An attacker drained roughly $1.73 million from Notional Finance’s legacy escrow contract early Friday, exploiting a coding flaw that made an enormous fabricated debt register as zero.
The stolen DAI and USDC became about 689 ether (ETH). The funds then went through Tornado Cash, a service that breaks the trail between wallets. Notional has said nothing publicly.
How the Notional Finance Exploit WorkedNotional Finance is a fixed-rate lending protocol on Ethereum. Its first version recorded future cash obligations as tokens called fCash. The system screened borrowers for collateral before letting them add debt.
That screening converted debt into ether terms through a raw uint128 conversion. Two mints summed to exactly two raised to the power of 128. That is the single value the conversion flattens to zero, QuillAudits found.
A checked conversion would have rejected the figure instead of quietly dropping its digits. Notional used the safer method elsewhere in the same file, according to the write-up.
The account then read as debt free. Etherscan records show the setup landed at 11:58 p.m. UTC Thursday and the withdrawal three minutes later.
That second transaction moved 69,257 DAI and 1,658,524 USDC out of the escrow. The attacker also tipped block builder Titan 0.07 ETH to route the trade privately.
Security firm PeckShield relayed a warning from on-chain monitor Specter. The escrow now holds about $60,600 in leftover tokens.
#PeckShieldAlert Specter has reported that the Notional Finance escrow contract may have been exploited, resulting in $1.7M in ethereum:0x6b175474e89094c44da98b954eedeac495271d0f and $USDC lost.
The exploiter has swapped the stolen funds into 689.2 $ETH and deposited them into… pic.twitter.com/Wd5Dc3MWtL
— PeckShieldAlert (@PeckShieldAlert) September 4, 2026 Dormant V1 Contracts Still Held Real MoneyNotional wound down its third version after the November 2025 Balancer exploit cascaded into its vaults. The V1 contracts stayed live and funded, and nobody swept them.
Independently audited protocols still account for most crypto hack losses, so an old review offered no cover here. June brought a close parallel, when an attacker drained legacy Solana pools at Raydium.
Notional’s NOTE token trades near $0.0065, up 3.5% over 24 hours, on a market value close to $400,700.
Notional Finance (NOTE) Price Performance. Source: BeInCryptoNotional had issued no statement, loss figure, or post-mortem at publication. Whether the drained cash belonged to users, the treasury, or a third party remains unconfirmed.
Notional Finance may have suffered a $1.7 million exploit involving an escrow contract, blockchain investigators reported on Sept. 4. The reported losses include approximately $69,242 in DAI and $1.66 million in USDC.
Summary
Researchers reported $1.7 million in DAI and USDC leaving an escrow contract linked to Notional. The reported losses comprise $69,242 in DAI and $1,658,423 in USDC, according to Specter researchers. The suspected attacker exchanged the stablecoins for 689.2 ETH before depositing funds into Tornado Cash. PeckShield cited Specter’s findings, while Notional had not publicly confirmed the incident when last checked. The exploit’s technical cause, affected users and prospects for recovering assets remain publicly unconfirmed. Security firm PeckShield cited findings published by blockchain investigation group Specter. Neither report provided a complete technical explanation of how the assets left the contract.
“The Notional Finance escrow contract may have been exploited,” PeckShield said, preserving uncertainty about the incident’s status.
#PeckShieldAlert Specter has reported that the Notional Finance escrow contract may have been exploited, resulting in $1.7M in ethereum:0x6b175474e89094c44da98b954eedeac495271d0f and $USDC lost.
The exploiter has swapped the stolen funds into 689.2 $ETH and deposited them into… pic.twitter.com/Wd5Dc3MWtL
— PeckShieldAlert (@PeckShieldAlert) September 4, 2026 Notional Finance exploit report identifies two addresses Researchers identified two Ethereum addresses allegedly connected to the movement of the assets. The first address is 0xC954…De69, while the second is 0xDaCC…Ce38.
The addresses were labelled as theft addresses by Specter. That description remains an investigator attribution rather than a finding confirmed by Notional Finance, law enforcement or a court.
The available reports do not identify the precise escrow function involved. They also do not establish whether the event resulted from a smart-contract vulnerability, compromised credentials, faulty permissions or another cause.
Stablecoins were reportedly converted into 689.2 ETH The suspected attacker reportedly exchanged the DAI and USDC for approximately 689.2 ETH. The Ether was then deposited into Tornado Cash, according to Specter and PeckShield.
Tornado Cash is a set of Ethereum smart contracts designed to reduce the visible connection between deposits and later withdrawals. Its use can complicate blockchain tracing, although depositing assets into the protocol does not independently prove criminal ownership or intent.
The rapid conversion of stablecoins may also reduce opportunities for issuers or centralized platforms to restrict the assets. Both DAI and USDC can be followed publicly before conversion, while subsequent withdrawals from a mixer become harder to associate with the original address.
In related coverage, crypto.news reported that an address tied to the Drift Protocol exploiter moved $44 million through Tornado Cash after remaining inactive for several months.
No technical cause or official response is available Notional Finance had not published a public incident report or confirmation through its official account when checked. The project had also not disclosed whether contracts were paused, whether remaining assets were secured or whether users needed to take protective action.
The lack of confirmation means the reported $1.7 million loss should remain described as preliminary. It is also unclear whether the affected assets belonged directly to users, the protocol treasury or another party using the escrow contract.
No verified market reaction can be attributed to the report. Without an official assessment, linking token-price movements or changes in deposited value directly to the suspected exploit would be premature.
Previous recoveries depended on rapid containment DeFi projects commonly respond to suspected exploits by pausing vulnerable contracts, contacting stablecoin issuers and exchanges, tracing connected wallets and offering return agreements. Those options can become more limited after assets enter privacy protocols.
Some projects have still recovered positions or protected unaffected products after an attack. As crypto.news reported, Term Labs recovered its affected fixed-rate positions following an $8.5 million governance exploit, although several products remained closed.
Stake DAO also secured its Ethereum backing and closed a bridge after an unauthorized minting incident, according to related coverage. Those cases involved direct project responses that are not yet available for Notional Finance.
Meanwhile, Notional Finance operates as an Ethereum-based lending protocol focused on fixed-rate, fixed-term borrowing. Its documentation explains that deposited currencies can support borrowing obligations denominated in other currencies.
This makes contract-level accounting and collateral controls central to maintaining solvent user positions. However, researchers have not established whether the reported escrow incident affected Notional’s primary lending system, a separate integration or an older contract.
DAI and USDC have long formed part of Notional’s supported lending markets. The protocol’s technical materials describe currency pairs connecting those stablecoins with their interest-bearing equivalents.
The reported loss therefore involves assets used within Notional’s broader lending architecture, but the available evidence does not show that open loans, collateral balances or fixed-term positions were affected. An official contract identification is needed before the exposure can be measured accurately.
What happens next for Notional Finance The next confirmed update would likely need to establish which contract was involved, how the transactions were authorized and whether other funds remain exposed. A post-mortem could also clarify the ownership of the lost assets.
Investigators may continue tracking any Ether withdrawn from Tornado Cash. Exchanges and blockchain analytics companies could monitor later transactions, but the reported mixer deposits make attribution and recovery more difficult. Until Notional publishes an assessment, the scale, cause and effect on users remain unresolved.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
PeckShield reported that an address tied to the Tectonic hack transferred 2,658.9 ETH, valued at $6.65 million, to Tornado Cash on September 3. The incident has drawn attention from exchanges and blockchain investigators, as the move represents one of the largest unrecovered sums following the Cronos network exploit on August 30.
Chain rollback leaves funds on Ethereum untouchedTectonic, recognized as the leading lending platform on Cronos, experienced a major security breach that prompted validators to halt the blockchain within hours. Cronos, a blockchain network built by Crypto.com, later announced the restoration of block production from block 90,896,189, rolling the chain back to just before the hack.
Though the rollback reversed nearly all funds connected to the attacker within the Cronos chain, it could not reclaim assets already bridged to Ethereum. Approximately $74 million in stolen funds were traced by PeckShield across three addresses. Of this amount, $60 million remained in one Cronos wallet, $8 million in a second, and $6 million on Ethereum.
Independent data showed the Ethereum balance at 2,592.2152 ETH, or $6.29 million, after the incident. According to TRM Labs, the attacker moved stolen funds initially using USDC, then converted them into roughly 2,500 ETH.
On-chain researchers, including Weilin Li, used $75 million as the estimated total loss, while archive-node analyses suggested that up to $119.5 million may have been impacted if contracts deployed by the attackers before the exploit are included.
SourceTotal Stolen ($ Million)Funds on Cronos ($ Million)Funds on Ethereum ($ Million)PeckShield74686TRM Labs / Weilin Li75UnspecifiedUnspecifiedArchive-node analysis119.5Includes contractsIncludes contractsPrice manipulation triggers catastrophic lossesSecurity firm TRM Labs explained that the attacker exploited TONIC, the native token of Tectonic, which had only $305,000 in weekly trading volume prior to the incident and a 20% collateral ratio. Halborn, a blockchain security company, found that the hacker artificially inflated the price of TONIC by nearly 100 times within 20 minutes, then used the overpriced token to borrow high-value assets from nine lending platforms.
Subsequent investigations revealed a second attacker’s wallet, raising the lost value estimate from $66 million to $75 million. The hack caused Tectonic’s total value locked (TVL) to plummet from $121.7 million to just $3 million, as tracked by DeFiLlama.
The attack on Tectonic hollowed out the platform, with TVL plunging more than $118 million within hours.
Tornado Cash remains the key laundering avenueWhile the $6.65 million transacted via Tornado Cash represents a smaller portion of the overall exploit, the transaction route stands out due to Tornado Cash’s continuing role in crypto money laundering. TRM Labs documented that Tornado Cash received over $700 million in 2026 through June alone, making it the largest mixer protocol on Ethereum networks.
Besides being used to conceal illicit transactions, Tornado Cash has also supported legitimate privacy needs. The US Treasury removed the protocol from its sanctions list on March 21, 2025, but it remains under close watch for its role in facilitating major attacks.
The Cronos network’s rollback sparked a discussion about blockchain finality. Halborn emphasized that rolling back the chain limited losses but also undermined confidence in ledger immutability. Amid this uncertainty, CRO, Cronos’s native token, lost about 10% of its value in one day.
Mini dictionary: Tornado Cash, a decentralized privacy protocol on Ethereum, allows users to mix coins and obscure transaction trails, making it popular among both privacy advocates and cybercriminals seeking to launder assets.
Tornado Cash plays a pivotal role in laundering stolen cryptocurrency, remaining critically important to law enforcement, exchanges, and the wider crypto ecosystem.
Record rise in price-manipulation attacksThe Tectonic exploit mirrors a broader spike in price-manipulation attacks this year. PeckShield counted 50 major hacks in August alone, a 67% increase from July’s 30 incidents, though total losses decreased to $136.3 million from July’s $270 million. Among these, the Tectonic incident accounted for the largest loss of the month and ranked as the fourth-largest crypto theft in 2026.
TRM Labs has recorded 32 price-manipulation exploits so far in 2026, setting a new yearly record. Experts highlight that attackers often exploit low-liquidity tokens when protocols assign them significant collateral power, enabling rapid losses across protocols and networks.
The Tectonic case demonstrated how quickly such attacks can escalate, progressing from price manipulation to cross-chain laundering, and ultimately challenging the industry’s security and regulatory frameworks.
Serenity: Sivers Expands InP Production Capacity, Unlocking Potential $100 Billion-Level Market Space for AI Optical Communications
Serenity has issued a statement noting that Sivers Semiconductors (SIVE) plans to expand its indium phosphide (InP) manufacturing capacity in Glasgow, Scotland, targeting an annual production output of approximately 100 million continuous-wave distributed feedback (CW DFB) lasers, with the expanded capacity set to launch in Q4 2027. The expansion plan was officially announced by Sivers. Based on Sivers’ historical pricing of roughly $50–$100 per 8-laser array, Serenity estimates the new capacity could generate potential annual revenue of $625 million to $1.25 billion—this is a model projection, not the company’s official revenue guidance. Serenity said it was surprised by the scale of capacity unlocked via Sivers’ hybrid manufacturing model, particularly amid ongoing laser supply constraints in the AI data center optical communications industry. The expansion is primarily aimed at meeting demand for AI data centers and high-speed optical interconnects.
5 minutes ago
Ukrainian police have dismantled a cryptocurrency fraud ring in Kyiv, with the case involving up to $1 million in monthly illicit proceeds.
Ukraine’s National Police and Security Service have seized a fake cryptocurrency investment platform network based in Kyiv. The scam group used Telegram to distribute fake investment ads, luring victims to a counterfeit trading platform to steal their wallet assets. Investigations confirmed the group defrauded 62 victims across more than 20 countries, including Germany, Poland, France, the UK, Canada, Israel, and other regions. Fraudsters displayed false returns via forged trading interfaces; when users applied for withdrawals, they tricked them into authorizing small test transactions under the pretext of “account verification”, then exploited built-in crypto-theft programs to transfer funds from victims’ wallets. Ukrainian security authorities stated the criminal ring is led by a 25-year-old IT professional, with a peak monthly operation scale of $1 million. Police conducted 34 searches in Kyiv and its surrounding areas, seizing over 100 computers, more than 100 mobile phones, 79 SIM cards, and a large number of related devices. The case remains under further investigation, as police pursue additional suspects, identify more victims, and trace the full scale of stolen funds.
5 minutes ago
OpenAI Accelerates Embodied Intelligence Push, Sam Altman Says It 'Will Definitely Develop Humanoid Robots'
Beating AI News Flash: OpenAI CEO Sam Altman stated that the company "will definitely develop humanoid robots, and will also explore other forms of robots." Altman believes that since most real-world facilities and tools are designed around humans, humanoid structures are better suited to operate in physical environments. OpenAI is currently restructuring its robotics team, recruiting talents in areas including robot control algorithms, actuator design, data collection, and Embodied AI. Earlier around 2021, OpenAI shut down its early robotics project due to insufficient real-world data to train robot systems. Now, with advancements in large models and robot data infrastructure, the company is re-investing heavily in this field. Altman has repeatedly expressed interest in Embodied AI and humanoid robots before, noting that it would be a limitation if AI had near-general intelligence but was unable to perform tasks in the real world.
5 minutes ago
Bloomberg: Low volatility in US equities may signal risks, while gold's advantage over US Treasuries is near a historic high.
Bloomberg commodities strategist Mike McGlone wrote in a note that U.S. stock market volatility relative to gold is at its lowest level since 2007, and as markets enter their traditional volatile season, this situation could impact the performance of gold, stocks, and bonds in the second half of this year. McGlone noted that the ratio of the SPDR Gold ETF (GLD) to the iShares 20+ Year U.S. Treasury Bond ETF (TLT), which he tracks, is near an all-time high, indicating gold is performing extremely strongly relative to long-term U.S. Treasuries. He said that historically, extremely low stock market volatility occurred ahead of the 2008 financial crisis, and whether the current market will repeat a similar scenario remains to be seen. After gold surged to around $5,600 per ounce in the first quarter of this year, it may face pullback pressure similar to that seen after crude oil prices peaked in 2008. McGlone pointed out that commodity markets have a reversal effect after "rising too fast". After crude oil hit its peak in 2008, it weakened continuously relative to its 60-month moving average, with successive lower highs and lower lows. At that time, crude oil's premium relative to its long-term moving average hit its highest level since the 1973-1974 oil crisis. In February this year, gold once reached a premium of about 2.2 times its 60-month moving average, a level last seen in 1980. However, the difference is that this round of gold's rise has set an unprecedented record amid a non-high-inflation environment, so its subsequent trend remains to be watched.
5 minutes ago
International oil prices continue to climb, with both WTI and Brent crude up over 1%.
According to Bitget market data, both US and Brent crude oil prices rose by over 1%. WTI crude oil is currently trading at $90.01 per barrel, while Brent crude oil stands at $95.26 per barrel.
