News linked to both this project and an event.
Odaily News: On-chain detective ZachXBT posted on X that he once posed as a client to infiltrate a criminal group suspected of laundering money for the North Korea-backed hacker organization Lazarus Group, and assisted in freezing funds related to the 2025 Bybit attack.ZachXBT stated that after Bybit suffered a $1.5 billion attack in February 2025, he discovered that more than 15 accounts in public Telegram and Discord groups were seeking help processing transactions related to the stolen funds. He subsequently contacted one of the Telegram users using the alias "Jimmy Green" and built trust through multiple transactions. According to his disclosure, on March 6, 2025, he transferred $3.497 million in USDC to an Ethereum address for a USDC-to-TRON-chain USDT exchange transaction with the counterparty. The source of gas funds for that address can be traced back to the Bybit attack funds and was publicly flagged as a Bybit attack blacklisted address.ZachXBT said that in subsequent communications, the counterparty revealed that their team had been involved in processing the stolen Bybit funds and disclosed in advance that the funds would be moved across chains including Solana. By matching transaction timing, amounts, and on-chain data, he identified a wallet cluster involving more than $12 million in Bybit attack funds, with fund paths spanning multiple networks including BTC→ETH→SOL→TRON. Approximately 442,000 USDT was frozen by Tether, and the group also attempted to launder money through Uniswap liquidity pools and low-liquidity tokens. Additionally, the counterparty disclosed having helped other clients process approximately $3 million in fraudulent proceeds, and ZachXBT traced the related funds to wallets associated with the sanctioned Huione Guarantee.ZachXBT revealed that in this investigation, he initially invested $3.497 million and bore a loss risk of approximately 5% per transaction. The intelligence ultimately obtained was provided to relevant investigative agencies and law enforcement authorities at the earliest opportunity. Since 2022, he has assisted in freezing over $75 million in funds related to North Korea-linked incidents.
victims of the Drift hack, a perpetual contract exchange on Solana, began filing claims on October 1. The recovery pool's initial funding stands at approximately $3.11 million against nearly $295.4 million in verified losses. Victims can redeem USDT through DFX tokens, with each $1 of loss converting to roughly 1.04 cents at launch, meaning a $1,000 loss corresponds to about $10.40.The total supply of DFX is fixed at 299,500,810.998 tokens, with each token corresponding to $1 of verified loss from the April incident, and no additional tokens will be minted. Holders can choose to burn DFX to redeem USDT, sell on secondary markets such as Raydium, or continue holding their claims. Completed redemptions are irreversible, and unclaimed tokens will expire after the claims window closes on January 1, 2028.Future funding for the recovery pool includes a portion of daily net protocol revenue from Velocity, the rebranded exchange rebuilt by Drift, up to $127.5 million in USDT committed by Tether, $20 million in USDT committed by strategic partners, and recovered stolen assets. On the first Friday after claims opened, approximately 216,480 DFX tokens were redeemed for about 2,250 USDT, with Velocity's first revenue transfer amounting to 31 USDT; approximately 13,025.9 ETH is spread across 4 Ethereum wallets, another approximately 2,309.4 ETH passed through Tornado Cash, and about $9.2 million in assets have been frozen at other addresses. (Bitcoin.com News)
Odaily reports: Cross-chain swap service Near Intents announced that the $3.8 million in funds stolen in a previous exploit has been fully returned, and the team has closed its investigation. Near Intents General Manager Alex Shevchenko had previously issued a 48-hour return deadline to the attacker, providing Bitcoin, BNB, Ethereum, and Solana addresses.The attacker acknowledged wrongdoing in an on-chain message, stating that all funds had been returned and urging others to report issues through the bug bounty program. The incident stemmed from a vulnerability in the interaction between its Omni deposit and withdrawal layer and the main smart contract. Near Intents had suspended services and promised full compensation to users. (Decrypt)
Odaily reports: Xie Jiaxin posted on X stating that this Bitget security incident involved multiple non-EVM chains and 10 tokens, and due to the different method of asset theft, different approaches to handling and restoring withdrawals were taken compared to last year's Bybit security incident in order to thoroughly eliminate potential risks.Additionally, Xie Jiaxin stated that he and Bitget CEO Gracy Chen will host a community livestream 30 minutes before withdrawals resume on Monday to discuss this security incident and answer community questions.Bitget announced on X that it will restore withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate normally, and users do not need to take any action in advance.
