Live financial news intelligence

Track market-moving stories before they get noisy

Real-time pulse of financial headlines curated from 5 premium feeds.

Latest market signal Czech Filtered by asset TORN
Coverage 165,954 Raw stories ingested 21,798 rewritten in CS_CZ • 0 to rewrite (last 2 days).
Agents 7 waiting Pipeline agents
  • FMP Stock News Fetch every minute 53s ago
  • FMP Forex News Fetch every 5 min 2m ago
  • CoinGecko News Fetch every 5 min 4m ago
  • FIO Stock News Fetch every 10 min 2m ago
  • Patria Stock News Fetch every 10 min 2m ago
  • Editorial rewrite Rewrite every minute 53s ago
  • Asset sync Assets every 1 hour 51m ago

Latest coverage

Market News Feed

Scan headlines quickly, then expand any story for source context.

View
Language
Relevance
Clear
Details Date Content Source Relevance
2026-09-04 07:33 5d ago
2026-09-04 05:45 5d ago
Notional Finance čelí podezření na exploit za 1,7 milionu USD
TORN Tornado Cash USDC USD Coin
CoinGecko News 88
Original source text
Notional Finance may have suffered a $1.7 million exploit involving an escrow contract, blockchain investigators reported on Sept. 4. The reported losses include approximately $69,242 in DAI and $1.66 million in USDC.

Summary

Researchers reported $1.7 million in DAI and USDC leaving an escrow contract linked to Notional. The reported losses comprise $69,242 in DAI and $1,658,423 in USDC, according to Specter researchers. The suspected attacker exchanged the stablecoins for 689.2 ETH before depositing funds into Tornado Cash. PeckShield cited Specter’s findings, while Notional had not publicly confirmed the incident when last checked. The exploit’s technical cause, affected users and prospects for recovering assets remain publicly unconfirmed. Security firm PeckShield cited findings published by blockchain investigation group Specter. Neither report provided a complete technical explanation of how the assets left the contract.

“The Notional Finance escrow contract may have been exploited,” PeckShield said, preserving uncertainty about the incident’s status.

#PeckShieldAlert Specter has reported that the Notional Finance escrow contract may have been exploited, resulting in $1.7M in ethereum:0x6b175474e89094c44da98b954eedeac495271d0f and $USDC lost.
The exploiter has swapped the stolen funds into 689.2 $ETH and deposited them into… pic.twitter.com/Wd5Dc3MWtL

— PeckShieldAlert (@PeckShieldAlert) September 4, 2026 Notional Finance exploit report identifies two addresses Researchers identified two Ethereum addresses allegedly connected to the movement of the assets. The first address is 0xC954…De69, while the second is 0xDaCC…Ce38.

The addresses were labelled as theft addresses by Specter. That description remains an investigator attribution rather than a finding confirmed by Notional Finance, law enforcement or a court.

The available reports do not identify the precise escrow function involved. They also do not establish whether the event resulted from a smart-contract vulnerability, compromised credentials, faulty permissions or another cause.

Stablecoins were reportedly converted into 689.2 ETH The suspected attacker reportedly exchanged the DAI and USDC for approximately 689.2 ETH. The Ether was then deposited into Tornado Cash, according to Specter and PeckShield.

Tornado Cash is a set of Ethereum smart contracts designed to reduce the visible connection between deposits and later withdrawals. Its use can complicate blockchain tracing, although depositing assets into the protocol does not independently prove criminal ownership or intent.

The rapid conversion of stablecoins may also reduce opportunities for issuers or centralized platforms to restrict the assets. Both DAI and USDC can be followed publicly before conversion, while subsequent withdrawals from a mixer become harder to associate with the original address.

In related coverage, crypto.news reported that an address tied to the Drift Protocol exploiter moved $44 million through Tornado Cash after remaining inactive for several months.

No technical cause or official response is available Notional Finance had not published a public incident report or confirmation through its official account when checked. The project had also not disclosed whether contracts were paused, whether remaining assets were secured or whether users needed to take protective action.

The lack of confirmation means the reported $1.7 million loss should remain described as preliminary. It is also unclear whether the affected assets belonged directly to users, the protocol treasury or another party using the escrow contract.

No verified market reaction can be attributed to the report. Without an official assessment, linking token-price movements or changes in deposited value directly to the suspected exploit would be premature.

Previous recoveries depended on rapid containment DeFi projects commonly respond to suspected exploits by pausing vulnerable contracts, contacting stablecoin issuers and exchanges, tracing connected wallets and offering return agreements. Those options can become more limited after assets enter privacy protocols.

Some projects have still recovered positions or protected unaffected products after an attack. As crypto.news reported, Term Labs recovered its affected fixed-rate positions following an $8.5 million governance exploit, although several products remained closed.

Stake DAO also secured its Ethereum backing and closed a bridge after an unauthorized minting incident, according to related coverage. Those cases involved direct project responses that are not yet available for Notional Finance.

Meanwhile, Notional Finance operates as an Ethereum-based lending protocol focused on fixed-rate, fixed-term borrowing. Its documentation explains that deposited currencies can support borrowing obligations denominated in other currencies. 

This makes contract-level accounting and collateral controls central to maintaining solvent user positions. However, researchers have not established whether the reported escrow incident affected Notional’s primary lending system, a separate integration or an older contract.

DAI and USDC have long formed part of Notional’s supported lending markets. The protocol’s technical materials describe currency pairs connecting those stablecoins with their interest-bearing equivalents. 

The reported loss therefore involves assets used within Notional’s broader lending architecture, but the available evidence does not show that open loans, collateral balances or fixed-term positions were affected. An official contract identification is needed before the exposure can be measured accurately.

What happens next for Notional Finance The next confirmed update would likely need to establish which contract was involved, how the transactions were authorized and whether other funds remain exposed. A post-mortem could also clarify the ownership of the lost assets.

Investigators may continue tracking any Ether withdrawn from Tornado Cash. Exchanges and blockchain analytics companies could monitor later transactions, but the reported mixer deposits make attribution and recovery more difficult. Until Notional publishes an assessment, the scale, cause and effect on users remain unresolved.
2026-09-04 05:13 5d ago
2026-09-04 03:38 5d ago
Adresa spojená s hackem Tectonic přesunula 6,65 milionu USD do Tornado Cash
TONIC Tectonic TORN Tornado Cash
CoinGecko News 92
Original source text
PeckShield reported that an address tied to the Tectonic hack transferred 2,658.9 ETH, valued at $6.65 million, to Tornado Cash on September 3. The incident has drawn attention from exchanges and blockchain investigators, as the move represents one of the largest unrecovered sums following the Cronos network exploit on August 30.

Chain rollback leaves funds on Ethereum untouchedTectonic, recognized as the leading lending platform on Cronos, experienced a major security breach that prompted validators to halt the blockchain within hours. Cronos, a blockchain network built by Crypto.com, later announced the restoration of block production from block 90,896,189, rolling the chain back to just before the hack.

Though the rollback reversed nearly all funds connected to the attacker within the Cronos chain, it could not reclaim assets already bridged to Ethereum. Approximately $74 million in stolen funds were traced by PeckShield across three addresses. Of this amount, $60 million remained in one Cronos wallet, $8 million in a second, and $6 million on Ethereum.

Independent data showed the Ethereum balance at 2,592.2152 ETH, or $6.29 million, after the incident. According to TRM Labs, the attacker moved stolen funds initially using USDC, then converted them into roughly 2,500 ETH.

On-chain researchers, including Weilin Li, used $75 million as the estimated total loss, while archive-node analyses suggested that up to $119.5 million may have been impacted if contracts deployed by the attackers before the exploit are included.

SourceTotal Stolen ($ Million)Funds on Cronos ($ Million)Funds on Ethereum ($ Million)PeckShield74686TRM Labs / Weilin Li75UnspecifiedUnspecifiedArchive-node analysis119.5Includes contractsIncludes contractsPrice manipulation triggers catastrophic lossesSecurity firm TRM Labs explained that the attacker exploited TONIC, the native token of Tectonic, which had only $305,000 in weekly trading volume prior to the incident and a 20% collateral ratio. Halborn, a blockchain security company, found that the hacker artificially inflated the price of TONIC by nearly 100 times within 20 minutes, then used the overpriced token to borrow high-value assets from nine lending platforms.

Subsequent investigations revealed a second attacker’s wallet, raising the lost value estimate from $66 million to $75 million. The hack caused Tectonic’s total value locked (TVL) to plummet from $121.7 million to just $3 million, as tracked by DeFiLlama.

The attack on Tectonic hollowed out the platform, with TVL plunging more than $118 million within hours.

Tornado Cash remains the key laundering avenueWhile the $6.65 million transacted via Tornado Cash represents a smaller portion of the overall exploit, the transaction route stands out due to Tornado Cash’s continuing role in crypto money laundering. TRM Labs documented that Tornado Cash received over $700 million in 2026 through June alone, making it the largest mixer protocol on Ethereum networks.

Besides being used to conceal illicit transactions, Tornado Cash has also supported legitimate privacy needs. The US Treasury removed the protocol from its sanctions list on March 21, 2025, but it remains under close watch for its role in facilitating major attacks.

The Cronos network’s rollback sparked a discussion about blockchain finality. Halborn emphasized that rolling back the chain limited losses but also undermined confidence in ledger immutability. Amid this uncertainty, CRO, Cronos’s native token, lost about 10% of its value in one day.

