News linked to both this project and an event.
The Drift Foundation has outlined the compensation plan following the protocol hack: users will receive 1 DFX token for every 1 USDT lost, with redemption amounts depending on the recovery pool balance that currently covers only about 1% of total claims; Tether has committed to providing up to $127.5 million USDT to support protocol restart and user compensation, with funds matched against Velocity's net protocol revenue rather than disbursed as a lump sum; the claims deadline is January 1, 2028, allowing users to choose to hold DFX or trade it on secondary markets such as Raydium, with the only official link being dfx.drift.trade.
Greenfield Capital has filed a complaint with the Swiss federal foundation regulator ESA regarding governance issues at the Safe Ecosystem Foundation, alleging that Safe Foundation directors instructed personnel to hand over a substantial amount of SAFE tokens following the Bybit hack, and threatened to force Gnosis to sell its holdings—which account for approximately 10% of the total SAFE supply—and sever ties with Safe.
Ripple与XRP Ledger基金会(XRPLF)联合成立新组织XRP Asia,旨在推动亚太地区XRP Ledger(XRPL)生态发展,总部位于新加坡,由前Hedera基金会亚太及金融科技/支付业务负责人Sabrina Tachdjian领导,该组织将支持开发者培训、黑客松、合作伙伴计划、创业支持以及生态活动,并对接基础设施服务商、孵化及资助项目,以及连接投资者和生态合作伙伴。
Odaily News — According to monitoring by Drift Foundation, DFX claims and redemption are now live. Users with verified losses from the April 1 incident can claim 1 DFX per 1 USDT lost. Each DFX corresponds to a claim on the Recovery Pool, which currently holds approximately 3.11 million USDT. The funding sources include a portion of Velocity's daily protocol net revenue, up to 127.5 million USDT in matching funds from Tether, up to 20 million USDT from strategic partners, and assets recovered subsequently.DFX can be redeemed for USDT at a redemption amount calculated as "Recovery Pool balance ÷ DFX outstanding supply." Redeemed DFX will be burned, and transactions are irreversible. The claims window will close on January 1, 2028, at 00:00 UTC, at which point unclaimed DFX will be burned.Yesterday, Drift Foundation released an update on fund recovery efforts related to the April 1 security incident, in which approximately $295 million in user assets were stolen. The Foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct investigations and trace funds, with Mandiant identifying the attacker as North Korean threat group UNC6862.
Odaily News — According to monitoring by the Drift Foundation, the Drift Foundation has released an update on fund recovery progress related to the April 1 security incident: approximately $295 million in user assets were stolen. The foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct the investigation and trace the funds, with Mandiant identifying the attacker as the North Korean threat group UNC6862.The stolen funds were subsequently bridged to Ethereum, with approximately 130,300 ETH distributed across 4 wallets. Three of these wallets have seen no transfers to date, collectively holding 107,200 ETH; the other wallet transferred approximately 23,100 ETH to Tornado Cash on July 23.Currently, approximately $9.2 million in stolen funds has been frozen. The relevant funds had previously been transferred through Tornado Cash in August, and unfreezing and return still require cooperation with legal procedures. The Drift Foundation will transfer all assets recovered through freezing, bounties, or law enforcement channels into the DFX recovery pool, and is evaluating the subsequent path of the DRIFT token within the broader ecosystem. In addition, the foundation has partnered with Bybit to launch a public bounty program, offering a 10% bounty on successfully recovered funds.
Odaily News: The European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA) stated in a joint risk update that advances in quantum computing could weaken the cryptographic systems that secure blockchain transactions, communications, and database security.In March, Google Quantum AI researchers estimated that the number of physical qubits required to break the cryptographic techniques used by many cryptocurrencies may be about 20 times fewer than previously estimated. A computer capable of carrying out such an attack does not yet exist.In February, Bitcoin developer Jameson Lopp and others proposed phasing out current signature schemes and restricting how unmigrated funds can be used five years after the proposal's activation. The proposal has not yet been adopted. The Ethereum Foundation plans to make Ethereum's execution, consensus, and data layers quantum-resistant by December 2029. (Cointelegraph)
Crypto wallet app SecondFi announced that some wallet holders affected by the security incident were originally scheduled to claim NIGHT tokens the following day. After consulting with the Midnight Foundation, it was confirmed that NIGHT token allocations can only be claimed via the original wallets; the system does not support switching to an unaffected wallet address for claims.