5 minutes ago
Claude E-commerce Agent open-sourced: Partner merchants see a 35% increase in shopping cart volume and a 60% rise in customer purchase rate.
Beating AI News Flash: Anthropic has open-sourced Claude Commerce Agents, a set of reference code enabling merchants to build their own shopping and operations agents. The suite includes two agents: one for consumers to search for products, compare items, bundle multiple goods, and add to cart; the other for merchants to monitor sales, inventory, pricing, and marketing. The code is licensed under Apache 2.0. Notably, the shopping agent only passes the cart to the merchant’s own checkout page—no direct payment processing interface is included. For the merchant agent, any adjustments to pricing, restocking, or promotions must first generate pending changes that require manual approval before implementation. These restrictions are not limited to prompts: rules around payments, product sourcing, pricing adjustment ranges, and manual approvals are enforced at the code level. Anthropic does not recommend splitting capabilities like search, returns, and pricing into multiple sub-agents. Instead, it uses a single Claude model that retains full conversation context, loading different skills on an as-needed basis. The company states that in comparisons across multiple enterprise deployments, this approach delivers higher quality, typically uses fewer tokens, and has lower latency. According to Anthropic, one partner saw a ~30%–35% increase in shopping cart size and a ~60% rise in customer purchase completion rates after deployment.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
TLDR An outdated Rain Solana contract allowed unauthorized withdrawals from card collateral accounts across multiple programs. Blockaid estimated about $1.1 million was stolen, with proceeds later entering Tornado Cash on Ethereum. Avici reported $500,859 drained from 1,685 users, while Tria identified $431,945 affecting 636 customers. Rain said every program using the vulnerable contract version has been upgraded since the attack. Self-custodial wallets were unaffected because the attacker targeted separate contracts holding funded card balances. An attacker exploited an outdated Rain card contract on Aug. 28, taking about $1.1 million from stablecoin card programs on Solana. Blockchain security firm Blockaid tracked the incident and published its findings.
Rain provides infrastructure that lets crypto companies issue cards funded with stablecoins. Customer deposits move into collateral accounts controlled by onchain contracts.
These collateral accounts are separate from a user’s personal wallet. Their safety depends on the code and controls set up by the infrastructure provider.
Blockaid found four contract deployments sharing the same code as the flawed version. The attacker drained funds from at least two of them.
Earlier today, Rain’s monitoring systems discovered a vulnerability impacting a small number of programs using an outdated version of our Solana contracts. Other programs were not impacted. Rain immediately launched an investigation to determine the full scope of the situation.…
— Rain (@raincards) August 28, 2026
How the Exploit Worked The outdated contract required two separate approvals before certain actions could happen. It used Solana’s Ed25519 verification system to check signatures.
Blockaid said the attacker reused one signature so it looked like two separate approvals. This let the attacker bypass the requirement without permission from account owners.
An attacker exploited an outdated Rain contract, draining $1.1M in user card balances from @avici, @useTria, and other crypto neobanks.
Blockaid's Onchain Monitoring gives stablecoin card issuers the capability to detect exploits across their fleet of contract deployments.
Read… pic.twitter.com/vzMQfPkdtT
— Blockaid (@blockaid_) September 2, 2026
After bypassing the check, the attacker gave itself admin access over individual accounts. It then withdrew USDC and USDT from those accounts.
Blockaid recorded 2,945 admin additions and 5,288 withdrawal calls. In total, it counted 8,233 exploit transactions over about two hours and 29 minutes.
The first two withdrawals happened three seconds apart. This pace suggests the attacker had built a system to target many accounts quickly.
Where the Funds Went The stolen stablecoins were sent to one Solana wallet. The attacker then swapped them for SOL using decentralized exchanges.
Blockaid traced the funds from Solana to Ethereum through the deBridge cross-chain protocol. About 455.9 ETH entered Tornado Cash between 19:20 and 19:49 UTC.
Tornado Cash mixes deposits so withdrawals can’t easily be linked to the original wallet. Blockaid said the funds had not been recovered as of its report.
Two Ethereum addresses were linked to the early funding of the attacker’s Solana activity. Neither Rain nor law enforcement has named who controls those addresses.
Avici said the attacker took $500,859.22 from 1,685 users. The company refunded all affected customers and added 10% cashback.
Tria reported losses of about $431,945 across 636 customers. It said each customer would be reimbursed.
Blockaid also named Solayer Pay as an affected program, though no confirmed loss figure was available for it. The gap between disclosed losses and Blockaid’s $1.1 million estimate has not been fully explained.
Avici’s token dropped 49% from its daily high after news of the exploit spread. It reached a low of $0.217 before recovering some value. Tria’s token also fell more than 10% at one point.
Rain said every program running the outdated contract has been upgraded. The company reported no further unauthorized activity since making the changes.
Rain has not released a full technical report or explained why older contract versions remained in use. It also has not said whether an audit caught the flaw before the attack happened.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Fables' pre-governance token PROLOGUE hits an all-time high: its market cap tops $12 million, with a 143% gain in the past 24 hours.
According to GMGN market data, Robinhood Chain-based token PROLOGUE has crossed $12 million in market capitalization, with a 143% 24-hour gain—hitting an all-time high—and $6.3 million in 24-hour trading volume. PROLOGUE is a pre-governance token on Robinhood Chain, backed by Fables, a dynamic-fee ve(3,3) DEX built on Uniswap v4. Its narrative is: "Every story has a beginning; this is just the prologue." At its Token Generation Event (TGE), PROLOGUE will be converted to the official governance token at a dynamic ratio, used for lock-up voting and fee sharing. BlockBeats Note: Token trading is highly volatile, largely driven by market sentiment and hype; investors should exercise caution.
13 minutes ago
Bitget has launched its "Niu Lai" perpetual contracts, supporting up to 10x leverage.
According to an official announcement, Bitget has launched its USDT-margined "Niu Lai" perpetual contracts, supporting up to 10x leverage. Contract trading bots will also be available simultaneously. For more details, please refer to Bitget's official platform.
13 minutes ago
Reports say Doubao 2.2 has been delayed: ByteDance catches up on coding, recruitment explicitly names Claude Code and Codex
Beating AI Insight News Brief: ByteDance’s originally planned August launch of Doubao 2.2 has been delayed. The company will allocate more training time to focus on strengthening coding, tool calling, and agent capabilities. This year, one of Seed’s core goals is to elevate its coding models to the top tier. Internally, the team aims to achieve performance on par with GLM-5.2 and Kimi-K3 by the end of the year, to earn genuine developer recognition for ByteDance’s coding models. In August, Seed underwent a major restructuring: teams originally segmented by text, speech, code, and vision were reorganized into four departments: Pretrain Data, Horizon RL, Product Posttrain-Work, and Product Posttrain-Chat. Horizon RL will handle coding post-training, while the Work team will focus on tool calling, GUI operations, and long-task execution. ByteDance has recently been intensively recruiting for these areas: its official website is hiring Code Agents, general Agents, and reinforcement learning algorithm engineers. One Multi-Agent Harness position explicitly requires research on Coding Agents such as Claude Code and Codex, plus building multi-agent and reinforcement learning environments capable of sustained long runs. When Seed 2.1 launched in June, it already highlighted coding, but ByteDance clearly deemed it inadequate. This time, Doubao 2.2 will delay its launch to first refine its coding capabilities to a more robust standard.
13 minutes ago
HyperLabs redeems 433,000 HYPE tokens worth about $36.14 million.
According to YuEjin Monitoring, the address of HyperLabs, the development team behind Hyperliquid, applied to redeem 433,000 HYPE tokens from staking 10 minutes ago, valued at roughly $36.14 million. The HYPE will fully exit staking in 7 days (September 6). Based on prior records, these tokens will be transferred to centralized exchanges via market maker Flowdesk post-staking exit.
13 minutes ago
Li Yihua: I hope everyone focuses on industry innovation and opportunities; a new bull market is about to start, and on-chain finance has opened up enormous potential.
Yilihua, founder of Liquid Capital, said: "Over the past decade in the crypto industry, it has been like a small world with its own social dynamics and cutthroat competition. Perhaps because it is too close to money or lacks clear rules, the sector is now dominated by negative voices and its reputation is worsening. I sincerely hope everyone refocuses on the industry’s innovations and opportunities. A new bull market is approaching; on-chain finance—especially tokenized stocks—has huge potential, and there are many meaningful projects and wealth-generating opportunities ahead. Moreover, the entire crypto industry is still in its early stages, and there is also the AI sector, which is dozens of times larger than crypto, worth exploring."
13 minutes ago
Uniswap trading volume surges on Robinhood, UNI price breaks above $5.2
According to HTX market data, UNI has broken through $5.24, with its 24-hour gain expanding to 18.9%. The primary catalyst driving UNI’s recent rally is the surge in real trading volume on Robinhood Chain, which has positioned Uniswap as the leading decentralized exchange (DEX) for tokenized stock RWAs on Robinhood. The daily trading volume of tokenized stocks on the chain once reached around $130 million, a nearly 10x increase in one month. Additionally, since Uniswap’s v4 version fee switch launched on Robinhood on July 27, the chain has become a major contributor to Uniswap’s fee revenue. Currently, Robinhood’s 24-hour protocol fees total approximately $11.29 million, with Uniswap and issuance platform Pons each contributing around $4.3 million, making Uniswap the top protocol by fee contribution. Per the v4 fee switch rules, this level of Uniswap protocol fees will fuel ongoing UNI token burns of $200,000 to $300,000 daily, equivalent to about 57,000 UNI tokens burned per day at current prices.
A U.S. federal judge has pushed Tornado Cash co-founder Roman Storm’s retrial to April 26, 2027, about six months later than planned, while his motion seeking to overturn his existing conviction remains unresolved.
Summary
Roman Storm’s retrial has been moved from October 2026 to April 26, 2027. His pending acquittal motion challenges his 2025 money transmitting conviction. Storm still faces money laundering and sanctions charges carrying up to 20 years each. The first jury deadlocked on both charges after convicting Storm on one separate count. The Aug. 25 court order states that U.S. District Judge Katherine Polk Failla granted Storm’s request to postpone the proceedings, moving the retrial from an October 2026 timetable after his defense cited scheduling conflicts and the pending motion for judgment of acquittal.
Storm filed the Rule 29 motion on Sept. 30, 2025, challenging his conviction for conspiracy to operate an unlicensed money transmitting business on the grounds that prosecutors had not presented enough evidence to sustain the verdict. Failla heard oral arguments on April 9, 2026, but had not ruled on the request when she issued the latest scheduling order.
Under the revised calendar, Storm will face another jury on two charges left unresolved during his first trial: conspiracy to commit money laundering and conspiracy to violate U.S. sanctions. Each carries a maximum prison sentence of 20 years.
Roman Storm retrial has been moved to April 2027 Storm’s defense asked Failla earlier in August to schedule the retrial no sooner than April 2027, according to the court proceedings, while prosecutors opposed extending the case and preferred the earlier October timetable.
The judge ultimately adopted the defense’s requested date of April 26, 2027, and reset the other pretrial deadlines around it. Expert disclosures will now take place in early 2027, with a final pretrial conference scheduled for April 20, six days before the trial is due to begin.
The new schedule reverses the timetable prosecutors had sought several months earlier. In March, crypto.news reported on prosecutors seeking an October retrial after the first jury failed to return unanimous verdicts on the money laundering and sanctions charges.
At the time, Storm said another trial would expose him to as much as 40 years in federal prison if he were convicted on both unresolved counts. He also said his legal resources had been heavily depleted during the first four-week trial.
The pending Rule 29 motion could affect another part of the case before Storm returns to court. Under the federal rule, a judge may enter a judgment of acquittal when the evidence introduced at trial is legally insufficient to support a conviction.
If Failla grants Storm’s motion, his conviction on the unlicensed money transmitting charge could be set aside. If the motion is denied, the conviction would remain in place while prosecutors proceed with their second attempt to secure verdicts on the two charges on which the original jury deadlocked.
The first jury convicted Storm on only one count Storm went to trial in Manhattan in the summer of 2025 on three criminal charges stemming from his involvement with Tornado Cash, the Ethereum-based privacy protocol he co-founded.
After several weeks of testimony and four days of deliberations, jurors returned a split verdict on Aug. 6, 2025. They found Storm guilty of conspiring to operate an unlicensed money transmitting business but could not unanimously decide the money laundering and sanctions conspiracy counts.
Failla declared a mistrial on the two unresolved counts, leaving prosecutors with the option to try Storm again before another jury.
The charge on which Storm was convicted carries a maximum sentence of five years in prison. The two counts awaiting retrial carry substantially higher penalties, with up to 20 years available on each if a conviction is secured.
Before the first trial began, the Justice Department had already reduced part of its case. In May 2025, prosecutors narrowed the money transmission allegation by dropping the portion based on Storm’s alleged failure to comply with federal money transmitter registration requirements under 18 U.S.C. § 1960(b)(1)(B).
Prosecutors continued with the remaining money transmission theory and the money laundering and sanctions allegations, saying their decision was consistent with an April 2025 Justice Department policy memorandum that instructed federal prosecutors to avoid using criminal cases to regulate the crypto industry through technical registration violations.
Storm was originally charged in August 2023 alongside Tornado Cash co-founder Roman Semenov. U.S. prosecutors accused the pair of helping operate a service that processed more than $1 billion in criminal proceeds, including funds connected to North Korea’s Lazarus Group.
The government’s case has focused partly on whether Storm and his co-founders continued developing, promoting and financially benefiting from Tornado Cash despite knowing that criminals and sanctioned actors were using the protocol.
Storm’s lawyers have disputed that interpretation, arguing that Tornado Cash operated through decentralized smart contracts and that its developers did not control individual transactions or take custody of funds moving through the protocol.
Tornado Cash sanctions were removed before the trial Tornado Cash allows users to deposit cryptocurrency into smart contracts and later withdraw funds to a separate address, reducing the direct on-chain connection between the sending and receiving wallets.
The U.S. Treasury Department’s Office of Foreign Assets Control sanctioned the protocol in August 2022, accusing it of being used to launder billions of dollars in virtual currency, including funds stolen by the Lazarus Group.
Legal challenges to those sanctions later produced an outcome separate from Storm’s criminal prosecution. In November 2024, the U.S. Court of Appeals for the Fifth Circuit ruled that immutable Tornado Cash smart contracts could not be treated as property under the International Emergency Economic Powers Act because they could not be owned or controlled.
Treasury subsequently removed Tornado Cash sanctions on March 21, 2025, reversing the designation imposed in 2022. The department continued to warn about North Korea’s use of digital assets for cybercrime and illicit financing after withdrawing the designation.
The sanctions decision did not terminate the criminal proceedings against Storm. Prosecutors continued arguing that his conduct before and during the period covered by the indictment could support the separate conspiracy charges.
An additional sanctions lawsuit brought by Coin Center was later closed after the government stopped defending the Tornado Cash designation following its removal.
Developer control remains disputed in Storm’s case Questions over how much control a software developer must exercise over a decentralized protocol before facing criminal liability have remained central to Storm’s defense.
Prosecutors have argued that Storm’s role went past publishing open-source software, alleging that Tornado Cash’s founders maintained parts of the project, promoted its use and profited from it while knowing illicit funds were passing through the protocol.
The defense has countered that Tornado Cash’s immutable smart contracts could continue operating without Storm and that users could interact with the contracts without the developers approving individual transfers.
Support for Storm has also come from parts of the Ethereum community. In January 2026, Ethereum co-founder Vitalik Buterin called for sentencing leniency and argued that privacy software can serve lawful purposes while open-source development should not by itself establish criminal liability. The report said Storm’s legal defense had raised more than $6.3 million with support from Buterin, the Ethereum Foundation and other donors.
The Ethereum Foundation had previously pledged up to $1 million in matching support for Storm’s legal defense following the 2025 verdict, while Storm remained free on bond as the criminal proceedings continued.