Mini dictionary: Tornado Cash, a decentralized privacy protocol on Ethereum, allows users to mix coins and obscure transaction trails, making it popular among both privacy advocates and cybercriminals seeking to launder assets.

Tornado Cash plays a pivotal role in laundering stolen cryptocurrency, remaining critically important to law enforcement, exchanges, and the wider crypto ecosystem.

Record rise in price-manipulation attacksThe Tectonic exploit mirrors a broader spike in price-manipulation attacks this year. PeckShield counted 50 major hacks in August alone, a 67% increase from July’s 30 incidents, though total losses decreased to $136.3 million from July’s $270 million. Among these, the Tectonic incident accounted for the largest loss of the month and ranked as the fourth-largest crypto theft in 2026.

TRM Labs has recorded 32 price-manipulation exploits so far in 2026, setting a new yearly record. Experts highlight that attackers often exploit low-liquidity tokens when protocols assign them significant collateral power, enabling rapid losses across protocols and networks.

The Tectonic case demonstrated how quickly such attacks can escalate, progressing from price manipulation to cross-chain laundering, and ultimately challenging the industry’s security and regulatory frameworks.
2026-09-03 10:33 6d ago
2026-09-03 09:52 6d ago
Zastaralý kontrakt Rain na Solaně umožnil krádež asi 1,1 milionu USD
SOL Solana TORN Tornado Cash
CoinGecko News 92
Original source text
TLDR An outdated Rain Solana contract allowed unauthorized withdrawals from card collateral accounts across multiple programs. Blockaid estimated about $1.1 million was stolen, with proceeds later entering Tornado Cash on Ethereum. Avici reported $500,859 drained from 1,685 users, while Tria identified $431,945 affecting 636 customers. Rain said every program using the vulnerable contract version has been upgraded since the attack. Self-custodial wallets were unaffected because the attacker targeted separate contracts holding funded card balances. An attacker exploited an outdated Rain card contract on Aug. 28, taking about $1.1 million from stablecoin card programs on Solana. Blockchain security firm Blockaid tracked the incident and published its findings.

Rain provides infrastructure that lets crypto companies issue cards funded with stablecoins. Customer deposits move into collateral accounts controlled by onchain contracts.

These collateral accounts are separate from a user’s personal wallet. Their safety depends on the code and controls set up by the infrastructure provider.

Blockaid found four contract deployments sharing the same code as the flawed version. The attacker drained funds from at least two of them.

Earlier today, Rain’s monitoring systems discovered a vulnerability impacting a small number of programs using an outdated version of our Solana contracts. Other programs were not impacted. Rain immediately launched an investigation to determine the full scope of the situation.…

— Rain (@raincards) August 28, 2026

How the Exploit Worked The outdated contract required two separate approvals before certain actions could happen. It used Solana’s Ed25519 verification system to check signatures.

Blockaid said the attacker reused one signature so it looked like two separate approvals. This let the attacker bypass the requirement without permission from account owners.

An attacker exploited an outdated Rain contract, draining $1.1M in user card balances from @avici, @useTria, and other crypto neobanks.

Blockaid's Onchain Monitoring gives stablecoin card issuers the capability to detect exploits across their fleet of contract deployments.

Read… pic.twitter.com/vzMQfPkdtT

— Blockaid (@blockaid_) September 2, 2026

After bypassing the check, the attacker gave itself admin access over individual accounts. It then withdrew USDC and USDT from those accounts.

Blockaid recorded 2,945 admin additions and 5,288 withdrawal calls. In total, it counted 8,233 exploit transactions over about two hours and 29 minutes.

The first two withdrawals happened three seconds apart. This pace suggests the attacker had built a system to target many accounts quickly.

Where the Funds Went The stolen stablecoins were sent to one Solana wallet. The attacker then swapped them for SOL using decentralized exchanges.

Blockaid traced the funds from Solana to Ethereum through the deBridge cross-chain protocol. About 455.9 ETH entered Tornado Cash between 19:20 and 19:49 UTC.

Tornado Cash mixes deposits so withdrawals can’t easily be linked to the original wallet. Blockaid said the funds had not been recovered as of its report.

Two Ethereum addresses were linked to the early funding of the attacker’s Solana activity. Neither Rain nor law enforcement has named who controls those addresses.

Avici said the attacker took $500,859.22 from 1,685 users. The company refunded all affected customers and added 10% cashback.

Tria reported losses of about $431,945 across 636 customers. It said each customer would be reimbursed.

Blockaid also named Solayer Pay as an affected program, though no confirmed loss figure was available for it. The gap between disclosed losses and Blockaid’s $1.1 million estimate has not been fully explained.

Avici’s token dropped 49% from its daily high after news of the exploit spread. It reached a low of $0.217 before recovering some value. Tria’s token also fell more than 10% at one point.

Rain said every program running the outdated contract has been upgraded. The company reported no further unauthorized activity since making the changes.

Rain has not released a full technical report or explained why older contract versions remained in use. It also has not said whether an audit caught the flaw before the attack happened.
2026-08-30 14:15 10d ago
2026-08-26 07:25 14d ago
Soud odložil nové projednání kauzy Romana Storma na 2027
TORN Tornado Cash
CoinGecko News 78
Original source text
A U.S. federal judge has pushed Tornado Cash co-founder Roman Storm’s retrial to April 26, 2027, about six months later than planned, while his motion seeking to overturn his existing conviction remains unresolved.

Summary

Roman Storm’s retrial has been moved from October 2026 to April 26, 2027. His pending acquittal motion challenges his 2025 money transmitting conviction. Storm still faces money laundering and sanctions charges carrying up to 20 years each. The first jury deadlocked on both charges after convicting Storm on one separate count. The Aug. 25 court order states that U.S. District Judge Katherine Polk Failla granted Storm’s request to postpone the proceedings, moving the retrial from an October 2026 timetable after his defense cited scheduling conflicts and the pending motion for judgment of acquittal.

Storm filed the Rule 29 motion on Sept. 30, 2025, challenging his conviction for conspiracy to operate an unlicensed money transmitting business on the grounds that prosecutors had not presented enough evidence to sustain the verdict. Failla heard oral arguments on April 9, 2026, but had not ruled on the request when she issued the latest scheduling order.

Under the revised calendar, Storm will face another jury on two charges left unresolved during his first trial: conspiracy to commit money laundering and conspiracy to violate U.S. sanctions. Each carries a maximum prison sentence of 20 years.

Roman Storm retrial has been moved to April 2027 Storm’s defense asked Failla earlier in August to schedule the retrial no sooner than April 2027, according to the court proceedings, while prosecutors opposed extending the case and preferred the earlier October timetable.

The judge ultimately adopted the defense’s requested date of April 26, 2027, and reset the other pretrial deadlines around it. Expert disclosures will now take place in early 2027, with a final pretrial conference scheduled for April 20, six days before the trial is due to begin.

The new schedule reverses the timetable prosecutors had sought several months earlier. In March, crypto.news reported on prosecutors seeking an October retrial after the first jury failed to return unanimous verdicts on the money laundering and sanctions charges.

At the time, Storm said another trial would expose him to as much as 40 years in federal prison if he were convicted on both unresolved counts. He also said his legal resources had been heavily depleted during the first four-week trial.

The pending Rule 29 motion could affect another part of the case before Storm returns to court. Under the federal rule, a judge may enter a judgment of acquittal when the evidence introduced at trial is legally insufficient to support a conviction.

If Failla grants Storm’s motion, his conviction on the unlicensed money transmitting charge could be set aside. If the motion is denied, the conviction would remain in place while prosecutors proceed with their second attempt to secure verdicts on the two charges on which the original jury deadlocked.

The first jury convicted Storm on only one count Storm went to trial in Manhattan in the summer of 2025 on three criminal charges stemming from his involvement with Tornado Cash, the Ethereum-based privacy protocol he co-founded.

After several weeks of testimony and four days of deliberations, jurors returned a split verdict on Aug. 6, 2025. They found Storm guilty of conspiring to operate an unlicensed money transmitting business but could not unanimously decide the money laundering and sanctions conspiracy counts.

Failla declared a mistrial on the two unresolved counts, leaving prosecutors with the option to try Storm again before another jury.

The charge on which Storm was convicted carries a maximum sentence of five years in prison. The two counts awaiting retrial carry substantially higher penalties, with up to 20 years available on each if a conviction is secured.

Before the first trial began, the Justice Department had already reduced part of its case. In May 2025, prosecutors narrowed the money transmission allegation by dropping the portion based on Storm’s alleged failure to comply with federal money transmitter registration requirements under 18 U.S.C. § 1960(b)(1)(B).

Prosecutors continued with the remaining money transmission theory and the money laundering and sanctions allegations, saying their decision was consistent with an April 2025 Justice Department policy memorandum that instructed federal prosecutors to avoid using criminal cases to regulate the crypto industry through technical registration violations.

Storm was originally charged in August 2023 alongside Tornado Cash co-founder Roman Semenov. U.S. prosecutors accused the pair of helping operate a service that processed more than $1 billion in criminal proceeds, including funds connected to North Korea’s Lazarus Group.

The government’s case has focused partly on whether Storm and his co-founders continued developing, promoting and financially benefiting from Tornado Cash despite knowing that criminals and sanctioned actors were using the protocol.

