Verus Ethereum Bridge byl podruhé za něco přes dva měsíce hacknut a přišel asi o 7,54 milionu USD v kryptoměnách. Útočník zneužil stejnou chybu jako v květnu.
The Verus Ethereum Bridge has been targeted by a major security breach for the second time in just over two months, resulting in the theft of approximately $7.54 million in various crypto assets. The incident occurred on July 23 when attackers exploited a vulnerability, once again raising concerns about the security of cross-chain protocols in decentralized finance (DeFi).
Attacker Drains Bridge’s Ethereum ReservesThe breach allowed the attacker to abuse the bridge’s submitImports function, which triggered Ethereum-side payouts without equivalent assets being locked on the Verus blockchain. This vulnerability enabled the unauthorized extraction of funds from the bridge’s reserves.
Blockchain security firm Blockaid and independent researcher exvulsec both confirmed and investigated the exploit. According to on-chain data, roughly 1,137 ETH, as well as tBTC, USDC, USDT, EURC, MKR, and scrvUSD, were drained from the bridge reserves at around 03:45 UTC. The stolen assets were quickly swapped through decentralized exchanges, then consolidated into nearly 3,916 ETH before parts of the funds were routed through Tornado Cash.
Mini dictionary: Tornado Cash, a decentralized non-custodial privacy solution on Ethereum, is designed to break the on-chain link between source and destination addresses, making transaction tracing more difficult.
AssetAmount stolenEstimated valueETH1,137Included in $7.54M totaltBTCUnknownUSDCUnknownUSDTUnknownEURCUnknownMKRUnknownscrvUSDUnknown Investigators noted that by exploiting the same contract, function entry point, and vulnerability as a previous May breach, the attacker bypassed standard cross-chain verification and triggered unbacked payouts, draining several digital assets from Verus’ Ethereum bridge reserves.
Recurring Security Flaws and Recent HistoryThe latest breach revived scrutiny over Verus’ handling of a previous exploit in May, which resulted in an $11.58 million loss. Experts stated that this attack exploited the exact vulnerability from the earlier incident, indicating that core issues may have remained unaddressed. Blockaid observed that while this latest event involved a different attacker wallet, the method and targeted contract remained unchanged.
Following the May attack, the same attacker returned 4,052 ETH—about 75% of the stolen funds—after reaching an agreement with Verus. Despite that partial restitution, the repetition of the exploit has heightened doubts regarding the bridge’s security remediation process.
Experts pointed out that the repeated vulnerability likely resulted from an incomplete technical fix after the earlier breach, leaving Verus exposed to additional attacks. There is growing pressure for the protocol team to publish a thorough incident report and technical breakdown.
Ongoing Investigations and Broader RisksThe Verus incident is one of several recent DeFi bridge attacks highlighted by on-chain monitoring services. Lookonchain reported that combined losses from incidents involving Verus, AFX Trade, and B² Network have climbed to approximately $35.55 million.
Mini dictionary: Lookonchain is an on-chain analytics platform known for monitoring blockchain transactions and identifying patterns related to hacks, large movements, and abnormal activities.
Security analysts explained that bridge protocols are increasingly targeted due to logical flaws in cross-chain messaging mechanisms, which, if exploited, can allow fund withdrawals without equivalent collateralization.
Next Steps for Verus and UsersAmid the investigation, Verus halted all bridge operations but has not announced a compensation plan or released a detailed technical report. The absence of a clear official explanation has drawn criticism from the user community.
Observers expect the Verus team to prioritize closing the technical vulnerability, improve their validation process, and offer a roadmap to locate and potentially recover missing assets. Until these steps are made public, scrutiny around trust and transparency in the protocol will likely continue.
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.
Exploiter z Drift po zhruba třech měsících neaktivity přesunul 23 095 ETH v hodnotě asi 44,4 milionu USD do Tornado Cash. Část transakcí směřovala i na adresy označené jako vklady Bybit.
A wallet tied to the $285 million Drift Protocol exploit moved 23,095.1 Ether, worth about $44.4 million, into Tornado Cash after roughly three months of inactivity.
Summary
Drift’s exploiter deposited 23,095 ETH into Tornado Cash after remaining inactive for three months. ZachXBT declined further tracking, citing resources required to monitor and freeze a nine-figure DPRK theft. Drift previously announced a recovery bounty program with Arkham and Bybit, contrary to online claims. The same address sent 0.85 ETH to wallets labeled as Bybit deposit addresses, according to Etherscan records and monitoring attributed to PeckShield.
Transfers began on July 23 and continued into July 24, on-chain records show. Researcher JL, known as 0xJaelle, flagged the movement and tagged ZachXBT. The investigator replied that he did not plan to keep following the funds without institutional support.