Failla has not issued a decision on Storm’s Sept. 30, 2025 Rule 29 motion. Under the new court schedule, the final pretrial conference on the unresolved money laundering and sanctions charges is set for April 20, 2027, with the retrial scheduled to start on April 26.
The retrial of Tornado Cash co-founder and developer Roman Storm has been postponed from Oct. 26, 2026, to April 26, 2027, as a federal judge weighs his motion for acquittal.
US District Judge Katherine Polk Failla said in a Tuesday order that the retrial would be adjourned “in light of” Storm’s pending motion and his related request for a continuance.
Storm’s lawyers requested the delay on Aug. 3, saying they needed at least 90 days after the court rules on the acquittal motion to prepare for another trial. Prosecutors opposed an adjournment, according to the filing.
In March, US prosecutors asked the court to schedule an October retrial on two charges after jurors failed to reach unanimous verdicts on either count. The charges were conspiracy to commit money laundering and conspiracy to violate US sanctions.
A Manhattan jury convicted Storm in August 2025 of conspiring to operate an unlicensed money-transmitting business, an offense carrying up to five years in prison. Storm subsequently asked the court to acquit him on all three charges, arguing prosecutors failed to prove he intended to help criminals misuse Tornado Cash.
“My acquittal motion is still sitting there, undecided,” Storm said Tuesday on X. “I honestly don’t know when this ends.”
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
The retrial of Tornado Cash co-founder and developer Roman Storm has been postponed from Oct. 26, 2026, to April 26, 2027, as a federal judge weighs his motion for acquittal.
US District Judge Katherine Polk Failla said in a Tuesday order that the retrial would be adjourned “in light of” Storm’s pending motion and his related request for a continuance.
Storm’s lawyers requested the delay on Aug. 3, saying they needed at least 90 days after the court rules on the acquittal motion to prepare for another trial. Prosecutors opposed an adjournment, according to the filing.
In March, US prosecutors asked the court to schedule an October retrial on two charges after jurors failed to reach unanimous verdicts on either count. The charges were conspiracy to commit money laundering and conspiracy to violate US sanctions.
A Manhattan jury convicted Storm in August 2025 of conspiring to operate an unlicensed money-transmitting business, an offense carrying up to five years in prison. Storm subsequently asked the court to acquit him on all three charges, arguing prosecutors failed to prove he intended to help criminals misuse Tornado Cash.
“My acquittal motion is still sitting there, undecided,” Storm said Tuesday on X. “I honestly don’t know when this ends.”
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
Roman Storm’s retrial has been postponed from October 2026 to April 26, 2027. His motion for acquittal remains unresolved after arguments earlier this year. Prosecutors plan to retry two charges on which the first jury deadlocked. The delay gives both sides additional time to address post-trial motions and prepare for a second trial.
A federal judge has postponed Tornado Cash co-founder Roman Storm’s retrial until April 26, 2027, extending one of the crypto industry’s most closely watched criminal cases while the court considers his pending motion for acquittal. The new schedule pushes back a retrial that had been set for October and leaves unresolved whether
Storm will face a second jury on money laundering and sanctions-related charges.
Why the Court Moved Storm’s Retrial to April 2027 U.S. District Judge Katherine Polk Failla issued the order on August 25 in the Southern District of New York.
The court directly cited two factors: Storm’s pending motion for acquittal and his related request to move the retrial into late April 2027. The new trial is scheduled to begin on April 26 at the Thurgood Marshall Courthouse in New York.
The court also excluded the period through the new trial date from calculations under the Speedy Trial Act. Judge Failla found that giving the parties and the court additional time to consider Storm’s post-trial motions and prepare for the retrial outweighed the interests served by holding it sooner.
The revised schedule now sets several deadlines:
February 5, 2027: Government expert disclosures March 5: Defense expert disclosures March 18: Rebuttal expert disclosures March 30: Daubert motions and motions in limine April 9: Oppositions to the March 30 motions April 20: Final pretrial conference April 26: Retrial begins The calendar provides substantially more preparation time, but the more immediate legal question comes before those deadlines: what Judge Failla decides on Storm’s pending acquittal motion.
The Acquittal Motion Could Reshape the Case Before Retrial Storm’s defense filed a Rule 29 motion for judgment of acquittal after his first trial. Oral arguments were held in April 2026, but the court has yet to rule.
According to Cornell Law School, a Rule 29 motion asks the judge to determine whether the prosecution presented legally sufficient evidence to sustain a conviction. It therefore differs from simply asking another jury to reconsider the facts.
That distinction gives the current delay greater significance than an ordinary scheduling change.
Storm was convicted in August 2025 of conspiracy to operate an unlicensed money transmitting business, an offense carrying a maximum sentence of five years. The jury, however, could not reach unanimous verdicts on the two more serious allegations: conspiracy to commit money laundering and conspiracy to violate U.S. sanctions.
Those unresolved counts are the basis for the planned retrial.
Each carries a potential maximum sentence of 20 years, meaning the charges returning to court carry substantially greater potential penalties than the count on which Storm was already convicted.
Storm’s Split Verdict Left the Hardest Questions Unresolved The first trial lasted four weeks and produced a result that gave neither side a complete victory.
Prosecutors secured a conviction on the money-transmission count, arguing that Storm knowingly participated in operating Tornado Cash as an unlicensed money transmitting business. The Justice Department said the service transmitted more than $1 billion in criminal proceeds.
Jurors were less convinced on the government’s broader theories.
They deadlocked on allegations that Storm conspired to launder proceeds from hacks and conspired to violate sanctions, including allegations involving funds connected to the North Korean Lazarus Group.
That division matters because the unresolved counts require the government to establish more than the money-transmission violation for which Storm was convicted.
The retrial therefore is not simply a repeat of the first case. Prosecutors will return to the two allegations that failed to produce unanimous verdicts, while Storm’s lawyers enter the second trial knowing where the first jury was unwilling to reach agreement.
Why the Case Matters Beyond Tornado Cash The broader significance of United States v. Storm comes from the difficult boundary it tests between software development and responsibility for how decentralized software is subsequently used.
Tornado Cash was designed to obscure the public blockchain connection between deposits and withdrawals, providing transaction privacy on Ethereum. Prosecutors argued that Storm and his co-founders went beyond merely publishing software and knowingly operated a service that processed criminal proceeds. Storm’s defense has maintained that the software itself was neutral and that developers should not be held criminally responsible for independent users’ conduct.
The first verdict did not fully resolve that conflict.
The money-transmission conviction demonstrated that a jury was willing to impose criminal liability under one theory of the government’s case. At the same time, the deadlock on money laundering and sanctions violations showed that proving knowledge and responsibility for the more serious conduct presented a higher hurdle.
For developers of decentralized protocols, that distinction is more useful than treating the case as a simple referendum on whether writing code creates criminal liability.
The eventual legal significance will depend on which specific activities courts determine can transform software development into participation in a regulated or unlawful financial service.
A Supreme Court Decision Has Entered Storm’s Defense Another issue could influence the next phase before jurors ever return to the courtroom.
Storm’s lawyers have pointed Judge Failla to a recent U.S. Supreme Court ruling involving internet provider Cox Communications and copyright infringement by its customers. The Supreme Court rejected part of the theory used to hold Cox responsible for providing services that customers subsequently misused. Storm’s defense has argued that the reasoning could have implications for determining when a technology provider can be held responsible for third-party conduct.
The cases arise under different areas of law, so the Supreme Court decision does not automatically dictate the outcome of Storm’s criminal prosecution.
Its relevance instead lies in the broader question of intent and secondary responsibility: how much knowledge of misuse, combined with continued provision of a service, is sufficient to establish liability?
Judge Failla’s treatment of that argument could provide additional guidance before the retrial.
April Is Not the Next Date That Matters The April 26 retrial now anchors the court calendar, but the pending Rule 29 decision remains the more immediate development.
A ruling on Storm’s post-trial motions could alter the legal landscape well before expert disclosures begin in February. The August 25 order itself makes that sequence clear by identifying the unresolved motions as one reason additional time is necessary.
The second issue to watch is how prosecutors refine the two charges that produced a deadlocked jury in 2025. A retrial gives the government an opportunity to adjust how it presents evidence, while the defense now has direct insight into which parts of the original case failed to secure unanimous agreement.
That makes the six-month postponement strategically meaningful for both sides. The next major development is therefore likely to come not from the April trial itself, but from Judge Failla’s ruling on the acquittal motion that helped push the case there.
In brief Judge Katherine Polk Failla adjourned Roman Storm's retrial to April 26, 2027, in an order entered Tuesday. His motion for acquittal, argued on April 9, remains undecided. Storm was convicted in August 2025 of conspiring to operate an unlicensed money transmitting business, with the jury split on money laundering and sanctions violation charges. Tornado Cash developer Roman Storm will not be retried on the two counts a jury deadlocked on until the spring of 2027, after Judge Katherine Polk Failla adjourned the proceeding by more than six months.
The order, entered Tuesday in the Southern District of New York, sets the retrial for April 26, 2027 at the Thurgood Marshall Courthouse and amends the pretrial schedule to run from expert disclosures on February 5, 2027 to a final conference on April 20. Failla excluded the intervening time under the Speedy Trial Act.
She cited Storm's pending motion for acquittal and "his related request to continue the retrial to a date in late April 2027," recording that the later date came from the defense.
Federal prosecutors under U.S. Attorney Jay Clayton had asked in March for a retrial beginning October 5 or 12 this year. Storm's lawyers called that premature while the acquittal motion was live.
A Manhattan jury convicted Storm in August 2025 of conspiring to operate an unlicensed money transmitting business and split on conspiracy to commit money laundering and conspiracy to violate U.S. sanctions. The two counts the government intends to retry carry a combined maximum of 40 years.
“Setting an example”Storm marked the order with a tweet arguing the case is aimed at the wider industry. "A jury deadlocked on the two most serious counts against me. And still SDNY won't stop," he wrote. "It's about setting an example."
One thing before I start: everything in this post is public information from my own docket. None of it is new, and I'm not revealing anything you can't already find in the court filings yourself.
The retrial just got pushed to April 26, 2027. The order came down today (Dkt.…
— Roman Storm 🇺🇸 🌪️ (@rstormsf) August 25, 2026
He cited a February 2024 New York City Bar Association event, filed as an exhibit on his docket, at which Tara La Morte, chief of SDNY's Illicit Finance and Money Laundering Unit, said her office wanted the industry to take notice and named the Tornado Cash prosecution as an example of bringing the sector into compliance.
In the tweet, Storm also highlighted that blockchain analysis firm Chainalysis "was running its OWN Tornado Cash relayer, and earning fees on the transactions flowing through it," pointing to trial transcripts as evidence. He added that after his lawyers subpoenaed Chainalysis to testify, "The jury never heard any of it" after the firm's witness pleaded the fifth.
Chainalysis declined to comment.
Developers and the lawStorm's case has drawn attention from privacy advocates including the Electronic Frontier Foundation and Ethereum co-founder Vitalik Buterin. Buterin, who backed Storm in January, described himself as "an active user of privacy tools, including those developed by Roman."
It is not the only prosecution of its kind. Alexey Pertsev, who worked on Tornado Cash alongside Storm, was convicted of money laundering in the Netherlands in May 2024 and sentenced to 64 months. He was released to electronic monitoring in February 2025 while appealing, and the Ethereum Foundation has pledged $1.25 million toward his defense.
In the U.S., Samourai Wallet co-founders Keonne Rodriguez and William Lonergan Hill pleaded guilty to conspiring to operate an unlicensed money transmitting business and were sentenced in November 2025 to five and four years respectively. U.S. President Donald Trump told Decrypt in December he would take a look at a pardon for Rodriguez, who began serving his sentence days later.
Storm's case sits awkwardly beside the Justice Department's own guidance. Days after his guilty verdict, Matthew Galeotti, then acting head of the department's criminal division, said prosecutors would no longer approve charges under the statute Storm was convicted on where software is decentralized and non-custodial, a policy he specified would apply going forward.
Storm has not yet been sentenced on the money transmitting count, which carries up to five years.
Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.
Fables' pre-governance token PROLOGUE hits an all-time high: its market cap tops $12 million, with a 143% gain in the past 24 hours.
According to GMGN market data, Robinhood Chain-based token PROLOGUE has crossed $12 million in market capitalization, with a 143% 24-hour gain—hitting an all-time high—and $6.3 million in 24-hour trading volume. PROLOGUE is a pre-governance token on Robinhood Chain, backed by Fables, a dynamic-fee ve(3,3) DEX built on Uniswap v4. Its narrative is: "Every story has a beginning; this is just the prologue." At its Token Generation Event (TGE), PROLOGUE will be converted to the official governance token at a dynamic ratio, used for lock-up voting and fee sharing. BlockBeats Note: Token trading is highly volatile, largely driven by market sentiment and hype; investors should exercise caution.
12 minutes ago
Bitget has launched its "Niu Lai" perpetual contracts, supporting up to 10x leverage.
According to an official announcement, Bitget has launched its USDT-margined "Niu Lai" perpetual contracts, supporting up to 10x leverage. Contract trading bots will also be available simultaneously. For more details, please refer to Bitget's official platform.
12 minutes ago
Reports say Doubao 2.2 has been delayed: ByteDance catches up on coding, recruitment explicitly names Claude Code and Codex
Beating AI Insight News Brief: ByteDance’s originally planned August launch of Doubao 2.2 has been delayed. The company will allocate more training time to focus on strengthening coding, tool calling, and agent capabilities. This year, one of Seed’s core goals is to elevate its coding models to the top tier. Internally, the team aims to achieve performance on par with GLM-5.2 and Kimi-K3 by the end of the year, to earn genuine developer recognition for ByteDance’s coding models. In August, Seed underwent a major restructuring: teams originally segmented by text, speech, code, and vision were reorganized into four departments: Pretrain Data, Horizon RL, Product Posttrain-Work, and Product Posttrain-Chat. Horizon RL will handle coding post-training, while the Work team will focus on tool calling, GUI operations, and long-task execution. ByteDance has recently been intensively recruiting for these areas: its official website is hiring Code Agents, general Agents, and reinforcement learning algorithm engineers. One Multi-Agent Harness position explicitly requires research on Coding Agents such as Claude Code and Codex, plus building multi-agent and reinforcement learning environments capable of sustained long runs. When Seed 2.1 launched in June, it already highlighted coding, but ByteDance clearly deemed it inadequate. This time, Doubao 2.2 will delay its launch to first refine its coding capabilities to a more robust standard.
12 minutes ago
HyperLabs redeems 433,000 HYPE tokens worth about $36.14 million.
According to YuEjin Monitoring, the address of HyperLabs, the development team behind Hyperliquid, applied to redeem 433,000 HYPE tokens from staking 10 minutes ago, valued at roughly $36.14 million. The HYPE will fully exit staking in 7 days (September 6). Based on prior records, these tokens will be transferred to centralized exchanges via market maker Flowdesk post-staking exit.
12 minutes ago
Li Yihua: I hope everyone focuses on industry innovation and opportunities; a new bull market is about to start, and on-chain finance has opened up enormous potential.
Yilihua, founder of Liquid Capital, said: "Over the past decade in the crypto industry, it has been like a small world with its own social dynamics and cutthroat competition. Perhaps because it is too close to money or lacks clear rules, the sector is now dominated by negative voices and its reputation is worsening. I sincerely hope everyone refocuses on the industry’s innovations and opportunities. A new bull market is approaching; on-chain finance—especially tokenized stocks—has huge potential, and there are many meaningful projects and wealth-generating opportunities ahead. Moreover, the entire crypto industry is still in its early stages, and there is also the AI sector, which is dozens of times larger than crypto, worth exploring."