Storm’s lawyers have disputed that interpretation, arguing that Tornado Cash operated through decentralized smart contracts and that its developers did not control individual transactions or take custody of funds moving through the protocol.

Tornado Cash sanctions were removed before the trial Tornado Cash allows users to deposit cryptocurrency into smart contracts and later withdraw funds to a separate address, reducing the direct on-chain connection between the sending and receiving wallets.

The U.S. Treasury Department’s Office of Foreign Assets Control sanctioned the protocol in August 2022, accusing it of being used to launder billions of dollars in virtual currency, including funds stolen by the Lazarus Group.

Legal challenges to those sanctions later produced an outcome separate from Storm’s criminal prosecution. In November 2024, the U.S. Court of Appeals for the Fifth Circuit ruled that immutable Tornado Cash smart contracts could not be treated as property under the International Emergency Economic Powers Act because they could not be owned or controlled.

Treasury subsequently removed Tornado Cash sanctions on March 21, 2025, reversing the designation imposed in 2022. The department continued to warn about North Korea’s use of digital assets for cybercrime and illicit financing after withdrawing the designation.

The sanctions decision did not terminate the criminal proceedings against Storm. Prosecutors continued arguing that his conduct before and during the period covered by the indictment could support the separate conspiracy charges.

An additional sanctions lawsuit brought by Coin Center was later closed after the government stopped defending the Tornado Cash designation following its removal.

Developer control remains disputed in Storm’s case Questions over how much control a software developer must exercise over a decentralized protocol before facing criminal liability have remained central to Storm’s defense.

Prosecutors have argued that Storm’s role went past publishing open-source software, alleging that Tornado Cash’s founders maintained parts of the project, promoted its use and profited from it while knowing illicit funds were passing through the protocol.

The defense has countered that Tornado Cash’s immutable smart contracts could continue operating without Storm and that users could interact with the contracts without the developers approving individual transfers.

Support for Storm has also come from parts of the Ethereum community. In January 2026, Ethereum co-founder Vitalik Buterin called for sentencing leniency and argued that privacy software can serve lawful purposes while open-source development should not by itself establish criminal liability. The report said Storm’s legal defense had raised more than $6.3 million with support from Buterin, the Ethereum Foundation and other donors.

The Ethereum Foundation had previously pledged up to $1 million in matching support for Storm’s legal defense following the 2025 verdict, while Storm remained free on bond as the criminal proceedings continued.

Failla has not issued a decision on Storm’s Sept. 30, 2025 Rule 29 motion. Under the new court schedule, the final pretrial conference on the unresolved money laundering and sanctions charges is set for April 20, 2027, with the retrial scheduled to start on April 26.
2026-08-20 16:28 19d ago
2026-08-20 12:18 20d ago
Uživatel Ethereum přišel po phishingu o 810 ETH
ETH Ethereum TORN Tornado Cash
CoinGecko News 78
Original source text
An Ethereum user reportedly lost 1,010 ETH after following an old Tornado Cash bookmark that allegedly redirected to a malicious frontend controlled by phishing attackers.

Summary

An Ethereum address received 810 ETH through nine transfers on August 18, onchain records confirm. Community reports claimed 1,010 ETH was stolen after a user visited a suspected phishing frontend. The cited wallet retained approximately 810 ETH, worth about $1.86 million when records were checked. Claims that attackers stole nearly 4,000 ETH over twelve months remain independently unverified by researchers. Tornado Cash’s website was accessible when checked, leaving the alleged domain takeover without official confirmation. Community accounts said the incident unfolded over approximately 12 hours. They alleged that attackers obtained the victim’s Tornado Cash deposit credentials and withdrew the funds before transferring them to several addresses.

Onchain records provide partial confirmation. The cited wallet received 810 ETH through nine transactions on Aug. 18. Eight transfers carried 100 ETH each, while the final transfer carried 10 ETH.

The transactions occurred between 5:56 a.m. and 6:05 a.m. UTC. The address retained approximately 810 ETH, valued by Etherscan at about $1.86 million when checked on Aug. 20.

Ethereum records confirm 810 ETH, not the full claim The verified transactions leave a 200 ETH gap between the 1,010 ETH loss reported by community users and the 810 ETH held by the cited wallet. The remaining amount may have reached another address, but no additional destination was included in the supplied evidence.

User Loses Over 1,000 ETH in Phishing Attack After Using Tornado Cash’s Expired Official Domain

According to community users, a user clicked an old link left in a related bookmark and was redirected to a phishing site through the expired official domain tornado. cash, which had… pic.twitter.com/8j7eQl3qX2

— Wu Blockchain (@WuBlockchain) August 20, 2026 No public statement from Tornado Cash, an established blockchain security firm or the reported victim had independently confirmed the full amount when this article was prepared.

Community accounts claimed the victim tracked a total loss of 1,010 Ethereum, but the provided address independently confirms only 810 Ethereum.

The cited wallet had recorded nine transactions and no outgoing transfer at the time of review. Its balance therefore supports the claim that most of the reported funds remained under the suspected attacker’s control.

At Ether’s price of approximately $2,295, the confirmed 810 Ethereum was worth about $1.86 million. The reported 1,010 Ethereum loss would be worth roughly $2.32 million at the same price.

Tornado Cash domain takeover remains unconfirmed Reports blamed the theft on the tornado.cash domain, claiming it expired after the project’s team failed to renew it during the disruption caused by U.S. sanctions. According to the accounts, an attacker subsequently registered the address and installed a fake user interface.

That account could not be fully verified. The domain was accessible and displayed a Tornado Cash interface when checked. No authoritative domain record, official Tornado Cash warning or named security researcher was found confirming that the address had expired and changed ownership.

Claims that the official domain was captured by an attacker therefore remain unconfirmed and should not be presented as an established cause.

A website loading correctly at the time of checking does not prove it was safe at an earlier time. Attackers can remove malicious code, redirect only selected visitors or restore a legitimate interface after collecting credentials.

Tornado Cash has faced previous frontend security problems. In 2024, researcher Gas404 found that malicious JavaScript had been inserted into an open source interface and could expose private deposit notes. Checkmarx later documented the supply chain compromise, although no evidence currently connects that episode with the latest transactions.

Deposit notes can give attackers control of funds Tornado Cash uses private deposit notes to let users withdraw assets from its pools. Anyone who obtains a valid note can generally initiate the corresponding withdrawal, making the note comparable to a private credential.

A fake frontend can capture this information when a user attempts to make a deposit or withdrawal. The attacker can then use the stolen note before the legitimate owner does.

The attack differs from approval phishing, where a victim signs a malicious transaction that authorizes a drainer contract. In related coverage, crypto.news explained how wallet drainers exploit deceptive signatures to gain access to tokens and nonfungible assets.

Old bookmarks present another risk because users often assume previously trusted links remain safe. Expired or transferred domains preserve their familiar names, search rankings and backlinks, making malicious replacements harder to identify.

As crypto.news recently reported, fake websites continue draining Ethereum wallets after users approve transactions or enter sensitive information. The safest approach is to verify domains through several current project channels before connecting a wallet.

Nearly 4,000 ETH claim needs more evidence Community reports also alleged that the same attackers stole almost 4,000 ETH through similar methods over the previous 12 months. No list of related addresses or attribution analysis accompanied that figure.

Without linked wallets, transaction hashes or a report from a security firm, the 4,000 ETH estimate cannot be independently verified. Blockchain transfers show where funds moved, but they do not automatically establish who controlled each address or which phishing campaign generated them.

The immediate priority is monitoring the confirmed 810 ETH. Transfers to exchanges could create an opportunity for platforms to identify or freeze assets, subject to their procedures and applicable law.

The victim should preserve browser history, bookmarked URLs, wallet logs and transaction records before reporting the incident to wallet providers, exchanges and law enforcement. Users who interacted with the same frontend should stop using it, move unaffected assets and revoke suspicious token approvals.

The available evidence supports a large Ethereum transfer into a newly active wallet. It does not yet prove the full 1,010 ETH loss, the alleged takeover of the official domain or the claimed 4,000 ETH campaign.
2026-08-17 21:40 22d ago
2026-08-17 20:27 22d ago
Podvodník přesunul další peníze z Coinbase do Tornado Cash
TORN Tornado Cash
CoinGecko News 78
Original source text
A threat actor responsible for more than $300 million in reported thefts from Coinbase users has once again moved a significant portion of stolen funds. On-chain investigator VAL reported that approximately $500,000 was recently converted to Ethereum and transferred to Tornado Cash, an Ethereum-based privacy protocol.

Investigators have linked these substantial losses to coordinated social engineering attacks rather than smart contract vulnerabilities. According to the research, scammers impersonated Coinbase customer support representatives, targeting account holders directly through deceptive communications.

Victims were tricked into sharing sensitive information such as account credentials, or into following fraudulent instructions, which resulted in unauthorized transfers or the approval of malicious transactions. These attacks exclusively targeted individual users, and there has been no evidence indicating an exploit within the Coinbase or Ethereum smart contract infrastructure.

On-chain investigator ZachXBT previously detailed that cumulative losses have exceeded $300 million. This figure accounts for multiple Coinbase accounts compromised during the course of the scam operation.

Tens of millions of dollars are believed to remain in wallets controlled by the threat actor, although investigators did not disclose the current total across all linked addresses.