Drift exploiter empties an Ethereum wallet The Etherscan address labeled “Drift Exploiter 4” processed hundreds of transactions during the movement. Records show repeated deposits of 100 ETH, 10 ETH and 1 ETH into the Tornado Cash router. Four other transfers totaling 0.85 ETH went to addresses labeled as Bybit deposits.
Onchain Lens first reported that the attacker had resumed activity and was sending 100 ETH batches into the mixer several times per minute. The wallet had remained largely inactive since the April attack.
Tornado Cash pools deposits and permits later withdrawals through different addresses. That can weaken the direct public link between sending and receiving wallets. Investigators may still use timing, transaction patterns and exchange activity, but the process requires more data and staff.
The movement covers only part of the original theft. Drift’s April recovery update valued stolen assets at $295.7 million across JLP, USDC, Bitcoin-linked tokens, SOL, WETH and other assets. The protocol said much of the converted value remained across four flagged Ethereum wallets.
ZachXBT cites cost of tracking North Korea-linked funds ZachXBT wrote, “Sorry I currently do not have any plans to track these funds further.” He said monitoring a nine-figure North Korea-linked exploit and working toward possible freezes would require resources beyond one independent investigator.
He described the task as “difficult for a team and not feasible for a single person.” ZachXBT also said Drift was not a donor or client. His response on X drew attention to the cost of investigations that continue for months.
The comments do not show that no organization is watching the wallets. Drift has said it works with law enforcement, Mandiant and blockchain intelligence firms. Etherscan continues to label the address, while exchanges can review deposits connected to flagged wallets.
Elsewhere, ZachXBT criticized Circle after about $232 million in stolen USDC crossed from Solana to Ethereum during the April attack. The funds moved through Circle’s cross-chain system before the attacker converted much of the value into ETH.
Drift had announced a recovery bounty program JL later said it was surprising that Drift had not created a recovery bounty. Drift’s public record shows that it had announced plans for one. On April 16, the protocol said it was developing a bounty program with support from Arkham and Bybit.
However, the update did not provide a final reward amount, eligibility rules or payment schedule. It remains unclear whether the program became fully active, whether it covered continuing wallet monitoring, or whether independent researchers could claim payment for later tracing work.
Drift also created a user recovery plan separate from stolen-fund tracking. Tether proposed up to $127.5 million in support. Drift plans to issue recovery tokens and fund redemptions through remaining assets, partner capital and future exchange revenue.
The protocol’s June investigation update said Mandiant attributed the attack to UNC6862, a North Korean threat group. Drift said the attackers used social engineering and compromised operational access rather than a smart contract flaw. As crypto.news reported, the attackers emptied key vaults within about 12 minutes.
Recovery continues as the trail becomes harder to follow Drift has focused on rebuilding its platform and funding user claims while forensic teams pursue the stolen assets. Its recovery framework states that recovered funds will enter the user recovery pool. The protocol also plans stronger signing controls for critical transactions.
The April attack affected other Solana projects. As previously reported, yield platform Carrot decided to shut down after losses linked to Drift erased most of its deposited value.
The Tornado Cash deposits do not prove that the attacker converted the ETH into usable cash. The deposits remain public, and investigators may still identify later withdrawals. However, they remove a simple wallet-to-wallet trail and make the next phase harder.
Neither Drift nor Solana had publicly responded to ZachXBT’s comments at the time of writing. Bybit had not announced whether it reviewed the small deposits shown on Etherscan. The remaining stolen funds and the status of Drift’s planned bounty program remain unresolved.
Útočník za exploit Summer.fi začal prát ukradené prostředky a přes Tornado Cash přesunul zhruba 1,35 milionu DAI. Summer.fi to označuje za signál, že nemá v úmyslu vrátit peníze dobrovolně.
Summer.fi's own post-mortem confirms the attacker began laundering the $6M haul through the mixer, calling it a sign of "limited intent to return the funds voluntarily."
The attacker behind the $6 million Summer.fi exploit has begun laundering the stolen funds, moving roughly $1.35 million in DAI through Tornado Cash, the sanctioned crypto mixer, according to Summer.fi's own post-mortem of the July 6 attack.
Summer.fi, the front-end for the Lazy Summer Protocol, said the attacker "swapped a portion of the proceeds and routed them through Tornado Cash... via an intermediary wallet (0x46e0…eBa7)," adding that the move "signals limited intent to return the funds voluntarily."
Laundering TrailOnchain Lens via Odaily, reported the exploiter's wallet received 6.017 million DAI from the attack and has since moved 1.35 million DAI, swapping it for ETH on Uniswap before sending it through the same intermediary wallet into Tornado Cash. The original wallet still holds about 4.67 million DAI, while the intermediary wallet holds 50 ETH, per the report.