Odaily News: Bitget posted on X platform that the vulnerability involved in the September 24 security incident has been identified and fixed. The team is conducting additional verification and security checks on the withdrawal infrastructure, with Mandiant and SlowMist continuing to assist with the investigation. The temporary suspension of withdrawals is a security measure and is unrelated to the availability of user assets; user account balances have not been affected, and the Bitget Protection Fund will cover the financial impact of this platform-wide incident.Bitget plans to resume withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on the Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on the Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate, and users do not need to take any action in advance.
As reported by Astana Times, Kazakhstan's regulated cryptocurrency market recorded a trading volume of $10.58 billion in 2025, marking a significant surge from $320 million in 2023, while the number of users increased from 53,000 to 215,000. At the same time, Kazakhstan ranked within the global top 10 for submission numbers to the International Solana Hackathon, with over 8,000 individuals completing training through the Solana ecosystem and more than 2,000 earning certificates. Additionally, 57 Web3 startups in the country have already received a combined total of approximately $262,000 in funding, and plan to complete the tokenization of real estate and logistics projects valued at up to $60 million by the end of 2026, exploring the feasibility of digital assets as a new channel for economic financing.
Odaily News: Trader loshmi stated that he closed all positions on September 13, realizing $327,400 in profits from 30 days of public trading. He said he began buying when STONK had a market cap of approximately $1 million over a month ago and continued to add to his position as the price declined.Stonkfun is a Solana token launch platform that went live on August 3, allowing creators to pair new tokens with tokenized stocks. STONK is the platform's native token.loshmi disclosed that his portfolio once rose from $5,000 to over $25,000 before falling back to $4,000; during this period, he also lost over $6,000 due to a hack. He cited fatigue from intensifying competition in recent market trading as the reason for closing his positions. (Bitcoin.com News)
Solana Mobile stated that its third-party marketing email service provider Brevo experienced a security incident, resulting in unauthorized access to its Brevo account. To date, no emails have been sent through the account, and the company is currently investigating the scope of information that may have been accessed.
: The G7 cybersecurity working group stated in its latest report that quantum computing poses both a security threat and an economic threat to public and private institutions, and related organizations should immediately begin migrating to post-quantum cryptography (PQC).The working group noted that the migration process could take several years, as attackers can already collect and store encrypted data today and decrypt it once sufficiently powerful quantum computers emerge. Quantum computing could also break digital signatures, leading to identity theft and exposing companies and their supply chains.The report did not mention cryptocurrencies, but similar public-key cryptography is used for blockchain wallets and transaction authorization. Current quantum computers are not yet capable of breaking Bitcoin's cryptography, but developers are considering post-quantum solutions such as BIP-360.Ethereum researchers plan to replace multiple cryptographic components used by accounts, validators, and applications. The Solana Foundation has tested post-quantum signatures on its testnet and launched an optional hash-based vault. The G7 working group also urged governments to support related research, public-private cooperation, and national PQC strategies. (Decrypt)
According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.
Aquifer, an automated market maker within the Solana ecosystem, suffered losses of approximately $2.5 million after its wallet addresses were compromised. The incident appears to stem from leaked wallet credentials rather than a smart contract vulnerability. The attackers operated across multiple blockchains, including Ethereum and Solana, suggesting potential cross-chain fund transfers. As of now, the specific cause of the wallet access breach and the progress of asset recovery remain unclear.
Oracle protocol Switchboard issued a statement disclosing a report of a potential overnight attack. The Switchboard team has partnered with relevant projects and security agencies to take measures, suspending its network services on the Aptos, Sui, IOTA, and Movement chains. Currently, there are no similar reports indicating a comparable intrusion attack on the Solana chain. However, for security reasons, official channels recommend that users migrate to alternative oracle solutions as soon as possible, at least temporarily, during the investigation period. The team continues to investigate the incident and will release further details subsequently.
A new bank in the Solana ecosystem, Avici, suffered a security breach, resulting in nearly $1 million being stolen from its crypto debit card vault. Following the news, the AVICI governance token experienced severe volatility, plummeting more than 40% in a single day.