Funds routed through Ethereum privacy protocolsVAL observed that in the most recent incident, the scammer converted around $500,000 into ETH before transferring it to Tornado Cash. Three weeks earlier, the same operator moved another $2 million using a similar method. Rather than executing a single large transfer, the threat actor used multiple discreet transactions to obscure the trail.

On the Ethereum blockchain, Tornado Cash functions through smart contracts that deposit and withdraw funds separately, complicating efforts to track assets once deposited in the protocol. Investigators noted it remains technically feasible to trace funds until the point of deposit into Tornado Cash contracts.

VAL identified two specific wallet addresses connected to the latest series of transactions: 0x5Da2…89D8a and 0x3ECe…f296. The operator has also been known to send custom messages within transactions to on-chain investigators, such as ZachXBT, often including taunts regarding ongoing efforts to identify the scammer.

Messages apparently mocked both ZachXBT and VAL as they pursued leads in the investigation, but so far no details have emerged about the suspect’s identity or the location of remaining funds.

Growing scrutiny and Web3 innovationBoth ZachXBT, who tracks aggregate losses, and VAL, who reports on the latest movements, have verified that these transactions form part of the same coordinated campaign targeting Coinbase users. In response to ongoing phishing schemes, Coinbase representatives have repeatedly emphasized that their staff will never request passwords, two-factor authentication codes, or asset transfers from customers.

As scams targeting traditional brokerage platforms and centralized exchanges continue, the landscape of asset management is rapidly evolving. While traditional markets rely on complex brokers, a massive shift is happening: Wall Street is moving to Web3. Investors are now using platforms like 1stepSwap to hold shares of major U.S. companies, gold, and silver directly in their crypto wallets. By tokenizing Real-World Assets (RWAs) and automatically finding the best market prices in seconds, it completely removes the middlemen.

Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.
2026-08-08 15:59 1mo ago
2026-08-08 09:21 1mo ago
Aztec útočník poslal dalších 300 ETH do Tornado Cash
TORN Tornado Cash
CoinGecko News 86
Original source text
A wallet linked to the Aztec Private Rollup Bridge exploit deposited another 300 ETH into Tornado Cash, bringing its total transfers to the mixer to 500 ETH.

Summary

The exploiter sent another 300 ETH, worth about $572,000, to Tornado Cash. Total deposits linked to the wallet have now reached 500 ETH, worth about $953,000 at the reported price. The Private Rollup Bridge lost approximately $2.165 million in a June exploit. Aztec said the affected legacy product was separate from its current network and AZTEC token. Aztec exploiter deposits 300 ETH into Tornado Cash Blockchain security firm PeckShield reported on Aug. 8 that an address labeled as the Aztec Private Rollup Bridge exploiter deposited 300 Ether into Tornado Cash.

The ETH was worth approximately $572,000 when PeckShield issued the alert. On-chain data included in the firm’s report showed three separate deposits of 100 ETH each.

PeckShield said the latest transactions raised the wallet’s cumulative Tornado Cash deposits to 500 ETH. Based on the valuation attached to its alert, the total was worth roughly $953,000 at press time.

Tornado Cash pools deposits and allows users to withdraw funds through different addresses. This process can obscure the direct connection between the original sending wallet and subsequent recipients, making asset tracking and recovery more difficult.

PeckShield did not identify the person or group controlling the address. There was also no immediate indication that any of the transferred funds had been recovered.

Private Rollup Bridge lost $2.165 million The latest transfers relate to an exploit that affected Aztec’s Private Rollup Bridge in June. Reports at the time placed the loss at approximately $2.165 million.

The stolen assets reportedly included 1,158 ETH, 150,000 DAI and 0.47 renBTC. Aztec said the affected bridge was a legacy product with no connection to the current Aztec network or its AZTEC token.

The Private Rollup Bridge incident followed a separate attack on Aztec Connect, another discontinued part of the project’s earlier infrastructure.

As crypto.news previously reported, an attacker drained around $2.1 million from Aztec Connect’s old RollupProcessor contract on June 14. The affected system had been discontinued about three years earlier and was no longer used by Aztec’s active network.

Security researchers said that the exploit involved a mismatch between the transactions covered by a zero-knowledge proof and those processed during settlement. The weakness allowed the attacker to create unbacked balances and withdraw assets from the contract.

Aztec Labs could not pause or upgrade the deprecated contract because it had surrendered its administrative keys. The design made the contract immutable but also removed the team’s ability to intervene after the flaw was exploited.

Tornado Cash transfers follow wider exploit surge The two Aztec incidents formed part of a wider increase in crypto security breaches during June.

Crypto.news reported that DefiLlama recorded $74.9 million in losses across 29 exploits during the month. Its data included two separate Aztec incidents valued at approximately $2.1 million each.

Other exploiters have also used Tornado Cash to move stolen assets. In July, a wallet associated with the Drift Protocol exploit deposited 23,095 ETH, then worth around $44.4 million, into the mixer after months of inactivity.

A wallet linked to the Radiant Capital attack previously transferred 2,834 ETH into Tornado Cash, while the Cork Protocol exploiter routed approximately 4,520 ETH through the service.

The latest Aztec deposits therefore follow an established pattern in which attackers convert stolen assets into ETH before sending them through mixing protocols.

Tornado Cash remains under US scrutiny The U.S. Treasury removed Tornado Cash and associated smart-contract addresses from its sanctions list in March 2025. The decision followed a federal appeals court ruling that the Treasury exceeded its authority by sanctioning immutable smart contracts.

However, U.S. authorities have continued to examine the use of crypto mixers in money laundering, sanctions evasion and cybercrime cases. Treasury officials have also maintained concerns about their use by North Korea-linked hacking groups.

The 500 ETH transferred by the Aztec exploiter represents less than half of the value reportedly taken from the Private Rollup Bridge. Further activity from the labeled address could show whether the remaining assets will also be routed through Tornado Cash or moved to other services.
2026-08-04 01:54 1mo ago
2026-08-03 18:52 1mo ago
Tornado Cash zaznamenal 968 vkladů, rekord roku 2026
TORN Tornado Cash
CoinGecko News 78
Original source text
The July 23 spike — worth about $57 million in ETH — was driven largely by the Drift exploiter, who pushed $44 million through the mixer in under two hours.

Tornado Cash processed 968 deposits on July 23, its busiest day of 2026, according to L2Beat data.

The spike shows large-scale attackers have returned to the privacy protocol since the U.S. Treasury lifted sanctions in March 2025 — and that its baseline usage keeps climbing even as developer Roman Storm awaits a retrial over operating it.

Depositors moved 29,573 ETH, worth about $57.2 million at July 23 prices, into the mixer's Ethereum pools that day across 110 addresses, per onchain data. Most of it came from one: the address labeled Drift Exploiter 4 made 245 deposits totaling 23,095 ETH, about $44.4 million and 78% of the day's inflow, in under two hours.

"The Drift Protocol exploiter who stole $285M has deposited 23,095 $ETH ($44.4M) into #TornadoCash today," onchain tracker Lookonchain wrote on X on July 24. "The exploiter still holds 107,165 $ETH ($201M)."

Security firm PeckShield posted the same figures, noting the exploiter also sent 0.85 ETH to Bybit.

Drift Money on the MoveThe deposits were the first movement of funds from the April 1 exploit of Drift, the Solana perps DEX drained of roughly $285 million in the largest DeFi hack of 2026. Blockchain forensics firms including TRM Labs and Elliptic have attributed the attack with medium-to-high confidence to UNC4736, the North Korea-linked cluster behind the $1.5 billion Bybit hack.

Even setting the exploiter aside, the day's remaining 723 deposits from 109 other addresses exceeded most full days in 2025, when July 23 of that year saw 177 deposits total.

Post-Delisting ReboundTornado Cash usage has rebounded steadily since Treasury's Office of Foreign Assets Control delisted it in March 2025, following a Fifth Circuit ruling that immutable smart contracts can't be sanctioned. The mixer has captured more than 20% of crypto mixing volume in 2026, with weekly inflows of $10 million to $80 million, according to TRM Labs — up from about 16% in the years after the 2022 sanctions. The 2026 peak still trails Nov. 5, 2025, when Richard Heart-linked wallets helped drive 1,363 deposits in a day.

Storm's case continues alongside the rebound. Prosecutors are seeking an October retrial of Storm on money-laundering and sanctions-conspiracy charges after a Manhattan jury hung on those counts in August 2025, while Judge Katherine Polk Failla weighs his acquittal bid on the single count where jurors convicted.
2026-07-24 18:09 1mo ago
2026-07-24 18:00 1mo ago
Verus Ethereum Bridge podruhé ztratil 7,54 milionu USD
ETH Ethereum TORN Tornado Cash USDC USD Coin
CoinGecko News 92
Original source text
The Verus Ethereum Bridge has been targeted by a major security breach for the second time in just over two months, resulting in the theft of approximately $7.54 million in various crypto assets. The incident occurred on July 23 when attackers exploited a vulnerability, once again raising concerns about the security of cross-chain protocols in decentralized finance (DeFi).

Attacker Drains Bridge’s Ethereum ReservesThe breach allowed the attacker to abuse the bridge’s submitImports function, which triggered Ethereum-side payouts without equivalent assets being locked on the Verus blockchain. This vulnerability enabled the unauthorized extraction of funds from the bridge’s reserves.

