The Ethereum blockchain project BackedFi suffered a suspicious attack, resulting in a loss of approximately $204,200.
Related
Hinkal's privacy protocol has suspended affected smart contracts due to abnormal USDC transactions on the Ethereum blockchain.
Odaily Odaily reports that decentralized privacy protocol Hinkal Protocol has announced it has noticed unusual activity involving USDC on the Ethereum network within its system. Currently, this only affects the Ethereum blockchain; other chains are unaffected. As a precaution, affected smart contracts have been suspended, and a comprehensive investigation and analysis of related on-chain transactions and activities is underway. The investigation is ongoing, and updates will be released as information becomes available. Previously, it was reported that Hinkal suffered a loss of $800,000 due to a suspicious USDC transaction.
BonkDAO was attacked by a malicious governance proposal, resulting in the theft of approximately $20 million in BONK.
According to Odaily Odaily, Bonk Inu's official X account stated that BonkDAO suffered a malicious governance proposal attack, resulting in the theft of approximately $20 million worth of BONK tokens from its DAO vault. Attackers allegedly transferred BonkDAO vault assets through a questionable governance proposal. The stolen BONK subsequently began flowing into exchanges, putting downward pressure on the BONK price. Data from The Block shows that the BONK price has fallen by more than 9%. South Korean exchange Upbit subsequently issued a statement saying it had temporarily suspended BONK deposits and withdrawals in response to the incident and to guard against potential risks. (The Block)
Aptos blockchain was found to have a critical vulnerability, with an attack cost of only a few hundred dollars; the team has promptly fixed it.
PANews reported on July 5th that, according to Coindesk, white-hat hackers at security firm Hexens discovered a vulnerability in the Aptos blockchain, which has since been patched. If maliciously exploited, this vulnerability could have put up to $70 billion in digital assets at systemic risk, including stablecoins and cross-chain bridges. In late February, Hexens researchers reported a critical vulnerability in the Move virtual machine (the execution environment for handling on-chain smart contracts) to the Aptos development team. They described it as an "expiration cache vulnerability" that could lead to type confusion, meaning the software could be tricked into mistaking one on-chain resource for another. Researchers simulated the attack in a real network environment with a success rate exceeding 90%.
Vulcan Forged, a blockchain game developer, responded to being added to the watchlist by Binance, stating that PYR and the project are no longer sustainable.
According to Foresight News , Vulcan Forged responded to being labeled a "watch" account by Binance on the X platform, stating that the team understands this (due to its low market capitalization). The team stated that it is now clear that market attention and funding are insufficient to support the continued existence of the PYR token and the Vulcan Forged project, and they anticipate facing significant criticism, anger, and shock. This incident has essentially destroyed any possibility of a revival for the Vulcan and PYR brands. Vulcan Forged revealed that it may relaunch some niche games under a new brand in the future, but for now, this is a fatal blow that the team cannot recover from. Vulcan Forged also expressed shock, noting that the community is aware of the team's consistent commitment to daily operations and development. For the past six years, the team has strived to maintain its belief in blockchain games, but now the focus is severely lacking, and its games, like most blockchain games, have only a few dozen active users.
CertiK: Edel Finance's lending market was attacked, resulting in losses of approximately $204,000.
According to Mars Finance, CertiK monitoring indicates that Edel Finance's lending market has been attacked. Attackers manipulated the collateral price of wGOOGLx (which depends on the balance of its GOOGLx account) to conduct illegal lending, resulting in a loss of approximately $204,000 for the platform. The affected transactions have been flagged, and security agencies are alerting users to the risks.
OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app
OneKey said it reproduced an exploit against an older version of the Ledger app in its lab environment, which Ledger fixed in its Ethereum app 1.22.2, with no user funds lost.