Connect with us
DAPA Banner

Crypto World

ZachXBT Slams Circle for Letting Millions in Stolen USDC Flow Freely After Drift Hack

Published

on

Onchain investigator ZachXBT accused Circle of failing to act while millions in stolen USDC moved freely through its own cross-chain bridge during the $285 million Drift Protocol exploit.

The criticism followed the April 1 attack on the Solana-based decentralized exchange, which ranks as the largest DeFi exploit of 2026 so far.

Circle Faces Backlash Over CCTP Inaction

Drift Protocol, a perpetual futures platform on Solana (SOL), suffered a massive vault drain on April 1. Security firm PeckShield and blockchain analytics platform Arkham Intelligence flagged roughly $285 million in outflows from Drift’s main vault to attacker-controlled wallets.

The attacker moved stolen assets, heavily involving USDC, across multiple wallets before bridging them from Solana to Ethereum using Circle’s Cross-Chain Transfer Protocol (CCTP).

ZachXBT pointed out the transfers occurred during U.S. business hours with no intervention.

Circle was asleep while many millions of USDC were swapped via CCTP from Solana to Ethereum for hours from the 9-figure Drift hack during US hours,” the blockchain investigator stated.

Security researcher Specter echoed those concerns. He noted that the attacker held USDC across wallets for 1 to 3 hours before swapping and deliberately avoided converting to Tether (USDT) during the bridging process, suggesting confidence that Circle would not freeze the funds.

A Pattern of Contradictory Responses

The timing intensified frustration. Just days before the Drift exploit, Circle froze the USDC balances of 16 unrelated business hot wallets on March 23, as part of a sealed U.S. civil case.

That action disrupted operations for exchanges, casinos, and payment processors.

ZachXBT previously called that freeze potentially the most incompetent he had seen in over five years. He argued that, based on on-chain analysis, the wallets engaged in legitimate activity.

Advertisement

Circle later unfroze one wallet linked to Goated.com on March 26, but most remained locked.

The contrast is stark. Circle acted aggressively on a civil matter affecting legitimate businesses. Yet during a confirmed nine-figure exploit, it took no steps to freeze stolen funds transiting its own infrastructure.

ZachXBT also tied this behavior to Circle’s proposed optional privacy features on its upcoming Arc blockchain. He suggested those features could reduce compliance accountability further by limiting who can view transactions.

What Comes Next for Circle and Drift

On the Ethereum side, stolen assets were swapped for roughly 129,000 ETH. Drift’s total value locked collapsed from approximately $550 million to $247 million, and its native DRIFT token fell nearly 28%.

Advertisement
Drift Protocol TVL
Drift Protocol TVL. Source: DefiLlama

Circle has not publicly responded to the criticism. The incident has reignited debate over whether centralized stablecoin issuers can justify their freeze authority if they apply it inconsistently.

The post ZachXBT Slams Circle for Letting Millions in Stolen USDC Flow Freely After Drift Hack appeared first on BeInCrypto.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Zcash patches critical bug affecting the Sprout shielded pool

Published

on

IoTeX confirms $2M hack, rejects $4.3M theft claims

Zcash has patched a major vulnerability that would have allowed bad actors to drain funds from the protocol’s deprecated Sprout shielded pool.

Summary

  • Zcash patched a critical flaw in zcashd nodes that skipped proof verification in the legacy Sprout pool, a bug that could have exposed more than 25,000 ZEC to potential draining.
  • The vulnerability remained present from July 2020 until the release of v6.12.0, with no exploitation detected and all user funds confirmed safe.

A disclosure report from security researcher Alex “Scalar” Sol, published on Tuesday, claims that a critical flaw was discovered in zcashd nodes that resulted in skipping proof verification for transactions involving the legacy Sprout pool.

Zcash’s Sprout pool is the original “shielded pool” that launched with the network in 2016. It was the first implementation of zero-knowledge proofs (zk-SNARKs) in a production cryptocurrency, allowing users to send and receive ZEC privately.

Advertisement

Although the pool was closed to new deposits in November 2020, it still holds approximately 25,424 ZEC, which are yet to be migrated to newer shielded pool versions.

According to the disclosure, the vulnerability spanned releases from July 2020 onward but was fixed through v6.12.0, which was released on Tuesday. So far, the flaw has not been exploited, and user funds remain safe.

Major mining pools, including Luxor, F2Pool, ViaBTC, and AntPool, have already deployed the fix by March 26, the report added.

Advertisement

The report added that the Zebra full node implementation was not affected. In the event of an attempted exploit, it would have resulted in a chain fork, acting as an additional safeguard.

Despite the severity of the issue, the Zcash Open Development Team has clarified that the network’s “turnstile” mechanism, which enforces that any coins exiting the Sprout pool must have previously entered it, would have prevented broader supply inflation.

For the Zcash network, this marks the second time a critical, systemic vulnerability has been uncovered within its shielded pools. In 2019, the Zcash team disclosed a “counterfeiting” bug, a flaw in the underlying cryptography that could have allowed an attacker to create an infinite amount of ZEC without detection.

Advertisement

Source link

Continue Reading

Crypto World

Crypto selloff deepens with $400 million liquidations and rising short interest

Published

on

Crypto selloff deepens with $400 million liquidations and rising short interest

Bitcoin gave back a large portion of its recent gains on Thursday, now trading at $66,700 having lost 2.4% of its value since midnight UTC.

