names, over 30 servers, and 80 vehicles, and froze approximately 778,000 euros in cryptocurrency. Operating as a "mixer-as-a-service," AudiA6 provided services to cybercriminals involved in ransomware attacks, helping them cash out crypto assets and conceal the flow of funds, charging commissions of 3% to 10% and claiming to complete the "cleaning" process within about an hour.Since 2021, the AudiA6 wallet has received approximately 10,333 BTC, valued at around $389 million at the time of the transactions. The investigation also revealed that the money laundering network used thousands of fake accounts created with stolen or purchased identities, involving over 6,000 KYC records; many of these accounts were linked to Russian-speaking intermediaries and were used to transfer criminal proceeds through cryptocurrency exchanges. The clearnet and darknet domains of AudiA6 and Dark2Web have been replaced with seizure banners. (Cointelegraph)
Odaily, Mitchell Amador, CEO of bug bounty platform Immunefi, stated at the WAIB Summit that new AI models such as Claude Opus 4.8 and ChatGPT 5.5 are shifting the balance of cybersecurity offense and defense in favor of attackers, leading to a resurgence in crypto hacks in 2026. Data from DefiLlama shows that in April 2026, illicit actors stole over $634 million from crypto platforms, the highest monthly total since the Bybit hack in February 2025 drove losses of approximately $1.4 billion.Amador stated that the crypto industry is in a critical survival period for the next three to four years until security teams leverage similar AI models to build codebases that attackers cannot breach; if the industry adopts more crowd-sourced security solutions, this timeline could be shortened to within two years. The latest Claude Mythos model, Fable 5, from AI company Anthropic, previously raised concerns about accelerating the ability to exploit crypto vulnerabilities.Anthropic stated that Fable 5 has safeguards in place that will redirect topics related to cybersecurity and similar fields to Claude Opus 4.8. On April 19, an attacker transferred approximately 116,500 restaked Ethereum (rsETH) from Kelp DAO's LayerZero-based rsETH bridge, valued at around $290 million to $293 million at the time. Cross-chain protocol LayerZero stated that the 1/1 decentralized verification network configuration of Kelp DAO relied on a single verification path for processing cross-chain messages, creating a single point of failure. (Cointelegraph)
CertiK data shows attack losses on crypto platforms fell to $68.3 million in May, down nearly 90% from $650 million in April. May became the third month in 2026 with losses below $100 million. Approximately $2.6 million of this came from phishing attacks, and about $9.4 million of the stolen funds have been recovered or returned. The largest single loss in May came from the Verus Protocol cross-chain bridge attack, with $11.5 million stolen; THORChain ranked second, with $10.1 million stolen. Code vulnerabilities were the attack type with the highest losses, totaling approximately $45 million, accounting for 66%; wallet or private key leaks resulted in $13.7 million in losses. Cross-chain bridges were the primary attack targets, suffering losses of $28.6 million, accounting for 42%.
According to Cointelegraph, phishing ads impersonating the decentralized exchange protocol Uniswap have appeared in Google search results, enabling attackers to steal at least $400,000. On-chain analyst b-block stated that the associated counterfeit websites are draining funds from multiple wallets; the implicated addresses currently hold a combined total of 146 ETH—worth approximately $306,000 at press time. Security Alliance (SEAL) noted that such fraudulent Google ads are a common source of phishing attacks, with attackers either purchasing ad placements or compromising legitimate advertising accounts to impersonate popular crypto protocols in sponsored search results. SEAL also reported that between March 13 and March 30, these attacks resulted in total losses amounting to $1.27 million.
stablecoin issuer StablR suffered a sustained attack, causing its euro stablecoin EURR and dollar stablecoin USDR to depeg.Blockchain security firm Blockaid stated that the attacker allegedly gained control by obtaining the private key of one of the owners of the minting multi-signature account. Exploiting the 1/3 signature threshold mechanism, the attacker replaced other administrators and minted an additional 8.35 million USDR and 4.5 million EURR.Subsequently, the attacker swapped tokens worth approximately $10.4 million for about 1,115 ETH on a DEX, yielding an actual profit of around $2.8 million. Following the incident, EURR fell to around $0.88, while USDR dropped to approximately $0.7.Blockaid noted that the incident was not caused by a smart contract vulnerability but rather by a failure in key management and governance mechanisms. (Cointelegraph)
According to Cointelegraph, Bitcoin mining company MARA Holdings spent $4.3 million on CEO Fred Thiel’s personal security in 2025, including $430,780 for vehicle armor, as well as residential and personal security expenses. Filings show related spending for 2024 totaled $191,040. In the same year, MARA also spent $3.9 million on CFO Salman Khan’s personal security. The report notes that personal safety costs for companies are rising amid an increase in “wrench attacks” targeting cryptocurrency executives and investors.