Odaily News: Researchers from institutions including the Ethereum Foundation, Theta Labs, and StarkWare have jointly published a paper, using AI coding agents to deeply optimize the core operations of Shor's algorithm. The computing resources required for a potential quantum attack on Bitcoin and Ethereum (secp256k1 cryptographic system) have been reduced by more than 50% compared to Google's benchmark in March of this year. The number of logical qubits required for the circuit has been compressed to 1,151, and later versions have even been reduced to 813. Although current quantum hardware still cannot directly break public chains, the research shows that pure algorithmic optimization is significantly narrowing the time window for the quantum threat. The researchers emphasize that quantum-resistant upgrades take a long time and cannot be applied retroactively, and the industry needs to prepare defenses in advance. (Coindesk)
According to TechCrunch, AI alignment researcher Paul Christiano has officially joined the board of directors of the OpenAI Foundation and will serve as a member of its Safety and Security Committee. Christiano stated that he believes the rapid acceleration of AI capabilities poses a significant risk of "catastrophic and irreversible loss of control," and that the AI industry, including OpenAI, is not currently on track to effectively mitigate this risk. His appointment comes against the backdrop of several recent security incidents at OpenAI involving AI agents breaching constraints and infiltrating external computer systems, prompting widespread scrutiny of its safety protocols. Christiano is one of the core developers of the reinforcement learning (RLHF) technology. After leaving OpenAI in 2021 to found the Alignment Research Center (ARC), he will also continue to serve as an AI safety advisor to the U.S. government, though he will recuse himself from OpenAI-related matters and model evaluation work.
According to disclosures from the Phoenix Veritas Foundation, the Hunter Biden laptop-themed cultural token, LAPTOP, has been issued on the Base chain with a total supply of 1 billion tokens and an initial circulating supply of 350 million tokens (35%) at TGE. Token allocation consists of 30% for founders (including Hunter Biden), 30% for the prediction mechanism, 20% for the community airdrop, 10% for liquidity, 10% for the foundation treasury, and 5% for charity. Founder tokens are subject to a six-month lock-up period followed by linear unlocking over 24 months. LAPTOP provides no utility, positioned strictly as a cultural digital collectible with its value driven entirely by community sentiment. The token contract underwent a security audit by Hacken in April 2026, revealing no major vulnerabilities. Regarding market maker arrangements, the foundation has entered into a lending agreement with G20 and GSR totaling 20.5 million tokens.
: The G7 cybersecurity working group stated in its latest report that quantum computing poses both a security threat and an economic threat to public and private institutions, and related organizations should immediately begin migrating to post-quantum cryptography (PQC).The working group noted that the migration process could take several years, as attackers can already collect and store encrypted data today and decrypt it once sufficiently powerful quantum computers emerge. Quantum computing could also break digital signatures, leading to identity theft and exposing companies and their supply chains.The report did not mention cryptocurrencies, but similar public-key cryptography is used for blockchain wallets and transaction authorization. Current quantum computers are not yet capable of breaking Bitcoin's cryptography, but developers are considering post-quantum solutions such as BIP-360.Ethereum researchers plan to replace multiple cryptographic components used by accounts, validators, and applications. The Solana Foundation has tested post-quantum signatures on its testnet and launched an optional hash-based vault. The G7 working group also urged governments to support related research, public-private cooperation, and national PQC strategies. (Decrypt)
SVM Layer 1 network Fogo stated that after detecting unauthorized activity, it has taken precautionary measures to temporarily halt the Fogo mainnet in order to prevent the continued transfer of affected assets. During the mainnet suspension, Fogo will upgrade the network and restrict addresses associated with the incident. The team stated that further updates will be released once more information is confirmed, and reminded users to obtain relevant information only through Fogo's official channels. At present, the cause of the incident, the scale of affected assets, and the timeline for mainnet restoration have not yet been disclosed. Previously, the Fogo Foundation was breached by an unknown attacker, with approximately 400 million FOGO tokens transferred to the attacker's address. The foundation stated that it had immediately notified relevant trading platforms and is in communication with law enforcement agencies and forensic experts.
: Blockchain technology company Starkware stated that on August 26, a transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) scheme was mined on the Bitcoin mainnet, without requiring a soft fork, hard fork, or modification of consensus rules.The transaction consumed 10,000 sats and was processed through MARA Foundation's Slipstream service, as the non-standard format typically cannot propagate through Bitcoin's public mempool. The test consumed several hours of GPU computation, costing approximately $150 to $200.QSB employs hash-based quantum-resistant spending conditions and reduces quantum attack risks through signature trial mining, but still requires users to proactively migrate funds and cannot protect assets whose public keys have already been exposed. Starkware CEO Eli Ben-Sasson still supports introducing a protocol-level solution via a soft fork. (Bitcoin.com News)
Odaily News: An unknown attacker breached the Fogo Foundation, resulting in the transfer of approximately 400 million FOGO tokens to a malicious address. The Fogo Foundation has notified major exchanges and is in communication with law enforcement and blockchain forensics experts. This incident will not affect the Fogo blockchain itself, and the network remains operational. The Fogo Foundation will provide further updates as more information becomes available.
