News linked to both this project and an event.
Odaily News — According to monitoring by Drift Foundation, DFX claims and redemption are now live. Users with verified losses from the April 1 incident can claim 1 DFX per 1 USDT lost. Each DFX corresponds to a claim on the Recovery Pool, which currently holds approximately 3.11 million USDT. The funding sources include a portion of Velocity's daily protocol net revenue, up to 127.5 million USDT in matching funds from Tether, up to 20 million USDT from strategic partners, and assets recovered subsequently.DFX can be redeemed for USDT at a redemption amount calculated as "Recovery Pool balance ÷ DFX outstanding supply." Redeemed DFX will be burned, and transactions are irreversible. The claims window will close on January 1, 2028, at 00:00 UTC, at which point unclaimed DFX will be burned.Yesterday, Drift Foundation released an update on fund recovery efforts related to the April 1 security incident, in which approximately $295 million in user assets were stolen. The Foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct investigations and trace funds, with Mandiant identifying the attacker as North Korean threat group UNC6862.
Odaily News — According to monitoring by the Drift Foundation, the Drift Foundation has released an update on fund recovery progress related to the April 1 security incident: approximately $295 million in user assets were stolen. The foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct the investigation and trace the funds, with Mandiant identifying the attacker as the North Korean threat group UNC6862.The stolen funds were subsequently bridged to Ethereum, with approximately 130,300 ETH distributed across 4 wallets. Three of these wallets have seen no transfers to date, collectively holding 107,200 ETH; the other wallet transferred approximately 23,100 ETH to Tornado Cash on July 23.Currently, approximately $9.2 million in stolen funds has been frozen. The relevant funds had previously been transferred through Tornado Cash in August, and unfreezing and return still require cooperation with legal procedures. The Drift Foundation will transfer all assets recovered through freezing, bounties, or law enforcement channels into the DFX recovery pool, and is evaluating the subsequent path of the DRIFT token within the broader ecosystem. In addition, the foundation has partnered with Bybit to launch a public bounty program, offering a 10% bounty on successfully recovered funds.
Odaily News: Headline: "Loss of 23.75 Million USDC: Ostium Price Data Attacked". According to Ostium's monitoring, Ostium has released an update on the security incident. Its liquidity provider treasury was attacked on July 15, resulting in a loss of 23,752,746 USDC. Preliminary investigations indicate that the attacker compromised the off-chain infrastructure that supplies price data to the protocol, submitting disguised, fraudulent price reports. By rapidly opening and closing multiple large positions, the attacker extracted artificially generated profits from the treasury. Ostium stated that trader collateral is stored in separate, isolated smart contracts and was unaffected by this incident; all trading positions remain open. The team paused trading and froze all trading contracts within 60 minutes of the first attack transaction. Currently, Ostium is cooperating with Mandiant, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies, and is coordinating with trading platforms, bridge contracts, and stablecoin issuers to advance the investigation. The engineering team is repairing and strengthening the relevant infrastructure to support a safe resumption of trading. Ostium stated it will notify at least 24 hours in advance before thawing the trading contracts. Once trading resumes, existing positions will be marked at the price at the time of reopening, unaffected by price fluctuations during the suspension.
Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.
Odaily Odaily News According to MAX monitoring, on July 16, the Cascade CLS treasury suspectedly experienced a security vulnerability, resulting in approximately $1.3 million in user fund losses. The platform has suspended all trading and withdrawals and has invited SEAL 911 and other third-party security teams to investigate and handle the incident. Cascade is a 24/7 multi-asset perpetual contract platform headquartered in New York, targeting the US market. It supports deposits via Arbitrum USDC or bank accounts and is currently still in an invitation-only private testing phase.
According to Cointelegraph, phishing ads impersonating the decentralized exchange protocol Uniswap have appeared in Google search results, enabling attackers to steal at least $400,000. On-chain analyst b-block stated that the associated counterfeit websites are draining funds from multiple wallets; the implicated addresses currently hold a combined total of 146 ETH—worth approximately $306,000 at press time. Security Alliance (SEAL) noted that such fraudulent Google ads are a common source of phishing attacks, with attackers either purchasing ad placements or compromising legitimate advertising accounts to impersonate popular crypto protocols in sponsored search results. SEAL also reported that between March 13 and March 30, these attacks resulted in total losses amounting to $1.27 million.
Kelp DAO released a community update on X, noting that the recent rsETH security incident has remained tense over the past several days. However, with support from partners and the broader community, discussions are progressing in a positive direction, and efforts to identify an appropriate resolution are being accelerated. The guiding principles have already been reflected in initial actions, and subsequent updates will continue along this path, aiming for a win-win outcome for all stakeholders. Over the past four days, the Kelp team has engaged in in-depth communication with partners and other relevant parties. Specific progress includes: the Arbitrum Security Council has taken measures to freeze the stolen funds, and the SEAL 911 emergency response team has swiftly stepped in to conduct preliminary investigations, providing a clear and objective analytical perspective on the incident. While some developments have not yet been fully disclosed, related work continues to advance steadily. Kelp DAO stated that its current priority is safeguarding user assets and strengthening the protocol itself. This incident is also viewed as a critical test—not only for the project but for the broader DeFi ecosystem—and key follow-up developments will continue to be shared via official channels.
Odaily News KelpDAO stated in a post on X platform that it will continue to explore all feasible avenues to support rsETH holders and mitigate the impact of the related security incident on the DeFi ecosystem.It mentioned that over the past two days, the team has collaborated with the Arbitrum Security Council and multiple ecosystem participants, providing context on the incident and assisting with the assessment efforts, while also expressing gratitude for the coordination and support from teams like SEAL 911. Previously, the Arbitrum Security Council had frozen approximately 30,700 ETH, involving assets related to the KelpDAO attacker.
LayerZero tweeted that it is aware of the rsETH vulnerability incident and has been actively collaborating with the KelpDAO team on response and remediation efforts since the incident occurred, while continuing to monitor the situation. LayerZero stated that, aside from the rsETH-related incident, all other applications remain secure. Regarding the root cause of the incident, LayerZero is jointly investigating with SEAL_Org and other parties, and pledged to jointly publish a comprehensive post-mortem report with KelpDAO once all information has been gathered.
Zerion disclosed that some of its corporate hot wallets were recently targeted by an AI-driven social engineering attack linked to North Korean hackers, resulting in losses of approximately $100,000. Zerion stated that user funds, applications, and infrastructure remain unaffected and proactively disabled its web application to mitigate risk. This incident marks the second such attack this month, following the $280 million breach of Drift Protocol, underscoring how North Korean hackers are leveraging AI to refine social engineering tactics—primarily targeting employees and developers at crypto firms. The Security Alliance (SEAL) tracked the hacker group UNC1069, which conducts low-pressure, multi-week social engineering campaigns across platforms including Telegram, LinkedIn, and Slack, using AI tools to edit images and videos to enhance attack efficiency.