Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Rubio: US and Iran to continue technical consultations at the end of this month
Multiple foreign media outlets reported on the 24th that US Secretary of State Rubio said technical teams from the United States and Iran will hold further talks in Switzerland by the end of June. (Xinhua News Agency)
6 hours ago
Over the past 24 hours, total crypto market liquidations hit $606 million, with more than 130,000 traders liquidated.
According to Coinglass data, the global cryptocurrency market recorded $606 million in liquidations over the past 24 hours, including $542 million in long-position liquidations and $68.22 million in short-position liquidations. A total of 135,785 traders worldwide were liquidated in the same period, with the largest single liquidation order occurring on Binance’s BTCUSDT trading pair, valued at $12.0111 million.
6 hours ago
Bitcoin falls below $60,000
According to HTX market data, Bitcoin has fallen below $60,000, with a 4.3% drop in the past 24 hours.
6 hours ago
US Treasury Secretary: AI boom may boost productivity and help curb inflation.
US Treasury Secretary Bessent told CNBC in an interview that he hopes the Federal Reserve will remain "open-minded" about the inflation pattern after the reversal of Iran-related energy price hikes. Bessent noted that the U.S. could enter an economic environment marked by high GDP growth without a corresponding rise in traditional inflation. He cited that in the 1990s, Alan Greenspan foresaw that office modernization and the internet could drive non-inflationary growth, and allowed the economy to keep expanding. Bessent believes the U.S. has a strong chance of seeing a similar scenario again. When asked whether the Fed still needs to worry about potential inflation and whether interest rate cuts are possible this year or next, Bessent declined to comment. However, he argued that it is necessary to stay open-minded about the price or inflation impacts from the Iran conflict, and monitor inflation performance after those effects subside. Bessent also said an open mind is needed, as the AI boom could boost productivity and deliver disinflationary effects, helping inflation return to the Fed’s target level. He added that he believes Kevin Warsh will choose the optimal path that meets both the Fed’s inflation and growth mandates. Bessent also noted that Warsh previously took a hawkish stance on inflation.
6 hours ago
US stocks' intraday storage sector sees broad declines, with Western Digital and Seagate Technology both falling over 4%.
According to Bitget data, during U.S. stock trading hours, the storage sector saw broad declines: Western Digital (WDC) fell 4.47%, Seagate Technology (STX) dropped 4.17%, SanDisk (SNDK) declined 2.31%, and Micron Technology (MU) edged down 0.96%. Most optical communication concept stocks rose, with Corning (GLW) leading the gains at 9.75%, followed by Ciena (CIEN) up 3.24%, Coherent (COHR) rising 2.93%, Lumentum (LITE) gaining 2.61%, and Nokia (NOK) advancing 1.82%. Additionally, Marvell Technology (MRVL) fell 2.59% and Applied Optoelectronics (AAOI) declined 1.90%.
6 hours ago
During intraday trading in U.S. stocks, crypto-related concept stocks fell broadly, with MSTR dropping more than 7%.
According to Bitget market data, the three major U.S. stock indexes rose broadly: the Dow Jones Industrial Average gained 0.94%, the S&P 500 increased 0.60%, and the Nasdaq rose 0.63%. Crypto-related stocks fell across the board, with declines as follows: Strategy (MSTR) down 7.33%; Circle (CRCL) down 4.35%; Bitmine (BMNR) down 3.97%; Coinbase (COIN) down 3.73%; Robinhood (HOOD) down 3.70%; Gemini (GEMI) down 3.27%; Bullish (BLSH) down 3.25%; Sharplink (SBET) down 3.19%.
Rubio: US and Iran to continue technical consultations at the end of this month
Multiple foreign media outlets reported on the 24th that US Secretary of State Rubio said technical teams from the United States and Iran will hold further talks in Switzerland by the end of June. (Xinhua News Agency)
6 hours ago
Over the past 24 hours, total crypto market liquidations hit $606 million, with more than 130,000 traders liquidated.
According to Coinglass data, the global cryptocurrency market recorded $606 million in liquidations over the past 24 hours, including $542 million in long-position liquidations and $68.22 million in short-position liquidations. A total of 135,785 traders worldwide were liquidated in the same period, with the largest single liquidation order occurring on Binance’s BTCUSDT trading pair, valued at $12.0111 million.
6 hours ago
Bitcoin falls below $60,000
According to HTX market data, Bitcoin has fallen below $60,000, with a 4.3% drop in the past 24 hours.
6 hours ago
US Treasury Secretary: AI boom may boost productivity and help curb inflation.
US Treasury Secretary Bessent told CNBC in an interview that he hopes the Federal Reserve will remain "open-minded" about the inflation pattern after the reversal of Iran-related energy price hikes. Bessent noted that the U.S. could enter an economic environment marked by high GDP growth without a corresponding rise in traditional inflation. He cited that in the 1990s, Alan Greenspan foresaw that office modernization and the internet could drive non-inflationary growth, and allowed the economy to keep expanding. Bessent believes the U.S. has a strong chance of seeing a similar scenario again. When asked whether the Fed still needs to worry about potential inflation and whether interest rate cuts are possible this year or next, Bessent declined to comment. However, he argued that it is necessary to stay open-minded about the price or inflation impacts from the Iran conflict, and monitor inflation performance after those effects subside. Bessent also said an open mind is needed, as the AI boom could boost productivity and deliver disinflationary effects, helping inflation return to the Fed’s target level. He added that he believes Kevin Warsh will choose the optimal path that meets both the Fed’s inflation and growth mandates. Bessent also noted that Warsh previously took a hawkish stance on inflation.
6 hours ago
US stocks' intraday storage sector sees broad declines, with Western Digital and Seagate Technology both falling over 4%.
According to Bitget data, during U.S. stock trading hours, the storage sector saw broad declines: Western Digital (WDC) fell 4.47%, Seagate Technology (STX) dropped 4.17%, SanDisk (SNDK) declined 2.31%, and Micron Technology (MU) edged down 0.96%. Most optical communication concept stocks rose, with Corning (GLW) leading the gains at 9.75%, followed by Ciena (CIEN) up 3.24%, Coherent (COHR) rising 2.93%, Lumentum (LITE) gaining 2.61%, and Nokia (NOK) advancing 1.82%. Additionally, Marvell Technology (MRVL) fell 2.59% and Applied Optoelectronics (AAOI) declined 1.90%.
6 hours ago
During intraday trading in U.S. stocks, crypto-related concept stocks fell broadly, with MSTR dropping more than 7%.
According to Bitget market data, the three major U.S. stock indexes rose broadly: the Dow Jones Industrial Average gained 0.94%, the S&P 500 increased 0.60%, and the Nasdaq rose 0.63%. Crypto-related stocks fell across the board, with declines as follows: Strategy (MSTR) down 7.33%; Circle (CRCL) down 4.35%; Bitmine (BMNR) down 3.97%; Coinbase (COIN) down 3.73%; Robinhood (HOOD) down 3.70%; Gemini (GEMI) down 3.27%; Bullish (BLSH) down 3.25%; Sharplink (SBET) down 3.19%.
Cover image via U.Today Disclaimer: The opinions expressed by our writers are their own and do not represent the views of U.Today. The financial and market information provided on U.Today is intended for informational purposes only. U.Today is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.
Fresh Ripple USD stablecoins (RLUSD) amounting to 150,000,000 RLUSD, which were recently minted at the Treasury, have been traced to Gemini Exchange. According to XRPL validator Vet, the minting came just after the exchange redeemed 128 million RLUSD on XRP Ledger.
Liquidity testing or demand surge behind RLUSD activity?Notably, the fresh minting by the Ripple Treasury was done in two batches of 92.3 million RLUSD and 58.2 million RLUSD. The successful minting and transfer to Gemini confirms that the exchange maintains 1:1 USD reserves in a Ripple-controlled account for minting.
Vet could not explain the reason Gemini exchange initially redeemed the 12 million RLUSD before the recent 150 million RLUSD. It is possible that the exchange was engaging in liquidity testing to assess the mint and burn infrastructure and how quickly Ripple could respond to its requests.
Now Gemini minted 150,000,000 $RLUSD on the XRP Ledger with Ripple.
This means Gemini has 1:1 the USD liquidity in a Ripple controlled bank account, to mint this amount.
I can't tell exactly the motivation or goal behind this sequence of events.
But Ripples mint/redeem engine… https://t.co/q2gF9LpHDK pic.twitter.com/WYVYNHBs84
— Vet (@Vet_X0) April 1, 2026 Additionally, Gemini might have experienced a demand surge shortly after burning the initial 128 million RLUSD previously.
In any case, Vet noted that the transaction confirms that "the Ripple mint/redeem engine for RLUSD works great." The XRPL validator acknowledged that funds are swiftly sent to distribution accounts to fund customers.
The development suggests that institutions are actively interacting with RLUSD infrastructure because of its efficiency. For their part, liquidity providers like Gemini are testing the blockchain infrastructure, while XRPL is being used for stablecoin settlement.