Blockchain security firm Blockaid and independent researcher exvulsec both confirmed and investigated the exploit. According to on-chain data, roughly 1,137 ETH, as well as tBTC, USDC, USDT, EURC, MKR, and scrvUSD, were drained from the bridge reserves at around 03:45 UTC. The stolen assets were quickly swapped through decentralized exchanges, then consolidated into nearly 3,916 ETH before parts of the funds were routed through Tornado Cash.

Mini dictionary: Tornado Cash, a decentralized non-custodial privacy solution on Ethereum, is designed to break the on-chain link between source and destination addresses, making transaction tracing more difficult.

AssetAmount stolenEstimated valueETH1,137Included in $7.54M totaltBTCUnknownUSDCUnknownUSDTUnknownEURCUnknownMKRUnknownscrvUSDUnknown Investigators noted that by exploiting the same contract, function entry point, and vulnerability as a previous May breach, the attacker bypassed standard cross-chain verification and triggered unbacked payouts, draining several digital assets from Verus’ Ethereum bridge reserves.

Recurring Security Flaws and Recent HistoryThe latest breach revived scrutiny over Verus’ handling of a previous exploit in May, which resulted in an $11.58 million loss. Experts stated that this attack exploited the exact vulnerability from the earlier incident, indicating that core issues may have remained unaddressed. Blockaid observed that while this latest event involved a different attacker wallet, the method and targeted contract remained unchanged.

Following the May attack, the same attacker returned 4,052 ETH—about 75% of the stolen funds—after reaching an agreement with Verus. Despite that partial restitution, the repetition of the exploit has heightened doubts regarding the bridge’s security remediation process.

Experts pointed out that the repeated vulnerability likely resulted from an incomplete technical fix after the earlier breach, leaving Verus exposed to additional attacks. There is growing pressure for the protocol team to publish a thorough incident report and technical breakdown.

Ongoing Investigations and Broader RisksThe Verus incident is one of several recent DeFi bridge attacks highlighted by on-chain monitoring services. Lookonchain reported that combined losses from incidents involving Verus, AFX Trade, and B² Network have climbed to approximately $35.55 million.

Mini dictionary: Lookonchain is an on-chain analytics platform known for monitoring blockchain transactions and identifying patterns related to hacks, large movements, and abnormal activities.

Security analysts explained that bridge protocols are increasingly targeted due to logical flaws in cross-chain messaging mechanisms, which, if exploited, can allow fund withdrawals without equivalent collateralization.

Next Steps for Verus and UsersAmid the investigation, Verus halted all bridge operations but has not announced a compensation plan or released a detailed technical report. The absence of a clear official explanation has drawn criticism from the user community.

Observers expect the Verus team to prioritize closing the technical vulnerability, improve their validation process, and offer a roadmap to locate and potentially recover missing assets. Until these steps are made public, scrutiny around trust and transparency in the protocol will likely continue.

Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.
2026-07-24 15:29 1mo ago
2026-07-24 08:20 1mo ago
Exploiter z Drift přesunul 44 milionů USD do Tornado Cash
TORN Tornado Cash
CoinGecko News 92
Original source text
A wallet tied to the $285 million Drift Protocol exploit moved 23,095.1 Ether, worth about $44.4 million, into Tornado Cash after roughly three months of inactivity.

Summary

Drift’s exploiter deposited 23,095 ETH into Tornado Cash after remaining inactive for three months. ZachXBT declined further tracking, citing resources required to monitor and freeze a nine-figure DPRK theft. Drift previously announced a recovery bounty program with Arkham and Bybit, contrary to online claims. The same address sent 0.85 ETH to wallets labeled as Bybit deposit addresses, according to Etherscan records and monitoring attributed to PeckShield.

Transfers began on July 23 and continued into July 24, on-chain records show. Researcher JL, known as 0xJaelle, flagged the movement and tagged ZachXBT. The investigator replied that he did not plan to keep following the funds without institutional support.

Drift exploiter empties an Ethereum wallet The Etherscan address labeled “Drift Exploiter 4” processed hundreds of transactions during the movement. Records show repeated deposits of 100 ETH, 10 ETH and 1 ETH into the Tornado Cash router. Four other transfers totaling 0.85 ETH went to addresses labeled as Bybit deposits.

Onchain Lens first reported that the attacker had resumed activity and was sending 100 ETH batches into the mixer several times per minute. The wallet had remained largely inactive since the April attack.

Tornado Cash pools deposits and permits later withdrawals through different addresses. That can weaken the direct public link between sending and receiving wallets. Investigators may still use timing, transaction patterns and exchange activity, but the process requires more data and staff.

The movement covers only part of the original theft. Drift’s April recovery update valued stolen assets at $295.7 million across JLP, USDC, Bitcoin-linked tokens, SOL, WETH and other assets. The protocol said much of the converted value remained across four flagged Ethereum wallets.

ZachXBT cites cost of tracking North Korea-linked funds ZachXBT wrote, “Sorry I currently do not have any plans to track these funds further.” He said monitoring a nine-figure North Korea-linked exploit and working toward possible freezes would require resources beyond one independent investigator.

He described the task as “difficult for a team and not feasible for a single person.” ZachXBT also said Drift was not a donor or client. His response on X drew attention to the cost of investigations that continue for months.

The comments do not show that no organization is watching the wallets. Drift has said it works with law enforcement, Mandiant and blockchain intelligence firms. Etherscan continues to label the address, while exchanges can review deposits connected to flagged wallets.

Elsewhere, ZachXBT criticized Circle after about $232 million in stolen USDC crossed from Solana to Ethereum during the April attack. The funds moved through Circle’s cross-chain system before the attacker converted much of the value into ETH.

Drift had announced a recovery bounty program JL later said it was surprising that Drift had not created a recovery bounty. Drift’s public record shows that it had announced plans for one. On April 16, the protocol said it was developing a bounty program with support from Arkham and Bybit.

However, the update did not provide a final reward amount, eligibility rules or payment schedule. It remains unclear whether the program became fully active, whether it covered continuing wallet monitoring, or whether independent researchers could claim payment for later tracing work.

Drift also created a user recovery plan separate from stolen-fund tracking. Tether proposed up to $127.5 million in support. Drift plans to issue recovery tokens and fund redemptions through remaining assets, partner capital and future exchange revenue.

The protocol’s June investigation update said Mandiant attributed the attack to UNC6862, a North Korean threat group. Drift said the attackers used social engineering and compromised operational access rather than a smart contract flaw. As crypto.news reported, the attackers emptied key vaults within about 12 minutes.

Recovery continues as the trail becomes harder to follow Drift has focused on rebuilding its platform and funding user claims while forensic teams pursue the stolen assets. Its recovery framework states that recovered funds will enter the user recovery pool. The protocol also plans stronger signing controls for critical transactions.

The April attack affected other Solana projects. As previously reported, yield platform Carrot decided to shut down after losses linked to Drift erased most of its deposited value.

The Tornado Cash deposits do not prove that the attacker converted the ETH into usable cash. The deposits remain public, and investigators may still identify later withdrawals. However, they remove a simple wallet-to-wallet trail and make the next phase harder.

Neither Drift nor Solana had publicly responded to ZachXBT’s comments at the time of writing. Bybit had not announced whether it reviewed the small deposits shown on Etherscan. The remaining stolen funds and the status of Drift’s planned bounty program remain unresolved.
2026-07-09 23:37 1mo ago
2026-07-09 16:24 2mo ago
Útočník Summer.fi pral ukradené prostředky v hodnotě 1,35 milionu DAI přes Tornado Cash
TORN Tornado Cash
CoinGecko News 78
Original source text
Summer.fi's own post-mortem confirms the attacker began laundering the $6M haul through the mixer, calling it a sign of "limited intent to return the funds voluntarily."

The attacker behind the $6 million Summer.fi exploit has begun laundering the stolen funds, moving roughly $1.35 million in DAI through Tornado Cash, the sanctioned crypto mixer, according to Summer.fi's own post-mortem of the July 6 attack.

Summer.fi, the front-end for the Lazy Summer Protocol, said the attacker "swapped a portion of the proceeds and routed them through Tornado Cash... via an intermediary wallet (0x46e0…eBa7)," adding that the move "signals limited intent to return the funds voluntarily."

Laundering TrailOnchain Lens via Odaily, reported the exploiter's wallet received 6.017 million DAI from the attack and has since moved 1.35 million DAI, swapping it for ETH on Uniswap before sending it through the same intermediary wallet into Tornado Cash. The original wallet still holds about 4.67 million DAI, while the intermediary wallet holds 50 ETH, per the report.

The exploit itself drained roughly $6.04 million from two Lazy Summer USDC vaults on Ethereum on July 6, after an attacker manipulated vault share pricing using a stale-valued token position built up over three months, Summer.fi said. The Defiant previously covered the initial exploit.

Summer.fi said its security partners, including SEAL 911, are continuing to trace the funds but that tracing "breaks down" once assets are swapped out of stablecoins and deposited into a mixer. The protocol publicly named the attacker's funder and beneficiary wallet, 0x7BF7…BDCa, "so the community and exchanges can flag associated activity."