The exploit itself drained roughly $6.04 million from two Lazy Summer USDC vaults on Ethereum on July 6, after an attacker manipulated vault share pricing using a stale-valued token position built up over three months, Summer.fi said. The Defiant previously covered the initial exploit.
Summer.fi said its security partners, including SEAL 911, are continuing to trace the funds but that tracing "breaks down" once assets are swapped out of stablecoins and deposited into a mixer. The protocol publicly named the attacker's funder and beneficiary wallet, 0x7BF7…BDCa, "so the community and exchanges can flag associated activity."
Roughly 4.67 million DAI of the original haul remains untouched in the exploiter's primary wallet, leaving open whether further funds will move through Tornado Cash.
Útočník na Step Finance prodal ukradené SOL za zhruba 21,4 milionu USD, nakoupil ETH a prostředky poslal přes Tornado Cash. Podle on-chain dat tak pokračuje praní výnosů z útoku.
The person (or persons) who drained Step Finance of roughly 261,854 SOL tokens has moved to the next phase of every crypto heist playbook: the laundering stage. The exploiter sold a significant chunk of stolen SOL, bridged $21.4 million to Ethereum, purchased ETH, and funneled the proceeds through Tornado Cash.
What happened at Step Finance Step Finance, a DeFi portfolio management platform built on Solana, was hit on January 31 when attackers gained unauthorized access to treasury and fee wallets. The haul came to approximately 261,854 SOL, worth somewhere between $27 million and $30 million at the time of the breach.
The attack vector was compromised executive team devices, likely through phishing or social engineering. The smart contracts worked fine. The people managing them did not.
Advertisement
Total losses ballooned to around $40 million when accounting for the full impact, with only about $4.7 million recovered through partnerships and features like Token22. That recovery rate, roughly 12% of total losses, is not exactly a victory lap.
By late February, Step Finance ceased operations entirely. Its affiliates, SolanaFloor and Remora Markets, also shut down as the fallout spread. The project announced plans for a buyback based on a pre-hack snapshot of the STEP token.
Following the money across chains The on-chain data, flagged by Arkham Intelligence, paints a clear picture of the attacker’s exit strategy. After sitting on the stolen SOL, the exploiter began selling, converting roughly $21 million worth of tokens before bridging $21.4 million over to Ethereum.
Once on Ethereum, the funds were swapped into ETH and then routed through Tornado Cash. The US Treasury’s Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash back in 2022, though those sanctions have faced significant legal challenges. The protocol continues to function because it’s a set of smart contracts on Ethereum that nobody can unilaterally shut down.
What investors should watch The $4.7 million recovery represents a fraction of total losses, and the movement of funds through Tornado Cash suggests that further recovery through on-chain means is unlikely without law enforcement intervention. Historically, funds that make it through mixing protocols are rarely clawed back unless the attacker makes an operational mistake later, like cashing out through a centralized exchange with KYC requirements.
The planned STEP token buyback based on a pre-hack snapshot is worth monitoring, though with the project’s operations ceased and affiliates shut down, the entity executing any buyback may have limited resources to work with.
The attacker’s decision to convert stolen SOL into ETH before laundering signals a practical reality about cross-chain liquidity. Ethereum’s deeper liquidity pools and more established mixing infrastructure make it the preferred destination for laundering large sums, which means that exploits on alternative L1s frequently end up impacting Ethereum’s on-chain analytics landscape as well.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Raydium potvrdil exploit starých poolů na Solaně za přibližně 1,34 milionu USD a slíbil plnou náhradu všem zasaženým. Aktivní pooly ani současní uživatelé nebyli zasaženi.
TLDR Hackers extracted approximately $1.34 million from five dormant Raydium liquidity pools operating on Solana The breach resulted in the theft of around 150,000 RAY tokens, 5,600 SOL, and 893,700 USDC The vulnerability existed in an obsolete AMM program discontinued in 2021, leaving active pools untouched Raydium announced its treasury would provide complete restitution to all impacted participants Security firm PeckShield identified roughly 810 ETH of the pilfered assets flowing into Tornado Cash On June 10, Raydium, a Solana-based decentralized exchange, disclosed that malicious actors successfully exploited outdated infrastructure components, siphoning approximately $1.34 million worth of cryptocurrency.
The compromised liquidity pools had been inaccessible via Raydium’s user interface ever since the platform discontinued its AMM V3 program back in 2021. According to Raydium’s statement, neither current platform users nor any actively maintained liquidity pools experienced any impact.
How the Attack Happened On-chain security analyst Specter revealed that the perpetrators utilized a fraudulent mint address to circumvent security validation protocols within the inactive pool infrastructure. The core vulnerability stemmed from inadequate verification processes for LP mints, creating an opportunity to sidestep proportion validation mechanisms.
The assailant successfully withdrew approximately 150,177 RAY tokens, 5,603 SOL, and 893,700 USDC from the compromised pools. According to Specter’s investigation, the attacker initially received funding through the KuCoin exchange before transferring the illicit assets to the Ethereum blockchain.
