
Ostium was exploited, with approximately $24 million in USDC stolen. The attacker exploited a combination of authorized oracle signing keys and the PriceUpKeep keeper role to submit correctly signed price reports with future dates, repeatedly opening and closing trading pairs to fabricate profits without real market exposure. The article highlights the frequency of such application-layer vulnerabilities, with attackers targeting operational infrastructure and human trust. It also argues against mitigation measures like withdrawal limits, as they introduce censorship risks, slippery slopes, and could exacerbate fragility.
20 hours ago

Binance Futures has launched perpetual contracts for two new assets: PONS, a utility token on Robinhood Chain, and HAJIMI, a meme coin on BNB Smart Chain. PONS, a leading launchpad token with a deflationary model, nears a $1B market cap, while HAJIMI is driven purely by Asian community hype with a 3x leverage cap. Shortly after listing, HAJIMI faced an MEV attack where bots used private RPC channels to pay high bribes for early buys and profits.
2026-09-06

Binance has alerted users to a surge in phishing text messages that impersonate account security alerts and contain malicious short links designed to steal login credentials. The exchange emphasizes it never asks users to verify accounts via SMS links and recommends using Binance Verify to check suspicious communications, enabling withdrawal address whitelisting, and other protective measures. The article does not disclose the number of affected users or specific losses.
2026-09-04

On September 2, Curve DAO approved yRisk as its new risk management provider, responsible for risk assessment and monitoring of crvUSD and Llamalend for a twelve-month term. yRisk will receive an annual budget of 125,000 frxUSD and 568,181 CRV, worth approximately $250,000. However, two core developers of yRisk are also lead developers of Resupply, which suffered a donation attack in June 2025 resulting in a loss of about $9.6 million. The proposal and Curve's comparison materials did not explicitly mention this security incident, raising community concerns. The proposal passed with 621.2 million veCRV in support and almost no opposition.
2026-09-04

OpenAI has announced that its unreleased model, Astra, has reached a 'critical' level in cybersecurity capabilities for the first time under its preparedness framework. Astra scored a perfect score on ExploitBench and can autonomously discover and chain two unknown zero-day vulnerabilities. The model can independently build a complete attack chain, break out of browser sandboxes, and gain host control. OpenAI states that Astra can reject 91.5% of cyber jailbreak attempts, and its advanced cybersecurity capabilities will first be made available to a small group of alpha testers.
2026-09-02

YAM Finance has suffered a governance attack where the attacker self-delegated approximately 504,000 YAM tokens (3.3% of total supply) to gain voting power exceeding the governance quorum and submitted proposal #45 to set the protocol's Timelock pending admin to an attacker-controlled address. If the proposal passes, the attacker would gain administrative control over the Timelock, thereby controlling the protocol contracts and DAO treasury, putting about $337,000 in assets at risk. Security firm Defimon reminds YAM holders to vote against the proposal before block 25,897,343.
2026-09-02

Fogo has resumed mainnet operations following a security incident that halted the network. The breach resulted in the theft of 400 million FOGO tokens, of which 237 million have been recovered and permanently removed from circulation. The remaining 163 million are still being traced through centralized exchanges and law enforcement. Fogo has not yet disclosed how the foundation was compromised, and the investigation is ongoing.
2026-09-02

Core DAO is coordinating an emergency hard fork after discovering that a small group of validators obtained CORE rewards beyond the protocol's intended issuance. The issue has been contained, and malicious validators can no longer extract additional rewards. The hard fork is a forward upgrade and will not roll back the network or undo confirmed transactions. Exchanges including Coinbase, Bithumb, and Coinone have restricted CORE transfers. Core has not disclosed the amount of excess CORE issued or whether it has entered the market.
2026-09-02

X is investigating a wave of unsolicited password reset emails and confirmation codes, but an initial review found no evidence of a system breach. The company advises users to enable two-factor authentication and password reset protection. The email wave coincides with X Money's expansion in the U.S., and attackers may be trying to gain account access. X has not disclosed who is responsible or how many accounts were affected.
2026-09-01

X (formerly Twitter) users are receiving unsolicited password reset emails and login alerts, with some accounts locked. X hasn't confirmed a new breach, but researchers link this to a 2021-2022 API vulnerability, a 2025 leak of 200 million records, an active botnet, and phishing campaigns since July. X engineers say no new vulnerability found, but attackers may be targeting accounts to access X Money. The article also mentions Proton mail outage, unrelated but possibly affecting users.
2026-09-01