Roughly 4.67 million DAI of the original haul remains untouched in the exploiter's primary wallet, leaving open whether further funds will move through Tornado Cash.
2026-07-05 08:35 2mo ago
2026-07-05 08:13 2mo ago
Útočník na Step Finance pral ukradené SOL přes Tornado Cash
TORN Tornado Cash
CoinGecko News 88
Original source text
The person (or persons) who drained Step Finance of roughly 261,854 SOL tokens has moved to the next phase of every crypto heist playbook: the laundering stage. The exploiter sold a significant chunk of stolen SOL, bridged $21.4 million to Ethereum, purchased ETH, and funneled the proceeds through Tornado Cash.

What happened at Step Finance Step Finance, a DeFi portfolio management platform built on Solana, was hit on January 31 when attackers gained unauthorized access to treasury and fee wallets. The haul came to approximately 261,854 SOL, worth somewhere between $27 million and $30 million at the time of the breach.

The attack vector was compromised executive team devices, likely through phishing or social engineering. The smart contracts worked fine. The people managing them did not.

Advertisement

Total losses ballooned to around $40 million when accounting for the full impact, with only about $4.7 million recovered through partnerships and features like Token22. That recovery rate, roughly 12% of total losses, is not exactly a victory lap.

By late February, Step Finance ceased operations entirely. Its affiliates, SolanaFloor and Remora Markets, also shut down as the fallout spread. The project announced plans for a buyback based on a pre-hack snapshot of the STEP token.

Following the money across chains The on-chain data, flagged by Arkham Intelligence, paints a clear picture of the attacker’s exit strategy. After sitting on the stolen SOL, the exploiter began selling, converting roughly $21 million worth of tokens before bridging $21.4 million over to Ethereum.

Once on Ethereum, the funds were swapped into ETH and then routed through Tornado Cash. The US Treasury’s Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash back in 2022, though those sanctions have faced significant legal challenges. The protocol continues to function because it’s a set of smart contracts on Ethereum that nobody can unilaterally shut down.

What investors should watch The $4.7 million recovery represents a fraction of total losses, and the movement of funds through Tornado Cash suggests that further recovery through on-chain means is unlikely without law enforcement intervention. Historically, funds that make it through mixing protocols are rarely clawed back unless the attacker makes an operational mistake later, like cashing out through a centralized exchange with KYC requirements.

The planned STEP token buyback based on a pre-hack snapshot is worth monitoring, though with the project’s operations ceased and affiliates shut down, the entity executing any buyback may have limited resources to work with.

The attacker’s decision to convert stolen SOL into ETH before laundering signals a practical reality about cross-chain liquidity. Ethereum’s deeper liquidity pools and more established mixing infrastructure make it the preferred destination for laundering large sums, which means that exploits on alternative L1s frequently end up impacting Ethereum’s on-chain analytics landscape as well.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
2026-06-25 06:10 2mo ago
2026-06-11 07:47 2mo ago
Raydium potvrdil exploit starých poolů a nahradí ztráty
RAY Raydium SOL Solana TORN Tornado Cash
CoinGecko News 92
Original source text
TLDR Hackers extracted approximately $1.34 million from five dormant Raydium liquidity pools operating on Solana The breach resulted in the theft of around 150,000 RAY tokens, 5,600 SOL, and 893,700 USDC The vulnerability existed in an obsolete AMM program discontinued in 2021, leaving active pools untouched Raydium announced its treasury would provide complete restitution to all impacted participants Security firm PeckShield identified roughly 810 ETH of the pilfered assets flowing into Tornado Cash On June 10, Raydium, a Solana-based decentralized exchange, disclosed that malicious actors successfully exploited outdated infrastructure components, siphoning approximately $1.34 million worth of cryptocurrency.

The compromised liquidity pools had been inaccessible via Raydium’s user interface ever since the platform discontinued its AMM V3 program back in 2021. According to Raydium’s statement, neither current platform users nor any actively maintained liquidity pools experienced any impact.

How the Attack Happened On-chain security analyst Specter revealed that the perpetrators utilized a fraudulent mint address to circumvent security validation protocols within the inactive pool infrastructure. The core vulnerability stemmed from inadequate verification processes for LP mints, creating an opportunity to sidestep proportion validation mechanisms.

The assailant successfully withdrew approximately 150,177 RAY tokens, 5,603 SOL, and 893,700 USDC from the compromised pools. According to Specter’s investigation, the attacker initially received funding through the KuCoin exchange before transferring the illicit assets to the Ethereum blockchain.

PeckShield, a prominent blockchain security organization, monitored the movement of stolen cryptocurrency following its transfer to Ethereum. Their analysis revealed that approximately 810 ETH was funneled into Tornado Cash, while an additional seven ETH moved through FixedFloat.

Notably, Tornado Cash was delisted from U.S. Treasury Department sanctions in March 2025. Nevertheless, the utilization of this privacy protocol may continue to present obstacles for investigators attempting to recover or trace the diverted funds.

Raydium Will Reimburse All Losses Raydium has publicly committed to utilizing its treasury reserves to compensate all financial damages stemming from this security breach. While the protocol emphasized that no current active users suffered losses, some participants maintained residual exposure through the deprecated pool contracts.

This marks the second occasion where Raydium has pledged to absorb user losses. Following an admin key security breach in December 2022 that affected operational pools, the project implemented a governance-approved compensation plan utilizing buyback fee revenue and vested team token allocations to restore liquidity provider funds.

The development team confirmed that all currently deployed mainnet programs remain secure and are presently undergoing comprehensive independent security audits.

Market response to the incident proved minimal. Raydium traded around $0.57, experiencing less than a 1% decline during the 24-hour window after the exploit became public. Solana experienced a modest drop of nearly 2%, settling around $63.88 throughout the identical timeframe.

The RAY token demonstrated resilience, actually gaining more than 2% on the day news of the security breach emerged.

Raydium clarified that both its SDK and decentralized application infrastructure lack functionality for interacting with the legacy AMM V3 pools on the mainnet, effectively confirming the attack remained isolated to decommissioned code.

Security researchers from PeckShield and Specter maintain ongoing efforts to track the movement of stolen digital assets. According to currently available blockchain data, the exploitation remained entirely confined to obsolete infrastructure components without penetrating Raydium’s operational trading ecosystem.
2026-06-25 06:10 2mo ago
2026-06-18 16:00 2mo ago
Útočník UXLink propral přes Tornado Cash 19,1 milionu dolarů
ETH Ethereum TORN Tornado Cash
CoinGecko News 78
Original source text
UXLink, a Web 3 social network that was targeted in September 2025, is making headlines once again. According to Specter, an on-chain investigator, the attacker responsible for the UXLink exploit has started relocating the stolen assets.

To obfuscate transaction trails, the wrongdoer converted some of the stolen DAI stablecoins into Ethereum [ETH]. Going forward, the illicit actor then deposited roughly $8.1 million worth of ETH into Tornado Cash.

Funds laundered According to the investigator, 46 distinct deposits of 100 ETH each were made as part of the laundering process.

Source: Specter For those unaware, this is a common strategy to conflate illegal funds with legal transactions and make blockchain tracing more difficult.

With this most recent action, the attacker has now reportedly laundered a total of $19.1 million in stolen assets.

However, the fact that the exploiter still has control over about $16 million in funds despite these transfers raises the possibility of further laundering.

How was UXLink attacked?  Well, back in September 2025 the exploiter had made over $800 billion, or 9 trillion $UXLINK. Interestingly, even hours after the original exploit, the hacker kept their access and kept minting more tokens.

The exploiter then started moving the proceeds to centralized exchanges and offloading the fraudulent tokens through decentralized exchanges. This in turn resulted in the depletion of Uniswap’s liquidity.

Source: Specter Notably, the attacker did not stop there, and signed a malicious transaction and lost 542 million UXLINK tokens to another malicious actor—often referred to as “theft stolen from theft.”

Even with this setback, the main exploiter still held about 900 million UXLINK tokens, putting a sizable portion of compromised assets in the hands of malicious actors. 

What’s more? This coincded with ETH declining by 1.01% over the previous day to trade at $1,745.11 at press time. 

In addition, on the 12th of June Humanity Protocol reported a targeted phishing attack against one of its directors.

This had resulted in the attacker using administrative credentials that were stolen to upgrade contracts, transfer tokens across Ethereum, and mint new $H tokens on the BNB Smart Chain. 

Furthermore, on the 15th of June, a suspicious transaction involving the depletion of assets valued at approximately $2.19 million occurred in Aztec Network’s Router contract.

Final Summary From September 2025 to the present time, the attackers have reportedly laundered a total of $19.1 million in stolen assets from the UXLink exploit. Back then, the  exploiter had made over 9 trillion $UXLINK, kept their access, and kept minting more tokens. 
2026-06-25 06:10 2mo ago
2026-06-23 10:04 2mo ago
Útočník spojený s Jaredfromsubway.eth přesunul 2 000 ETH přes Tornado Cash
TORN Tornado Cash
CoinGecko News 78
Original source text
The person who pulled off one of the most brazen exploits in Ethereum’s MEV ecosystem is not sitting still. The attacker who drained the infamous Jaredfromsubway.eth sandwich bot has now routed approximately 2,000 ETH through Tornado Cash, the privacy mixer that remains the go-to laundering tool for on-chain criminals.

On top of the mixing, the exploiter swapped 1,422 ETH for roughly 2.45 million DAI. That leaves a minimal ETH balance in the attacker’s wallets.