Overall, it signals bullish infrastructure growth for the Ripple, which has sparked mixed reactions among community members. While some consider this a confirmation of "Ripple's stablecoin infrastructure firing on all cylinders," others are not impressed.
A user, Evelyn Anderson, observed that minting 150 million RLUSD does not prove strength; rather, it is evidence of capacity. She argues that without real demand, the minted RLUSD is just numbers on the blockchain.
RLUSD growth Strategy targets $2 billion market cap You Might Also Like
Although the reason for Gemini’s initial burn of 128 million RLUSD remains unknown, it is consistent with Ripple’s overall strategy.
Over the last 16 months since the launch of RLUSD, Ripple’s USD stablecoin desk has been maintaining a strict supply control and balance. It has regularly conducted burn and mint exercises, only to repeat the entire process again.
This strategy supported its break into the top 100 crypto assets less than 10 months after it hit the market. It also ensured that RLUSD maintained an average of about $150 million in daily volume at the time.
The growth trajectory of RLUSD continues to impress market observers as it has set its sights set on hitting $2 billion in market cap soon.
Rubio: US and Iran to continue technical consultations at the end of this month
Multiple foreign media outlets reported on the 24th that US Secretary of State Rubio said technical teams from the United States and Iran will hold further talks in Switzerland by the end of June. (Xinhua News Agency)
6 hours ago
Over the past 24 hours, total crypto market liquidations hit $606 million, with more than 130,000 traders liquidated.
According to Coinglass data, the global cryptocurrency market recorded $606 million in liquidations over the past 24 hours, including $542 million in long-position liquidations and $68.22 million in short-position liquidations. A total of 135,785 traders worldwide were liquidated in the same period, with the largest single liquidation order occurring on Binance’s BTCUSDT trading pair, valued at $12.0111 million.
6 hours ago
Bitcoin falls below $60,000
According to HTX market data, Bitcoin has fallen below $60,000, with a 4.3% drop in the past 24 hours.
6 hours ago
US Treasury Secretary: AI boom may boost productivity and help curb inflation.
US Treasury Secretary Bessent told CNBC in an interview that he hopes the Federal Reserve will remain "open-minded" about the inflation pattern after the reversal of Iran-related energy price hikes. Bessent noted that the U.S. could enter an economic environment marked by high GDP growth without a corresponding rise in traditional inflation. He cited that in the 1990s, Alan Greenspan foresaw that office modernization and the internet could drive non-inflationary growth, and allowed the economy to keep expanding. Bessent believes the U.S. has a strong chance of seeing a similar scenario again. When asked whether the Fed still needs to worry about potential inflation and whether interest rate cuts are possible this year or next, Bessent declined to comment. However, he argued that it is necessary to stay open-minded about the price or inflation impacts from the Iran conflict, and monitor inflation performance after those effects subside. Bessent also said an open mind is needed, as the AI boom could boost productivity and deliver disinflationary effects, helping inflation return to the Fed’s target level. He added that he believes Kevin Warsh will choose the optimal path that meets both the Fed’s inflation and growth mandates. Bessent also noted that Warsh previously took a hawkish stance on inflation.
6 hours ago
US stocks' intraday storage sector sees broad declines, with Western Digital and Seagate Technology both falling over 4%.
According to Bitget data, during U.S. stock trading hours, the storage sector saw broad declines: Western Digital (WDC) fell 4.47%, Seagate Technology (STX) dropped 4.17%, SanDisk (SNDK) declined 2.31%, and Micron Technology (MU) edged down 0.96%. Most optical communication concept stocks rose, with Corning (GLW) leading the gains at 9.75%, followed by Ciena (CIEN) up 3.24%, Coherent (COHR) rising 2.93%, Lumentum (LITE) gaining 2.61%, and Nokia (NOK) advancing 1.82%. Additionally, Marvell Technology (MRVL) fell 2.59% and Applied Optoelectronics (AAOI) declined 1.90%.
6 hours ago
During intraday trading in U.S. stocks, crypto-related concept stocks fell broadly, with MSTR dropping more than 7%.
According to Bitget market data, the three major U.S. stock indexes rose broadly: the Dow Jones Industrial Average gained 0.94%, the S&P 500 increased 0.60%, and the Nasdaq rose 0.63%. Crypto-related stocks fell across the board, with declines as follows: Strategy (MSTR) down 7.33%; Circle (CRCL) down 4.35%; Bitmine (BMNR) down 3.97%; Coinbase (COIN) down 3.73%; Robinhood (HOOD) down 3.70%; Gemini (GEMI) down 3.27%; Bullish (BLSH) down 3.25%; Sharplink (SBET) down 3.19%.
Polkadot (DOT), an open-source sharded multichain protocol, was exploited after an attacker minted 1 billion tokens and dumped them for 108.2 ETH ($237K), crashing the bridged DOT price from $1.22 to near $1.
Multiple exchanges, including Upbit, suspended DOT deposits and withdrawals in response.
How The Polkadot (DOT) Exploit HappenedOn April 13, 2026, the attacker sent a fake proof to a vulnerable contract on Ethereum. This proof looked real to the system, so it passed the security checks and triggered an important function in the bridge.
That single action caused two major problems. First, it gave the attacker full control of the bridged DOT token contract by changing the admin to their own wallet. This meant they now had the power to manage and create tokens.
After gaining control, the attacker minted 1 billion DOT tokens out of thin air and sent them to a new wallet. This was around 2,805 times more than the actual supply at that time.
They then dumped all the tokens into Uniswap V4 in a single move, draining about 108.2 ETH (around $237,000) from the liquidity pool.
The attacker routed the funds through Odos Router V3 and sent them back to their wallet, while the fake supply crashed the token value.
Why This Happened: HyperBridge Security FailureThe exploit was possible due to a flaw in how the bridge verified cross-chain messages. This happened because the system trusted a fake proof.
Hyperbridge developers built the system to remove human control and rely only on cryptographic proofs for cross-chain verification. But the attacker managed to create forged proof that the system mistakenly accepted as valid.
Once that fake proof passed, the contract automatically executed it, giving the attacker control and allowing them to change permissions and mint tokens.
The impact was felt almost instantly; the DOT token price crashed from around $1.22 to nearly $1 in the same transaction block.
Some platforms have already reacted quickly. Upbit temporarily suspended DOT deposits and withdrawals as a precaution.
Developers are now working to investigate the exploit and fix the vulnerability. Exchanges may continue adding more restrictions until teams fully understand the issue and assess ongoing risks.
Hyperbridge and Polytope Labs have not released any official detailed statement on mitigation steps, recovery plans, or system pauses yet.
Story Ends Here
Trust with CoinPedia:CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.
Investment Disclaimer:All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.
Sponsored and Advertisements:Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.
As hacking incidents continue to increase in the cryptocurrency market, the latest news comes from Ethereum (ETH).
According to blockchain security firm PeckShield, a cyberattack occurred on the Ethereum (ETH) network in which a large amount of Polkadot (DOT) was minted without authorization.
Hackers reportedly minted approximately 1 billion Polkadot (DOT) tokens without authorization on the Ethereum network and sold them on the market.
Analyses suggest that a security vulnerability on the Polkadot Bridge may be the cause.
Analysts note that the losses experienced in DOT are relatively small due to the limited and low liquidity of the token.
According to the data, DOT continues to trade at $1.18, down approximately 3.6%, while South Korean exchanges Upbit and Bithumb have suspended DOT deposits and withdrawals.
Polkadot has not yet made an official statement.
*This is not investment advice.
Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data!
13 April 2026 | 10:37 The Hyperbridge cross-chain gateway connecting Polkadot to Ethereum was exploited on April 13.
Key Takeaways
Hyperbridge exploit minted 1 billion DOT on Ethereum. Attacker minted tokens worth $1.1B at prior market rates, realized only 108.2 ETH. Bridged DOT collapsed from $1.22 to near zero within one hour of the dump. Native DOT on Polkadot relay chain unaffected – down ~4% in sympathy. What Happened The Hyperbridge cross-chain gateway, a bridge connecting Polkadot to Ethereum, was exploited on April 13, 2026. The attacker identified a vulnerability that allowed them to seize admin privileges over the DOT token contract on Ethereum, transfer control to a malicious address, and forge gateway messages to authorize minting. One billion DOT were created and immediately dumped into available liquidity pools.
The timing is the most damaging contextual detail. In March 2026, six weeks before this exploit, the Polkadot community implemented a hard supply cap of 2.1 billion DOT through governance. The decision was designed to give DOT, which recently got its first spot ETF on Nasdaq, monetary credibility through enforced scarcity.
BRIDGED POLKADOT JUST GOT EXPLOITED
An attacker exploited a third-party bridge to mint 1 Billion DOT tokens on Ethereum. They sold them straight into the liquidity pool, removing over $240K in ETH across multiple transactions.
Track the attacker on Arkham using the link below: pic.twitter.com/2glmVWsDjS
— Arkham (@arkham) April 13, 2026
According to Yahoo Finance, the exploit minted tokens equal to nearly 48% of that entire capped supply in a single transaction. The governance mechanism that was supposed to make DOT scarcer was bypassed entirely through a cross-chain contract that operated on different infrastructure.