12 minutes ago
Uniswap trading volume surges on Robinhood, UNI price breaks above $5.2
According to HTX market data, UNI has broken through $5.24, with its 24-hour gain expanding to 18.9%. The primary catalyst driving UNI’s recent rally is the surge in real trading volume on Robinhood Chain, which has positioned Uniswap as the leading decentralized exchange (DEX) for tokenized stock RWAs on Robinhood. The daily trading volume of tokenized stocks on the chain once reached around $130 million, a nearly 10x increase in one month. Additionally, since Uniswap’s v4 version fee switch launched on Robinhood on July 27, the chain has become a major contributor to Uniswap’s fee revenue. Currently, Robinhood’s 24-hour protocol fees total approximately $11.29 million, with Uniswap and issuance platform Pons each contributing around $4.3 million, making Uniswap the top protocol by fee contribution. Per the v4 fee switch rules, this level of Uniswap protocol fees will fuel ongoing UNI token burns of $200,000 to $300,000 daily, equivalent to about 57,000 UNI tokens burned per day at current prices.
Fables' pre-governance token PROLOGUE hits an all-time high: its market cap tops $12 million, with a 143% gain in the past 24 hours.
According to GMGN market data, Robinhood Chain-based token PROLOGUE has crossed $12 million in market capitalization, with a 143% 24-hour gain—hitting an all-time high—and $6.3 million in 24-hour trading volume. PROLOGUE is a pre-governance token on Robinhood Chain, backed by Fables, a dynamic-fee ve(3,3) DEX built on Uniswap v4. Its narrative is: "Every story has a beginning; this is just the prologue." At its Token Generation Event (TGE), PROLOGUE will be converted to the official governance token at a dynamic ratio, used for lock-up voting and fee sharing. BlockBeats Note: Token trading is highly volatile, largely driven by market sentiment and hype; investors should exercise caution.
12 minutes ago
Bitget has launched its "Niu Lai" perpetual contracts, supporting up to 10x leverage.
According to an official announcement, Bitget has launched its USDT-margined "Niu Lai" perpetual contracts, supporting up to 10x leverage. Contract trading bots will also be available simultaneously. For more details, please refer to Bitget's official platform.
12 minutes ago
Reports say Doubao 2.2 has been delayed: ByteDance catches up on coding, recruitment explicitly names Claude Code and Codex
Beating AI Insight News Brief: ByteDance’s originally planned August launch of Doubao 2.2 has been delayed. The company will allocate more training time to focus on strengthening coding, tool calling, and agent capabilities. This year, one of Seed’s core goals is to elevate its coding models to the top tier. Internally, the team aims to achieve performance on par with GLM-5.2 and Kimi-K3 by the end of the year, to earn genuine developer recognition for ByteDance’s coding models. In August, Seed underwent a major restructuring: teams originally segmented by text, speech, code, and vision were reorganized into four departments: Pretrain Data, Horizon RL, Product Posttrain-Work, and Product Posttrain-Chat. Horizon RL will handle coding post-training, while the Work team will focus on tool calling, GUI operations, and long-task execution. ByteDance has recently been intensively recruiting for these areas: its official website is hiring Code Agents, general Agents, and reinforcement learning algorithm engineers. One Multi-Agent Harness position explicitly requires research on Coding Agents such as Claude Code and Codex, plus building multi-agent and reinforcement learning environments capable of sustained long runs. When Seed 2.1 launched in June, it already highlighted coding, but ByteDance clearly deemed it inadequate. This time, Doubao 2.2 will delay its launch to first refine its coding capabilities to a more robust standard.
12 minutes ago
HyperLabs redeems 433,000 HYPE tokens worth about $36.14 million.
According to YuEjin Monitoring, the address of HyperLabs, the development team behind Hyperliquid, applied to redeem 433,000 HYPE tokens from staking 10 minutes ago, valued at roughly $36.14 million. The HYPE will fully exit staking in 7 days (September 6). Based on prior records, these tokens will be transferred to centralized exchanges via market maker Flowdesk post-staking exit.
12 minutes ago
Li Yihua: I hope everyone focuses on industry innovation and opportunities; a new bull market is about to start, and on-chain finance has opened up enormous potential.
Yilihua, founder of Liquid Capital, said: "Over the past decade in the crypto industry, it has been like a small world with its own social dynamics and cutthroat competition. Perhaps because it is too close to money or lacks clear rules, the sector is now dominated by negative voices and its reputation is worsening. I sincerely hope everyone refocuses on the industry’s innovations and opportunities. A new bull market is approaching; on-chain finance—especially tokenized stocks—has huge potential, and there are many meaningful projects and wealth-generating opportunities ahead. Moreover, the entire crypto industry is still in its early stages, and there is also the AI sector, which is dozens of times larger than crypto, worth exploring."
12 minutes ago
Uniswap trading volume surges on Robinhood, UNI price breaks above $5.2
According to HTX market data, UNI has broken through $5.24, with its 24-hour gain expanding to 18.9%. The primary catalyst driving UNI’s recent rally is the surge in real trading volume on Robinhood Chain, which has positioned Uniswap as the leading decentralized exchange (DEX) for tokenized stock RWAs on Robinhood. The daily trading volume of tokenized stocks on the chain once reached around $130 million, a nearly 10x increase in one month. Additionally, since Uniswap’s v4 version fee switch launched on Robinhood on July 27, the chain has become a major contributor to Uniswap’s fee revenue. Currently, Robinhood’s 24-hour protocol fees total approximately $11.29 million, with Uniswap and issuance platform Pons each contributing around $4.3 million, making Uniswap the top protocol by fee contribution. Per the v4 fee switch rules, this level of Uniswap protocol fees will fuel ongoing UNI token burns of $200,000 to $300,000 daily, equivalent to about 57,000 UNI tokens burned per day at current prices.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
A fundraiser supporting Tornado Cash co-founder Roman Storm has crossed $1.3 million in crypto donations, with Zcash emerging as the overwhelming source of support. According to figures displayed on the fundraiser, $ZEC contributions account for nearly $1.29 million of the total raised. Bitcoin ($BTC) donations stand at roughly $3,280, while Bitcoin Cash ($BCH) adds approximately $9,267.
Helius CEO Mert Mumtaz flagged the Zcash dominance as a notable development, pointing to the symbolism of a privacy-focused network rallying behind a developer prosecuted over privacy-focused code.
A Long Legal Battle With High Stakes Storm, one of the co-founders of the Ethereum-based cryptocurrency mixer Tornado Cash, was formally indicted by the Department of Justice in 2023 on charges stemming from his development of the Tornado Cash protocol, a software solution designed to give crypto users financial privacy. Prosecutors allege that through Tornado Cash, Storm knowingly facilitated more than $1 billion in criminal proceeds, including funds linked to North Korean hacker group Lazarus.
A jury convicted Storm on one count of conspiracy to operate an unlicensed money transmitting business, but could not reach a unanimous verdict on the remaining two charges, resulting in a partial mistrial. That conviction carries a maximum sentence of five years, while a guilty verdict on the two deadlocked counts could add up to 40 years. The Department of Justice filed a letter requesting a retrial on the deadlocked charges, proposing a start date of October 5 or 12, 2026.
Storm's legal team argues that Tornado Cash was never a business but a decentralized and immutable protocol that operated beyond any individual's control. His supporters frame the case as a test of whether writing open-source code can be treated as a criminal act.
Broader Community Support The fight has drawn wide community backing. The Ethereum Foundation launched a matching campaign of up to $500,000, which helped drive total defense funds past $5 million. Ethereum co-founder Vitalik Buterin and other prominent figures in the crypto industry have also contributed to Storm's legal fund. The latest Zcash-led surge adds a fresh dimension to that support, underlining how deeply the privacy coin community is invested in the outcome.
The case is widely seen as a potential precedent for how courts treat open-source privacy tools, with serious implications for decentralized finance and developer liability more broadly.
Sources:
Free Roman Storm: Legal Defense Fund
The Block: Ethereum Foundation pledges to match up to $500,000 in donations for Roman Storm
DeFi Education Fund: U.S. v. Storm 2026 Update
TLDR: A malicious Tornado Cash frontend captured withdrawal notes and enabled attackers to drain 1,010 ETH from one user. Attackers allegedly stole nearly 4,000 ETH through similar expired-domain phishing operations during the previous 12 months. On-chain data traced 73 BTC through Whirlpool before part of the funds moved to Ethereum and Tornado Cash. The incident shows how expired domains and outdated bookmarks can expose users despite legitimate underlying smart contracts. A Tornado Cash phishing attack has cost one user 1,010 ETH after an old bookmarked link led to a malicious website. The attackers reportedly controlled Tornado Cash’s expired tornado.cash domain and used it to imitate the protocol’s interface.
The victim deposited funds into legitimate smart contracts but exposed private withdrawal information through the malicious frontend. Reports also linked the stolen funds to suspicious Bitcoin activity, raising questions about the victim’s earlier transactions.
Tornado Cash Phishing Attack Exploits Expired Official Domain According to Wu Blockchain, the user accessed the malicious website through an old bookmark. The expired tornado.cash domain redirected the user to an attacker-controlled frontend.
The victim then deposited ETH through Tornado Cash’s legitimate smart contracts. However, the fake interface reportedly captured private withdrawal notes required to later access the funds.
Attackers allegedly drained the 1,010 ETH within 12 hours of the deposit. The stolen assets now remain largely in addresses connected to the attackers.
Tornado Cash lost control of the domain after U.S. sanctions targeted the protocol in 2022. The team reportedly failed to renew the domain during that period, allowing attackers to register it later.
The attackers then recreated a frontend resembling the original Tornado Cash interface. Wu Blockchain reported that similar phishing operations may have stolen nearly 4,000 ETH during the past year.
User Loses Over 1,000 ETH in Phishing Attack After Using Tornado Cash’s Expired Official Domain
According to community users, a user clicked an old link left in a related bookmark and was redirected to a phishing site through the expired official domain tornado. cash, which had… pic.twitter.com/8j7eQl3qX2
— Wu Blockchain (@WuBlockchain) August 20, 2026
The incident shows how expired domains can create risks even when underlying smart contracts remain legitimate. Users who rely on old bookmarks may unknowingly interact with attacker-controlled interfaces.
The phishing website did not require attackers to alter Tornado Cash’s smart contracts. Instead, the operation targeted sensitive information generated during the withdrawal process.
Users generally need those private notes to recover deposited funds. Once attackers obtained them, they could potentially claim the associated ETH.
On-Chain Data Adds Another Layer to Tornado Cash Attack On-chain researcher Specter examined the victim’s earlier transactions and questioned the source of the funds. He said the wallet moved 73 BTC, worth roughly $4.6 million, from a Whirlpool mixer.
Part of those Bitcoin funds later moved across chains into Ethereum. The assets eventually reached the phishing Tornado Cash interface, according to the transaction trail.
The victim reportedly claimed that an earlier Coldcard-related incident prompted the Bitcoin-to-Ethereum transfer. Specter questioned why the wallet used multiple mixing services before the phishing event.
The victim could be a threat actor, and the funds may themselves have been stolen.
He claimed to have moved his funds from Bitcoin to Ethereum because of the Coldcard hack.
Looking on-chain, however, the 73 BTC ($4.6m) originally came from a Whirlpool mixer two weeks ago which… https://t.co/6x2jKeCjjF pic.twitter.com/KrZQUG9PQ9
— Specter (@SpecterAnalyst) August 20, 2026
Specter also reported connections between the individual and Telegram groups focused on private-key discovery and brute-force activity. The available information does not independently establish the person’s role or ownership of earlier stolen funds.
Still, the transaction history created a second layer of scrutiny around the case. It also raised the possibility that the stolen ETH originated from another suspicious source.
The immediate loss, however, followed the expired-domain phishing operation. The case centered on a malicious frontend rather than a failure within Tornado Cash’s smart contracts.
The incident adds to a broader security concern surrounding dormant crypto domains. Old bookmarks can remain active long after project teams lose control of a website.
An Ethereum user reportedly lost 1,010 ETH after following an old Tornado Cash bookmark that allegedly redirected to a malicious frontend controlled by phishing attackers.
Summary
An Ethereum address received 810 ETH through nine transfers on August 18, onchain records confirm. Community reports claimed 1,010 ETH was stolen after a user visited a suspected phishing frontend. The cited wallet retained approximately 810 ETH, worth about $1.86 million when records were checked. Claims that attackers stole nearly 4,000 ETH over twelve months remain independently unverified by researchers. Tornado Cash’s website was accessible when checked, leaving the alleged domain takeover without official confirmation. Community accounts said the incident unfolded over approximately 12 hours. They alleged that attackers obtained the victim’s Tornado Cash deposit credentials and withdrew the funds before transferring them to several addresses.
Onchain records provide partial confirmation. The cited wallet received 810 ETH through nine transactions on Aug. 18. Eight transfers carried 100 ETH each, while the final transfer carried 10 ETH.
The transactions occurred between 5:56 a.m. and 6:05 a.m. UTC. The address retained approximately 810 ETH, valued by Etherscan at about $1.86 million when checked on Aug. 20.
Ethereum records confirm 810 ETH, not the full claim The verified transactions leave a 200 ETH gap between the 1,010 ETH loss reported by community users and the 810 ETH held by the cited wallet. The remaining amount may have reached another address, but no additional destination was included in the supplied evidence.
User Loses Over 1,000 ETH in Phishing Attack After Using Tornado Cash’s Expired Official Domain
According to community users, a user clicked an old link left in a related bookmark and was redirected to a phishing site through the expired official domain tornado. cash, which had… pic.twitter.com/8j7eQl3qX2
— Wu Blockchain (@WuBlockchain) August 20, 2026 No public statement from Tornado Cash, an established blockchain security firm or the reported victim had independently confirmed the full amount when this article was prepared.
Community accounts claimed the victim tracked a total loss of 1,010 Ethereum, but the provided address independently confirms only 810 Ethereum.
The cited wallet had recorded nine transactions and no outgoing transfer at the time of review. Its balance therefore supports the claim that most of the reported funds remained under the suspected attacker’s control.
At Ether’s price of approximately $2,295, the confirmed 810 Ethereum was worth about $1.86 million. The reported 1,010 Ethereum loss would be worth roughly $2.32 million at the same price.
Tornado Cash domain takeover remains unconfirmed Reports blamed the theft on the tornado.cash domain, claiming it expired after the project’s team failed to renew it during the disruption caused by U.S. sanctions. According to the accounts, an attacker subsequently registered the address and installed a fake user interface.
That account could not be fully verified. The domain was accessible and displayed a Tornado Cash interface when checked. No authoritative domain record, official Tornado Cash warning or named security researcher was found confirming that the address had expired and changed ownership.
Claims that the official domain was captured by an attacker therefore remain unconfirmed and should not be presented as an established cause.
A website loading correctly at the time of checking does not prove it was safe at an earlier time. Attackers can remove malicious code, redirect only selected visitors or restore a legitimate interface after collecting credentials.
Tornado Cash has faced previous frontend security problems. In 2024, researcher Gas404 found that malicious JavaScript had been inserted into an open source interface and could expose private deposit notes. Checkmarx later documented the supply chain compromise, although no evidence currently connects that episode with the latest transactions.
Deposit notes can give attackers control of funds Tornado Cash uses private deposit notes to let users withdraw assets from its pools. Anyone who obtains a valid note can generally initiate the corresponding withdrawal, making the note comparable to a private credential.
A fake frontend can capture this information when a user attempts to make a deposit or withdrawal. The attacker can then use the stolen note before the legitimate owner does.
The attack differs from approval phishing, where a victim signs a malicious transaction that authorizes a drainer contract. In related coverage, crypto.news explained how wallet drainers exploit deceptive signatures to gain access to tokens and nonfungible assets.
Old bookmarks present another risk because users often assume previously trusted links remain safe. Expired or transferred domains preserve their familiar names, search rankings and backlinks, making malicious replacements harder to identify.
As crypto.news recently reported, fake websites continue draining Ethereum wallets after users approve transactions or enter sensitive information. The safest approach is to verify domains through several current project channels before connecting a wallet.
Nearly 4,000 ETH claim needs more evidence Community reports also alleged that the same attackers stole almost 4,000 ETH through similar methods over the previous 12 months. No list of related addresses or attribution analysis accompanied that figure.