How the original exploit went down The exploit, which security firm Blockaid characterized as a “counter-MEV honeypot” attack, was almost poetic in its construction. The attacker deployed fake token contracts and liquidity pools designed to trick the bot into granting token approvals. The exploiter built a trap that looked like a juicy sandwich opportunity, and the bot took the bait.

Advertisement

The scheme played out over several weeks before culminating in a drain that siphoned off more than $7.5 million in various assets. The stolen haul included 1,474.58 WETH, 2.87 million USDC, and 2 million USDT. All of it was converted into approximately 4,400 ETH.

The bounty that went nowhere After the exploit came to light around June 20-21, the Jaredfromsubway.eth operator posted an on-chain message offering a white-hat bounty. The deal was 50% of the stolen funds, roughly 2,150 ETH, in exchange for returning the rest within 48 hours. The message also carried the implicit threat of legal action if the attacker refused.

Rather than returning anything, the attacker has been systematically moving funds through Tornado Cash. The 2,000 ETH transfer, valued at approximately $3.44 million at the time of the transaction, represents a significant chunk of the stolen proceeds being pushed through the mixer.

What this means for MEV and DeFi security The counter-MEV honeypot technique essentially weaponizes a bot’s own aggression against it. MEV bots rely on automated token approvals to execute trades at speed. That same mechanism — the willingness to approve and interact with any contract that presents a profitable opportunity — is exactly what the attacker exploited.

Despite being sanctioned by the US Treasury’s Office of Foreign Assets Control back in 2022, Tornado Cash remains operational as a decentralized protocol. Every major exploit that routes funds through it renews the debate about whether privacy tools are a necessary feature of financial freedom or primarily an enabler of theft.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
2026-06-25 06:09 2mo ago
2026-06-25 00:23 2mo ago
Útočník KyberSwap vypral přes 80 % ukradených ETH
TORN Tornado Cash
CoinGecko News 78
Original source text
According to PeckShield’s monitoring, an address identified as the KyberSwap attacker has once again transferred 2,000 ETH to Tornado Cash. Over the past two years, this attacker has cumulatively transferred and mixed 16,100 ETH via Tornado Cash, equivalent to roughly $40 million at current prices, accounting for over 80% of the $48.8 million lost in the KyberSwap attack in November 2023. Some of the stolen funds have not yet been fully transferred.

Relevant content

Preview: The U.S. May core PCE data will be released at 20:30 tonight, and is projected to hit its highest level since October 2023.

The Fed’s key inflation gauge, the Personal Consumption Expenditures (PCE) price index, will be released at 20:30 tonight, with markets expecting a sharp rise in May inflation that could reignite rate hike bets. The headline PCE year-over-year growth rate is projected to hit 4.1% in May, up from 3.8% in April and marking its highest level since 2023. Core PCE, which excludes food and energy, is forecast to rise to 3.4% year-over-year, up from 3.3% in April and its highest reading since October 2023. Core PCE has remained above the Fed’s 2% inflation target since 2021. The recent short-term inflation uptick was driven mainly by surging gasoline prices amid the Iran conflict in May. Oil prices have since edged lower following the signing of a peace deal between the U.S. and Iran, but core inflation has strengthened in tandem, indicating that price pressures are not solely tied to geopolitical oil shocks. Data from the CME FedWatch Tool shows that as of Wednesday, markets are pricing in a 34% probability of a 25 basis point rate hike in July. Aditya Bhave, U.S. economist at Bank of America Securities, noted that the recent inflation rebound stems in part from tariffs and one-off disruptions, but successive supply shocks have eroded the Fed’s patience, while deflationary room in the housing sector has largely been exhausted. Data shows that core PCE dipped to 2.6% in April, its lowest level since 2022, but annualized core PCE growth over the past three and six months has hovered near 3.8%.

4 minutes ago

SK Hynix plans to list on NASDAQ on July 10: A crypto whale opens 90% of its bullish positions in a single day, with all $21.27 million in long positions in unrealized profit.

According to Hyperinsight’s monitoring, SK Hynix officially announced its U.S. listing date today, targeting a July 10 debut on the NASDAQ. The company had previously disclosed a over $29 billion listing fundraising plan yesterday afternoon. Driven by listing optimism, SKHX surged 14% intraday, hitting $1930 at press time, with a daily trading volume of $407 million and open interest of $237 million. Since the news broke yesterday, 10 whales have built positions in SKHX on Hyperliquid, 9 of which opened long positions totaling around $21.27 million, at an average entry price of ~$1797.8 and average unweighted liquidation price of ~$1390.6. With price gains, all 9 long positions are now in unrealized profit. Market data shows that positions of over $1 million amount to roughly $140 million, with a long-short ratio (longs/shorts) of ~0.715. The average entry price for longs is ~$1672, while shorts average ~$1640. The nearest short liquidation threshold stands at $2149, just $200 away from the current price, mounting short-side pressure. -HyperInsight Bot is now live. Add @HyperInsightBot to your Telegram group, set it as admin (enable message sending permission) to auto-sync on-chain updates.

4 minutes ago

The "Retail vs. Wall Street" concept-linked token WEN continues its strong run, rising over 18% in after-hours trading.

According to Bitget market data, Wendy's (WEN) rallied 25.66% in the regular trading session, then climbed an extra 18.96% in after-hours trading, now changing hands at $9.35. Earlier reports noted that Serenity took to Twitter to mock the latest meme stock movement unfolding on Reddit's high-risk trading communities, targeting U.S. fast-food chain Wendy's. The Reddit community's meme warning reads: "If Wendy's goes bankrupt, we'll all be out of jobs, and after losing all our trading money, we'll have to work behind Wendy's trash cans." Serenity later clarified that they hold no positions, only found the activity amusing, and added they were unsure if the campaign would succeed. Wendy's holds a special cultural status on Reddit's WallStreetBets community; for years, "working behind Wendy's trash cans" has been a staple joke among retail investors mocking their trading losses.

4 minutes ago

Danske Bank: Federal Reserve may raise interest rates at least twice

Danske Bank senior analyst Kirstine Kundby-Nielsen and chief analyst Jens Peter Sorensen stated in a report that they expect the U.S. Federal Reserve to raise interest rates twice, in December 2026 and March 2027 respectively, bringing the federal funds rate to 4.00%-4.25%. "However, we emphasize there is a risk that rate hikes could come earlier and that the number of hikes may exceed two," they said. The first Federal Reserve meeting led by Kevin Warsh sent a clear signal that the Fed is increasingly moving away from forward guidance surrounding future monetary policy decisions. "All signs indicate that (the Fed) is leaning toward having greater discretion in future policy decisions," the Danske Bank analysts added. Source: Jin10

4 minutes ago

SK Hynix's stock price rise widened to 15.4%, while Samsung Electronics gained 6.3%.

According to Bitget data, SK Hynix’s stock price gain has widened to 15.4%, with Samsung Electronics up 6.3%.

4 minutes ago

The entire cryptocurrency market is down across the board; funding rates indicate BTC remains in bearish territory, while ETH’s bullish sentiment is significantly stronger than BTC’s.

According to HTX market data, Bitcoin is currently trading at $61,684.51, down 1.88% in the past 24 hours; Ethereum is at $1,647.36, down 1.48% over the same period. Current funding rates on major centralized exchanges (CEXs) show a clear divergence between BTC and ETH: BTC rates across all platforms have fallen back into bearish territory, while ETH rates on most platforms remain above the neutral range, indicating significantly stronger bullish sentiment for ETH than BTC. BlockBeats Note: Funding rates are fees set by cryptocurrency trading platforms to maintain the balance between contract prices and underlying asset prices, typically applicable to perpetual contracts. They serve as a fund exchange mechanism between long and short traders; platforms do not collect these fees, instead using them to adjust the cost or return of traders holding contracts, so that contract prices stay close to the underlying asset prices. A funding rate of 0.01% is the benchmark. A rate above 0.01% indicates broad bullish market sentiment, while a rate below 0.005% signals widespread bearish sentiment.

4 minutes ago
2026-06-25 02:48 2mo ago
2024-11-30 21:00 1yr ago
Soud zrušil sankce uvalené OFAC na Tornado Cash
AZERO Aleph Zero TORN Tornado Cash
CoinGecko News 78
Original source text
The following is a guest article from Matthew Niemerg, co-founder of Aleph Zero.

The Fifth Circuit Court of Appeals handed down a landmark ruling yesterday that could fundamentally reshape how cryptocurrency protocols are regulated. In Van Loon v. Department of Treasury, the court found that the Treasury Department's Office of Foreign Assets Control (OFAC) exceeded its authority when it sanctioned Tornado Cash's immutable smart contracts.

The ruling hinges on a deceptively simple question: can computer code that cannot be modified or controlled be considered “property”? The appellate court's answer was an emphatic no.

Tornado Cash is a cryptocurrency anonymizing service that helps preserve privacy by pooling users' digital assets together, making transactions harder to trace. In 2022, OFAC sanctioned it after North Korean hackers allegedly used it to launder over $455 million in stolen funds. But the court found that since Tornado Cash's core protocols are “immutable” – meaning they cannot be changed or controlled by anyone – they don't qualify as property that can be sanctioned under existing law.