PeckShield, a prominent blockchain security organization, monitored the movement of stolen cryptocurrency following its transfer to Ethereum. Their analysis revealed that approximately 810 ETH was funneled into Tornado Cash, while an additional seven ETH moved through FixedFloat.
Notably, Tornado Cash was delisted from U.S. Treasury Department sanctions in March 2025. Nevertheless, the utilization of this privacy protocol may continue to present obstacles for investigators attempting to recover or trace the diverted funds.
Raydium Will Reimburse All Losses Raydium has publicly committed to utilizing its treasury reserves to compensate all financial damages stemming from this security breach. While the protocol emphasized that no current active users suffered losses, some participants maintained residual exposure through the deprecated pool contracts.
This marks the second occasion where Raydium has pledged to absorb user losses. Following an admin key security breach in December 2022 that affected operational pools, the project implemented a governance-approved compensation plan utilizing buyback fee revenue and vested team token allocations to restore liquidity provider funds.
The development team confirmed that all currently deployed mainnet programs remain secure and are presently undergoing comprehensive independent security audits.
Market response to the incident proved minimal. Raydium traded around $0.57, experiencing less than a 1% decline during the 24-hour window after the exploit became public. Solana experienced a modest drop of nearly 2%, settling around $63.88 throughout the identical timeframe.
The RAY token demonstrated resilience, actually gaining more than 2% on the day news of the security breach emerged.
Raydium clarified that both its SDK and decentralized application infrastructure lack functionality for interacting with the legacy AMM V3 pools on the mainnet, effectively confirming the attack remained isolated to decommissioned code.
Security researchers from PeckShield and Specter maintain ongoing efforts to track the movement of stolen digital assets. According to currently available blockchain data, the exploitation remained entirely confined to obsolete infrastructure components without penetrating Raydium’s operational trading ecosystem.
Útočník spojený s UXLink poslal do Tornado Cash zhruba 8,1 milionu dolarů v ETH ve 46 vkladech po 100 ETH. Celkem už má podle Specter propráno 19,1 milionu dolarů ukradených aktiv.
UXLink, a Web 3 social network that was targeted in September 2025, is making headlines once again. According to Specter, an on-chain investigator, the attacker responsible for the UXLink exploit has started relocating the stolen assets.
To obfuscate transaction trails, the wrongdoer converted some of the stolen DAI stablecoins into Ethereum [ETH]. Going forward, the illicit actor then deposited roughly $8.1 million worth of ETH into Tornado Cash.
Funds laundered According to the investigator, 46 distinct deposits of 100 ETH each were made as part of the laundering process.
Source: Specter For those unaware, this is a common strategy to conflate illegal funds with legal transactions and make blockchain tracing more difficult.
With this most recent action, the attacker has now reportedly laundered a total of $19.1 million in stolen assets.
However, the fact that the exploiter still has control over about $16 million in funds despite these transfers raises the possibility of further laundering.
How was UXLink attacked? Well, back in September 2025 the exploiter had made over $800 billion, or 9 trillion $UXLINK. Interestingly, even hours after the original exploit, the hacker kept their access and kept minting more tokens.
The exploiter then started moving the proceeds to centralized exchanges and offloading the fraudulent tokens through decentralized exchanges. This in turn resulted in the depletion of Uniswap’s liquidity.
Source: Specter Notably, the attacker did not stop there, and signed a malicious transaction and lost 542 million UXLINK tokens to another malicious actor—often referred to as “theft stolen from theft.”
Even with this setback, the main exploiter still held about 900 million UXLINK tokens, putting a sizable portion of compromised assets in the hands of malicious actors.
What’s more? This coincded with ETH declining by 1.01% over the previous day to trade at $1,745.11 at press time.
In addition, on the 12th of June Humanity Protocol reported a targeted phishing attack against one of its directors.
This had resulted in the attacker using administrative credentials that were stolen to upgrade contracts, transfer tokens across Ethereum, and mint new $H tokens on the BNB Smart Chain.
Furthermore, on the 15th of June, a suspicious transaction involving the depletion of assets valued at approximately $2.19 million occurred in Aztec Network’s Router contract.
Final Summary From September 2025 to the present time, the attackers have reportedly laundered a total of $19.1 million in stolen assets from the UXLink exploit. Back then, the exploiter had made over 9 trillion $UXLINK, kept their access, and kept minting more tokens.
Útočník spojený s Jaredfromsubway.eth přesunul asi 2 000 ETH přes Tornado Cash a směnil 1 422 ETH za zhruba 2,45 milionu DAI. Z ukradených více než 7,5 milionu USD tak dál odtékají prostředky.
