Data: CertiK monitored an attack on Hinkal Protocol, resulting in the theft of approximately $800,000 in USDC.
Related
BonkDAO was attacked by a malicious governance proposal, resulting in the theft of approximately $20 million in BONK.
According to Odaily Odaily, Bonk Inu's official X account stated that BonkDAO suffered a malicious governance proposal attack, resulting in the theft of approximately $20 million worth of BONK tokens from its DAO vault. Attackers allegedly transferred BonkDAO vault assets through a questionable governance proposal. The stolen BONK subsequently began flowing into exchanges, putting downward pressure on the BONK price. Data from The Block shows that the BONK price has fallen by more than 9%. South Korean exchange Upbit subsequently issued a statement saying it had temporarily suspended BONK deposits and withdrawals in response to the incident and to guard against potential risks. (The Block)
CertiK Hack3D Report: Web3 Losses Exceed $1.3 Billion in the First Half of 2026, Attacks Are Accelerating Towards High-Value Targets
Odaily Odaily reports that Web3 security company CertiK released its "Hack3D: First Half of 2026 Report." The report shows that 344 security incidents occurred in the Web3 ecosystem in the first half of 2026, resulting in a total loss of approximately $1.32 billion. While this figure represents a 46.8% decrease compared to the same period last year, if the impact of the $1.45 billion security incident involving Bybit is excluded, the actual loss in the first half of this year increased by approximately 28% year-on-year, indicating that the overall security environment of the industry has not seen substantial improvement. The report points out that wallet theft has become the type of attack causing the biggest financial loss, resulting in approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks decreased by more than 50% year-on-year, the amount of losses only decreased by about 10.8%, reflecting that attackers are shifting their focus to high-net-worth individuals and institutions, launching more targeted and high-value attacks. Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running smart contracts that lack re-auditing. The report also shows that large-scale attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents causing approximately $577 million in losses, accounting for 44% of total losses in the first half of the year. In terms of the number of incidents, the impact of individual attacks, and changes in attack patterns, the Web3 industry is facing increasingly complex and continuously escalating security challenges.
hinkal will fully compensate users for their funds, confirming that approximately 797,000 USDC was withdrawn by attackers and exchanged for 454 ETH.
Mars Finance reports that the decentralized privacy protocol hinkal has released a security incident update, confirming that attackers withdrew approximately 797,000 USDC from its Ethereum contracts through a series of transactions and exchanged it for approximately 454 ETH. Of this, approximately 410 ETH was subsequently transferred to Tornado Cash, and the remaining approximately 44.67 ETH was transferred to the Bitcoin network via THORChain. The company is currently working with external security teams to track the flow of funds. hinkal stated that the impact of this security incident is limited to the relevant on-chain liquidity pools; other on-chain contracts were unaffected, but all contracts have been temporarily suspended for repairs and security verification. All affected users will receive full compensation on a 1:1 basis; the specific compensation process and timeline will be announced in a subsequent update.
Revolut attackers threaten daily customer data leaks
Attackers reportedly published identity documents and selfies belonging to Revolut customers and threatened to release more data each day until the fintech pays.
Data: TAC Protocol (TAC) plummeted 90% in 15 minutes, currently trading at $0.0061.
According to Mars Finance, market data shows that TAC Protocol (TAC) plummeted 90% in 15 minutes and is currently trading at $0.0061.
Summer.fi An attack has been officially confirmed; all vaults in the Lazy Summer Protocol have been suspended.
According to Foresight News , Lazy Summer Protocol has officially confirmed an attack and has suspended all vaults under its umbrella. The cause is currently under investigation, and updates will be provided as they become available.