A Watershed Moment for Crypto“Because these immutable smart contracts are unchangeable and unremovable, they remain available for anyone to use,” wrote Judge Don Willett, noting that even under sanctions, “the targeted North Korean wrongdoers are not actually blocked from retrieving their assets.”

This represents a watershed moment for the cryptocurrency industry. For the first time, a federal appeals court has acknowledged that certain decentralized protocols operate entirely as something completely different from traditional property or businesses. Since no one “owns” the protocols underlying email or the web, these autonomous smart contracts exist independent of any controlling entity.

The implications are significant. The ruling effectively creates a safe harbor for truly decentralized protocols that cannot be modified or controlled. While OFAC can still sanction individuals and companies, it cannot sanction the underlying code itself – at least under current law.

Balancing Privacy and SecurityHowever, the court explicitly left the door open for Congress to update the 1977 International Emergency Economic Powers Act (IEEPA) to address modern technologies. “Perhaps Congress will update IEEPA, enacted during the Carter Administration, to target modern technologies like crypto-mixing software,” the ruling noted. “Until then, we hold that Tornado Cash's immutable smart contracts…cannot be blocked under IEEPA.”

CryptoSlate Daily Brief

Daily signals, zero noise.Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

You’re subscribed. Welcome aboard.

This highlights the broader challenge of regulating privacy-preserving technologies that can be used for both legitimate and illegitimate purposes. As the court record shows, Tornado Cash was used by individuals seeking to protect their privacy when donating to Ukrainian war efforts and avoid harassment. But it was also exploited by bad actors for money laundering.

The crypto industry still has work to do in preventing illicit use while preserving privacy rights. Some proposed approaches include allowing users to voluntarily prove the legitimacy of their funds, or implementing “anonymity revoking” systems that could unmask users only under specific circumstances with proper oversight.

The Path ForwardJudge Willett acknowledged the government's concerns about illicit finance as “undeniably legitimate.” But he emphasized that courts must apply the law as written, not “tinker with it.” The ruling concludes:

“Mending a statute's blind spots or smoothing its disruptive effects falls outside our lane.”

This balanced approach – recognizing both the importance of preventing criminal activity and the need to protect privacy-enhancing innovation – points the way forward. Rather than trying to force new technologies into old regulatory frameworks, legislators need to craft updated laws that understand the unique nature of decentralized systems while addressing legitimate security concerns.

For now though, this ruling represents a victory for technological innovation and a recognition that not everything in the digital age fits neatly into traditional legal categories of property and ownership. The challenge ahead is building a regulatory framework as sophisticated as the technology it aims to govern.
2026-06-25 01:19 2mo ago
2024-08-07 15:07 2yr ago
Hacker z Unizen přesunul ukradené miliony do Tornado Cash
TORN Tornado Cash ZCX Unizen
CoinGecko News 78
Original source text
Following the March 9 attack orchestrated by a malicious actor on Unizen, a decentralized finance (DeFi) protocol, which resulted in the loss of around $2.1 million, it has now been revealed that the hacker behind the attack has moved the stolen assets to Tornado Cash.

In a post by blockchain security firm PeckShield, it was revealed that the hacker moved 2,179,859 DAI from the wallet used in the attack to an unknown wallet on August 7. They then changed the DAI into 865.4 Ether (ETH) and sent it to Tornado Cash in 26 separate transactions. This will be the first time the stolen Unizen funds have been moved since the attack 151 days ago.

After the March exploitation, the Unizens said they would return the stolen funds to users. The plan was led by the CEO Sean Noga, who released personal money to the company to pay back users who lost less than $750,000. For people who lost more, the company said they would look at each case separately.

More so, days after the attack, Unizen chief technology officer, Martin Granström, stated that the company is working with security experts and law enforcement agencies to track down the hacker’s identity. He noted that they gathered various evidence and can now proceed with the post-mortem.

In the same post, he assured users that the firm would invest more in improving its security with every new upgrade as they owed it to their community. However, despite the firm’s effort to catch the bad actor, it does not seem like they have made any headway, as the hacker now has zero balance in their wallet.

Crypto Hacking: A Growing Concern in the Industry The attacker used a decentralized mixer that makes it hard to trace the origin of cryptocurrency transactions. Bad actors often deploy this tactic to hide stolen money.

Similar scenarios have occurred in other major hacks, such as the $308 million hack of the DMM Bitcoin system. In that case, the hackers used Huione Guarantee, an online marketplace that lets people do scams and other shady things, to launder the stolen assets.

Recently, another DeFi protocol Nexera was hacked, and a sum of $1.5M was exploited, which resulted in the company warning its users to stop trading the NXRA token. It was also revealed that the bad actor has already started selling the token for ETH and has already bridged some to the BNB chain.

The bad actor’s address behind the Nexera attack was said to be connected to recent private key compromise cases, such as Concentric Finance, OKX DEX, and Serenity Shield.

The continuous cyber attacks in the crypto space show the need for further industry security improvement. Many investors have lost a lot of funds because bad actors are becoming more rampant. The attack on WazirX last month, which resulted in the loss of over $230 million, further testifies why a quick solution needs to be found to mitigate the act.

Disclaimer: Coinspeaker is committed to providing unbiased and transparent reporting. This article aims to deliver accurate and timely information but should not be taken as financial or investment advice. Since market conditions can change rapidly, we encourage you to verify information on your own and consult with a professional before making any decisions based on this content.

Cybersecurity News, News

Temitope is a writer with more than four years of experience writing across various niches. He has a special interest in the fintech and blockchain spaces and enjoy writing articles in those areas. He holds bachelor's and master's degrees in linguistics. When not writing, he trades forex and plays video games. 

Temitope Olatunji on X
2026-06-25 00:19 2mo ago
2024-10-08 13:46 1yr ago
Binance převede 10 delistovaných tokenů na USDC
BNB BNB BOND BarnBridge DOCK Dock ETH Ethereum OMG OmiseGO POLS Polkastarter SCR Scroll TORN Tornado Cash USDC USD Coin VAI Vai WAVES Waves XEM NEM
CoinGecko News 78
Original source text
In a blog post on Tuesday, Binance Exchange, the largest crypto trading platform by volume, announced the automatic conversion of several delisted tokens to USDC.

This action will be executed based on the average token to USDC exchange rate within the conversion period.

What Binance Exchange Users Need To KnowAfter delisting 10 tokens from its catalog, Binance said in a follow-up message that it would convert them to USDC automatically, enabling holders to access their funds. After the conversion happens, the exchange will credit the stablecoin equivalent of the affected tokens to users’ wallets by April 28, 2025. The tokens include:

Vai (VAI) Tornado Cash (TORN) OMG Network (OMG) Waves (WAVES) NEM (XEM) BarnBridge (BOND) Dock (DOCK) Mdex (MDX) Polkastarter (POLS) Pundi X PURSE (PURSE) Read more: Binance Review 2024: Is It the Right Crypto Exchange for You?

Holders of these tokens should adjust their trading strategies accordingly to prepare for the upcoming changes. Failure to do so by October 28 would see them automatically converted to USDC, effectively phasing out the affected tokens from the exchange.

“During the Conversion Period [between October 29, 2024 and April 28, 2025], users will not be able to view the above tokens in their Binance wallets,” Binance articulated.

In this regard, it is worth mentioning that the history of Binance’s tokens delisting often inspires volatility. For instance, the exchange delisted six altcoins around mid-August, causing double-digit price drops for PowerPool (CVP) and Ellipsis (EPX). These tokens also featured among the delisted assets.

However, Binance is not only removing several tokens but also adding new ones to its platform. One of the notable additions is Scroll (SCR), a zkRollup scaling solution for Ethereum.

As per the announcement, SCR will be listed on October 11, with pre-market trading for the SCR/USDT pair set to open. This move supports Ethereum’s scalability by enabling faster, more efficient transactions while maintaining security and decentralization.

“Binance is excited to announce the 60th project on Binance Launchpool – Scroll (SCR), a Bytecode-level compatible zkEVM Rollup,” an excerpt in Binance’s announcement read.

Read more: What are Crypto Airdrops?

With this listing notice, Binance becomes the first platform to list Scroll’s powering token. The exchange will also airdrop 55,000,000 SCR, representing 5.5% of the total supply. Airdrop farming will start on Wednesday, October 9. The participants must lock their BNB and FDUSD to receive the SCR tokens.
2026-06-25 00:11 2mo ago
2026-06-01 09:21 3mo ago
Fluid přišel o 215 000 USD na odměnách
ETH Ethereum INST Instadapp TORN Tornado Cash
CoinGecko News 92
Original source text
PANews reported on June 1st that, according to BlackHart, the reward distribution mechanism of the DeFi project Fluid on Ethereum was exploited, resulting in the theft of approximately $215,000 in assets. Fluid employs a Merkle reward list mechanism where one key initiates and another approves. The attacker possessed both operating private keys, submitted and approved a list of rewards to be distributed only to themselves, and then used a null proof to complete the claim. The stolen assets came from three reward distributors, including 112,883 FLUID, 47,903 GHO, and a small amount of cbBTC, which were later exchanged for ETH and transferred via Tornado Cash. Fluid's lending market, vault, DEX, and user deposits were unaffected. The team replaced the compromised key and transferred the remaining reward funds within approximately 10 hours, but the public statement only mentioned that reward claims were temporarily suspended, without mentioning details of the private key leak and the loss.