The native Polkadot relay chain was not affected. The supply cap on the native chain remains intact. The exploit targeted only the bridged representation of DOT on Ethereum, but for holders of that bridged asset, the distinction is academic.
Current Status Security firms PeckShield and CertiK have flagged the exploit and are tracking the movement of the 108.2 ETH the attacker realized. Upbit suspended all DOT deposits and withdrawals immediately, the first exchange action, and a signal that the industry is treating the bridged asset as compromised regardless of what the Polkadot team says officially.
Efforts are underway to isolate the compromised Hyperbridge contract to prevent further unauthorized minting. Users are warned not to interact with bridged or wrapped DOT on Ethereum until a new secure contract is deployed. As of reporting, neither the Web3 Foundation nor the Hyperbridge team has issued a formal statement.
The Liquidity Number That Tells the Whole Story The exploit mechanics explain how it happened. The $237,000 figure explains what it actually meant for the market.
The attacker minted tokens with an apparent market value of $1.1 billion at prior rates and walked away with 108.2 ETH, approximately $237,000. The gap between those two numbers is not a quirk of the execution. It is the precise measure of the actual liquidity depth of the bridged DOT market on Ethereum. Available liquidity in the pools the attacker dumped into was approximately $237,000. The asset that was supposedly worth $1.1 billion could absorb that much selling before the price collapsed to near zero.
The bridged DOT on Ethereum did not have $1.1 billion worth of real market depth. It had $237,000. Everything above that figure was price discovery built on the assumption that the bridged asset was redeemable for native DOT. Once that assumption was broken, the apparent value evaporated instantly.
If the apparent value was never real liquidity, reimbursing holders means replacing something that was never fully backed, and the treasury cannot do it even if the community wanted to.
The Reimbursement Problem The community that just voted for monetary scarcity is now being asked to consider inflating supply by 48% to fix a bridge it did not build. That tension has no clean resolution, and it is the first thing any reimbursement proposal will have to confront.
The Polkadot Treasury currently holds approximately 44 million DOT. The exploit involved 1 billion DOT, more than 22 times the treasury balance. Full reimbursement through a standard treasury spend is mathematically impossible. Any meaningful compensation would require either minting new tokens, directly undermining the supply cap governance decision made six weeks ago, or some unprecedented protocol-level intervention the community has not previously used.
If a proposal is eventually submitted, it must pass through Polkadot’s on-chain governance system, OpenGov, under the Big Spender or Wish for Change tracks. These require a lead-in period of several days before voting begins, conviction voting where holders lock tokens to increase their influence, and an enactment delay before any funds move. The governance process is designed for deliberation. It is not designed for emergency response at this scale.
The most likely outcome is not full reimbursement. It is partial compensation directed at the most affected liquidity providers, funded through a combination of whatever treasury allocation the community will approve without triggering the inflation question, and a separate accountability process aimed at the Hyperbridge team, which built and maintained the contract that was exploited.
The Polkadot governance system did not create this vulnerability. The bridge did. That distinction will matter in how the community frames any response.
The supply cap survived the exploit. The bridge did not. And the treasury cannot cover the difference.
The information provided in this article is for educational purposes only and does not constitute financial, investment, or trading advice. Coindoo.com does not endorse or recommend any specific investment strategy or cryptocurrency. Always conduct your own research and consult with a licensed financial advisor before making any investment decisions.
Author
Kosta has reported on cryptocurrency markets and blockchain infrastructure since 2020, bringing over six years of hands-on experience in the crypto industry built through daily tracking of markets, trends, and emerging blockchain developments. Specializing in Bitcoin on-chain analysis, institutional ETF flows, and digital asset price action, his work at Coindoo has been cited by other news agencies and consistently covers market developments with a focus on data-driven reporting across Bitcoin, Ethereum, Solana, and XRP. Over the years, Kosta has contributed to multiple crypto media outlets in different regions, authoring over 6,000 articles across the sector. His reporting spans cryptocurrency markets and the broader fintech industry, tracking not only price action but also the technological and regulatory forces shaping the ecosystem. To support his analysis, Kosta actively leverages on-chain data and metrics from leading platforms such as Santiment, Glassnode, and CryptoQuant, enabling deeper, evidence-based market insights. He believes in the power of transparency and the data that underpins the blockchain ecosystem. His academic background in Marketing Management from Denmark further complements his analytical approach, adding a strong understanding of communication strategy and content positioning to his work.
Rubio: US and Iran to continue technical consultations at the end of this month
Multiple foreign media outlets reported on the 24th that US Secretary of State Rubio said technical teams from the United States and Iran will hold further talks in Switzerland by the end of June. (Xinhua News Agency)
6 hours ago
Over the past 24 hours, total crypto market liquidations hit $606 million, with more than 130,000 traders liquidated.
According to Coinglass data, the global cryptocurrency market recorded $606 million in liquidations over the past 24 hours, including $542 million in long-position liquidations and $68.22 million in short-position liquidations. A total of 135,785 traders worldwide were liquidated in the same period, with the largest single liquidation order occurring on Binance’s BTCUSDT trading pair, valued at $12.0111 million.
6 hours ago
Bitcoin falls below $60,000
According to HTX market data, Bitcoin has fallen below $60,000, with a 4.3% drop in the past 24 hours.
6 hours ago
US Treasury Secretary: AI boom may boost productivity and help curb inflation.
US Treasury Secretary Bessent told CNBC in an interview that he hopes the Federal Reserve will remain "open-minded" about the inflation pattern after the reversal of Iran-related energy price hikes. Bessent noted that the U.S. could enter an economic environment marked by high GDP growth without a corresponding rise in traditional inflation. He cited that in the 1990s, Alan Greenspan foresaw that office modernization and the internet could drive non-inflationary growth, and allowed the economy to keep expanding. Bessent believes the U.S. has a strong chance of seeing a similar scenario again. When asked whether the Fed still needs to worry about potential inflation and whether interest rate cuts are possible this year or next, Bessent declined to comment. However, he argued that it is necessary to stay open-minded about the price or inflation impacts from the Iran conflict, and monitor inflation performance after those effects subside. Bessent also said an open mind is needed, as the AI boom could boost productivity and deliver disinflationary effects, helping inflation return to the Fed’s target level. He added that he believes Kevin Warsh will choose the optimal path that meets both the Fed’s inflation and growth mandates. Bessent also noted that Warsh previously took a hawkish stance on inflation.
6 hours ago
US stocks' intraday storage sector sees broad declines, with Western Digital and Seagate Technology both falling over 4%.
According to Bitget data, during U.S. stock trading hours, the storage sector saw broad declines: Western Digital (WDC) fell 4.47%, Seagate Technology (STX) dropped 4.17%, SanDisk (SNDK) declined 2.31%, and Micron Technology (MU) edged down 0.96%. Most optical communication concept stocks rose, with Corning (GLW) leading the gains at 9.75%, followed by Ciena (CIEN) up 3.24%, Coherent (COHR) rising 2.93%, Lumentum (LITE) gaining 2.61%, and Nokia (NOK) advancing 1.82%. Additionally, Marvell Technology (MRVL) fell 2.59% and Applied Optoelectronics (AAOI) declined 1.90%.
6 hours ago
During intraday trading in U.S. stocks, crypto-related concept stocks fell broadly, with MSTR dropping more than 7%.
According to Bitget market data, the three major U.S. stock indexes rose broadly: the Dow Jones Industrial Average gained 0.94%, the S&P 500 increased 0.60%, and the Nasdaq rose 0.63%. Crypto-related stocks fell across the board, with declines as follows: Strategy (MSTR) down 7.33%; Circle (CRCL) down 4.35%; Bitmine (BMNR) down 3.97%; Coinbase (COIN) down 3.73%; Robinhood (HOOD) down 3.70%; Gemini (GEMI) down 3.27%; Bullish (BLSH) down 3.25%; Sharplink (SBET) down 3.19%.
Cover image via U.Today Disclaimer: The opinions expressed by our writers are their own and do not represent the views of U.Today. The financial and market information provided on U.Today is intended for informational purposes only. U.Today is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.
The cryptocurrency market is experiencing one of the most dynamic moments of the year as Bitcoin has surpassed the psychological $78,000 mark for the first time in two months. This breakout is accompanied by a strong inflow of liquidity; on the Solana blockchain alone, 500 million USDC were issued within a short period of time, according to Whale Alert.
The main catalyst for growth was a sharp positive shift in geopolitics. The market reacted to news of a possible deescalation in the Middle East. Statements from the parties about opening the Strait of Hormuz for commercial shipping triggered a drop in oil prices below $80 for WTI and a sharp rise in risk assets — first of all BTC.
BTC/USD price chart with Whale Alert post, Source: TradingViewUSDC printing press: 500 million “in the moment”Against this backdrop, the Whale Alert system recorded the creation of two batches of 250,000,000 USDC, worth a total of $500 million in Circle’s treasury. The majority of the new issuance was deployed on the Solana network, bringing the weekly stablecoin issuance volume on this chain to a record $3.25 billion in 2026.
