BTCTechnical AnalysisFederal ReserveAsian markets
The New York City Department of Finance's public property assessment database has sparked controversy due to its easy searchability. Crypto industry figures criticize the database for consolidating scattered public records into a searchable tool, effectively creating a directory of wealthy property owners and increasing their risk of physical attacks, such as crypto kidnappings and violent assaults. Uniswap founder Hayden Adams called it the 'worst mass doxxing,' while Helius CEO Mert Mumtaz and Castle Island Ventures partner Nic Carter expressed concerns, noting multiple kidnappings and murders of crypto holders in Europe.
11 hours ago

Cardano wallet SecondFi has released a recovery roadmap following a June hack that resulted in the theft of 16.1 million ADA. The project will permanently cease regular operations, focusing on securely extracting remaining assets and distributing compensation. The roadmap consists of three phases: claim submission (now open), migration tools (mid-August), and a zero-knowledge proof-based refund portal (early September). In collaboration with the Cardano Foundation, the team is launching the first Web3 ZK compensation tool, allowing affected users to prove ownership without revealing private keys. Users are also warned about phishing scams.
ADASecondFiZK-proofphishing19 hours ago

GCSA Global Cybersecurity Alliance has released an in-depth analysis report on the Fastjson 1.2.83 'gadget-free' vulnerability. This vulnerability can trigger remote code execution without relying on traditional gadgets, and has been successfully reproduced in JDK 8, 17, 21, 25, and Spring Boot Loader environments. Attackers can achieve unauthenticated remote code execution by controlling JSON input, posing a severe impact. The report also provides defense recommendations, including enabling SafeMode, migrating to Fastjson 2.x, and restricting outbound network policies.
21 hours ago

Thailand's Securities and Exchange Commission (SEC) has filed a criminal complaint against crypto exchange Bitkub and two former directors for allegedly submitting false reports to conceal asset losses after a $47 million hack in May 2021. The SEC claims Bitkub failed to reflect the stolen digital assets in its daily capital declarations from May to October 2021. Bitkub stated that customer funds are safe and that the co-founder had already covered the stolen assets with personal funds. The case has been referred to police and prosecutors.
ETHcriminal complaintCrypto Exchangefalse reports23 hours ago

Garden Finance temporarily took its app offline after an attacker compromised the off-chain database of an independent solver, stealing approximately $450,000 in USDT from HTLC contracts. Protocol contracts and user funds remain unaffected. The team is working with security firms to trace the stolen assets.
BTCoff-chain databasesolver compromisesecurity incident2026-07-27

Singapore stablecoin payments firm Triple A confirmed unauthorized access to its treasury wallet, resulting in a loss of its own digital assets, but client funds and payment operations remain unaffected. The company stated that the financial impact will be covered by treasury reserves and operations have returned to normal. On-chain investigators estimate the loss at approximately $11.8 million. Triple A is cooperating with cybersecurity experts and the Singapore Police to trace the stolen assets.
ETHTreasury Wallet ExploitOnchain InvestigationUnauthorized Access2026-07-27

WEMIX confirmed that the owner key of its WEMIX$ stablecoin contract was compromised on July 26, leading to the unauthorized minting of approximately 5.23 million WEMIX$, worth about $6.25 million. The attacker converted some funds to USDC.e and bridged them to Ethereum and BNB Smart Chain, then swapped for ETH and USDT, with some funds flowing to centralized exchanges. WEMIX has frozen bridges, liquidity pools, and related services, and is working with exchanges and blockchain security firms to track and freeze suspicious funds. The incident follows a 2025 bridge attack on WEMIX and occurs during its transition to USDC.e services.
WEMIXcross-chain transferstablecoin mintingowner-key breach2026-07-27

South Korean exchange Upbit removed its trading warning for Taiko (TAIKO) after reviewing the project's explanation and subsequent security measures regarding a June bridge exploit. The warning, triggered on June 22 due to a security vulnerability, led to deposit suspensions. Following a 32-day review, Upbit deemed the warning cause resolved and will resume TAIKO deposits in KRW, BTC, and USDT markets. The exploit targeted Taiko's bridge and chain state verification system, causing losses over $1 million. TAIKO tokens rose after delisting fears eased, but Upbit warned of potential price volatility upon deposit resumption.
2026-07-24

Hackers hijacked Robinhood CEO Vlad Tenev's X account to launch the token $VLAD via the Pons launchpad. The token's liquidity is permanently locked, preventing a rug pull, but the hackers generate continuous revenue through transaction fees. The article analyzes this novel scam model: transforming traditional rug pulls into a perpetual fee mechanism, using anti-fraud infrastructure itself as a tool for fraud.
VLADliquidity lockPons launchpadVlad Tenev2026-07-24

Lien Finance suffered a $542K loss in USDC due to a logic bug in its bond token system. The attacker exploited a validation flaw in the exchangeEquivalentBonds function of the BondMakerCollateralizedEth contract, minting invalid bond tokens without burning the corresponding input bonds, then draining liquidity via three pre-approved endpoints. Security firms SlowMist and DefimonAlerts attributed the issue to missing integrity checks and unrestricted bond registration and pricing mechanisms.
USDCValidation FlawDeFi ExploitLien Finance2026-07-24