Without linked wallets, transaction hashes or a report from a security firm, the 4,000 ETH estimate cannot be independently verified. Blockchain transfers show where funds moved, but they do not automatically establish who controlled each address or which phishing campaign generated them.
The immediate priority is monitoring the confirmed 810 ETH. Transfers to exchanges could create an opportunity for platforms to identify or freeze assets, subject to their procedures and applicable law.
The victim should preserve browser history, bookmarked URLs, wallet logs and transaction records before reporting the incident to wallet providers, exchanges and law enforcement. Users who interacted with the same frontend should stop using it, move unaffected assets and revoke suspicious token approvals.
The available evidence supports a large Ethereum transfer into a newly active wallet. It does not yet prove the full 1,010 ETH loss, the alleged takeover of the official domain or the claimed 4,000 ETH campaign.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Amid the August 19 (819) rally, multiple suspected insider addresses have emerged. BlockBeats has compiled the details below: The newly created address 0xedcdcaa1f18350c50c10bef860e64daa9785d05a first took profits from its long position in HYPE last night, then switched to a 4x leveraged long position in ETH at an average entry price of $1,936. As of press time, it holds 20,000 ETH long contracts, with an unrealized profit exceeding $6 million. Address 0xde8d9e530b0528ffa7b1190f862536c055dd9524 started building its ETH position on the 17th. As of press time, it has accumulated 10,657 ETH (totaling $20.7 million, at an average entry price of $1,942), which has now been directly deposited for staking. Additionally, a suspected hacker address obtained 17,124 ETH via Tornado Cash, sold it at a high nine months ago, and last night used 38.535 million DAI/USDS to purchase 18,273 ETH at an average price of $2,109.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Whale 0x8447 bought another 5,000 $ETH($9.53M) 7 hours ago and staked it. This whale has bought a total of 10,657 $ET...
Whale 0x8447 bought another 5,000 $ETH($9.53M) 7 hours ago and staked it. This whale has bought a total of 10,657 $ETH($20.07M).
31 minutes ago
A new address withdrew 57,000 HYPE tokens from Coinbase, valued at approximately $3.36 million.
According to monitoring by Onchain Lens, a newly created wallet has withdrawn a cumulative total of 57,000 HYPE tokens from Coinbase, valued at approximately $3.36 million.
31 minutes ago
Morgan Stanley cuts Pop Mart’s target price by 13%, citing pressures including a high base effect.
Morgan Stanley cut Pop Mart’s target price from HK$247 to HK$214, citing high base pressure in the second half of the year and a sharp slowdown in overseas sales. Analysts noted in the report that amid a lack of incremental information and high-frequency data pointing to a sharp slowdown in overseas sales, investors are broadly bearish ahead of the earnings release, anchoring on the most negative metrics. Excessive expectations among retail investors remain a key downside risk, as they account for a large proportion of the shareholder base. The firm forecasts 29% year-on-year growth in first-half revenue and an 18% rise in net profit to RMB 5.4 billion. It expects management to guide for second-half revenue exceeding the first half, while remaining cautious on the year-on-year outlook. Morgan Stanley maintained an "Overweight" rating, projecting a 13% compound annual growth rate (CAGR) in earnings from 2026 to 2028, driven mainly by a reacceleration in overseas market sales, and forecasts total revenue will resume growth in 2027.
31 minutes ago
A large number of pirated copies of the film "Odyssey" hide malware designed to steal cryptocurrency.
Security firm Bitdefender announced this week that a surge of pirated download files masquerading as the newly released blockbuster *The Odyssey* have surfaced online, each bundled with the Lumma Stealer information-stealing malware. The malware is designed to siphon sensitive data including cryptocurrency wallet credentials. Per Bitdefender, these malicious files began appearing just days after the film’s premiere, disguised as high-definition WEBRip and Blu-ray copies, with filenames crafted to mimic legitimate torrent resources. In truth, the files are Windows executables that infect devices upon launch, not media for viewing. To amplify their deception, attackers frequently use icons resembling VLC Media Player or standard video files to mask the malicious programs. Because Windows hides file extensions by default, many users cannot easily distinguish an '.exe' executable from a genuine video file, raising the risk of accidental execution.
31 minutes ago
Michael Saylor: Strategy may initiate a stock repurchase when its share price falls to a sufficiently "cheap" level.
Michael Saylor, founder of Strategy, said share repurchases are not a current priority, but the company may buy back its own stock if MSTR’s share price falls to a sufficiently cheap level. During a Monday Q&A event, Saylor stated: “If MSTR trades at a very, very deep discount to its net asset value (NAV), you might see us take such action.” Saylor added that the company plans to maintain a large cash reserve to gain greater flexibility, which can be used to purchase Bitcoin, repurchase MSTR shares or preferred stock, or pay down debt. This flexibility also applies to Bitcoin. “We must be able to both sell Bitcoin and buy Bitcoin,” he noted. The company’s strategy prioritizes the development of STRC, cash reserves, and credit operations over share repurchases. He also explained how Bitcoin’s price will impact Strategy’s future purchase plans: when BTC trades well above its 200-week moving average, Strategy may hold onto more of the cash it raises; when Bitcoin’s price approaches or falls below this long-term average, it could be viewed as a buying opportunity. For MSTR investors, Saylor said they should view the investment with a minimum four-year time horizon, ideally holding for 7 to 10 years. He concluded: “I can feel your pain. But I think we must be prepared to go through tough years.”
31 minutes ago
South Korea denies reports that it will make its first investment in the U.S. in chips.
South Korea has denied reports that it was discussing making semiconductors its first investment in the U.S. The South Korean presidential office said Tuesday, "The claim that the two countries discussed semiconductors as a candidate for the first strategic investment project is not true." The presidential office did not disclose details of negotiations between Seoul and Washington on the investment commitment. Earlier, JoongAng Ilbo reported that South Korea’s first investment project, which it had planned to announce later this month, faced uncertainty after Washington suddenly sought investment in U.S. memory chip facilities. According to the newspaper, the request was the focus of a closed-door trade meeting held at the presidential office on August 13. South Korea had initially targeted the energy sector for its first major investment in the U.S., and officials present generally deemed investing in a U.S. memory chip factory unrealistic, as Samsung Electronics and SK Hynix have pledged to invest at least $880 billion in building chips and data centers.
A threat actor responsible for more than $300 million in reported thefts from Coinbase users has once again moved a significant portion of stolen funds. On-chain investigator VAL reported that approximately $500,000 was recently converted to Ethereum and transferred to Tornado Cash, an Ethereum-based privacy protocol.
Investigators have linked these substantial losses to coordinated social engineering attacks rather than smart contract vulnerabilities. According to the research, scammers impersonated Coinbase customer support representatives, targeting account holders directly through deceptive communications.
Victims were tricked into sharing sensitive information such as account credentials, or into following fraudulent instructions, which resulted in unauthorized transfers or the approval of malicious transactions. These attacks exclusively targeted individual users, and there has been no evidence indicating an exploit within the Coinbase or Ethereum smart contract infrastructure.
On-chain investigator ZachXBT previously detailed that cumulative losses have exceeded $300 million. This figure accounts for multiple Coinbase accounts compromised during the course of the scam operation.
Tens of millions of dollars are believed to remain in wallets controlled by the threat actor, although investigators did not disclose the current total across all linked addresses.
Funds routed through Ethereum privacy protocolsVAL observed that in the most recent incident, the scammer converted around $500,000 into ETH before transferring it to Tornado Cash. Three weeks earlier, the same operator moved another $2 million using a similar method. Rather than executing a single large transfer, the threat actor used multiple discreet transactions to obscure the trail.
On the Ethereum blockchain, Tornado Cash functions through smart contracts that deposit and withdraw funds separately, complicating efforts to track assets once deposited in the protocol. Investigators noted it remains technically feasible to trace funds until the point of deposit into Tornado Cash contracts.
VAL identified two specific wallet addresses connected to the latest series of transactions: 0x5Da2…89D8a and 0x3ECe…f296. The operator has also been known to send custom messages within transactions to on-chain investigators, such as ZachXBT, often including taunts regarding ongoing efforts to identify the scammer.
Messages apparently mocked both ZachXBT and VAL as they pursued leads in the investigation, but so far no details have emerged about the suspect’s identity or the location of remaining funds.
Growing scrutiny and Web3 innovationBoth ZachXBT, who tracks aggregate losses, and VAL, who reports on the latest movements, have verified that these transactions form part of the same coordinated campaign targeting Coinbase users. In response to ongoing phishing schemes, Coinbase representatives have repeatedly emphasized that their staff will never request passwords, two-factor authentication codes, or asset transfers from customers.
As scams targeting traditional brokerage platforms and centralized exchanges continue, the landscape of asset management is rapidly evolving. While traditional markets rely on complex brokers, a massive shift is happening: Wall Street is moving to Web3. Investors are now using platforms like 1stepSwap to hold shares of major U.S. companies, gold, and silver directly in their crypto wallets. By tokenizing Real-World Assets (RWAs) and automatically finding the best market prices in seconds, it completely removes the middlemen.
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
The stolen XRP was converted to ETH, routed through THORChain and ultimately sent to Tornado Cash after the bridge was drained.
On August 9, a bridge connecting the XRP Ledger and Coreum (now rebranded as tx) lost close to 200,000 XRP after an attacker tricked its deposit-checking system into treating a wallet-to-wallet transfer as a real deposit.
The bridge has since halted, and both the operator and outside researchers have traced the failure to Coreum-side software rather than anything on the XRP Ledger itself.
What Happened, and How the Alarm Went Out The first public warning came from a trader posting as playa, who flagged that the bridge’s XRPL account rxXXXeMX8Gy5YvibvGLnQJ1XKKD7UswM1, was bleeding funds and pointed to the account’s DefaultRipple setting as the cause.
Playa said the balance had gone from 93,700 XRP to 77,200 XRP within minutes, a reading taken from an eleven-minute slice of what turned out to be a ninety-seven-minute drain.
Another user, Vet, pushed back in the same thread, writing that “the reason is the coreum bridge was being actively exploited.” Playa later agreed, posting, “I was rushing when I posted and didn’t dig in properly.”
The tx team confirmed the exploit in a statement, saying its software “incorrectly registered transactions that never actually delivered any XRP to the bridge.”
A technical breakdown from Reza Bashash filled in the mechanism: the attacker sent the bridge’s own wrapped token between two of their own wallets, attached a bridge-deposit memo, and because the token is issued by the bridge, the transfer showed up in its history and was read as a genuine deposit.
You may also like: ONE Dumps to ATL as Harmony Exploited in Unauthorized Mint of 4B Tokens Important Ripple News and XRP Price Update: August 11 Major XRP Ledger Upgrade Targets Institutional Adoption But There’s a Catch Relayers approved it, unbacked assets were minted on the Coreum side, and the attacker withdrew real XRP against them. Bashash put the total at 198,715.88 XRP, converted to ETH, routed through THORChain, and ultimately sent to Tornado Cash.
The tx says the vulnerability has been identified, the bridge remains halted, and it has filed a report with the FBI’s Internet Crime Complaint Center. No other bridged assets were affected, and the operator says a plan for compensating users is still being worked out.
A Deeper Look, and a Market Already Under Pressure A later on-chain review found the same root cause from a different angle: 21 separate Coreum relayers each attested to the same phantom deposit, letting the attacker mint bridge assets with nothing backing them, then repeated the trick with escalating amounts before cashing out.
Every payout that followed on the XRPL Ledger carried a valid multisignature from the bridge’s own relayer quorum, which is why the DefaultRipple explanation didn’t hold up once the transaction data was checked. Native XRP has no trust line to ripple along in the first place, and the flag governs only the bridge’s issued tokens.
The exploit landed while XRP was already sliding. The token sits near $1.02, close to a 21-month low, down roughly 4.4% this week as Bitcoin fell to about $64,000 and the broader crypto market shed some $40 billion in a day.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
An Ethereum ICO participant makes a test transfer to Coinbase after 11 years of dormancy.
Ethereum ICO participant '0x6A53' has deposited 0.1 ETH into Coinbase after 11 years of inactivity. Back during the original Ethereum ICO, he invested just $620 to acquire 2,000 ETH, which are now valued at $3.83 million, delivering an astounding 6,184x return on investment.
7 minutes ago
A suspected Bitcoin miner has deposited 2,802 BTC worth $182 million into Binance over the past two days.
According to Yuqing Monitoring, a suspected Bitcoin miner has deposited 2,802 BTC (valued at $182 million) into Binance over the past two days. Over the last 20 days, the miner has made total deposits of as much as 6,494 BTC ($421 million) into Binance, at an average price of approximately $64,798.
7 minutes ago
Iran nears agreement with Oman on strait management.
On August 8, Iranian Foreign Minister Araghchi stated that Iran is currently negotiating with Oman on legal mechanisms, management approaches for the Strait of Hormuz, and the determination of shipping routes through the strategic waterway, with the two sides very close to reaching an agreement. However, whether the Strait of Hormuz can reopen depends on other conditions, including the U.S. making amends for its violation of the U.S.-Iran Memorandum of Understanding. Araghchi noted that a traffic separation scheme previously operated in the Strait of Hormuz, but Iran considers the original route no longer suitable for ship passage and cannot accept its continued use. A new navigation mechanism is therefore necessary, though it involves complex technical and legal issues. The two sides are currently discussing an interim navigation route. Before the finalization of the new official navigation route, an interim shipping lane will be established first to serve as the basis for the future formal route. On this matter, the military departments of Iran and Oman have already held consultations based on existing nautical charts. Once the relevant negotiations are completed and a final conclusion is reached, the new navigation route will be confirmed.
7 minutes ago
Ledger: BIP-110 lacks replay protection, transferring or selling forked coins may endanger mainnet assets
Hardware wallet vendor Ledger has issued a security alert regarding the BIP-110 Bitcoin fork, stating that BIP-110 is a Bitcoin soft fork scheme lacking built-in replay protection. If a separate chain is formed, BTC holders may receive an equivalent amount of corresponding assets on the new chain, though transactions signed by both chains may be accepted initially. If users attempt to transfer or sell assets on the BIP-110 chain, the relevant transactions could be "replayed" to the Bitcoin main chain, resulting in the simultaneous withdrawal of the corresponding BTC. Ledger noted that its devices can technically sign such transactions, but advises users not to claim or handle BIP-110 fork coins until replay protection mechanisms are added.
7 minutes ago
Following SpaceX's sustained sharp rally, short sellers may be forced to cover their positions, with record options trading volume indicating funds are flowing back.
Following two consecutive days of sharp rebounds in SpaceX’s stock price in the latter half of this week, investors who had previously bet on a price drop are under heavy pressure. Over 250 million SpaceX shares remain sold short, equivalent to roughly 16% of its currently tradable stock. If the stock price rises rapidly, forced short covering could drive further gains. Meanwhile, trading in SpaceX’s options market has also seen unusual activity. As of 1:50 PM ET on Friday, SpaceX’s options volume hit 2.24 million contracts, with call option volume reaching 1.3 million contracts – a record high, indicating capital is flowing back in. However, the sharp stock rebound does not mean market concerns over SpaceX’s high valuation have faded. As the supply shock from lock-up expirations is gradually absorbed, investors still face a core question: before SpaceX fully delivers on the potential of its AI, satellite internet, and aerospace businesses, will the market continue to assign such a high valuation to it?
7 minutes ago
Vance: Iran has informed the U.S. that it has no current plan to impose tolls on vessels transiting the Strait of Hormuz.
US Vice President JD Vance stated in an interview with Fox News that Iran has informed the U.S. it has "no immediate" plans to impose tolls on the Strait of Hormuz. "Some individuals within Iran’s establishment have certainly discussed levying such tolls. However, Iran has told us it has no plans to charge tolls for passage through the Strait of Hormuz, and has also conveyed this position to us—something the entire Gulf coalition expects. But we do not take such statements at face value; we will verify them. Our focus is not on people’s words, but on their actions."