HOT Stories
You Might Also Like
Historically, such large USDC issuances precede phases of active buying or are used by institutions to collateralize margin positions amid rising volatility.
Despite the euphoria, experts from Glassnode and JPMorgan warn of a “sell wall” and potential profit-taking. Support is now located in the $75,000-$76,000 range. The ceiling for BTC in this rally is marked at $86,796, where the 200-day moving average is currently stretching.
At 17:35 UTC on Saturday, April 18, 2026, someone minted 116,500 rsETH on Ethereum mainnet that had no backing behind it. That’s roughly 18% of KelpDAO’s entire circulating supply, worth about $292 million at the time the forged LayerZero packet cleared. Within minutes it was sitting as collateral on Aave, borrowing WETH against itself. Within an hour it had produced the largest single DeFi extraction of 2026 so far.
This piece was written in the first evening after the drain. KelpDAO and LayerZero have both promised post-mortems; final numbers on bad debt, compensation, and any supply migration will shift over the coming days. Treat the specific figures below as the best on-chain and analyst estimates available as of April 18–19, 2026.
The restaking contracts didn’t fail. The EigenLayer delegations are still intact. Mainnet rsETH is still backed by the legitimate user deposits sitting in KelpDAO’s node delegators. The core product was fine. What broke was the bridge — a LayerZero OFT adapter running on a one-of-one validator stack, which let a single forged signature instruct the adapter’s mainnet escrow to release tokens that shouldn’t have moved. Everything downstream is composability fallout.
Here is what happened, what broke, and who actually pays.
What KelpDAO Is, and Why the Bridge Mattered KelpDAO is one of the larger liquid restaking token (LRT) protocols built on EigenLayer. Users deposit ETH or a whitelisted LST, the protocol delegates to a set of EigenLayer operators, and users receive rsETH: a token representing a claim on the restaked position plus accrued yield. By April, rsETH had crossed $1 billion in TVL and was integrated as collateral across most of the major lending markets and yield venues in DeFi.
rsETH lives natively on Ethereum, where the restaking contracts sit. But its utility depends on being everywhere: Arbitrum, Base, Mantle, Unichain, Linea, and roughly a dozen other L2s and sidechains. KelpDAO uses a LayerZero OFT (Omnichain Fungible Token) adapter to move rsETH across chains. The adapter is the bridge. When rsETH leaves Ethereum, it’s locked in an escrow contract on mainnet, and a matching amount is minted on the destination chain. When a cross-chain message comes back, the escrow releases.
That escrow release is what got spoofed.
The Attack: A Single Forged lzReceive Call The entire drain happened in one transaction:
The call landed on LayerZero’s EndpointV2 contract at 0x1a44076050125825900e736c501f859c50fE728c with a forged origin packet claiming to come from source Endpoint ID (EID) 30320. The endpoint passed the payload to KelpDAO’s rsETH OFT adapter at 0x85d456B2DfF1fd8245387C0BfB64Dfb700e98Ef3. The adapter, trusting the message, released 116,500 rsETH from escrow into attacker address 0x8B1b6c9A6DB1304000412dd21Ae6A70a82d60D3b. One Transfer, one OFTReceived, one PacketDelivered. Roughly $292 million.
The forgery worked because the adapter’s security stack was configured to accept the attestation of a single verifier. LayerZero’s OApp configuration model lets the application developer choose how many “DVNs” (Decentralized Verifier Networks) must sign off on an incoming message before it’s delivered, plus any optional verifiers. For the rsETH OFT, both sender-side and receiver-side configs read the same way:
requiredDVNs: [LayerZero Labs] requiredDVNCount: 1 optionalDVNs: [] optionalDVNCount: 0 The sender-side DVN contract (0x282b3386571f7f794450d5789911a9804fa346b4) and the receiver-side DVN (0x589dedbd617e0cbcb916a9223f4d1300c294236b) both ran a one-of-one validator stack operated by LayerZero Labs. One forged signature was enough to make any cross-chain message look real. An entirely legitimate rsETH transaction had settled through the exact same DVN two days earlier, so this wasn’t a dormant testnet artifact; it was the live production setup.
On-chain analyst @senamakel was the first to post the OApp config publicly, roughly three hours after the drain. A follow-up reply from researcher @BranchM in the same thread clarified something important: the compromise wasn’t Unichain-specific. The DVN contract and its signing keys sit on Ethereum, so the attacker could have spoofed any source chain the adapter trusted. Changing the source EID from Unichain to Arbitrum would have produced the same outcome. The DVN itself was the single point of failure; the source chain was cosmetic.
LayerZero’s protocol wasn’t broken. The configuration KelpDAO (and whoever advised them) deployed was. A multi-DVN stack, typically two-of-three or three-of-five in production deployments handling significant value, would have required the attacker to compromise multiple independent verifier networks simultaneously. They only had to compromise one.
The Cashout: Unbacked Collateral Meets a Ready Lending Market The attacker didn’t try to sell 116,500 rsETH into DEX liquidity. That would have crashed the price inside the first block and capped the extraction at whatever the curves could absorb. Instead, they did the thing every post-2024 exploit playbook describes: they used the tokens as collateral.
According to on-chain accounting compiled by Chaos Labs and cross-checked against the adapter events:
On Aave V3/V4 Ethereum, the attacker supplied rsETH and borrowed 52,834 WETH. On Aave V3/V4 Arbitrum, they bridged a portion of the stolen supply and borrowed 29,782 WETH plus 821 wstETH. Smaller positions were opened on Compound V3 and Euler before those markets were frozen, adding an undisclosed additional slice of WETH/ETH borrows on top of the Aave numbers. Total extracted value sits in the $200M–$236M range depending on exact execution prices and the wstETH mark. That’s the money that actually left the attacker’s address as borrowed liquidity. A portion of the borrowed funds was then routed through Tornado Cash (ZachXBT flagged the first mixer-bound hops within twenty minutes of the drain), while the rest sits in wallets on-chain sleuths are actively tracking.
KelpDAO’s operations multisig paused the rsETH contracts on Ethereum and every L2 where the adapter was deployed within 46 minutes of the initial mint. That pause stopped any follow-up forgery and prevented the attacker from minting a second tranche. It didn’t, and couldn’t, reverse the positions already opened on third-party lenders.
The Blast Radius: Who Actually Got Hit The exploit was tightly contained at the smart-contract layer. Core EigenLayer pools, rsETH’s underlying backing, and LayerZero’s non-Kelp traffic were untouched. But rsETH had been so thoroughly composed into DeFi that the forced pause rippled outward immediately.
Aave took the brunt. rsETH was an accepted collateral asset across V3 and V4 instances on both Ethereum and Arbitrum. Within hours, Aave’s risk team froze every rsETH market and pushed a public message urging WETH suppliers to pull their liquidity while the situation was being scoped. Marc Zeller and Chaos Labs both confirmed the exploit itself didn’t touch any Aave contract. The risk is purely that the collateral backing the attacker’s ~$200M in borrows is now known to be worthless. The AAVE governance token traded off roughly 10% in the hours after the news broke, reflecting market uncertainty about how much of the deficit lands on token holders versus Umbrella stakers.
SparkLend, Fluid, and Upshift froze or paused rsETH positions on the same timeline. Compound V3 and Euler paused new rsETH borrows after the first attacker positions were opened.
Yield venues and structured products cut exposure the moment the news hit X:
Ethena paused rsETH usage in its vaults. Yearn froze any vault with rsETH allocations. Pendle paused its rsETH PT/YT markets to stop mispriced trading during the chaos. Beefy froze rsETH-denominated strategies. Lombard Finance preemptively paused unrelated LayerZero LBTC routes “out of caution,” which tells you something about the current level of trust in OFT configurations industry-wide. The knock-on damage runs deepest on the roughly 20 L2s and sidechains where rsETH was bridged. Because the minted supply on Ethereum is now partially unbacked, every wrapped derivative downstream is structurally impaired. Holders of rsETH on Arbitrum, Base, Mantle, Linea, and the other bridged chains are sitting on tokens that can no longer be confidently redeemed against a 1:1 claim on Ethereum escrow. Withdrawals are paused, liquidity has evacuated DEX pools, and any lending market on those chains that accepted wrapped rsETH as collateral is running into the same bad-debt math Aave is running into on mainnet, just at smaller scale.
Untouched: stETH, wstETH, rETH, cbETH, and every other major LST/LRT outside of KelpDAO. There is no systemic restaking contagion here. The failure is specific to one adapter, one DVN, one trust model.
The $177M Bad Debt vs a $56M Umbrella The Aave bad debt number being quoted by every serious on-chain analyst is roughly $177 million, sitting in the WETH reserves across V3 and V4 on Ethereum and Arbitrum, plus a small wstETH slice on Arbitrum. The range from different sources runs $177M–$196M depending on exactly how partial liquidations and wstETH marks are accounted for. $177M is the median figure from Chaos Labs’ real-time reporting, and the one most post-mortems will anchor to.