The person who pulled off one of the most brazen exploits in Ethereum’s MEV ecosystem is not sitting still. The attacker who drained the infamous Jaredfromsubway.eth sandwich bot has now routed approximately 2,000 ETH through Tornado Cash, the privacy mixer that remains the go-to laundering tool for on-chain criminals.
On top of the mixing, the exploiter swapped 1,422 ETH for roughly 2.45 million DAI. That leaves a minimal ETH balance in the attacker’s wallets.
How the original exploit went down The exploit, which security firm Blockaid characterized as a “counter-MEV honeypot” attack, was almost poetic in its construction. The attacker deployed fake token contracts and liquidity pools designed to trick the bot into granting token approvals. The exploiter built a trap that looked like a juicy sandwich opportunity, and the bot took the bait.
Advertisement
The scheme played out over several weeks before culminating in a drain that siphoned off more than $7.5 million in various assets. The stolen haul included 1,474.58 WETH, 2.87 million USDC, and 2 million USDT. All of it was converted into approximately 4,400 ETH.
The bounty that went nowhere After the exploit came to light around June 20-21, the Jaredfromsubway.eth operator posted an on-chain message offering a white-hat bounty. The deal was 50% of the stolen funds, roughly 2,150 ETH, in exchange for returning the rest within 48 hours. The message also carried the implicit threat of legal action if the attacker refused.
Rather than returning anything, the attacker has been systematically moving funds through Tornado Cash. The 2,000 ETH transfer, valued at approximately $3.44 million at the time of the transaction, represents a significant chunk of the stolen proceeds being pushed through the mixer.
What this means for MEV and DeFi security The counter-MEV honeypot technique essentially weaponizes a bot’s own aggression against it. MEV bots rely on automated token approvals to execute trades at speed. That same mechanism — the willingness to approve and interact with any contract that presents a profitable opportunity — is exactly what the attacker exploited.
Despite being sanctioned by the US Treasury’s Office of Foreign Assets Control back in 2022, Tornado Cash remains operational as a decentralized protocol. Every major exploit that routes funds through it renews the debate about whether privacy tools are a necessary feature of financial freedom or primarily an enabler of theft.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Útočník KyberSwap poslal dalších 2 000 ETH do Tornado Cash; za dva roky už přes Tornado Cash převedl a promíchal 16 100 ETH, tedy zhruba 40 milionů dolarů, což představuje přes 80 % z 48,8 milionu dolarů ukradených při útoku na KyberSwap v listopadu 2023. Část ukradených prostředků zatím nebyla plně převedena.
According to PeckShield’s monitoring, an address identified as the KyberSwap attacker has once again transferred 2,000 ETH to Tornado Cash. Over the past two years, this attacker has cumulatively transferred and mixed 16,100 ETH via Tornado Cash, equivalent to roughly $40 million at current prices, accounting for over 80% of the $48.8 million lost in the KyberSwap attack in November 2023. Some of the stolen funds have not yet been fully transferred.
Relevant content
Preview: The U.S. May core PCE data will be released at 20:30 tonight, and is projected to hit its highest level since October 2023.
The Fed’s key inflation gauge, the Personal Consumption Expenditures (PCE) price index, will be released at 20:30 tonight, with markets expecting a sharp rise in May inflation that could reignite rate hike bets. The headline PCE year-over-year growth rate is projected to hit 4.1% in May, up from 3.8% in April and marking its highest level since 2023. Core PCE, which excludes food and energy, is forecast to rise to 3.4% year-over-year, up from 3.3% in April and its highest reading since October 2023. Core PCE has remained above the Fed’s 2% inflation target since 2021. The recent short-term inflation uptick was driven mainly by surging gasoline prices amid the Iran conflict in May. Oil prices have since edged lower following the signing of a peace deal between the U.S. and Iran, but core inflation has strengthened in tandem, indicating that price pressures are not solely tied to geopolitical oil shocks. Data from the CME FedWatch Tool shows that as of Wednesday, markets are pricing in a 34% probability of a 25 basis point rate hike in July. Aditya Bhave, U.S. economist at Bank of America Securities, noted that the recent inflation rebound stems in part from tariffs and one-off disruptions, but successive supply shocks have eroded the Fed’s patience, while deflationary room in the housing sector has largely been exhausted. Data shows that core PCE dipped to 2.6% in April, its lowest level since 2022, but annualized core PCE growth over the past three and six months has hovered near 3.8%.
4 minutes ago
SK Hynix plans to list on NASDAQ on July 10: A crypto whale opens 90% of its bullish positions in a single day, with all $21.27 million in long positions in unrealized profit.