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
US crude oil inventories have posted a historic decline to 712 million barrels, hitting their lowest level since March 1984.
US crude oil inventories are experiencing an unprecedented decline: total inventories have fallen for 17 consecutive weeks, the longest such decline period on record. This streak surpasses the previous record of 16 straight weeks of decline set in 2021. Since early April, total crude inventories have dropped by 166 million barrels to 712 million barrels, hitting their lowest level since March 1984. US Strategic Petroleum Reserve (SPR) inventories alone have decreased by 111 million barrels since March, currently standing at 305 million barrels, the lowest level since February 1983. Meanwhile, US gasoline inventories have declined for 10 consecutive weeks, matching the 2018 record.
11 minutes ago
A whale shorting $102 million worth of Bitcoin was partially liquidated, with the liquidation price for its remaining positions standing at around $65,300.
According to monitoring by TheDataNerd, a large whale that shorted $102 million worth of Bitcoin using 40x leverage recently faced partial liquidations, suffering a $1.46 million loss over the past week. The whale has since added margin, cutting its short position to roughly $60 million. The position’s entry price is $64,212.5, and its liquidation price is $65,310.2.
11 minutes ago
AI stock guru Leopold becomes a 'hero' after his liquidation, sparking a craze among Silicon Valley capital.
After 25-year-old rising Wall Street AI stock prodigy Leopold’s hedge fund Situational Awareness faced a margin liquidation, Silicon Valley capital has instead launched a wave of pursuit for him. Insiders revealed that a large number of Silicon Valley investors have contacted the fund voluntarily within just a few days, expressing their willingness to add investment. Sequoia Capital partner Pat Grady publicly stated he will remain a key figure in Silicon Valley for the long term; veteran venture capitalist Elad Gil even announced his first application to invest in the fund; Redpoint Ventures managing director Logan Bartlett bluntly said, “There’s a hero archetype here—Leopold got punched, but it sparked everyone’s unity.” Despite the heavy blow, the fund has still posted around 80% positive returns this year, with its remaining portfolio valued at roughly $100 billion. However, Situational Awareness has informed investors it is temporarily not accepting new capital. In a letter to investors, Leopold announced he has unwound all leverage, characterizing the crisis as a costly but invaluable lesson, and will at least temporarily stop using bank prime brokerage services to amplify positions. This incident has laid bare the deep divide between Silicon Valley and Wall Street: Wall Street views it as a classic case of excessive leverage, with S3 Partners’ founder pointing out bluntly, “This is a super-concentrated, super-crowded, and super-high-leverage position”; Barclays even previously refused to take the fund on as a client citing excessive industry concentration; while Silicon Valley sees it as a buying opportunity at a low point. A New York University professor explained that Silicon Valley rewards those who make correct judgments on transformative technology directions, while Wall Street rewards those who generate risk-adjusted returns while preserving principal.
11 minutes ago
Berkshire Hathaway has shifted from a wait-and-see stance to taking action, bringing an end to its 14-quarter streak of net stock selling, with net purchases of roughly $20 billion in stocks during Q2.
Berkshire Hathaway released its Q2 2026 financial report today, with the market’s most closely watched detail being that its cash reserves dropped to $365.51 billion in the second quarter, down from approximately $397.4 billion in Q1. This marks the end of Berkshire’s 14 consecutive quarters of net selling, its first period of significant net buying since Q4 2022. In Q2, Berkshire’s net stock purchases totaled nearly $20 billion, including a roughly $10 billion private placement in Alphabet, Google’s parent company, to support its AI data center and other investments. It also acquired homebuilder Taylor Morrison for approximately $6.8 billion—a full acquisition, not an open-market stock trade—and repurchased about $4.5 billion of its own shares. After accounting for these major items, there remains roughly $3 billion in "unexplained" net open-market equity purchases, with specific stocks to be disclosed in the 13F filing around August 14. Alphabet has now officially entered Berkshire’s top five holdings, alongside American Express, Apple, Bank of America, and Coca-Cola, with these five core positions making up roughly 66% of its stock portfolio. Buffett previously noted that the prolonged net selling cycle was driven mainly by high market valuations, which made it difficult to find sufficiently attractive opportunities. This shift is viewed as a clear signal of more active capital allocation since Greg Abel took over as CEO, with Berkshire moving from "waiting patiently" to "taking action."
11 minutes ago
Vance briefs on Iran 'negotiations': Some progress has been made in the past few days
US Vice President Vance stated that some progress has been made in Iran negotiations over the past few days. Key focuses include maximizing oil and gas production in the Strait of Hormuz, and securing Iran’s commitment to refrain from firing on ships.
11 minutes ago
Nansen Founder: Bitcoin Will Never Drop Below $60,000 Again, No Signs Global Monetary Easing Cycle Is Ending
Nansen founder and CEO Alex Svanevik stated that Bitcoin’s current price of roughly $60,000 may have marked the low point of this cycle. “I personally don’t think Bitcoin will drop below $60,000 again— that’s a thing of the past, and I believe it’s forever,” he said. Svanevik’s assessment is rooted in Bitcoin’s role as a hedge against global central bank monetary expansion, with no signs of an imminent end to the global monetary easing cycle. He added that the crypto industry is undergoing a fundamental shift: crypto assets were previously in the “toy world” phase of blockchain, and are now entering the “real world” era. On the public chain ecosystem, Svanevik holds a long-term bullish stance on Solana, dismissing the view that it is merely a “meme coin chain” as completely absurd. He praised Solana for having “possibly the most effective business development (BD) team” and an “incredible team.” However, Svanevik refused to translate this positive outlook into a specific price prediction for SOL: “Intuitively, I would expect it to rise, but I can’t be certain.” Svanevik is also optimistic about Robinhood Chain, which launched just this July. He argues that it is emerging as a strong competitor to Base thanks to its outstanding user distribution capabilities, but judges that Robinhood is unlikely to issue a token. The reasons: first, it has no need to do so; second, as a Nasdaq-listed company, issuing a token would logically conflict with competing against its own stock. “All value should be channeled into HOOD stock,” he noted.
A wallet linked to the Aztec Private Rollup Bridge exploit deposited another 300 ETH into Tornado Cash, bringing its total transfers to the mixer to 500 ETH.
Summary
The exploiter sent another 300 ETH, worth about $572,000, to Tornado Cash. Total deposits linked to the wallet have now reached 500 ETH, worth about $953,000 at the reported price. The Private Rollup Bridge lost approximately $2.165 million in a June exploit. Aztec said the affected legacy product was separate from its current network and AZTEC token. Aztec exploiter deposits 300 ETH into Tornado Cash Blockchain security firm PeckShield reported on Aug. 8 that an address labeled as the Aztec Private Rollup Bridge exploiter deposited 300 Ether into Tornado Cash.
The ETH was worth approximately $572,000 when PeckShield issued the alert. On-chain data included in the firm’s report showed three separate deposits of 100 ETH each.
PeckShield said the latest transactions raised the wallet’s cumulative Tornado Cash deposits to 500 ETH. Based on the valuation attached to its alert, the total was worth roughly $953,000 at press time.
Tornado Cash pools deposits and allows users to withdraw funds through different addresses. This process can obscure the direct connection between the original sending wallet and subsequent recipients, making asset tracking and recovery more difficult.
PeckShield did not identify the person or group controlling the address. There was also no immediate indication that any of the transferred funds had been recovered.
Private Rollup Bridge lost $2.165 million The latest transfers relate to an exploit that affected Aztec’s Private Rollup Bridge in June. Reports at the time placed the loss at approximately $2.165 million.
The stolen assets reportedly included 1,158 ETH, 150,000 DAI and 0.47 renBTC. Aztec said the affected bridge was a legacy product with no connection to the current Aztec network or its AZTEC token.
The Private Rollup Bridge incident followed a separate attack on Aztec Connect, another discontinued part of the project’s earlier infrastructure.
As crypto.news previously reported, an attacker drained around $2.1 million from Aztec Connect’s old RollupProcessor contract on June 14. The affected system had been discontinued about three years earlier and was no longer used by Aztec’s active network.
Security researchers said that the exploit involved a mismatch between the transactions covered by a zero-knowledge proof and those processed during settlement. The weakness allowed the attacker to create unbacked balances and withdraw assets from the contract.
Aztec Labs could not pause or upgrade the deprecated contract because it had surrendered its administrative keys. The design made the contract immutable but also removed the team’s ability to intervene after the flaw was exploited.
Tornado Cash transfers follow wider exploit surge The two Aztec incidents formed part of a wider increase in crypto security breaches during June.
Crypto.news reported that DefiLlama recorded $74.9 million in losses across 29 exploits during the month. Its data included two separate Aztec incidents valued at approximately $2.1 million each.
Other exploiters have also used Tornado Cash to move stolen assets. In July, a wallet associated with the Drift Protocol exploit deposited 23,095 ETH, then worth around $44.4 million, into the mixer after months of inactivity.
A wallet linked to the Radiant Capital attack previously transferred 2,834 ETH into Tornado Cash, while the Cork Protocol exploiter routed approximately 4,520 ETH through the service.
The latest Aztec deposits therefore follow an established pattern in which attackers convert stolen assets into ETH before sending them through mixing protocols.
Tornado Cash remains under US scrutiny The U.S. Treasury removed Tornado Cash and associated smart-contract addresses from its sanctions list in March 2025. The decision followed a federal appeals court ruling that the Treasury exceeded its authority by sanctioning immutable smart contracts.
However, U.S. authorities have continued to examine the use of crypto mixers in money laundering, sanctions evasion and cybercrime cases. Treasury officials have also maintained concerns about their use by North Korea-linked hacking groups.
The 500 ETH transferred by the Aztec exploiter represents less than half of the value reportedly taken from the Private Rollup Bridge. Further activity from the labeled address could show whether the remaining assets will also be routed through Tornado Cash or moved to other services.
The individual responsible for draining funds from Aztec’s deprecated Connect rollup in June has now transferred a total of 500 ETH to Tornado Cash, according to blockchain security firm PeckShield. This follows an additional 300 ETH sent to the mixer, highlighting an evolving approach among cybercriminals to laundering stolen assets from decentralized finance contracts.
Patterned withdrawals raise new questionsUnlike some previous high-profile incidents, the exploiter opted for smaller, sporadic transfers instead of a swift and single deposit. The recent 300 ETH move, worth approximately $572,100 at the time, was recorded on August 8. PeckShield had earlier identified a 145 ETH deposit on July 2, valued at about $227,650, pushing the cumulative sum moved through Tornado Cash to 200 ETH before the latest activity.
This deposit occurred 37 days after the preceding transfer, suggesting a deliberate, calculated timetable. Rather than moving all 909 ETH siphoned in the original hack at once, the attacker broke the sum into small tranches, transferring about 55% so far across multiple sessions.
The slow movement of funds via Tornado Cash stands in marked contrast to cases like the 2022 Beanstalk incident, where perpetrators executed 270 transactions involving 24,930 ETH within moments of each other, exploiting the anonymity of the mixer but relying on speed.
In the case of Aztec, TRM Labs noted that patterns in transaction timing, wallet activity, and behavior outside the mixer can still yield valuable clues. Despite the intent to mask asset movement, modern analytics tools, including behavioral correlation and off-ramp monitoring, have helped track even funds routed through mixing protocols.
Origins of the Aztec exploitOn June 14, an attacker exploited vulnerabilities in outdated Aztec Connect rollup contracts, securing roughly $2.19 million through a single transaction. According to Blockaid, the stolen assets included 909 ETH, 270,513 DAI, 168 wstETH, and additional tokens.
A follow-up incident saw the same attacker drain another $88,000 in residual funds from the legacy protocol just a day later, using nearly identical methods to empty the remaining bridge positions.
Investigation into the method revealed that the underlying cryptography of Aztec was not compromised. Instead, Blockaid identified a flaw in proof verification and settlement handling, which enabled the hacker to generate synthetic balances unsupported by corresponding deposits.
The affected contracts had already been deprecated, and Aztec Labs no longer controlled their administrative keys. This meant the main Aztec Network and current AZTEC token were not impacted by the attack.
Cyclical trends in crypto launderingThe Aztec incident adds to a persistent pattern in blockchain security. TRM Labs reported 207 crypto hacks in the first half of 2026, resulting in $972 million in losses. Although the total amount stolen fell sharply compared to the $2.3 billion lost during the same period in 2025, the actual number of attacks rose, with 125 smart-contract exploits and a median loss of $219,000 per incident.
Tornado Cash has continued to feature prominently in the movement of illicit funds, reportedly accounting for 20% of all global mixer transactions so far in 2026. Despite a decrease in overall market share following U.S. sanctions imposed in 2022, it remains a dominant service on Ethereum-based platforms.
Academic studies from the University of Birmingham and University of Sydney indicate that Tornado Cash facilitated 78.33% of hacking events on Ethereum within the examined period, demonstrating its continued relevance among cybercriminals, even after attempts at regulatory suppression.
In March 2025, the legal environment shifted when the U.S. Treasury lifted sanctions against Tornado Cash. The determination by the Fifth Circuit clarified that immutable smart contracts do not fall under the Office of Foreign Assets Control’s property jurisdiction.
For users and decentralized finance participants, the slow withdrawal strategy observed in the Aztec scenario underscores the enduring risks of legacy smart contracts. Funds residing in outdated protocols remain vulnerable, and once stolen, the laundering techniques seldom deviate from established norms.
Amid heightened market scrutiny of attack patterns and technical weaknesses, comprehensive tracking of wallet flows, transaction size, and timing becomes increasingly vital. Platforms like CryptoAppsy, which require no account creation hassle, combine real-time crypto prices, portfolio management, macroeconomic data such as Fed interest rates, and customizable alerts in a unified dashboard—making it easier for investors to monitor key indicators and respond rapidly to market-moving events.
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.
Key Takeaways Over $130 million in Bitcoin has been stolen due to a critical firmware vulnerability affecting Coldcard hardware wallets Daily active Bitcoin addresses surged to 980,000, marking the highest activity since December 2024 as users rush to secure their holdings Security researchers have identified at least 15 distinct attackers exploiting the weakness, with a potential fourth attack wave underway Stolen cryptocurrency is being laundered through mixing services, including 64 Bitcoin via Wasabi and 200 Ether through Tornado Cash This security incident represents the third-largest cryptocurrency hack recorded in 2026 A critical security vulnerability discovered in Coldcard hardware wallets has resulted in one of 2026’s most significant Bitcoin theft incidents, with total losses surpassing $130 million.
The security flaw originated from a firmware defect introduced in March 2021, which compromised the randomness of seed phrase generation on impacted devices. This weakness reduced cryptographic key strength from the standard 128 bits down to merely 40 bits, enabling attackers to crack wallet security through brute force methods without requiring physical device access.
According to Galaxy Digital’s analysis, the exploit has been executed in at least three distinct attack campaigns, compromising approximately 7,300 individual wallets. Evidence suggests a fourth coordinated attack may be in progress, potentially increasing the overall financial damage.
Network Activity Surges as Users Respond to Security Threat Data from blockchain intelligence provider Glassnode indicates that Bitcoin active addresses climbed to approximately 980,000 daily transactions in the wake of the security breach. This represents the network’s most active period since December 2024.
However, Glassnode emphasized that this increased activity stems from security precautions rather than positive market sentiment. The analytics firm characterized the movement as “an operational security response, not a change in market conviction.”
Previously dormant Bitcoin holdings valued at nearly 200 times the initial theft amount have been transferred across the blockchain, indicating widespread preventive measures by cryptocurrency holders concerned about their wallet security.
The catalyst for this broad network response was a July 31 theft of 594 Bitcoin, valued at approximately $38 million when stolen. Subsequent analysis by Galaxy Research confirmed total losses had climbed beyond 1,596 Bitcoin, representing more than $100 million in value.