That deficit is what Aave’s Umbrella module was built for. The awkward part is that Umbrella currently only runs on Ethereum mainnet.
Umbrella is the on-chain risk backstop that replaced the old Safety Module in mid-2025. The old Safety Module required a governance vote to slash stakers, which meant that in practice it had never actually been slashed. It was a theoretical insurance fund. Umbrella is different by design:
Per-asset, per-network isolation. Stakers deposit into a specific asset vault on a specific network. The WETH vault on Ethereum covers WETH deficits on Aave Ethereum and nothing else. USDC and GHO stakers are untouched. Ethereum-only, for now. Umbrella launched on mainnet in mid-2025 and has not yet been deployed to Arbitrum, Base, or any other network. Bad debt recorded on a non-Ethereum Aave instance falls back to legacy cover-of-last-resort: the DAO Collector first, then AAVE token issuance via governance, then pro-rata socialization onto suppliers if those prove insufficient. Automated slashing. UmbrellaCore monitors realized bad debt in the corresponding Aave reserve. When the recorded deficit crosses a configurable threshold (the “deficit offset,” currently 100,000 units of the base asset, absorbed by the DAO Collector first), UmbrellaCore permissionlessly calls slash() on the relevant StakeToken contract. No governance vote, no delay. Pro-rata dilution. Slashing burns a proportional share of the vault’s underlying assets and sends them to the Collector, which repays the pool. Every staker’s share value drops by the same percentage. 20-day cooldown. You can’t exit instantly. Once you request withdrawal, you remain fully exposed (and fully rewarded) for 20 days. This is the structural reason bank-run dynamics can’t short-circuit the backstop. Minimum assets floor. The contract refuses to drain the vault below a minimum level, and slashing is capped at the actual recorded deficit. The Ethereum WETH Umbrella vault was carrying roughly $56M in TVL heading into the weekend. The attacker’s borrows split roughly 52,834 WETH on Ethereum versus 29,782 WETH and 821 wstETH on Arbitrum, which maps the $177M deficit to something like ~$113M on Ethereum WETH, ~$64M on Arbitrum WETH, and a few million in Arbitrum wstETH. The Ethereum slice alone is roughly twice the size of the Umbrella vault standing against it.
The slash math is therefore brutal and simple. Umbrella gets fully drained — the entire $56M vault slashed down to its minimum-assets floor — and still leaves roughly $55M of residual WETH bad debt on Ethereum uncovered. The Arbitrum deficit, roughly $67M combined across WETH and wstETH, has no Umbrella backstop at all and flows directly to DAO-level mechanisms. Net shortfall against Aave’s existing Umbrella capacity lands somewhere around $120M even after the Ethereum vault is wiped to the floor.
The DAO’s $100K deficit offset is a rounding error at that scale. The Collector balance helps, but not enough. That leaves two real levers for the residual: governance-authorized AAVE issuance (minting tokens, selling them, and pushing the proceeds into the Collector — the classic MakerDAO-style dilution playbook), or direct haircuts on WETH suppliers on the affected instances. AAVE issuance is the politically easier path and the one governance chatter is converging on, but the dilution burden shrinks meaningfully only if KelpDAO socializes a portion of the loss on its side, most likely by haircutting wrapped rsETH on bridged chains rather than touching the mainnet token.
The Hierarchy of Pain Strip away the dashboards and there’s a clean ranking of who actually absorbs the $292M.
Tier 1: Aave Umbrella WETH stakers on Ethereum. They signed up to be the first-loss backstop in exchange for extra yield on top of the aWETH supply rate. That trade-off is now live, and not partially — the Ethereum WETH deficit is roughly twice the size of the vault, so the entire $56M gets slashed down to its minimum-assets floor. Loss is immediate, pro-rata, automatic, and close to total. Umbrella stakers in other assets (USDC, GHO) are untouched because of per-asset isolation.
Tier 2: AAVE token holders. Once Umbrella is exhausted, the ~$120M combined residual (Ethereum WETH remainder plus the entire Arbitrum deficit, which has no Umbrella backstop) has to come from somewhere. Governance is already discussing AAVE issuance as the primary cover mechanism, which dilutes existing holders. The ~10% AAVE drop in the hours after the exploit is the market pricing in exactly this scenario.
Tier 3: rsETH holders on bridged chains. An 18% supply inflation at the Ethereum layer translates to structurally impaired wrapped rsETH everywhere else. The recovery plan analysts are modeling, which KelpDAO has not yet officially committed to, is a selective socialization that haircuts the bridged-chain float while leaving Ethereum mainnet rsETH as close to whole as possible. The math and the legal optics both favor pushing losses onto the smaller, more diffuse holder base rather than the mainnet holders sitting on the largest pools and the loudest megaphones. Rough modeling puts a haircut on bridged positions somewhere around the 15–20% range, with the exact number depending on whether KelpDAO chooses to top up partial compensation from treasury.
Tier 4: Leveraged rsETH loopers. The standard LRT trade through April was borrowing WETH against rsETH on Aave or Spark to loop into more rsETH, earning the spread between staking yield (~2.5% blended) and ETH borrow rates. With rsETH frozen and ETH borrow rates spiking into the 8–9% range on the utilization crunch, these positions are burning equity by the hour and can’t be unwound without manual intervention. Some will end up undercollateralized during the unwind and generate secondary bad debt on whichever lender they sit on.
Tier 5: Aave WETH suppliers on Arbitrum. This is the tier Aave’s risk team was most worried about when they pushed the “withdraw” message on Friday. Arbitrum has no Umbrella backstop, so the DAO response determines whether suppliers there get made whole via AAVE issuance or forced to share the loss pro-rata. The longer governance takes, and the smaller KelpDAO’s socialization ends up being, the higher the probability that some portion of the Arbitrum hit lands on suppliers directly. Ethereum WETH suppliers face the same risk at a smaller scale only if AAVE issuance proves politically unworkable.
Tier 6: Everyone else. KelpDAO the DAO will likely spend treasury on partial compensation. LayerZero will eat reputational damage and is under obvious pressure to tighten its default DVN recommendations in the aftermath. Competing LRT protocols (Ether.fi, Renzo, Puffer) are not directly exposed, but the whole category is going to see users reassess bridge security, with an advantage to issuers already running multi-DVN or alternative messaging layers.
The Uncomfortable Questions Why was a $1B protocol running a 1-of-1 DVN? LayerZero’s own security model gives applications full control over their verifier stack precisely so they can match it to the value they’re securing, and multi-DVN setups have been standard recommendation for any OFT handling significant value. Somebody at KelpDAO, at an advising firm, or at an integrator signed off on a single-DVN production config for a token that had grown to over $1B in TVL. That decision is now the story, not LayerZero’s protocol design.
Were the DVN keys actually compromised, or was the attestation logic bypassed some other way? Both KelpDAO and LayerZero have promised a root-cause post-mortem. The forensic question that matters for every other OFT in production is whether the LayerZero Labs DVN key material leaked, a signer was socially engineered, or a signature-forging bug existed upstream. The answer determines whether every other 1-of-1 OFT on LayerZero is currently exposed. And there are many.
How did audits miss this? They probably didn’t. The bridge adapter code is standard LayerZero OFT boilerplate; there’s nothing wrong with the contract. The fault is in the deployment configuration, which sits outside the usual scope of a Solidity audit. Config reviews are a much newer discipline, and this exploit is going to accelerate that market considerably.
What does Aave do about LRTs as collateral going forward? This is the second time in 2026 that an LRT collateral accepted on Aave has produced a nine-figure incident downstream of a non-Aave failure. Risk parameters will tighten, loan-to-value ratios on restaking collateral will come down, and the debate over whether LRTs should be isolation-mode-only on every major lending market is going to get louder.
What does this mean for LayerZero’s institutional pitch? LayerZero has been positioning itself as the messaging layer for traditional finance’s tokenization rollout. A production failure at this scale, in a configuration that was always within the application developer’s control rather than an inherent protocol flaw, is a setback, but it’s also a case study. If the post-mortem is clean, defaults tighten, and existing OFTs migrate to multi-DVN stacks quickly, the damage is contained. If it drags out, the institutional counterparty diligence LayerZero has spent two years building up takes a real hit.
The Lesson That Keeps Repeating Every nine-figure DeFi incident of the last two years has the same structural shape. The core protocol does what it’s supposed to do. Some privileged component on the edge, whether that’s an off-chain signer, a bridge validator, an operator key, or a configuration that was supposed to be temporary, carries more trust than the rest of the stack was aware of. Somebody figures out where that concentration sits, and the full weight of the composed system falls through it.
The Resolv USR exploit in March was a single-signer SERVICE_ROLE that could mint arbitrary amounts of a stablecoin. The KelpDAO exploit is a single-verifier DVN that could authorize arbitrary cross-chain releases. Different protocol, different token class, identical architectural shape: one key, no meaningful check beyond it, and a downstream composability layer that had already assumed the thing behind the key was sound.