According to Hyperinsight’s monitoring, SK Hynix officially announced its U.S. listing date today, targeting a July 10 debut on the NASDAQ. The company had previously disclosed a over $29 billion listing fundraising plan yesterday afternoon. Driven by listing optimism, SKHX surged 14% intraday, hitting $1930 at press time, with a daily trading volume of $407 million and open interest of $237 million. Since the news broke yesterday, 10 whales have built positions in SKHX on Hyperliquid, 9 of which opened long positions totaling around $21.27 million, at an average entry price of ~$1797.8 and average unweighted liquidation price of ~$1390.6. With price gains, all 9 long positions are now in unrealized profit. Market data shows that positions of over $1 million amount to roughly $140 million, with a long-short ratio (longs/shorts) of ~0.715. The average entry price for longs is ~$1672, while shorts average ~$1640. The nearest short liquidation threshold stands at $2149, just $200 away from the current price, mounting short-side pressure. -HyperInsight Bot is now live. Add @HyperInsightBot to your Telegram group, set it as admin (enable message sending permission) to auto-sync on-chain updates.
4 minutes ago
The "Retail vs. Wall Street" concept-linked token WEN continues its strong run, rising over 18% in after-hours trading.
According to Bitget market data, Wendy's (WEN) rallied 25.66% in the regular trading session, then climbed an extra 18.96% in after-hours trading, now changing hands at $9.35. Earlier reports noted that Serenity took to Twitter to mock the latest meme stock movement unfolding on Reddit's high-risk trading communities, targeting U.S. fast-food chain Wendy's. The Reddit community's meme warning reads: "If Wendy's goes bankrupt, we'll all be out of jobs, and after losing all our trading money, we'll have to work behind Wendy's trash cans." Serenity later clarified that they hold no positions, only found the activity amusing, and added they were unsure if the campaign would succeed. Wendy's holds a special cultural status on Reddit's WallStreetBets community; for years, "working behind Wendy's trash cans" has been a staple joke among retail investors mocking their trading losses.
4 minutes ago
Danske Bank: Federal Reserve may raise interest rates at least twice
Danske Bank senior analyst Kirstine Kundby-Nielsen and chief analyst Jens Peter Sorensen stated in a report that they expect the U.S. Federal Reserve to raise interest rates twice, in December 2026 and March 2027 respectively, bringing the federal funds rate to 4.00%-4.25%. "However, we emphasize there is a risk that rate hikes could come earlier and that the number of hikes may exceed two," they said. The first Federal Reserve meeting led by Kevin Warsh sent a clear signal that the Fed is increasingly moving away from forward guidance surrounding future monetary policy decisions. "All signs indicate that (the Fed) is leaning toward having greater discretion in future policy decisions," the Danske Bank analysts added. Source: Jin10
4 minutes ago
SK Hynix's stock price rise widened to 15.4%, while Samsung Electronics gained 6.3%.
According to Bitget data, SK Hynix’s stock price gain has widened to 15.4%, with Samsung Electronics up 6.3%.
4 minutes ago
The entire cryptocurrency market is down across the board; funding rates indicate BTC remains in bearish territory, while ETH’s bullish sentiment is significantly stronger than BTC’s.
According to HTX market data, Bitcoin is currently trading at $61,684.51, down 1.88% in the past 24 hours; Ethereum is at $1,647.36, down 1.48% over the same period. Current funding rates on major centralized exchanges (CEXs) show a clear divergence between BTC and ETH: BTC rates across all platforms have fallen back into bearish territory, while ETH rates on most platforms remain above the neutral range, indicating significantly stronger bullish sentiment for ETH than BTC. BlockBeats Note: Funding rates are fees set by cryptocurrency trading platforms to maintain the balance between contract prices and underlying asset prices, typically applicable to perpetual contracts. They serve as a fund exchange mechanism between long and short traders; platforms do not collect these fees, instead using them to adjust the cost or return of traders holding contracts, so that contract prices stay close to the underlying asset prices. A funding rate of 0.01% is the benchmark. A rate above 0.01% indicates broad bullish market sentiment, while a rate below 0.005% signals widespread bearish sentiment.
Federální odvolací soud rozhodl, že OFAC překročil svou pravomoc, když sankcionoval neměnné chytré kontrakty Tornado Cash. Soud uvedl, že takový kód nelze podle stávajícího práva považovat za majetek, na který lze uvalit sankce.
The following is a guest article from Matthew Niemerg, co-founder of Aleph Zero.
The Fifth Circuit Court of Appeals handed down a landmark ruling yesterday that could fundamentally reshape how cryptocurrency protocols are regulated. In Van Loon v. Department of Treasury, the court found that the Treasury Department's Office of Foreign Assets Control (OFAC) exceeded its authority when it sanctioned Tornado Cash's immutable smart contracts.
The ruling hinges on a deceptively simple question: can computer code that cannot be modified or controlled be considered “property”? The appellate court's answer was an emphatic no.
