Months After the $292M Kelp Hack, Chainlink Lets Institutions Add Their Own Bridge Checks
Related
White House Lets Private Firms Hack Cybercriminals—At Their Own Legal Risk
President Donald Trump signed a memorandum Tuesday that lets vetted U.S. companies carry out offensive cyber operations against foreign criminal networks. Here's what the program actually authorizes.
AI Agents Hacked Their Own Test Environment to Cheat, Cybersecurity Firm Finds
Darktrace's new Signal Labs found AI agents hacking their own evaluation environment to fake a perfect score—and tricking coding assistants into running unauthorized network attacks.
ETH wallet exploit backfires as MEV bot captures $7.7M, Kelp freezes address
An MEV bot known as “Yoink” front-ran an attacker attempting to exploit a custom Safe module, capturing the stolen rsETH before Kelp temporarily froze the receiving address.
SpaceX's marked address transferred a small amount of BTC for the first time in six months, suspected to be a test transfer.
According to BlockBeats, on July 8th, Arkham monitoring revealed that an address tagged as SpaceX transferred Bitcoin for the first time in six months. Data shows that SpaceX address 15atF initiated a test BTC transaction of approximately $88 to SpaceX address bc1q9, which appears to be a test transfer.
EMURGO announced that SecondFi, the Cardano wallet that was hacked, will permanently cease operations.
ChainCatcher reports that Cardano's founding entity, EMURGO, stated on Monday that SecondFi, the wallet service that suffered a hack, will not resume normal operations even after a security audit is completed. All users are required to migrate their assets through the official recovery process. SecondFi is a rebranded version of the Yoroi wallet and is described by EMURGO as Cardano's largest wallet provider. According to EMURGO's incident report on June 25th, the service suffered four separate wallet thefts on June 22nd, with 374 addresses compromised and approximately 16 million ADA (worth about $2.4 million at the time) stolen. The team also took emergency measures to recover approximately 129 million ADA. EMURGO stated that compromised wallets should be considered permanently exposed at the address and private key levels, and restoring the damaged seed phrase to other wallets cannot eliminate the risk. EMURGO plans to launch an isolated wallet state inspection tool this week, followed by a secure export tool and an offline migration workshop in Tokyo. They are also building a dedicated recovery fund for the on-chain recovery system, and will return assets to affected users after the external audit is completed.
CertiK Hack3D Report: Web3 Losses Exceed $1.3 Billion in the First Half of 2026, Attacks Are Accelerating Towards High-Value Targets
Odaily Odaily reports that Web3 security company CertiK released its "Hack3D: First Half of 2026 Report." The report shows that 344 security incidents occurred in the Web3 ecosystem in the first half of 2026, resulting in a total loss of approximately $1.32 billion. While this figure represents a 46.8% decrease compared to the same period last year, if the impact of the $1.45 billion security incident involving Bybit is excluded, the actual loss in the first half of this year increased by approximately 28% year-on-year, indicating that the overall security environment of the industry has not seen substantial improvement. The report points out that wallet theft has become the type of attack causing the biggest financial loss, resulting in approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks decreased by more than 50% year-on-year, the amount of losses only decreased by about 10.8%, reflecting that attackers are shifting their focus to high-net-worth individuals and institutions, launching more targeted and high-value attacks. Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running smart contracts that lack re-auditing. The report also shows that large-scale attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents causing approximately $577 million in losses, accounting for 44% of total losses in the first half of the year. In terms of the number of incidents, the impact of individual attacks, and changes in attack patterns, the Web3 industry is facing increasingly complex and continuously escalating security challenges.