The LRT category in particular has spent the last year adding more layers (more chains, more wrappers, more lending integrations, more yield vaults that lend against vaults that lend against wrappers) on top of a base that is fundamentally a three-way trust assumption between the staker, the restaker, and the bridge. Each additional layer compounds yield by a handful of basis points. Each additional layer also compounds the attack surface in ways that are hard to price. The rsETH supply on the 20 bridged chains wasn’t a feature. It was a liability that grew quietly until one forged packet turned it all into bad debt.
The practical takeaway for anyone actually using this stuff is narrow and boring: before you treat a bridged LRT as interchangeable with its mainnet counterpart, look at the bridge’s verifier configuration. Lenders integrating LRTs as collateral have to reckon with a simple fact: the counterparty isn’t the LRT issuer alone. It’s the LRT issuer plus whatever messaging stack sits between mainnet and wherever the wrapped token shows up. At the ecosystem level, the boring parts of security (key management, config reviews, multi-party attestation) are where the next nine-figure incident is going to come from too. Until someone finally makes the boring parts the default.
Aave will recover. Umbrella stakers on Ethereum will take the full hit they volunteered for, the DAO will vote AAVE issuance to cover the residual the vault couldn’t absorb, and the event will accelerate Umbrella’s expansion to every network that wasn’t covered this weekend. rsETH will either migrate to a multi-DVN stack or lose meaningful share to the LRT competitors that already run one. LayerZero will quietly tighten its defaults. And the next exploit will come from whichever protocol hasn’t yet asked the question: “what single key is currently trusted to authorize nine figures on our system?”
That’s the question every DeFi product owner should be writing down today.
We believe in full transparency with our readers. Some of our content includes affiliate links, and we may earn a commission through these partnerships. However, this potential compensation never influences our analysis, opinions, or reviews. Our editorial content is created independently of our marketing partnerships, and our ratings are based solely on our established evaluation criteria. Read More
Ad Disclosure
Ad Disclosure
We believe in full transparency with our readers. Some of our content includes affiliate links, and we may earn a commission through these partnerships. However, this potential compensation never influences our analysis, opinions, or reviews. Our editorial content is created independently of our marketing partnerships, and our ratings are based solely on our established evaluation criteria. Read More
Ahmed Barakat
Author
Ahmed Barakat
Part of the Team Since
Aug 2025
About Author
Ahmed Balaha is a journalist and copywriter based in Georgia with a growing focus on blockchain technology, DeFi, AI, privacy, digital assets, and fintech innovation.
Has Also Written
Fact Checked by
CryptoNews Editorial Team
Author
CryptoNews Editorial Team
Part of the Team Since
Sep 2018
About Author
The CryptoNews editorial team is composed of seasoned writers specializing in cryptocurrency and blockchain technology. Their expertise ensures comprehensive, accurate, and insightful content for...
Has Also Written
Ad Disclosure
Ad Disclosure
We believe in full transparency with our readers. Some of our content includes affiliate links, and we may earn a commission through these partnerships. However, this potential compensation never influences our analysis, opinions, or reviews. Our editorial content is created independently of our marketing partnerships, and our ratings are based solely on our established evaluation criteria. Read More
Last updated:
April 21, 2026
Tether just dropped a 1 billion USDT on Ethereum just as the memecoin scene in the chain is heating up. Arkham Intelligence flagged the event just shortly after Bitcoin pushed past $76,000. Following this, the Total USDT supply now stands at $193 billion, dominating the $320 Billion stablecoins size by 58%.
Institutional capital is moving, and Tether mints of this scale historically precede accelerated exchange inflows. The market is watching where this billion lands.
Discover: The best crypto to diversify your portfolio with
Is Tether 1 Billion USDT Mint a Reliable Liquidity Signal for On-Chain Trading?Glassnode’s USDT Holder Accumulation Ratio sits at 57.63%, above the 50% threshold that indicates net accumulation by holders. Onchain Lens noted this mint as a precursor to heightened on-chain activity, with tokens expected to flow rapidly toward exchanges and DeFi platforms once deployed.
Stablecoins, DefillamaTransaction volume data reinforces the dominance picture. USDT’s volume of $484.17 billion already surpasses USDC’s $319.2 billion, a $164.97 billion gap that reflects USDT’s stranglehold on crypto payments infrastructure. Tron’s low-fee environment (driving 50%+ USDT network dominance) makes rapid deployment operationally straightforward once Ardoino’s team activates the inventory.
Institutional momentum is building, but the question is whether deployment timing aligns with the current sentiment window.
Discover: The best pre-launch token sales
Maxi Doge Eyes Big Upside as USDT Liquidity Hunts YieldWhen $1 billion in fresh stablecoin liquidity enters the ecosystem, it doesn’t sit idle. History shows it finds its way into high-beta plays, and meme tokens with active communities tend to capture disproportionate inflows during liquidity expansion windows.
Maxi Doge ($MAXI) is positioned squarely in that window. Built on Ethereum as an ERC-20 token, the project combines meme-first marketing with structural utility: holder-only trading competitions with leaderboard rewards, a Maxi Fund treasury for liquidity and partnerships, and dynamic staking APY.
The presale has raised $4.7 million at a current price of $0.0002814. Memecoin activity on Ethereum is picking up alongside rising USDT liquidity. It’s the timing that $MAXI’s community is watching closely.
Research Maxi Doge before the next price tier moves.
At 21:21 UTC on Monday, May 18, 2026, someone minted 1,000 eBTC on Monad. At Bitcoin’s spot of roughly $77,000, that’s about $77M of unbacked wrapped Bitcoin appearing from nothing on Echo Protocol’s Monad books. The attacker converted ~$870K of it into real WBTC by depositing a slice as collateral on Curvance and borrowing against it. The other 99% of the fake supply is parked on the attacker’s wallet, because Monad’s lending and DEX depth can’t absorb more.
This piece was written in the first hour after the drain. The initial public flag came from @dcfgod on X, who linked the suspicious mint transaction and tagged the affected teams; Monad co-founder @keoneHD acknowledged the incident shortly after and said the team and external security researchers were investigating. Echo Protocol and Curvance have not yet published statements at the time of writing. Final numbers on bad debt, attacker holdings, and any recovery plan will shift as post-mortems land. Treat the figures below as the best on-chain reads available as of the evening of May 18, 2026.
The dollar amount is small. The architectural shape makes this worth writing about. The same privileged-role failure mode that produced the Resolv USR exploit in March and the KelpDAO rsETH exploit in April just produced another one, on a new chain, against a new asset class. The realized loss is roughly 30× smaller than Resolv and over 250× smaller than KelpDAO. The pattern is the same.
What Echo, Curvance, and Monad Are Echo Protocol is a Bitcoin liquidity and yield project most visible to date on Move-based ecosystems. The Monad deployment is newer and smaller, and eBTC is its wrapped Bitcoin token there. The product shape is the familiar one: deposit BTC, hold a transferable representation that can move into lending, DEXs, and yield strategies the way WBTC does on Ethereum. The identification of this exploited contract with the Echo Protocol team specifically is currently community attribution; the project itself has not yet publicly confirmed the affected deployment as of writing.
Curvance is an omnichain lending protocol that lists collateral assets and lets users borrow against them, similar in shape to Aave or Morpho. On Monad it had a fresh eBTC/WBTC market running, with eBTC accepted as collateral against real WBTC borrows. The protocol’s lending logic was not the failure point here; it treated the collateral it received as exactly what the token contract said it was, and the token contract was the problem.
Monad is a young high-performance EVM L1 that opened to a wider set of deployments earlier this year. Echo, Curvance, and most of the assets sitting on Monad lending markets right now are fresh deployments, often without the operational layers (multisig admin keys, timelocks, monitoring, paranoid role separation) that the equivalent contracts on Ethereum have accumulated over years of incidents.
The Attack: Role Takeover, Then Mint On the eBTC token contract at 0xd691b0aFed67F96CEC28Ab6308Cbe5b2C103b7e9, the attacker ran a short sequence of role-manipulation transactions: granted themselves DEFAULT_ADMIN_ROLE, used that admin role to self-grant MINTER_ROLE, and then revoked the admin role to clean up. With minter authority in hand, the actual mint was a one-line follow-up: mint() to the attacker’s address (0x6a0109d3c5ab56277096c75e8f5d1d1d45243415), 1,000 eBTC issued directly from the zero address. The mint transaction (Monad block 75,477,995) sits at:
How the attacker got that initial DEFAULT_ADMIN_ROLE grant is the part nobody outside the Echo team can answer yet. The plausible options are the standard ones: a compromised admin private key, a misconfigured initial deployment that left the role grantable, or a contract-level access control bug that let an unprivileged caller escalate.
The Cashout: Deposit, Borrow, Bridge The attacker did not try to dump 1,000 eBTC into a DEX. Monad’s eBTC liquidity is thin, and the slippage would have eaten most of the extraction. They used the lending path instead, the same playbook Resolv’s attacker used to convert fake USR into ETH and KelpDAO’s attacker used to convert fake rsETH into WETH.