Tornado Cash is a cryptocurrency anonymizing service that helps preserve privacy by pooling users' digital assets together, making transactions harder to trace. In 2022, OFAC sanctioned it after North Korean hackers allegedly used it to launder over $455 million in stolen funds. But the court found that since Tornado Cash's core protocols are “immutable” – meaning they cannot be changed or controlled by anyone – they don't qualify as property that can be sanctioned under existing law.
A Watershed Moment for Crypto“Because these immutable smart contracts are unchangeable and unremovable, they remain available for anyone to use,” wrote Judge Don Willett, noting that even under sanctions, “the targeted North Korean wrongdoers are not actually blocked from retrieving their assets.”
This represents a watershed moment for the cryptocurrency industry. For the first time, a federal appeals court has acknowledged that certain decentralized protocols operate entirely as something completely different from traditional property or businesses. Since no one “owns” the protocols underlying email or the web, these autonomous smart contracts exist independent of any controlling entity.
The implications are significant. The ruling effectively creates a safe harbor for truly decentralized protocols that cannot be modified or controlled. While OFAC can still sanction individuals and companies, it cannot sanction the underlying code itself – at least under current law.
Balancing Privacy and SecurityHowever, the court explicitly left the door open for Congress to update the 1977 International Emergency Economic Powers Act (IEEPA) to address modern technologies. “Perhaps Congress will update IEEPA, enacted during the Carter Administration, to target modern technologies like crypto-mixing software,” the ruling noted. “Until then, we hold that Tornado Cash's immutable smart contracts…cannot be blocked under IEEPA.”
CryptoSlate Daily Brief
Daily signals, zero noise.Market-moving headlines and context delivered every morning in one tight read.
5-minute digest 100k+ readers
Free. No spam. Unsubscribe any time.
You’re subscribed. Welcome aboard.
This highlights the broader challenge of regulating privacy-preserving technologies that can be used for both legitimate and illegitimate purposes. As the court record shows, Tornado Cash was used by individuals seeking to protect their privacy when donating to Ukrainian war efforts and avoid harassment. But it was also exploited by bad actors for money laundering.
The crypto industry still has work to do in preventing illicit use while preserving privacy rights. Some proposed approaches include allowing users to voluntarily prove the legitimacy of their funds, or implementing “anonymity revoking” systems that could unmask users only under specific circumstances with proper oversight.
The Path ForwardJudge Willett acknowledged the government's concerns about illicit finance as “undeniably legitimate.” But he emphasized that courts must apply the law as written, not “tinker with it.” The ruling concludes:
“Mending a statute's blind spots or smoothing its disruptive effects falls outside our lane.”
This balanced approach – recognizing both the importance of preventing criminal activity and the need to protect privacy-enhancing innovation – points the way forward. Rather than trying to force new technologies into old regulatory frameworks, legislators need to craft updated laws that understand the unique nature of decentralized systems while addressing legitimate security concerns.
For now though, this ruling represents a victory for technological innovation and a recognition that not everything in the digital age fits neatly into traditional legal categories of property and ownership. The challenge ahead is building a regulatory framework as sophisticated as the technology it aims to govern.
Following the March 9 attack orchestrated by a malicious actor on Unizen, a decentralized finance (DeFi) protocol, which resulted in the loss of around $2.1 million, it has now been revealed that the hacker behind the attack has moved the stolen assets to Tornado Cash.
In a post by blockchain security firm PeckShield, it was revealed that the hacker moved 2,179,859 DAI from the wallet used in the attack to an unknown wallet on August 7. They then changed the DAI into 865.4 Ether (ETH) and sent it to Tornado Cash in 26 separate transactions. This will be the first time the stolen Unizen funds have been moved since the attack 151 days ago.
After the March exploitation, the Unizens said they would return the stolen funds to users. The plan was led by the CEO Sean Noga, who released personal money to the company to pay back users who lost less than $750,000. For people who lost more, the company said they would look at each case separately.
More so, days after the attack, Unizen chief technology officer, Martin Granström, stated that the company is working with security experts and law enforcement agencies to track down the hacker’s identity. He noted that they gathered various evidence and can now proceed with the post-mortem.
In the same post, he assured users that the firm would invest more in improving its security with every new upgrade as they owed it to their community. However, despite the firm’s effort to catch the bad actor, it does not seem like they have made any headway, as the hacker now has zero balance in their wallet.
Crypto Hacking: A Growing Concern in the Industry The attacker used a decentralized mixer that makes it hard to trace the origin of cryptocurrency transactions. Bad actors often deploy this tactic to hide stolen money.
Similar scenarios have occurred in other major hacks, such as the $308 million hack of the DMM Bitcoin system. In that case, the hackers used Huione Guarantee, an online marketplace that lets people do scams and other shady things, to launder the stolen assets.
