News linked to both this project and an event.
victims of the Drift hack, a perpetual contract exchange on Solana, began filing claims on October 1. The recovery pool's initial funding stands at approximately $3.11 million against nearly $295.4 million in verified losses. Victims can redeem USDT through DFX tokens, with each $1 of loss converting to roughly 1.04 cents at launch, meaning a $1,000 loss corresponds to about $10.40.The total supply of DFX is fixed at 299,500,810.998 tokens, with each token corresponding to $1 of verified loss from the April incident, and no additional tokens will be minted. Holders can choose to burn DFX to redeem USDT, sell on secondary markets such as Raydium, or continue holding their claims. Completed redemptions are irreversible, and unclaimed tokens will expire after the claims window closes on January 1, 2028.Future funding for the recovery pool includes a portion of daily net protocol revenue from Velocity, the rebranded exchange rebuilt by Drift, up to $127.5 million in USDT committed by Tether, $20 million in USDT committed by strategic partners, and recovered stolen assets. On the first Friday after claims opened, approximately 216,480 DFX tokens were redeemed for about 2,250 USDT, with Velocity's first revenue transfer amounting to 31 USDT; approximately 13,025.9 ETH is spread across 4 Ethereum wallets, another approximately 2,309.4 ETH passed through Tornado Cash, and about $9.2 million in assets have been frozen at other addresses. (Bitcoin.com News)
Odaily reports: Cross-chain swap service Near Intents announced that the $3.8 million in funds stolen in a previous exploit has been fully returned, and the team has closed its investigation. Near Intents General Manager Alex Shevchenko had previously issued a 48-hour return deadline to the attacker, providing Bitcoin, BNB, Ethereum, and Solana addresses.The attacker acknowledged wrongdoing in an on-chain message, stating that all funds had been returned and urging others to report issues through the bug bounty program. The incident stemmed from a vulnerability in the interaction between its Omni deposit and withdrawal layer and the main smart contract. Near Intents had suspended services and promised full compensation to users. (Decrypt)
according to monitoring by Stani Kulechov, Aave founder Stani Kulechov stated that what was exploited was a third-party external adapter built on top of Aave v3, and the Aave v3 contracts themselves were not affected. The FlashLoopAdapter in the Aave v3 Loop Safe module involved had access control vulnerabilities in its open() and close() functions. The attacker forged Safe authentication and arbitrary module execution to steal approximately 114.09 ETH from two Safe multisig addresses, and repaid approximately 1,300 WETH in debt to unlock collateral.
SlowMist has issued a security alert stating that a vulnerability has been discovered in the Aave V3 Loop Safe Module. Attackers exploited forged Safe authentication and arbitrary Module execution to steal approximately 114.09 ETH from two Safe multisig wallets.The attackers bypassed authentication by forging a Safe that always returns true, and leveraged an arbitrarily controllable router and calldata to execute module transactions, transferring weETH and Aave collateral. The attackers repaid approximately 1,300 WETH in debt to unlock the collateral.
Ethena founder Guy Young stated that USDe backing assets currently have no direct exposure to stETH or other liquid staking tokens, and he expects this incident will not impact Ethena.
ether.fi stated that it is aware of the security incident involving Ethereum node operators that occurred previously. Currently, weETH is unaffected and has no related exposure, and all user funds remain secure.
Odaily News — According to monitoring by the Drift Foundation, the Drift Foundation has released an update on fund recovery progress related to the April 1 security incident: approximately $295 million in user assets were stolen. The foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct the investigation and trace the funds, with Mandiant identifying the attacker as the North Korean threat group UNC6862.The stolen funds were subsequently bridged to Ethereum, with approximately 130,300 ETH distributed across 4 wallets. Three of these wallets have seen no transfers to date, collectively holding 107,200 ETH; the other wallet transferred approximately 23,100 ETH to Tornado Cash on July 23.Currently, approximately $9.2 million in stolen funds has been frozen. The relevant funds had previously been transferred through Tornado Cash in August, and unfreezing and return still require cooperation with legal procedures. The Drift Foundation will transfer all assets recovered through freezing, bounties, or law enforcement channels into the DFX recovery pool, and is evaluating the subsequent path of the DRIFT token within the broader ecosystem. In addition, the foundation has partnered with Bybit to launch a public bounty program, offering a 10% bounty on successfully recovered funds.
— According to Quit monitoring, the Payment Processor V2 (PPV2) exploit attack is still ongoing. Even if users were not affected in the September 25 incident, as long as they have not revoked the relevant approvals, their assets may still be at risk. Users are advised to revoke approvals immediately.About 1 hour ago, an address lost 0.15246 WETH in the next block after accepting a quote and receiving funds. The attacker paid 99% of it as a tip to Titan Builder and kept only about 0.0015 ETH, making it nearly impossible to rescue the funds through frontrunning.Quit suggests that OpenSea could check whether a user still has risky approvals before they accept a quote and require them to revoke them first; when transferring NFTs, it should also check whether the receiving address has any related approvals remaining.