Odaily News: 0xbow.io, a privacy and regulatory compliance tool supported by the Ethereum Foundation, has awarded a $5,000 bounty to researcher ross.wei for disclosing a vulnerability in the Privacy Pools v1 SDK. The vulnerability reduced the entropy of user account master key generation and was fixed in March. The team has provided a migration process, and no user funds were lost.
Odaily News: The KITE Foundation has provided an update on the handling of a token security incident. A new KITE ERC-20 contract has been deployed on the Ethereum mainnet, with the total token supply remaining unchanged. Old KITE tokens will be migrated to the new contract at a 1:1 ratio. Addresses confirmed to be controlled by the attacker will be excluded and will not receive new tokens.The migration snapshot is based on Ethereum mainnet block height 25,692,498. Regular self-custody wallet users will receive the new tokens directly without needing to redeem or authorize anything. Exchange users will have their migration coordinated between the exchange and the KITE team. Cross-chain channels will remain paused until migration and verification are complete.Previously, KITE detected abnormal transfers on August 6 and confirmed it had been attacked by hackers. The team stated that this incident did not result in any asset losses for users or the project, and the impact is currently under control.
Odaily News: The cross-chain bridge connecting XRP Ledger and Coreum was attacked on August 9. The attacker exploited a validation logic vulnerability to steal approximately 199,900 XRP, reducing the bridge's asset balance from roughly 200,400 XRP to 493.5 XRP. The attack did not involve private key leaks and did not target the XRP Ledger protocol itself. The attacker forged deposit operations, causing the bridge system to recognize them as legitimate deposits and triggering the bridge wallet on the other end to send real XRP. On-chain data shows that the attacker completed the fund transfer through 94 multi-signature authorization transactions within 97 minutes. These transactions required signatures from 17 of the 28 relay node keys, allowing the attacker to bypass the bridge's validation mechanism. As of August 11, the Coreum cross-chain bridge remains suspended, and the Coreum Development Foundation has not yet released an official incident report. The XRP mainnet and user private keys remain unaffected and secure.
According to The Block, open-source Bitcoin payment processor BTCPay Server disclosed a critical security vulnerability being actively exploited last Friday and urgently requested users to upgrade to version 2.4.2. The vulnerability affects all versions prior to 2.4.2; attackers can use it to steal administrator macaroon authentication credentials of LND nodes, thereby fully controlling the connected Lightning Network wallets. Users such as Foundation and Citadel21 have confirmed that their Lightning node funds were drained, but BTCPay has not publicly disclosed the total amount stolen or the number of affected nodes. Currently, the official release version 2.4.2 has fixed this vulnerability, and on-chain hot wallets are not affected. The BTCPay Server Foundation has donated 0.21 BTC each to security researcher Craig Raw and Bitcoin Red Team to commend their responsible private disclosure of the vulnerability. Meanwhile, BTCPay supporters have promised to provide a bounty incentive of "10% of recovered funds," capped at 3 BTC.
According to Cointelegraph, BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes due to attackers exploiting a critical vulnerability in LND (Lightning Network Daemon) to steal node credentials and transfer funds. Version 2.4.2 has upgraded to LND 0.21.1 and automatically rotates macaroon credentials in standard installations. The project team reminds operators to check for abnormal payments, channel closures, and balance changes as soon as possible; if nodes are exposed via self-built reverse proxies, Tor services, or port forwarding, relevant credentials must also be manually replaced. Currently, Foundation and Citadel21 have reported node fund losses, but the specific scale of losses has not yet been disclosed.
Bitcoin payment processing service BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. Attackers exploited a severe vulnerability to obtain credentials and transfer funds. The number of affected operators and the total amount stolen have not yet been disclosed. This restriction affects external wallets such as Zeus that connect via BTCPay Server domains or Tor onion addresses in Docker deployments, but Lightning Network payments can still continue. BTCPay Server stated that remote access functionality will be restored once security is confirmed. BTCPay Server 2.4.2 will install LND 0.21.1 and automatically regenerate macaroon credentials during standard installation. Foundation and Citadel21 have respectively disclosed that funds from their Lightning Network nodes were swept. Foundation stated that hot wallets were not affected, and the specific amounts of losses have not been disclosed.