Recently, another DeFi protocol Nexera was hacked, and a sum of $1.5M was exploited, which resulted in the company warning its users to stop trading the NXRA token. It was also revealed that the bad actor has already started selling the token for ETH and has already bridged some to the BNB chain.
The bad actor’s address behind the Nexera attack was said to be connected to recent private key compromise cases, such as Concentric Finance, OKX DEX, and Serenity Shield.
The continuous cyber attacks in the crypto space show the need for further industry security improvement. Many investors have lost a lot of funds because bad actors are becoming more rampant. The attack on WazirX last month, which resulted in the loss of over $230 million, further testifies why a quick solution needs to be found to mitigate the act.
Disclaimer: Coinspeaker is committed to providing unbiased and transparent reporting. This article aims to deliver accurate and timely information but should not be taken as financial or investment advice. Since market conditions can change rapidly, we encourage you to verify information on your own and consult with a professional before making any decisions based on this content.
Cybersecurity News, News
Temitope is a writer with more than four years of experience writing across various niches. He has a special interest in the fintech and blockchain spaces and enjoy writing articles in those areas. He holds bachelor's and master's degrees in linguistics. When not writing, he trades forex and plays video games.
Binance automaticky převede 10 delistovaných tokenů na USDC a do 28. dubna 2025 připíše odpovídající hodnotu do peněženek uživatelů. Mezi nimi jsou VAI, TORN, OMG, WAVES, XEM, BOND, DOCK, MDX, POLS a PURSE.
In a blog post on Tuesday, Binance Exchange, the largest crypto trading platform by volume, announced the automatic conversion of several delisted tokens to USDC.
This action will be executed based on the average token to USDC exchange rate within the conversion period.
What Binance Exchange Users Need To KnowAfter delisting 10 tokens from its catalog, Binance said in a follow-up message that it would convert them to USDC automatically, enabling holders to access their funds. After the conversion happens, the exchange will credit the stablecoin equivalent of the affected tokens to users’ wallets by April 28, 2025. The tokens include:
Vai (VAI) Tornado Cash (TORN) OMG Network (OMG) Waves (WAVES) NEM (XEM) BarnBridge (BOND) Dock (DOCK) Mdex (MDX) Polkastarter (POLS) Pundi X PURSE (PURSE) Read more: Binance Review 2024: Is It the Right Crypto Exchange for You?
Holders of these tokens should adjust their trading strategies accordingly to prepare for the upcoming changes. Failure to do so by October 28 would see them automatically converted to USDC, effectively phasing out the affected tokens from the exchange.
“During the Conversion Period [between October 29, 2024 and April 28, 2025], users will not be able to view the above tokens in their Binance wallets,” Binance articulated.
In this regard, it is worth mentioning that the history of Binance’s tokens delisting often inspires volatility. For instance, the exchange delisted six altcoins around mid-August, causing double-digit price drops for PowerPool (CVP) and Ellipsis (EPX). These tokens also featured among the delisted assets.
However, Binance is not only removing several tokens but also adding new ones to its platform. One of the notable additions is Scroll (SCR), a zkRollup scaling solution for Ethereum.
As per the announcement, SCR will be listed on October 11, with pre-market trading for the SCR/USDT pair set to open. This move supports Ethereum’s scalability by enabling faster, more efficient transactions while maintaining security and decentralization.
“Binance is excited to announce the 60th project on Binance Launchpool – Scroll (SCR), a Bytecode-level compatible zkEVM Rollup,” an excerpt in Binance’s announcement read.
Read more: What are Crypto Airdrops?
With this listing notice, Binance becomes the first platform to list Scroll’s powering token. The exchange will also airdrop 55,000,000 SCR, representing 5.5% of the total supply. Airdrop farming will start on Wednesday, October 9. The participants must lock their BNB and FDUSD to receive the SCR tokens.
Fluid na Ethereu byl zneužit přes mechanismus odměn a útočník odcizil asi 215 000 USD v aktivech. Zasaženy byly jen distribuce odměn, ostatní části projektu zůstaly nedotčeny.
PANews reported on June 1st that, according to BlackHart, the reward distribution mechanism of the DeFi project Fluid on Ethereum was exploited, resulting in the theft of approximately $215,000 in assets. Fluid employs a Merkle reward list mechanism where one key initiates and another approves. The attacker possessed both operating private keys, submitted and approved a list of rewards to be distributed only to themselves, and then used a null proof to complete the claim. The stolen assets came from three reward distributors, including 112,883 FLUID, 47,903 GHO, and a small amount of cbBTC, which were later exchanged for ETH and transferred via Tornado Cash. Fluid's lending market, vault, DEX, and user deposits were unaffected. The team replaced the compromised key and transferred the remaining reward funds within approximately 10 hours, but the public statement only mentioned that reward claims were temporarily suspended, without mentioning details of the private key leak and the loss.