Odaily News — Gracy Chen, CEO of cryptocurrency exchange Bitget, said the company is not optimistic about recovering the $388 million in crypto assets lost in last week's security incident. Citing the Bybit hack in 2025 as a reference, she noted that approximately one year after that incident, only about 3.5% of the stolen funds had been frozen, and that this does not equate to a completed recovery.Bitget has set up a bounty program offering 5% rewards for frozen funds and recovered funds respectively. The NEAR Intents team said it has intercepted over $50 million in assets related to the attack and frozen approximately $500,000. Tether and Circle have blacklisted the relevant wallets, freezing $318,000 worth of USDT and USDC.Gracy Chen stated that preliminary investigations indicate the attack may match VPN addresses used by North Korea-linked groups, but Bitget has not yet fully ruled out the possibility of an insider job. Bitget has resumed withdrawals in phases, starting with Bitcoin transactions on Monday and continuing with ETH transactions on Tuesday. (Cointelegraph)
Odaily News: According to monitoring by Bitget CEO, Bitget was hacked on September 24, with approximately $387.5 million in funds stolen, a large portion of which was transferred across chains and primarily consolidated on Ethereum. A report released by NEAR Intents shows that its risk intelligence layer SHIELD detected over $50 million in suspected money laundering transfer attempts; of this, $166,000 in funds went through, while $503,000 was frozen during execution. The frozen funds remain restricted pending subsequent legal and recovery proceedings.
Odaily reports, according to Lookonchain monitoring, the Bitget hacker (0xf7bC...96C3) swapped ETH for BTC via THORChain, having stolen $351.6 million.
DYORSWAP has released an "Official Statement Regarding the Fake GIWA Mainnet 9134 Incident," stating that the incident was not a DYOR contract vulnerability, but rather was caused by a fraudulent network impersonating GIWA Chain 9134. This network had a bridge and batcher similar to OP Stack, deployed on September 27, 2026, at 02:10:59 (UTC+8). Approximately 8.5 hours before deployment, the address received about 0.045 ETH from a ChangeHero-related address. Data shows that a total of 1,335 addresses bridged approximately 767.65 ETH to it, of which about 766.25 ETH was ultimately transferred out from the cross-chain bridge.DYORSWAP stated that it has already used its own funds to compensate affected users with over 200 ETH. Additionally, the team is still tracking the cross-chain bridge deployer, the source of funds, early test wallets, and the subsequent flow of the transferred funds.
Bitget announces that approximately $387.5 million has been stolen; the CEO's request for THORchain to compromise addresses was denied; Vitalik Buterin states that Ethereum is evolving into a "cryptographic world computer".
Slow Mist's Cosine posted on X platform, stating that the Bitget hack incident has spread widely, involves a huge amount of funds, and the related funds were quickly linked to North Korean hackers. Institutions such as Circle and Tether promptly assisted in freezing the related funds, with Circle freezing the USDC held by the hackers.Regarding THORChain, Cosine pointed out that when THORChain itself previously suffered a hack, it also quickly intervened in its so-called "decentralized" platform; but this time, when facing a major industry security incident, it responded on the grounds of being "decentralized and having no right to interfere," likened itself to Bitcoin and Ethereum, and continued to earn fees from the hackers' large cross-chain transactions.He stated that decentralization should not just be a slogan. After major security incidents occur, the key is to distinguish which issues need to be solved jointly by the industry. He also believes that platforms such as THORChain should not be easily mentioned in the same breath as Bitcoin and Ethereum, as there are clear differences in the degree of decentralization and mechanisms among different systems.
MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.
Odaily News: Today, THORChain officially posted on X platform stating, "We have noticed the recent Bitget hack and are deeply saddened by it. We can imagine this is a difficult time for everyone in the industry. (However,) THORChain is as decentralized and permissionless as Bitcoin, Ethereum, and BNB Chain. When dealing with known stolen funds, what responsibility should Bitcoin, Ethereum, and BNB Chain bear?" Subsequently, it called out OKX CEO Star and Bitget CEO Gracy.However, crypto community members in the comments pointed out that when THORChain previously suffered an attack, it once suspended services for 39 days, and they are deeply ashamed of the differentiated treatment between the two situations.
Odaily News: OKX Star posted on X in response to THORChain, stating that he does not believe THORChain's TSS + validator model represents true decentralization. THORChain's validators collectively control the underlying assets in the TSS vault, and funds can be moved once the signature threshold is reached. Therefore, from a custody perspective, it cannot be compared to the underlying consensus mechanisms of Bitcoin and Ethereum, but instead acts as an intermediary between users and native chains. "TSS distributes control among multiple participants, but decentralizing an intermediary does not eliminate the intermediary itself."Previously, discussions arose after some stolen Bitget funds were transferred through THORChain. THORChain responded that it is decentralized and permissionless, just like Bitcoin, Ethereum, and BNB Chain, and stated that if stolen funds were known to flow through Bitcoin, Ethereum, or BNB Chain, what responsibility should those networks bear?
According to AMLBot monitoring, some of the stolen funds from the Bitget hack have reportedly begun being mixed through Wasabi CoinJoin. The related funds originally came from a TRON wallet on Bitget. The attacker swapped TRX for USDT, then bridged via USDT0 to Ethereum and exchanged it for approximately 145 ETH, which was subsequently swapped through THORChain into approximately 4.59 BTC. These BTC were then split and pre-processed before entering CoinJoin.
Odaily news: According to Lookonchain monitoring, about 11 hours ago, an address withdrew 257.6 ETH, worth $692,000, and 545,000 USDT from Binance, then swapped 545,000 USDT for 200.2 ETH. About 1 hour ago, the address transferred all 457.9 ETH, worth $1.23 million, into the Bitget hacker wallet.
Yuga Labs blockchain vice president Quit posted on X that the asset claim website for NFTs stolen in the previous Payment Processor vulnerability incident has gone live. However, if an NFT collection uses the ERC721C or ERC1155C standard, its holders may temporarily be unable to claim assets through the NFT claim website. A number of NFT collections are currently affected by this issue. The relevant collections controlled by Yuga Labs are expected to be fixed by tomorrow. In the meantime, users can enable "7702 delegate OTC" in the transfer verifier settings, or add the specified Ethereum address and ApeChain address to the 7702 delegated address whitelist to remove the relevant restrictions.