Stolen Cryptocurrency Channeled Through Privacy Protocols Blockchain security monitoring firm CertiK has documented the flow of stolen assets to privacy-enhancing services. Approximately 64 Bitcoin valued at $4.17 million was transferred to Wasabi, a privacy-focused Bitcoin mixing platform. Additionally, attackers sent 200 Ether worth roughly $380,000 to Tornado Cash.
#CertiKInsight 🚨
Our alert system detected two 200 ETH transactions sent to Tornado Cash linked to the ongoing @COLDCARDwallet attack.
The funds were bridged from BTC to ETH address 0x41B7529a411EeA979a8d468bdEBd36b0ad703268 via THORChain before being sent to Tornado Cash. pic.twitter.com/JLazHWIEvo
— CertiK Alert (@CertiKAlert) August 5, 2026
CertiK analysts believe some transactions may originate from opportunistic attackers rather than the original exploit group. “We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit,” according to a CertiK representative.
Analysis from TRM Labs reveals that the majority of stolen cryptocurrency remains consolidated in a limited number of attacker-controlled addresses. Variations in attack methodology across different waves indicate involvement by at least 15 independent threat actors.
Haseeb Qureshi, managing partner at Dragonfly, observed that certain artificial intelligence systems were able to identify the underlying security weakness in under 20 minutes. He argued that minimal AI-assisted security testing, costing approximately two dollars, could have identified and prevented this vulnerability.
Cybersecurity professionals emphasize that simply updating device firmware is insufficient for affected wallet owners. Users who generated wallets on compromised Coldcard devices are strongly advised to create entirely new wallets and transfer their cryptocurrency holdings immediately.
Based on confirmed losses, the Coldcard security breach currently stands as 2026’s third-largest cryptocurrency theft incident.
A critical firmware vulnerability in Coldcard hardware wallets has resulted in the theft of over $130 million in Bitcoin, marking the third-largest crypto hack so far in 2026.
Hardware wallets compromised by weak key generationColdcard, a widely used Bitcoin hardware wallet developed by Coinkite, fell victim to a significant security lapse introduced in March 2021. Researchers found that a firmware update weakened the randomness of seed phrase generation within affected devices. This flaw diminished the cryptographic strength of wallet keys from 128 bits to just 40 bits, allowing attackers to exploit the deficiency using brute force attacks—no physical device access required.
According to an analysis by Galaxy Digital, the exploit has been leveraged in at least three separate attack waves, impacting around 7,300 wallets. The company also warned of indications that a fourth coordinated campaign may now be under way, raising concerns about potential further losses.
The breach represents one of the most severe cryptocurrency software incidents of the year, with losses continuing to mount as new attacks come to light.
Mini dictionary: Coldcard is a dedicated hardware wallet for securely generating, storing, and managing Bitcoin private keys and transactions, manufactured by Coinkite, a company specializing in Bitcoin security products.
Network activity surges as users respondBlockchain analytics provider Glassnode reported that Bitcoin daily active addresses surged to nearly 980,000, reaching their highest level since December 2024. This surge appears linked to widespread user efforts to secure funds following news of the vulnerability, with large holders and regular users alike moving their Bitcoin to safer wallets out of precaution. Glassnode noted that the elevated transaction volume reflects operational security measures rather than renewed market enthusiasm.
Significant sums have moved across the Bitcoin network, including funds from previously inactive wallets. Analysts observed that dormant holdings totaling nearly 200 times the value of the initial theft changed hands as security concerns swept through the user base.
One major incident on July 31 saw 594 Bitcoin, worth about $38 million at the time, stolen in a single attack. Galaxy Research later confirmed that the total value lost had exceeded 1,596 Bitcoin, with the financial toll climbing as coordinated theft campaigns evolved.
Attack waveWallets compromisedTotal BTC stolenDate (where known)First to thirdApprox. 7,300Over 1,596 BTCOngoing 2024–2026Fourth (suspected)UnknownLosses increasing2026Stolen funds laundered through privacy platformsCertiK, a blockchain security firm, recorded the movement of sizeable portions of stolen Bitcoin to mixing services designed to obscure transaction trails. At least 64 Bitcoin, valued at $4.17 million, was sent to Wasabi, a popular privacy mixing platform. Attackers also converted a portion of assets to Ether, routing 200 ETH (about $380,000) through Tornado Cash—a service that anonymizes blockchain transactions.
CertiK analysts stated that some of the suspect transactions may be unrelated to the main exploit group. The firm noted, “There’s likely a few copycats after the initial exploit.”
TRM Labs, another digital asset intelligence company, indicated that most stolen funds remain concentrated in a small number of attacker-controlled addresses. Investigators identified at least 15 separate hackers involved, based on differences in tactics used across the various attack waves.
Mini dictionary: Wasabi is a privacy-focused Bitcoin wallet and mixing service that uses the CoinJoin protocol to combine multiple transactions, making it difficult to trace specific payments. Tornado Cash is a decentralized Ethereum mixing protocol that allows users to hide the source and destination of their transactions.
Haseeb Qureshi, managing partner at Dragonfly, observed that automated security systems powered by artificial intelligence found the vulnerability within just 20 minutes. He emphasized that low-cost, AI-based tests could have identified the flaw, suggesting a missed opportunity for preventive action at a price of only around two dollars.
Cybersecurity professionals urgently recommend that anyone who generated a wallet using affected Coldcard hardware immediately create new wallets and transfer their funds. Simple firmware updates are not enough to address the compromised seed generation vulnerability.
Based on confirmed on-chain losses, the Coldcard incident ranks as the third-largest cryptocurrency hack of 2026, trailing only behind two major exchange breaches this year.
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Upbit to List BSB Trading Pairs Against KRW, BTC, and USDT
According to an official announcement, Upbit will list BSB/KRW, BTC/KRW, and USDT/KRW trading pairs.
12 minutes ago
Nasdaq’s 23-hour trading system has been approved by the SEC and will officially launch on December 6.
According to Nasdaq’s Q1 2026 financial report and its 8-K filing with the U.S. Securities and Exchange Commission (SEC), the exchange’s 23-hour, 5-day trading system (23/5) has been approved by the SEC and will go live on December 6, 2026. Once launched, U.S. stock markets will only close for one hour daily (20:00–21:00 ET) for system clearing and data processing, with trading operating continuously for the remaining 23 hours.
12 minutes ago
Hong Kong-listed MINIMAX surged nearly 25%, with Zhipu rising over 17%.
According to Bitget market data, Hong Kong-listed large language model concept stocks have continued their upward trend. MINIMAX-W (00100.HK) rose nearly 25%, while Zhipu (02513.HK) gained over 17%.
12 minutes ago
Microsoft: Discovers new attack campaign hiding malicious code via BNB Chain smart contracts, affecting thousands of devices globally.
Microsoft’s Threat Intelligence Team has released a report disclosing a set of compromised websites that use ClickFix and TerminalFix to launch social engineering attacks, combined with EtherHiding technology, to access smart contracts via the BNB Smart Chain RPC gateway for retrieving subsequent malicious commands. Since the malicious content is stored in on-chain smart contracts, only the wallet owner that deployed the contract can modify it, making it hard to eliminate through traditional takedown or blocking measures. Attackers forge CAPTCHA verification pages to trick users into opening Windows’ Run window, Terminal, or PowerShell, then pasting and executing malicious commands. The attack workflow extensively leverages system tools including conhost, PowerShell, mshta, rundll32, curl, WMI, and WebDAV for obfuscation and Living-off-the-Land (LotL) attacks. Microsoft points out that ClickFix and TerminalFix have emerged as high-frequency initial intrusion vectors, impacting thousands of enterprise and personal devices worldwide daily. Multiple threat actors use these tactics to spread malware such as Lumma Stealer, Xworm, AsyncRAT, and MintsLoader, which can further lead to credential theft, lateral movement, and ransomware attacks. The tech giant advises users against following prompts from CAPTCHAs, web error pages, emails, or ads to paste and execute any commands in Windows Run, Terminal, PowerShell, or Command Prompt.
12 minutes ago
Bithumb will list BlockStreet (BSB) KRW trading pair.
According to an official announcement, Bithumb will list the BlockStreet (BSB) KRW trading pair.
12 minutes ago
Jaredfromsubway exploiter loses $505K on $ETH trades, buying back 2,063 $ETH at higher price after month-long theft
The Jaredfromsubway exploiter is terrible at trading. A month ago, the exploiter stole $7.7M and swapped it for $ETH. The exploiter later sold 2,327 $ETH($3.94M) at $1,695, then bought back 2,063 $ETH($3.94M) at $1,912 10 hours ago. He lost 264 $ETH($505K).
Approximately 64 Bitcoin valued at $4.17 million and 200 Ether worth $380,000, linked to the recent Coldcard exploit, have been transferred to cryptocurrency mixing protocols, according to blockchain security firm CertiK.
Stolen crypto routed through mixersCertiK reported that the stolen Bitcoin originated from address bc1q0 and was sent to privacy-focused mixer Wasabi on Tuesday. The firm stated that, based on blockchain data, the Bitcoin was moved in a single transaction. The following day, certiK detected a transfer of 200 Ether to Tornado Cash, another well-known mixing protocol.
A spokesperson for CertiK suggested that the addresses involved may belong to smaller actors or copycats imitating the original exploit. Cryptocurrency mixing protocols like Tornado Cash are designed to obscure transaction history, blending digital assets from multiple users so that the origin of funds becomes extremely difficult to trace. This process significantly lowers the chances of successfully recovering stolen assets.
The Coldcard exploit has now become one of the largest crypto security incidents of 2026, ranking as the third-largest hack by value.
Scale and impact of Coldcard exploitThe Coldcard attack totaled at least $100 million stolen in Bitcoin, targeting some 7,300 victim wallets over three distinct attack waves, according to digital asset company Galaxy Digital. Galaxy also pointed to a suspected fourth attack wave, potentially pushing losses to $130 million in Bitcoin.
Most of the stolen digital assets remain within several addresses still under the control of attackers, as recently confirmed by TRM Labs’ onchain analysis. The blockchain intelligence company highlighted that the majority of funds have experienced limited attempts at obfuscation, with only a small portion moved to mixing services so far.
Attack WaveEstimated LossesVictim WalletsMixing ActivityWaves 1-3 (Confirmed)$100 million BTC7,300LimitedSuspected 4th WaveAdditional $30 million BTCNot disclosedOngoingTRM Labs observed that each attack wave featured distinct transaction characteristics, indicating the probable involvement of multiple perpetrators. This assessment aligns with Galaxy Digital’s findings, which identified at least 15 separate attackers exploiting the same Coldcard vulnerability.
Coldcard, produced by Coinkite, is a hardware wallet used for securing Bitcoin and other cryptocurrencies. The wallet’s reputation for security was challenged by this incident, which exploited a flaw in its firmware.
Mini dictionary: Tornado Cash, a decentralized privacy tool for the Ethereum blockchain, allows users to deposit and withdraw ETH in a manner that breaks any onchain link between the sender and receiver, thereby increasing transactional privacy.
Technical details and responseTRM Labs attributed the root cause of the attack to a firmware bug present since March 2021, which weakened the seed randomness in certain Coldcard wallets. The bug reduced the cryptographic key strength from 128 bits to 40 bits, making it feasible for attackers to extract private keys without needing physical device access.
Galaxy Digital noted that “differences in transaction construction” across the attack waves suggest several attackers gained knowledge of the vulnerability over time.
Haseeb Qureshi, managing partner at Dragonfly, remarked that only minimal protection—including upgrades costing about $2 per device—could have prevented the exploit. He cited reports indicating that some artificial intelligence models successfully identified the flaw within 20 minutes.
Qureshi commented that “$2 of AI hardening” might have mitigated the Coldcard incident, highlighting the potential benefits of AI-driven security audits.
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.
Sources: Iran and Oman reach preliminary consensus on reopening the Strait of Hormuz
According to Saudi media outlet Alhadath, senior sources have stated that Iran and Oman have reached a preliminary consensus on reopening the Strait of Hormuz. The deal could be announced in the coming days, though it still requires approval from Iran's Supreme National Security Council. The 60-day agreement is designed to restore navigation in the strategic waterway.
12 minutes ago
Hong Kong Police Update on Virtual Currency-Related "Fun Coffee" Fraud Case: Total Losses Rise to Approximately HK$104 Million
According to Hong Kong 01, the Hong Kong Police Force has updated details of the "Fun Coffee" virtual currency fraud case, disclosing that as of August 5, a total of 255 related reports have been received, an increase of 30 from earlier, with total case losses rising to approximately HK$104 million. Separately, the Macau Judiciary Police arrested two women in connection with 9 cases involving around MOP 3.6 million. Regarding a TVB artist who once hosted events linked to the Fun Coffee fraud, the Hong Kong Police said that during the investigation, they will contact victims and relevant parties to identify the fraud mastermind and the roles of all involved. BlockBeats Note: "Fun Coffee" claims to be a large-scale coffee investment enterprise based in Vietnam’s Phu Quoc Island, with capital exceeding US$1 billion. It entered Hong Kong at the end of 2025, building its image by hosting marathons, dinners, social events, distributing leaflets (even under the "anti-fraud" banner), and inviting artists to endorse it, while registering a company, opening an office and physical stores in Hong Kong. In reality, it lured the public to download an app to "complete tasks" and recharge with cryptocurrencies like Tether (USDT) under the guise of investing in "high-tech coffee equipment, gene optimization technology, and agricultural gear". The platform promised annualized returns as high as 197%–278% (with some claims reaching 222% or more), stating that larger investments and longer deposit periods would yield higher returns, and set up an upline-downline commission system to encourage referrals. In July 2026, the Hong Kong Securities and Futures Commission (SFC) classified it as a suspicious investment product. Later that month, the app suddenly shut down, withdrawals were blocked, customer service went missing, and its office and stores were vacated – marking the collapse of the fraud.
12 minutes ago
Viewpoint: Bitcoin’s rebound is supported by liquidity contraction, with no new demand emerging yet.
CryptoQuant analyst Axel Adler Jr. stated in a post that while Bitcoin has rebounded to $64,600, two on-chain flow metrics have not confirmed an influx of new demand. The Demand/Issuance Ratio is -5.43, and the coin-age net flow stands at -85,500 BTC. Both metrics have recovered from their July lows but remain negative. A Demand/Issuance Ratio below zero means the volume of young coins is shrinking faster than new issuance, a trend that has lasted around five months. A negative coin-age net flow signals that 85,500 BTC have been moved into the long-term holding category (held for over one year) over the past 30 days, pointing to a continued contraction in liquidity supply. The analyst added that the current rebound is primarily supported by liquidity supply contraction (coin aging, long-term holders’ reluctance to sell) and accumulation behavior, rather than new demand. A return of both metrics to above zero is an improvement signal, and a sustained Demand/Issuance Ratio above 1 is needed to confirm a genuine recovery.
12 minutes ago
Stocks in the US storage sector traded lower across the board in pre-market trading, with SanDisk down over 8%.
According to market data from BIT (bit.com), U.S. storage sector stocks fell collectively in pre-market trading. SanDisk dropped over 8% due to poor performance guidance, Western Digital fell 12%, and SK Hynix declined 6%. Additionally, the recently sharply rebounding CPO sector saw a slight pre-market dip: AAOI was down 2.79% and LITE fell 0.52%.
12 minutes ago
Hong Kong stocks closed, with MINIMAX-W rising nearly 17%.
Hong Kong stocks closed lower, with the Hang Seng Index down 1.49% and the Hang Seng Tech Index down 2.28%. MINIMAX-W rose approximately 17%, while Baidu and Semiconductor Manufacturing International Corporation (SMIC) fell around 4%.
12 minutes ago
Coinbase launches 24/5 US stock trading in the UK, offering zero-commission trades and fractional shares.