Casa co-founder Jameson Lopp has warned of a new phishing attack, where attackers leverage legitimate Google account recovery forms to hide malicious links within large amounts of blank space. This technique involves embedding "invisible" or overlooked whitespace characters within long text, making the malicious link less noticeable to users, thereby tricking them into clicking and exposing their account information.Lopp advises users to remain vigilant when handling account recovery emails or forms, and to avoid clicking on links that are from unknown sources or intentionally hidden. (Cointelegraph)
According to Cointelegraph, privacy-focused messaging app Signal stated it may exit the Canadian market if required to comply with Canada’s proposed lawful access bill, Bill C-22. Udbhav Tiwari, Signal’s Vice President of Strategy and Global Affairs, said the bill could compel service providers to build technical surveillance capabilities and retain certain user metadata for up to one year—potentially undermining end-to-end encryption and increasing the risk of cyberattacks. The report notes that Bill C-22 has not yet entered into force and still requires parliamentary review and royal assent. In addition to Signal, VPN provider Windscribe has also indicated it may follow suit and withdraw from Canada if the bill is passed.
According to Cointelegraph, Tezos ecosystem developers have launched the quantum-resistant privacy payment prototype TzEL on the testnet. TzEL employs post-quantum cryptography and zk-STARK proofs to defend against “harvest now, decrypt later” attacks, safeguarding transaction data and encrypted payment metadata. The prototype also integrates Tezos’ data availability layer to handle the relatively large size of post-quantum proofs. According to the whitepaper, the quantum-resistant zk-STARK proofs used by TzEL are approximately 300 KB in size. TzEL is currently running on the Tezos testnet, and the Tezos ecosystem’s transition to post-quantum cryptography remains in its early stages.
According to Cointelegraph, a New York judge has postponed the hearing on Aave’s emergency motion to unfreeze approximately $71 million worth of ETH and ordered Aave and Gerstein Harrow LLP to submit additional case briefs. A new hearing is scheduled for June 5. The court noted that Aave previously failed to adequately explain why users’ funds would suffer “derivative losses” if the restraining order remained in effect. The assets in question are linked to the Kelp DAO hack, which involved approximately $293 million and was previously frozen by Arbitrum. The judge also directed both parties to further clarify several legal issues, including the applicable law governing the hacker’s transactions, the legal distinction between fraud and theft, the priority ranking of creditors’ claims, the applicability of constructive trust, and whether assets can be proportionally returned to victims.
According to Cointelegraph, Marlon Ferro, a 20-year-old man from California known online as “GothFerrari,” was sentenced to 78 months in federal prison, three years of supervised release, and ordered to pay $2.5 million in restitution for his involvement in a cryptocurrency theft ring responsible for over $250 million in losses. Prosecutors stated that when co-conspirators were unable to remotely breach victims’ systems or trick them into surrendering their crypto assets, Ferro carried out physical break-ins to steal hardware wallets containing the funds. The group operated from late 2023 through early 2025 and its members were also involved in database intrusions, target identification, scam phone calls, and money laundering. The investigation was led by the FBI and the IRS Criminal Investigation Division.
According to Cointelegraph, Coinbase has been sued in a U.S. federal court in California over frozen funds linked to a $55 million DAI phishing theft that occurred in 2024. The plaintiffs allege that some traceable stolen funds—after being mixed via Tornado Cash—were deposited into Coinbase retail user accounts and remain frozen. Coinbase states it can only release the assets after a court rules on their ownership. The complaint also links the theft to the malicious wallet drainer platform Inferno Drainer. Victims had engaged Zero Shadow and Five Stones Intelligence to track the stolen funds.