According to on-chain accounting reconstructed from the attacker wallet’s history, the cashout sequence was:
Deposit roughly 45 eBTC into Curvance’s eBTC market as collateral. The attacker received Curvance’s wrapped collateral receipt (ceBTC) in return. Borrow against that collateral across multiple transactions, pulling out approximately 11.296 WBTC in total. The reason the borrow stopped there is some combination of Curvance’s available WBTC supply, the LTV ceiling on the eBTC market, and any borrow caps set on the asset; which of those was the binding constraint isn’t yet confirmed. Bridge the borrowed WBTC off Monad. Community researchers tracking the wallet flagged LayerZero as the likely route; the exit transaction itself has not been independently confirmed at the time of writing. Route the proceeds toward a mixer. Tornado-style obfuscation has been mentioned by multiple analysts on X, again as the most likely path rather than a confirmed on-chain fact. The attacker still holds the bulk of the minted supply: roughly 955 eBTC sitting idle in the wallet, plus a small ceBTC position on Curvance. The residual sits there because Monad simply doesn’t have anywhere for it to go — no lender on the chain has the depth to absorb another borrow at that size, and DEX liquidity on eBTC would collapse against any meaningful dump.
The Curvance market is the immediate casualty. The lender is sitting on collateral whose redemption is in dispute against an outstanding WBTC borrow of 11.296 tokens, roughly $870K at current spot. Whether that hole gets backfilled by Echo, by Curvance’s treasury, or absorbed by suppliers depends on a recovery plan that hasn’t been published yet.
The Blast Radius This incident is small and localized, and that’s worth saying clearly.
The damage is contained to Curvance’s eBTC/WBTC market on Monad. Curvance’s lending logic was not exploited; the protocol behaved correctly given inputs it had no way to verify. Other Curvance markets, on Monad and on the chains Curvance is deployed across, are not affected. Aave, Morpho, Spark, Fluid, and the rest of the major lending markets on Ethereum and the L2s have no Echo eBTC exposure.
Inside Monad, the secondary risk is anything else that listed Echo’s eBTC as collateral or held it in a vault. That list is short today because the asset is young, but it’s worth watching. Any DEX pool with eBTC liquidity is sitting next to a wallet that owns 955 of the things and has demonstrated willingness to dump them, so DEX LPs face slow-bleed risk if the attacker decides extraction-via-DEX is worth the slippage hit.
Untouched: real Bitcoin, real WBTC on every other chain, every other Bitcoin wrapper, and every other lending market that didn’t list eBTC. The failure here is asset-specific and chain-specific.
The Uncomfortable Questions How did the attacker get the admin role in the first place? This is the question Echo has to answer, and it’s the only one whose answer matters past the immediate cleanup. If a hot admin key leaked, the lesson is operational. If the deployment left the role grantable to addresses it shouldn’t have, the same template needs reviewing on any other chain Echo deployed it on. If there’s an access-control bug in the contract logic itself, the scope expands.
Why did escalating one role break the whole thing? Whatever the entry point, the contract was structured so that a single compromise produced the entire outcome: no timelock between admin role grant and minter role grant, no separate “mint authority” multisig sitting downstream of the admin, no rate limit on freshly-granted minter roles. Multisigs, timelocks, and rate-limited mint authority on wrapped Bitcoin contracts exist precisely so this kind of single compromise can’t immediately produce 1,000 fake BTC. None of those were present here.
Should Curvance have listed eBTC at all, and with what parameters? The realized bad debt is small in absolute terms (~$870K) partly because the LTV on the market appears to have been kept fairly tight (11.3 WBTC borrowed against ~45 eBTC of deposited collateral isn’t aggressive leverage) and partly because the lender’s WBTC supply on the market was modest. The harder question is whether a freshly-deployed wrapped Bitcoin token with mint authority sitting on a single admin role should have been accepted as collateral in the first place, on any LTV, by a lender that had no way to monitor for unauthorized issuance.
Will Monad’s lending markets tighten listing standards? Monad has spent its early months courting builders and shipping tokens fast. That’s the right strategy for getting an L1 ecosystem off the ground; it’s also exactly the condition that produced this incident. Whether the lending markets respond by tightening parameters on freshly-listed assets, or wait for a larger event to do that, is the question worth watching.
The Lesson, Again Strip away the specifics and this is the same exploit as Resolv and KelpDAO.
Resolv’s USR exploit was a single externally owned address that could pass arbitrary mint amounts into completeSwap(), and ~$25M of real value walked out the door. KelpDAO’s rsETH exploit was a one-of-one DVN on a LayerZero adapter, and ~$236M of real value walked out the door. Echo’s eBTC exploit was a single admin role on a Bitcoin wrapper, and ~$870K of real value walked out the door.
What recurs across all three is the architectural shape: a privileged component on the edge carrying more authority than the surrounding system understood, with a downstream lending layer already composed against the asset as if the privileged component were sound. The lender behaves correctly. The token behaves correctly within its own access-control rules. The composition fails. The trust assumption embedded in the asset turns out to be weaker than the trust assumption the lender was operating on.
The realized losses look very different across the three incidents because the lending markets sitting downstream are very different. Mature lenders on Ethereum have learned to cap their exposure to any single collateral asset, to scrutinize the access controls of anything they list, and to keep blast radius small even when an upstream component breaks. New chains and new asset issuers haven’t built those reflexes yet. Until they do, each new ecosystem gets to learn the same lesson over again at whatever scale its lending markets happen to be running at the moment.
What Happens Next The Monad team has acknowledged the incident publicly and said security researchers are reviewing the contract and the wallet history. The real outstanding answers fall to two teams. Echo has to explain the chain of custody on the admin role and what the recovery plan looks like for the unauthorized supply. Curvance has to address the listing decision and how the bad debt gets covered.
The attacker’s wallet is being tracked, and any further movement of the residual ~955 eBTC or of the bridged WBTC will be visible quickly. Whether the bad debt gets socialized to Curvance suppliers, absorbed by Curvance’s treasury, or covered by Echo as the upstream point of failure is the call Curvance has to make.
For anyone using newly-launched lending markets on newly-launched chains, the practical takeaway is narrow: before you supply real assets, look at what the borrowable collateral actually is, who can mint it, and whether anything stops them from minting more. If your lender can’t tell you which keys can produce that collateral, neither can you.
Hacking incidents in the cryptocurrency market seem never-ending. Most recently, another DeFi protocol was targeted.
Accordingly, the Bitcoin-focused DeFi protocol Echo Protocol was vulnerable today, making it the latest in a wave of DeFi attacks this year.
Echo Protocol, a Monad (MON)-based Bitcoin liquidity project, announced via its X account that a security vulnerability had occurred in its bridge.
The team stated that they are investigating the incident and announced that they have temporarily suspended all cross-chain transactions.
This announcement comes after Onchain Lens reported that Echo Protocol was exposed to a security vulnerability worth $76.7 million.
According to onchain analyst Onchain lnes, the attacker generated 1,000 eBTC, the protocol’s liquidity token, on Monad and used it as collateral to borrow WBTC.
He then bridged the WBTC to Ethereum, converting it to ETH, and sent it to the cryptocurrency mixer Tornado Cash.
Following the hack news, the price of Echo Protocol (ECHO) fell. ECHO is listed on Binance Alpha, Binance’s pre-listing pool.
*This is not investment advice.
Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data!
A serious security breach has occurred targeting the MAP Protocol and ButterNetwork infrastructure operating within the cryptocurrency ecosystem. According to an urgent alert issued by the community, the bridge system running on the Ethereum and BNB Smart Chain (BSC) networks has been attacked.
Initial findings indicate that the attacker manipulated the “OmniServiceProxy” mechanism in the Butter Bridge V3.1 infrastructure to mint approximately 1 quadrillion counterfeit MAPO tokens. This amount is estimated to be approximately 4.8 million times the legitimate circulating supply of MAPO tokens, which is around 208 million.
The tokens in question were transferred directly to a newly created external wallet address (EOA). The attacker then reportedly sold approximately 1 billion MAPO tokens, withdrawing 52.21 ETH from the ETH/MAPO liquidity pool on Uniswap V4. Based on the current market value, the estimated loss is around $180,000.
On the other hand, it is added that the main risk continues. Because it is stated that the attacker still has approximately 999.999 billion MAPO tokens in his possession, and if these tokens are released into the market, they could pose a serious threat to both the liquidity pools of decentralized exchanges (DEX) and the centralized exchanges (CEX) that list MAPO.
MAPO’s price plummeted by 72% following the development.
The chart shows the price drop of MAPO. *This is not investment advice.
Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data!
Cover image via U.Today Disclaimer: The opinions expressed by our writers are their own and do not represent the views of U.Today. The financial and market information provided on U.Today is intended for informational purposes only. U.Today is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.
Ripple USD (RLUSD) stablecoin has seen $0 minted so far on June 4 despite $27.5 million tokens removed from circulation.
RLUSD activity continues in June after the month began with significant minting activity. $127.4 million was minted alone on June's first day with $12 million burned.
However, this figure dropped in the days that followed with $3.7 million and $16.8 million burned on June 2 and 3, respectively.
