BTC $64,156.94 +0.48%
ETH $1,866.29 +0.69%
BNB $566.63 +1.31%
XRP $1.09 +0.23%
SOL $74.03 +0.28%
TRX $0.3296 -0.23%
DOGE $0.0706 +2.94%
ADA $0.1645 +0.36%
BCH $209.82 +0.44%
LINK $8.35 +0.32%
HYPE $57.53 -2.12%
AAVE $91.54 -3.10%
SUI $0.7074 -1.06%
XLM $0.1782 +0.43%
ZEC $476.83 -4.04%
BTC $64,156.94 +0.48%
ETH $1,866.29 +0.69%
BNB $566.63 +1.31%
XRP $1.09 +0.23%
SOL $74.03 +0.28%
TRX $0.3296 -0.23%
DOGE $0.0706 +2.94%
ADA $0.1645 +0.36%
BCH $209.82 +0.44%
LINK $8.35 +0.32%
HYPE $57.53 -2.12%
AAVE $91.54 -3.10%
SUI $0.7074 -1.06%
XLM $0.1782 +0.43%
ZEC $476.83 -4.04%

affected

All
Article
Flash

Ostium releases an update on the attack incident, price data was attacked, but traders' collateral and positions were not affected

Ostium released an update on the attack incident. Its liquidity provider fund was attacked on July 15, resulting in a loss of 23,752,746 USDC. Preliminary investigations indicate that the attacker compromised the off-chain infrastructure that provides price data to the protocol and submitted disguised illegal price reports, extracting artificially generated profits from the fund by quickly opening and closing multiple large positions.Ostium stated that traders' collateral is stored in independently isolated smart contracts and was not affected by this incident, with all trading positions remaining open. The team paused trading and froze all trading contracts within 60 minutes after the first attack transaction occurred. Currently, Ostium is collaborating with Mandiant, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies, coordinating with trading platforms, bridging contracts, and stablecoin issuers to advance the investigation. The engineering team is focused on repairing and strengthening the relevant infrastructure to support the secure resumption of trading.Ostium indicated that it will notify at least 24 hours in advance before unfreezing the trading contracts. After trading resumes, existing positions will be marked at the price at the time of reopening, unaffected by price fluctuations during the pause. Addressing the affected liquidity providers and securely resuming trading remains the current top priority.

Axelar responds to security incident: Axelar and IBC are unaffected, the vulnerability originates from a third-party token contract's "infinite minting" issue

The cross-chain protocol Axelar Network released a statement regarding the recent security incident related to Secret Network, stating that there is a misunderstanding within the community about the event. Both Axelar and the Inter-Blockchain Communication Protocol (IBC) were not attacked or compromised. The affected token smart contracts were neither developed, deployed, nor maintained by Axelar, and Axelar's firewall mechanism also prevented the impact from spreading to other chains.It is reported that the exploited contract is a forked version based on CW20-ICS20, but the developers removed two core security checks, resulting in an "infinite minting" vulnerability. By deleting the verification mechanisms originally used to prevent such issues, this fork altered the original trust model of the contract and did not undergo a new security audit.Axelar Network explained that anyone can deploy contracts for cross-chain asset wrapping through IBC, and similar contracts have also been used to wrap tokens from other chains into Secret Network. However, the Secret side fork version in this incident has vulnerabilities due to the removal of key security checks. This incident is not a unique logical flaw, nor is it an issue with the IBC protocol itself, but rather a security risk introduced by modifications to third-party contracts.

Humanity releases the investigation report on the security incident: the main network bridge was not affected, and the attack tools and methods exhibit characteristics of North Korean hackers

Humanity released an independent investigation report by Quantstamp, which disclosed that in the H token security incident, the attacker used tools and methods characteristic of North Korean hackers, disguising themselves as communication from the Bithumb exchange through phishing emails, inducing project directors to click on malicious attachments, thereby deploying a remote control Trojan on their devices, ultimately gaining full desktop control and wallet private keys. Subsequently, on Ethereum and BNB Chain, they launched on-chain attacks: on the Ethereum side, by stealing keys to upgrade contracts and transferring approximately 141.18 million H tokens, and on the BSC side, by taking over the ProxyAdmin contract and minting new tokens. The stolen assets were then continuously sold on Uniswap and PancakeSwap for about 8 hours, causing significant impact on liquidity and market prices.Currently, the H token contract on the Ethereum side has been frozen, the mainnet bridge remains unaffected, but the BSC deployment has been controlled by the attacker and still has minting permissions. The team is working with exchanges and security parties to advance subsequent disposal and recovery plans, while reminding users to be wary of false "compensation/claim" links, and stated that further progress will be announced through official channels.Previously, the Humanity Protocol was attacked, resulting in the leak of a private key from a member of the Humanity Foundation, leading to over 31 million dollars in funds being stolen.

Raydium core contributors: will fully compensate for stolen assets, the current mainnet program has not been affected

Raydium core contributor InfraRAY posted on platform X, stating that the team has confirmed that the old version of the AMM V3 program, which was previously discontinued in 2021, has been attacked. The attacker unauthorizedly removed part of the liquidity, but this incident does not affect current Raydium users, and the related liquidity pools have been unable to interact through the official Raydium UI since being disabled. The Raydium SDK and DApp also do not support operations on the mainnet old version AMM V3 liquidity pools.The five affected liquidity pools include: Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, and RAY-SOL. Preliminary statistics show that the stolen assets include approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC, with a total value of about $1.34 million. The related losses will be fully compensated by the treasury.Investigations reveal that the vulnerability originated from insufficient verification of the LP token minting address. The attacker created new LP tokens and impersonated legitimate LP tokens, bypassing the protocol's ratio verification mechanism to extract funds. However, this incident is classified as an independent logical vulnerability and is not due to private key leakage or permission intrusion, and there is no risk of spread. Currently, all existing Raydium mainnet programs have not been affected.

PiggyBank discloses details of the LAB basis trading manipulation incident and will compensate affected users

PiggyBank released a detailed report on the LAB incident on June 6, stating that the protocol experienced a net withdrawal of approximately $579,000 on June 6, primarily due to a LAB token basis trade being manipulated by the market.In early May, PiggyBank purchased 142,800 locked LAB tokens (approximately $102,500) through an OTC intermediary while simultaneously opening a perpetual contract short hedge. However, market participants continuously maintained the spot price above the perpetual contract price, resulting in a deeply negative funding rate (annualized -17,000%), and the high hedging costs forced the shorts to close, resulting in a loss of approximately $476,000. The currently locked LAB tokens have a spot value of about $1 million, but due to poor liquidity and lack of hedging, they have been excluded from the NAV calculation.PiggyBank will undergo structural reforms: increasing transparency of on-chain mechanisms, strategy logic, and fund allocation will be publicly verifiable, while basis trading and funding rate arbitrage will be gradually phased out. In terms of compensation, affected users will receive USDC compensation based on actual losses, with funding sources including NAV discrepancies, future LAB sales (expected to unlock from August 14 to October 14, currently valued at approximately $1 million), and 50% of future platform revenue. All users recorded in the snapshot on June 6 are eligible for compensation.
app_icon
ChainCatcher Building the Web3 world with innovations.