Coinbase has rolled out stock trading in the UK, enabling British users to buy and sell nearly 4,000 US stocks within the same app. The feature supports 24/5 trading and shares a unified account with the platform’s cryptocurrency and fiat assets. It is reported that the service charges zero commissions, allows fractional share trading, and stocks are cleared and executed in the U.S. by Apex Clearing. Users can fund trades using either British pounds (GBP) or USDC.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
The July 23 spike — worth about $57 million in ETH — was driven largely by the Drift exploiter, who pushed $44 million through the mixer in under two hours.
Tornado Cash processed 968 deposits on July 23, its busiest day of 2026, according to L2Beat data.
The spike shows large-scale attackers have returned to the privacy protocol since the U.S. Treasury lifted sanctions in March 2025 — and that its baseline usage keeps climbing even as developer Roman Storm awaits a retrial over operating it.
Depositors moved 29,573 ETH, worth about $57.2 million at July 23 prices, into the mixer's Ethereum pools that day across 110 addresses, per onchain data. Most of it came from one: the address labeled Drift Exploiter 4 made 245 deposits totaling 23,095 ETH, about $44.4 million and 78% of the day's inflow, in under two hours.
"The Drift Protocol exploiter who stole $285M has deposited 23,095 $ETH ($44.4M) into #TornadoCash today," onchain tracker Lookonchain wrote on X on July 24. "The exploiter still holds 107,165 $ETH ($201M)."
Security firm PeckShield posted the same figures, noting the exploiter also sent 0.85 ETH to Bybit.
Drift Money on the MoveThe deposits were the first movement of funds from the April 1 exploit of Drift, the Solana perps DEX drained of roughly $285 million in the largest DeFi hack of 2026. Blockchain forensics firms including TRM Labs and Elliptic have attributed the attack with medium-to-high confidence to UNC4736, the North Korea-linked cluster behind the $1.5 billion Bybit hack.
Even setting the exploiter aside, the day's remaining 723 deposits from 109 other addresses exceeded most full days in 2025, when July 23 of that year saw 177 deposits total.
Post-Delisting ReboundTornado Cash usage has rebounded steadily since Treasury's Office of Foreign Assets Control delisted it in March 2025, following a Fifth Circuit ruling that immutable smart contracts can't be sanctioned. The mixer has captured more than 20% of crypto mixing volume in 2026, with weekly inflows of $10 million to $80 million, according to TRM Labs — up from about 16% in the years after the 2022 sanctions. The 2026 peak still trails Nov. 5, 2025, when Richard Heart-linked wallets helped drive 1,363 deposits in a day.
Storm's case continues alongside the rebound. Prosecutors are seeking an October retrial of Storm on money-laundering and sanctions-conspiracy charges after a Manhattan jury hung on those counts in August 2025, while Judge Katherine Polk Failla weighs his acquittal bid on the single count where jurors convicted.
The Verus Ethereum Bridge has been targeted by a major security breach for the second time in just over two months, resulting in the theft of approximately $7.54 million in various crypto assets. The incident occurred on July 23 when attackers exploited a vulnerability, once again raising concerns about the security of cross-chain protocols in decentralized finance (DeFi).
Attacker Drains Bridge’s Ethereum ReservesThe breach allowed the attacker to abuse the bridge’s submitImports function, which triggered Ethereum-side payouts without equivalent assets being locked on the Verus blockchain. This vulnerability enabled the unauthorized extraction of funds from the bridge’s reserves.
Blockchain security firm Blockaid and independent researcher exvulsec both confirmed and investigated the exploit. According to on-chain data, roughly 1,137 ETH, as well as tBTC, USDC, USDT, EURC, MKR, and scrvUSD, were drained from the bridge reserves at around 03:45 UTC. The stolen assets were quickly swapped through decentralized exchanges, then consolidated into nearly 3,916 ETH before parts of the funds were routed through Tornado Cash.
Mini dictionary: Tornado Cash, a decentralized non-custodial privacy solution on Ethereum, is designed to break the on-chain link between source and destination addresses, making transaction tracing more difficult.
AssetAmount stolenEstimated valueETH1,137Included in $7.54M totaltBTCUnknownUSDCUnknownUSDTUnknownEURCUnknownMKRUnknownscrvUSDUnknown Investigators noted that by exploiting the same contract, function entry point, and vulnerability as a previous May breach, the attacker bypassed standard cross-chain verification and triggered unbacked payouts, draining several digital assets from Verus’ Ethereum bridge reserves.
Recurring Security Flaws and Recent HistoryThe latest breach revived scrutiny over Verus’ handling of a previous exploit in May, which resulted in an $11.58 million loss. Experts stated that this attack exploited the exact vulnerability from the earlier incident, indicating that core issues may have remained unaddressed. Blockaid observed that while this latest event involved a different attacker wallet, the method and targeted contract remained unchanged.
Following the May attack, the same attacker returned 4,052 ETH—about 75% of the stolen funds—after reaching an agreement with Verus. Despite that partial restitution, the repetition of the exploit has heightened doubts regarding the bridge’s security remediation process.
Experts pointed out that the repeated vulnerability likely resulted from an incomplete technical fix after the earlier breach, leaving Verus exposed to additional attacks. There is growing pressure for the protocol team to publish a thorough incident report and technical breakdown.
Ongoing Investigations and Broader RisksThe Verus incident is one of several recent DeFi bridge attacks highlighted by on-chain monitoring services. Lookonchain reported that combined losses from incidents involving Verus, AFX Trade, and B² Network have climbed to approximately $35.55 million.
Mini dictionary: Lookonchain is an on-chain analytics platform known for monitoring blockchain transactions and identifying patterns related to hacks, large movements, and abnormal activities.
Security analysts explained that bridge protocols are increasingly targeted due to logical flaws in cross-chain messaging mechanisms, which, if exploited, can allow fund withdrawals without equivalent collateralization.
Next Steps for Verus and UsersAmid the investigation, Verus halted all bridge operations but has not announced a compensation plan or released a detailed technical report. The absence of a clear official explanation has drawn criticism from the user community.
Observers expect the Verus team to prioritize closing the technical vulnerability, improve their validation process, and offer a roadmap to locate and potentially recover missing assets. Until these steps are made public, scrutiny around trust and transparency in the protocol will likely continue.
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.
A wallet tied to the $285 million Drift Protocol exploit moved 23,095.1 Ether, worth about $44.4 million, into Tornado Cash after roughly three months of inactivity.
Summary
Drift’s exploiter deposited 23,095 ETH into Tornado Cash after remaining inactive for three months. ZachXBT declined further tracking, citing resources required to monitor and freeze a nine-figure DPRK theft. Drift previously announced a recovery bounty program with Arkham and Bybit, contrary to online claims. The same address sent 0.85 ETH to wallets labeled as Bybit deposit addresses, according to Etherscan records and monitoring attributed to PeckShield.
Transfers began on July 23 and continued into July 24, on-chain records show. Researcher JL, known as 0xJaelle, flagged the movement and tagged ZachXBT. The investigator replied that he did not plan to keep following the funds without institutional support.
Drift exploiter empties an Ethereum wallet The Etherscan address labeled “Drift Exploiter 4” processed hundreds of transactions during the movement. Records show repeated deposits of 100 ETH, 10 ETH and 1 ETH into the Tornado Cash router. Four other transfers totaling 0.85 ETH went to addresses labeled as Bybit deposits.
Onchain Lens first reported that the attacker had resumed activity and was sending 100 ETH batches into the mixer several times per minute. The wallet had remained largely inactive since the April attack.
Tornado Cash pools deposits and permits later withdrawals through different addresses. That can weaken the direct public link between sending and receiving wallets. Investigators may still use timing, transaction patterns and exchange activity, but the process requires more data and staff.
The movement covers only part of the original theft. Drift’s April recovery update valued stolen assets at $295.7 million across JLP, USDC, Bitcoin-linked tokens, SOL, WETH and other assets. The protocol said much of the converted value remained across four flagged Ethereum wallets.
ZachXBT cites cost of tracking North Korea-linked funds ZachXBT wrote, “Sorry I currently do not have any plans to track these funds further.” He said monitoring a nine-figure North Korea-linked exploit and working toward possible freezes would require resources beyond one independent investigator.
He described the task as “difficult for a team and not feasible for a single person.” ZachXBT also said Drift was not a donor or client. His response on X drew attention to the cost of investigations that continue for months.
The comments do not show that no organization is watching the wallets. Drift has said it works with law enforcement, Mandiant and blockchain intelligence firms. Etherscan continues to label the address, while exchanges can review deposits connected to flagged wallets.
Elsewhere, ZachXBT criticized Circle after about $232 million in stolen USDC crossed from Solana to Ethereum during the April attack. The funds moved through Circle’s cross-chain system before the attacker converted much of the value into ETH.
Drift had announced a recovery bounty program JL later said it was surprising that Drift had not created a recovery bounty. Drift’s public record shows that it had announced plans for one. On April 16, the protocol said it was developing a bounty program with support from Arkham and Bybit.
However, the update did not provide a final reward amount, eligibility rules or payment schedule. It remains unclear whether the program became fully active, whether it covered continuing wallet monitoring, or whether independent researchers could claim payment for later tracing work.
Drift also created a user recovery plan separate from stolen-fund tracking. Tether proposed up to $127.5 million in support. Drift plans to issue recovery tokens and fund redemptions through remaining assets, partner capital and future exchange revenue.
The protocol’s June investigation update said Mandiant attributed the attack to UNC6862, a North Korean threat group. Drift said the attackers used social engineering and compromised operational access rather than a smart contract flaw. As crypto.news reported, the attackers emptied key vaults within about 12 minutes.
Recovery continues as the trail becomes harder to follow Drift has focused on rebuilding its platform and funding user claims while forensic teams pursue the stolen assets. Its recovery framework states that recovered funds will enter the user recovery pool. The protocol also plans stronger signing controls for critical transactions.
The April attack affected other Solana projects. As previously reported, yield platform Carrot decided to shut down after losses linked to Drift erased most of its deposited value.
The Tornado Cash deposits do not prove that the attacker converted the ETH into usable cash. The deposits remain public, and investigators may still identify later withdrawals. However, they remove a simple wallet-to-wallet trail and make the next phase harder.
Neither Drift nor Solana had publicly responded to ZachXBT’s comments at the time of writing. Bybit had not announced whether it reviewed the small deposits shown on Etherscan. The remaining stolen funds and the status of Drift’s planned bounty program remain unresolved.
Morgan Stanley expects the Federal Reserve to hold steady next week
Morgan Stanley strategists said in a report that recent data indicates the Federal Reserve will hold steady at its July policy meeting and likely maintain interest rates unchanged for the rest of the year. They wrote: “The Fed is losing patience with inflation above its target. The trajectory of inflation in the coming months is critical—we expect inflation to cool as anticipated—otherwise the Fed may pivot to raising rates later this year.” Currently, money markets have priced in expectations of nearly two Fed rate hikes by the end of the year. However, the slowing inflation trend may prompt the Fed to hold rates steady this year, keeping the federal funds rate in the 3.50% to 3.75% range. “We expect the downward trend in inflation will keep the Fed on hold this year.”
12 minutes ago
Elon Musk: AI could surpass human intelligence within 5 years, and the importance of currency may decline in 10 years.
Tesla and SpaceX founder Elon Musk told *The Economist* in a 90-minute interview that artificial intelligence (AI) could surpass human intelligence within the next five years, and predicted that AI and robots would push the world into an "era of high prosperity" in roughly a decade. Musk argued that once AI systems and robots have sufficiently advanced digital intelligence and production capacity, the global economy could approach a state of "infinite supply", making human work no longer a necessity for survival and gradually reducing the importance of currency. He noted that with enough robots in the future, society would have a "quasi-infinite economy" where AI can produce more goods and services than humanity can consume. He even predicted that by around 2036, the traditional monetary system would likely see its importance decline significantly. On future economic operation models, Musk said governments may maintain social function by distributing funds directly to the public, adding that AI-driven productivity gains could lead to deflation rather than inflation. However, Musk acknowledged that issues including corporate profit models, government fiscal sources, and social transformation mean the AI era’s economic structure could differ drastically from traditional economic laws. Additionally, Musk discussed the integration of AI and space development, stating that future AI computing could be supported by space-deployed data centers, and reiterating his long-term plan for human exploration of Mars. During the interview, Musk also reflected on his prior involvement with the Trump administration’s Department of Government Efficiency (DOGE). He admitted to investing too much energy in politics, saying he "got sidetracked" in some areas, and noted that if given the choice again, he would likely devote more time to his own companies.
12 minutes ago
A whale’s $30 million tech stock trading plan: AMD plans to close short positions and go long, while Micron and SanDisk will wait for a rebound to open short positions.
According to Hyperinsight monitoring, as of press time, the largest single order related to tech stocks on Hyperliquid has been placed by an intraday swing whale (0x4e2), who holds a total of 209 orders worth approximately $30.679 million. The trading plan includes: "Close AMD short at low levels, add short positions on storage stocks during rebounds": - AMD stop-loss to close short: Currently holds ~$6.051 million in AMD short positions, with an unrealized loss of ~$74,000. A buy order worth $4.012 million has been placed at $542.4 to $544.6, planning to reduce about two-thirds of the short positions first. - AMD reverse to long: Another buy order worth $16.444 million is placed at $531 to $541. The strategy is to close the short position when the price drops to ~$540.48, then reverse to long; if fully filled, the final long position is estimated at ~$14.659 million, with an average price of ~$537.7. - MU add short on rebound: A sell order worth $8.187 million is placed at $1012 to $1080. If fully filled, MU's short position is estimated to expand to ~$7.76 million based on the current mark price, with an average price of ~$1038.3. - SNDK add short on rebound: A sell order worth $2.036 million is placed at $1675 to $1849. If fully filled, SNDK's short position is estimated to expand to ~$1.946 million based on the current mark price, with an average price of ~$1700.7. No triggerable stop-loss orders have been observed so far, and there are no take-profit buy orders for MU and SNDK. The overall strategy is: close AMD short when it falls below the break-even point, then reverse to long; add short positions in the storage sector during rebounds. Previous update: The "US stock market big winner" just pocketed $6.57 million. What are the next take-profit and swing trading levels for the new $58 million order?
12 minutes ago
JPMorgan Chase raises Intel's price target from $45 to $85.
JPMorgan Chase raised its price target on Intel (INTC.O) from $45 to $85, following the chipmaker’s release of an unexpectedly strong revenue forecast that signals surging data center spending is fueling its long-awaited recovery. Intel projected third-quarter sales of $15.8 billion to $16.8 billion; even the lower end of this range comfortably exceeds the average analyst estimate of $15.1 billion. The outlook underscores Intel’s growth momentum among data center customers, who are urgently in need of chips to meet artificial intelligence computing demands. Last quarter, sales in this segment surged 59%—more than double Intel’s overall revenue growth rate.
12 minutes ago
$285M Drift Protocol exploiter deposits $44.4M $ETH into Tornado Cash
The Drift Protocol exploiter who stole $285M has deposited 23,095 $ETH ($44.4M) into #TornadoCash today. The exploiter still holds 107,165 $ETH ($201M).
12 minutes ago
Tech stocks continue to slump, forcing bulls out as 3 whales cut losses on $7.26 million worth of long positions.
According to Hyperinsight monitoring, as of press time, SK Hynix, Google, and the Nasdaq 100 have declined roughly 5.8%, 4.2%, and 1.9% respectively. Within the noon hour, three whales sold their existing long positions, totaling around $7.2637 million in trading volume and generating realized losses of approximately $79,800: The address starting with 0x960 liquidated 167.0 Nasdaq 100 long positions, with a trading volume of ~$4.729 million and a loss of ~$46,000; the address starting with 0x943 liquidated 1248.3 SKHX long positions, with a trading volume of ~$1.502 million and a loss of ~$18,000, then immediately shorted SKHX worth $225,700; the address starting with 0x61c liquidated 3262.0 GOOGL long positions, with a trading volume of ~$1.032 million and a loss of ~$14,000. Only the GOOGL trade is confirmed to have been triggered by a $317 stop-loss order, while the rest were voluntarily closed at a loss.