Ether (ETH) performed even worse, tumbling by 4.4% as the broader crypto market struggles to deal with continued risk-off sentiment.

The latest plunge was spurred by U.S. president Donald Trump, who said on Wednesday evening that the war in Iran would continue with extensive strikes on Iran.

“Over the next two to three weeks, we’re going to bring them back to the stone ages where they belong,” he said.

Advertisement

The comments led to an immediate spike in oil prices, with brent crude rising by around 10% to $108 per barrel as U.S. equities diverged.

Nasdaq 100 and S&P 500 futures lost 1.5% and 1.1% respectively while the U.S. dollar increased by 0.5% to above 100 points.

Derivatives positioning

  • BTC’s price has dropped over 2% since midnight UTC hours alongside a slightly uptick in open interest in major USD- and USDT-denominated futures. Plus, perpetual funding rates have dropped to their most negative since March 12. This combination suggests that traders are bearish and shorting the falling market.
  • In ether’s case, funding rates are most negative since October last year, a sign of strong bias for bearish bets. Meanwhile, bearishness in solana (SOL) is surprisingly more measured despite the overnight hack.
  • Privacy-focused zcash (ZEC) and have seen a notable decline in open interest (OI) in 24 hours, a sign of capital outflows.
  • Nearly $400 million in futures positions have been liquidated due to margin shortfalls. That’s a 17% increase in losses compared to the previous day.
  • Despite renewed risk-off tone, bitcoin and ether’s 30-day implied volatility indices remain flat in recent ranges. It points to orderly selling in the spot market rather than panic.
  • There is little scope for panic because traders are already positioned for market swoon. They have been consistently chasing bitcoin and ether put options (downside hedges) since the start of the year. As of writing, bitcoin and ether puts remained pricier than calls across all tenors on Deribit.
  • Block flows featured demand for ether straddles, a volatility strategy, and put spreads and bitcoin call spreads.

Token talk

  • The worst performing benchmark on Thursday was CoinDesk’s DeFi Select Index (DFX), which lost 5.9% since midnight UTC, closely followed by the CoinDesk Computing Select Index (CPUS) that tumbled by 5%.
  • Ethena (ENA) led the downside move as it fell by more than 10% on Thursday, there was also a heavy drawdown among DeFi tokens UNI, LDO, SKY and AAVE – all shedding between 4.2% and 6.5% during Asian and European hours on Thursday.
  • Algorand (ALGO) bucked the bearish market trend, rising by around 0.8% on Thursday as it continues its rich vein of form having rallied by 22% in the past week.
  • CoinMarketCap’s “altcoin season” index is down from 50/100 to 42/100 since March 30, highlighting relative weakness across the sector.

Source link

Continue Reading

Crypto World

CLARITY Act Nearing Senate Markup, Floor Vote

Published

on

CLARITY Act Nearing Senate Markup, Floor Vote

Coinbase chief legal officer Paul Grewal said the US Digital Asset Market Clarity Act is “moving toward” a markup hearing in the US Senate Banking Committee and could eventually move to a floor vote if senators resolve the stablecoin yield dispute and schedule a markup.

Speaking in a Wednesday interview on Fox Business, Grewal said lawmakers are nearing agreement on core elements of the crypto market structure bill, even as debate continues over stablecoin yield. “I think we’re very close to a deal,” he said.

The remarks point to possible movement on one of the last major sticking points in Senate talks over crypto market structure legislation: whether stablecoin issuers or platforms should be allowed to offer yield or similar rewards. The dispute has helped delay a Senate Banking Committee markup, leaving the broader effort to set federal rules for digital asset oversight still unresolved.

US banks have pushed for restrictions, arguing that such incentives could draw deposits away from traditional institutions and disrupt the banking system. Grewal pushed back on that claim, saying there is no evidence to support fears of deposit flight.

Advertisement

The US House of Representatives passed the CLARITY Act on July 17, 2025. In January, Senate Banking Committee Chair Tim Scott delayed a planned markup, which has yet to be rescheduled.

Related: Crypto investor sentiment will rise once CLARITY Act is passed: Bessent

Trump blames banks for stalling crypto bill

Last month, US President Donald Trump accused banks of undermining efforts to pass crypto market structure legislation, saying they are blocking progress over disagreements on stablecoin yield payments. “The Banks should not be trying to undercut The Genius Act, or hold The Clarity Act hostage,” he wrote.

It was later reported that Trump met privately with Coinbase CEO Brian Armstrong just hours before issuing the statement.

Advertisement
Coinbase shares are down 23% YTD. Source: Yahoo! Finance

In January, Armstrong said Coinbase could not back the market structure bill “as written,” pointing to draft amendments that would eliminate stablecoin rewards and let banks restrict competition.

Related: CLARITY Act 2026 odds ‘extremely low’ if not passed before April: Exec

CLARITY delay could expose crypto to crackdowns

Last week, Coin Center executive director Peter Van Valkenburgh warned that failure to pass the CLARITY Act could leave the crypto industry vulnerable to a future US administration taking a tougher stance. He argued that rejecting developer protections in favor of short-term business interests risks creating a system shaped by political shifts rather than clear law.

“The point of passing CLARITY is not to trust this administration. It is to bind the next one,” he said.

Magazine: Bitcoin may take 7 years to upgrade to post-quantum — BIP-360 co-author

Advertisement