Odaily News, Avici announced that its card partner Rain discovered today a vulnerability in an old Solana card contract used by Avici and a few other projects. The relevant contract has now been upgraded across all projects, and no further unauthorized activity has been detected. This incident only affected the standalone Solana contract used to hold post-deposit card balances; users' Avici wallets and card balances are isolated from each other, and funds in Solana and EVM self-custody wallets are safe and unaffected. Upon review, a total of 1,685 users were affected, with combined card balances of approximately $500,900. Avici has committed to fully refunding card balances to all affected users and has filed a report with the FBI's Internet Crime Complaint Center (IC3). Previously reported, Avici, a crypto banking project, saw its native token AVICI allegedly suffer a hacker attack, with losses of approximately $1.02 million. The attacker transferred 10,000 SOL stolen from the project to another wallet, converted it into approximately $1.02 million USDC, and then swapped the funds into approximately 418 ETH via cross-chain operations.
Avici stated that its card-issuing partner, Rain, discovered a vulnerability in a specific version of the Solana card contract used by Avici and a few other projects. The relevant contracts have since been upgraded, and no further unauthorized activity has been detected to date. Avici clarified that user wallets and card balances are independent, meaning funds in Solana and EVM wallets remain unaffected; this incident only impacted the isolated Solana contract designated for storing card balances. Current reconciliations indicate that 1,685 users were affected, involving card balances totaling $500,859.22. All affected users will receive full refunds.
Odaily News, according to Onchain Lens monitoring, AVICI has been attacked, with losses of approximately $1.02 million. An address transferred 10,000 SOL to another wallet, exchanged it for approximately $1.02 million USDC, and then bridged the funds across chains to exchange for about 418 ETH.
According to BeInCrypto, Kylie Jenner’s X account appears to have been compromised, with an attacker posting the ticker and Pump.fun page link for the Solana-based memecoin kylie before the post was subsequently deleted. The token’s market cap briefly spiked to approximately $1.19 million before retreating by around 68%; at press time, it stood at roughly $378,500.
According to reporter Kate Irwin (@kateirwin), GalaChain experienced an anomalous on-chain capital outflow this Tuesday. Approximately 1.99 billion GALA tokens (worth roughly $2.9 million), along with other tokens, were transferred from five major addresses to a newly created wallet, subsequently bridged out and swapped for ETH within approximately one hour. Of these, approximately 1.639 billion GALA (representing roughly 82%) originated from a wallet linked to Gala Games CEO and co-founder Eric Schiermeyer, which simultaneously transferred out other tokens valued at over $500,000. Within hours of the incident, the Gala development team urgently merged a fix commit on GitHub, classifying the event as resulting from a GalaChain EIP-712 unsigned field injection vulnerability. The Gala Ethereum cross-chain bridge has since been halted, with the Solana bridge concurrently deactivated. While officially cited as routine maintenance, users have been unable to access the cross-chain bridge services normally for several consecutive days.
According to CryptoSlate, researchers from USENIX Security publicly disclosed a clock attack vulnerability against Solana’s Proof of History (PoH) mechanism on August 12. The vulnerability had been privately reported to the Solana development team as early as December 2025. Research indicates that a malicious scheduler leader could manipulate the PoH logical clock through "re-anchoring," slowing the progression of logical time. This would yield a longer transaction selection window within physical time, allowing the attacker to isolate honest leaders' blocks via the TowerBFT fork-choice mechanism, with the required stake for the attack falling below 33%. The Alpenglow security contest hosted by Anza, which offered a 50,000 SOL prize pool, concluded on August 19. However, the vulnerability was excluded from the evaluation scope because the contest rules explicitly excluded "behaviors that can only be triggered when Alpenglow is inactive." The Solana development team confirmed awareness of the issue, stating that the probability of the worst-case scenario occurring under current conditions is low. They expect the Alpenglow upgrade to fundamentally eliminate the attack's prerequisites. The Alpenglow code is already integrated into the Agave 4.2 client but remains inactive on the mainnet, with full deployment expected alongside Agave 4.3. Until then, the transitional risks associated with this vulnerability have yet to receive public implementation-level analysis or official responses.
Odaily News: According to Onchain Lens monitoring, addresses associated with the Solana OG attacker (0xd229...9D15, 0x501...f051) have transferred 2,290 ETH, worth $4.39 million, to Tornado Cash. This operation occurred nearly a month after the $14.2 million attack incident; the same cluster of addresses also used Tornado Cash two weeks ago.