HOT Stories
There is a possibility that a minting transaction might occur as the day progresses, but a similar trend in May lessens this probability.
You Might Also Like
On May 3 and 4, $0 RLUSD was minted while over $17 million tokens were burned. Whether this is a coincidence or a deliberate trend wherein Ripple briefly pauses minting activity to strategize for the month remains unknown.
Demand for RLUSD growsOn Wednesday, Mastercard announced it was supporting settlement with Ripple's RLUSD across a range of supported blockchain networks including Arbitrum, Coinbase's Base, Canton Network's Canton, Ethereum, Polygon, Solana, Tempo and XRPL.
You Might Also Like
The announcement revealed plans by the payment giant to expand settlement capabilities to include stablecoin, intraday, holiday, and weekend options, giving partners more choice in how and when transactions are settled. This provides the option to settle in fiat or regulated stablecoins and improve liquidity management for time-sensitive, cross-border flows.
Ripple reacted to this milestone, highlighting that the demand for modern, always-on settlement infrastructure continues to grow. It noted that Mastercard's support for RLUSD and the XRP Ledger reflects growing demand for trusted digital assets and blockchain infrastructure that can power faster, more flexible settlement.
Jack McDonald, SVP of Stablecoins at Ripple, described it as another major milestone for the adoption of stablecoins in mainstream payments.
The Ripple USD stablecoin marked a milestone this week, now available to institutions in Turkey through new partnerships with BiLira Kripto, Bitexen and Bitlo.
Security researcher Taylor Hornby used Anthropic’s Opus 4.8 to find a critical bug in Zcash’s Orchard pool that could have minted undetectable counterfeit ZEC, sending the token down 31%.
Posted June 5, 2026 at 3:47 am EST.
A security researcher using Anthropic’s Opus 4.8 model uncovered a critical vulnerability in Zcash’s Orchard shielded pool that could have been exploited to create unlimited undetectable counterfeit ZEC, according to adisclosure published Thursday by Shielded Labs, the nonprofit that funds Zcash development.
Independent security engineer Taylor Hornby, hired by Shielded Labs in April for an ongoing protocol review, discovered the bug on May 29 using a custom AI auditing framework paired with Opus 4.8, which Anthropic released the day before on May 28. Hornby wrote a complete exploit program that successfully generated unlimited counterfeit ZEC in a local test environment. The vulnerability had been live since Orchard’s activation in May 2022, evading years of scrutiny by some of the world’s top cryptographers. The Zcash Open Development Lab and the Zcash Foundation coordinated an emergency two-phase network upgrade, with the fix completed on June 2.
This story is an excerpt from the Unchained Daily newsletter.
Subscribe here to get these updates in your email for free
The flaw stemmed from an under-constrained element of the Orchard circuit, which allowed arbitrary false inputs to pass through an elliptic curve multiplication check and still validate. Because Orchard hides balances and amounts using zero-knowledge proofs, any counterfeit ZEC produced through the exploit would have been indistinguishable from legitimate tokens. Shielded Labs said prior exploitation appears unlikely but cannot be ruled out cryptographically. “What makes this particularly challenging is that, due to the privacy properties of Orchard and the nature of the bug, there is no definitive way to determine using only cryptography whether such exploitation occurred,” the post said.
ZEC fell 31% in 24 hours to $409.64 by Thursday evening, with most of the decline coming in the five hours after disclosure. Arthur Hayes posted that he had dumped his entire ZEC position, writing the privacy thesis “demands perfection” and that uncertainty over supply integrity was disqualifying.
The disclosure is the cleanest counterpoint yet to the AI-attacker thesis that has dominated DeFi security discourse this spring. Former OpenZeppelin CTO Manuel Aráoz argued last week that AI gives attackers asymmetric advantage because defenders must fix every bug while attackers need only one.
Helius CEO Mert Mumtaz wrote on X that the team’s proactive use of advanced AI red-teaming and rapid patch coordination should be read as bullish for the protocol, not bearish. Shielded Labs is now preparing a follow-up network upgrade proposal that would deploy a new shielded pool with turnstile accounting on coins exiting Orchard, allowing anyone to verify the integrity of the Zcash supply.
Related Listen: Is ‘All of DeFi Unsafe’? What You Need to Know About Holding Assets Onchain
The debate over Zcash’s recently patched Orchard Pool vulnerability is far from settled. While some investors fear the worst, Dragonfly partner Haseeb Qureshi says the market may be overstating the immediate risks. He also confirmed that Dragonfly continues to hold ZEC despite the controversy.
The vulnerability remained undiscovered for years before developers patched it. In theory, an attacker could have used it to create unlimited counterfeit shielded ZEC. However, Qureshi argues that any damage would likely have stayed within the shielded pool rather than spreading across the broader ZEC market.
Why Qureshi Thinks the Threat Is LimitedQureshi explained that anyone creating counterfeit shielded ZEC would eventually need to convert those coins into transparent ZEC before selling them on major exchanges.
Because transparent ZEC remains fully auditable, the network can easily detect attempts to move excessive amounts into the visible supply. For that reason, Qureshi believes most traders and exchange users faced little direct risk. Shielded pool users would have carried the bulk of the exposure.
He also pointed to recent network data. Over the last 48 hours, the shielded pool’s share of supply fell from 31% to 30%. Qureshi says that a modest decline does not suggest panic among privacy-focused users.
Not Everyone AgreesHowever, Zcash creator Wei Dai says the situation may be more complicated.
Responding to claims that a major exploit would have resulted in obvious withdrawals from the Orchard Pool, Dai argued that a sophisticated attacker would likely avoid draining the pool entirely. Instead, he suggested the Orchard Pool itself could serve as a laundering mechanism. A hacker could potentially keep counterfeit ZEC inside the shielded ecosystem and distribute it gradually through private transactions while the pool remained active.
Dai also proposed another scenario. An attacker who discovered the bug early could have quietly opened a large short position against ZEC before the vulnerability became public. Because ZEC has liquid perpetual futures markets, such a strategy could generate significant profits while leaving few obvious traces.
Dragonfly Remains BullishDespite the ongoing debate, Qureshi remains confident in Zcash’s path forward.
The Zcash team is planning a new turnstile mechanism and a fresh shielded pool that will effectively verify whether the existing pool was inflated. Qureshi compared it to taking attendance after a field trip to ensure no extra coins slipped into circulation.
He also disclosed that Dragonfly still holds ZEC, while he personally remains invested in ZODL, signaling continued confidence even as the industry wrestles with one of the biggest privacy-coin security debates in years.
Story Ends Here
Trust with CoinPedia:CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.
Investment Disclaimer:All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.
Sponsored and Advertisements:Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.
Syscoin paused its bridge immediately and urged exchanges to freeze deposits connected to the tainted transaction trail.
An attacker exploited a validation flaw in Syscoin’s bridge system, minting about 5 billion SYS tokens without authorization and sending the token’s price into a nearly 20% freefall.
This incident was revealed by the Syscoin team in an early postmortem published on X, and it comes during a tough stretch for SYS, which was already deeply in the red across the last few weeks and months.
What Happened According to Syscoin’s postmortem, the attacker exploited a validation issue in the bridge relay path, which incorrectly accepted or interpreted a transaction proof. That error caused the system to treat a fraudulent transaction as valid and create an unauthorized output of approximately 5 billion SYS, then valued at just under $10 million.
Per the Syscoin team, the stolen funds were sent to the address sys1qgaelv…9wvcw and then split across two other wallets, one holding about 4 billion SYS and the other the remaining 1 billion.
Syscoin immediately paused the bridge and has since contacted exchanges and ecosystem partners asking them to blacklist or freeze any deposits connected to the tainted UTXO trail and its downstream transactions. The team also said that it had identified the affected validation path and had put in place a fix pending security review and implementation.
According to blockchain analytics account Hupzy, operated by Spot On Chain, the incident was a recurring structural problem. It also noted that while blacklisting by exchanges may contain the secondary damage, the reputational hit to the bridge model will persist.
A Token Already Under Pressure The exploit couldn’t have landed at a worse time for SYS holders, considering that when it happened, the token was already down more than 43% in seven days and over 82% in the last month.
You may also like: Jaredfromsubway Hacker Ignores 50% Bounty, Routes Funds to Tornado Cash Over 1,400 Liquidity Providers Hit in $7.3 Million DxSale Exploit Verus Bridge Exploiter Returns $8.5M, Keeps $2.8M as Bounty Reward A lot of that longer-term decline was already in motion after Binance delisted SYS last month alongside four other tokens following a review of its listing standards.
Shortly after the delisting news broke, the Syscoin community responded by pulling well over 300 million SYS from the exchange, with over 600 new nodes reportedly added to the network.
The attack on the Syscoin bridge is the latest in a string of cross-chain security incidents that have kept DeFi on edge. They include an $11 million exploit on the Verus network in May and the draining of $7.3 million from more than 1,400 DxSale liquidity pools on the BNB Chain.
Luckily for Verus, the hacker later returned about $8.5 million, keeping $2.8 million for themselves as a white-hat bounty.