Connect with us

Crypto World

Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks

Published

on

Ripple-backed OUSD launch hit by fake issuer scam on XRP Ledger

Cosmos Labs has disclosed that attackers exploited a critical Cosmos EVM vulnerability across six blockchain networks between Aug. 20 and Aug. 25, converting stolen tokens into about $5.72 million in assets through decentralized and centralized exchanges.

Summary

  • Attackers exploited a critical Cosmos EVM flaw across six networks between Aug. 20 and Aug. 25, converting stolen tokens into about $5.72 million in other assets.
  • Cosmos Labs first received the vulnerability report in April but initially concluded that production networks were not at risk and handled the fix through its silent patch process.
  • MANTRA lost 720.9 million tokens worth about $3.6 million, while TAC and KiiChain later suffered separate attacks using the same method.
  • The first attack began about 20 hours after patched Cosmos EVM versions were released without a vulnerability specific advisory to network operators.
  • Cosmos Labs coordinated with 40 chains during the response and helped 13 networks patch or halt before they could be attacked.

Cosmos Labs said in a technical post-mortem published Friday that the flaw had first been reported through its bug bounty program on April 25, nearly four months before the attacks began. Its testers were unable to reproduce the exploit against configurations used by known production Cosmos EVM networks and concluded at the time that live user funds were not at risk.

Based on that assessment, developers handled the vulnerability through a silent public patch instead of privately distributing a security fix to affected chains. Cosmos Labs merged the fix in May without telling network operators which vulnerability it addressed.

Advertisement

The assessment later proved incorrect after independent researchers established in early August that the bug affected all Cosmos EVM chains. Cosmos Labs then obscured the fix to make reverse engineering more difficult and released patched versions at 7:01 p.m. ET on Aug. 19.

Release notes referred to “important” security fixes without describing the vulnerability. The first known attack began at 3:06 p.m. ET on Aug. 20, about 20 hours after the patched software became available.

Cosmos EVM flaw allowed attackers to drain large accounts

The vulnerability involved an integer underflow in Cosmos EVM, the ecosystem’s Ethereum-compatible framework built from the open-source Evmos codebase.

An attacker could first create an account containing locked tokens and delegate more tokens to a validator than the account was able to spend. Subtracting the delegated amount caused the balance to fall below zero, making the value wrap around to the maximum possible figure of 2^256-1 base units.

Advertisement

The attacker could then use the inflated balance against another account. Sending the amount to a target pushed its recorded balance past the same numerical ceiling, causing an overflow that wrapped the value back down and left the attacker holding the target’s tokens.

No additional tokens were created through the process, according to Cosmos Labs, and total token supply remained effectively unchanged. MANTRA said the exploit changed its supply by only one base unit, the smallest divisible denomination of the token.

Cosmos Labs said attackers targeted accounts holding large balances, including burn addresses and multisignature wallets created when networks launched. Its advisory classified the flaw as critical and identified Cosmos EVM releases before v0.6.2 and v0.7.2 as vulnerable.

Advertisement

The incident followed another security disclosure involving Cosmos software earlier this year. Crypto.news previously reported that a researcher had disclosed a CometBFT flaw in April that could cause nodes to stall during block synchronization. The CVSS 7.1 issue did not allow direct asset theft.

Networks had about 20 hours after the patch

Once independent researchers confirmed the Cosmos EVM flaw could affect production chains, Cosmos Labs prepared the security releases that went live on Aug. 19.

Network operators were not given a vulnerability-specific warning explaining what the upgrade fixed. MANTRA later said 20 hours was not enough to assess, build, test and coordinate a state-breaking upgrade across its 38 independent validators.

“Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, particularly without a vulnerability-specific advisory,” MANTRA wrote in its post-mortem.

Another disclosure occurred before the first theft. At 3:16 a.m. ET on Aug. 20, a Push Chain developer publicly submitted a code change describing the vulnerability and its exploitation path. The filing credited the finding to an audit by security firm Hacken and listed versions considered vulnerable.

Advertisement

The submission said no released version contained the fix, though its version table omitted v0.6.2 and v0.7.2, which Cosmos Labs had published roughly eight hours earlier.

Cosmos Labs described publication of an exact exploitation path by a downstream developer as “highly unusual” and said such disclosures can raise the risk that a vulnerability will be exploited.

MANTRA placed the public security finding 11 hours and 45 minutes before the attacker’s first probe. However, the attacker’s wallet had been funded almost four hours before the finding was filed.

“We state the timing as fact and draw no conclusion from it,” MANTRA said.

A withdrawal of 472.70 MANTRA from a customer account at a centralized exchange funded the gas fees used throughout the attack, according to the network.

Advertisement

MANTRA lost $3.6 million before halting its chain

MANTRA suffered the largest publicly disclosed loss from the attacks, with 720.9 million MANTRA tokens then valued at about $3.6 million taken from two addresses.

One was the network’s burn address. The second was a dormant multisignature wallet left from an earlier incentive campaign.

No automated warning was generated when tokens first moved from the burn address because MANTRA’s monitoring systems treated the address as immovable and did not watch it for outgoing transactions.

The attack remained undetected for almost four hours, giving the attacker time to drain the dormant multisig wallet.

Advertisement

MANTRA halted the network at 7:13 p.m. ET on Aug. 20. About 38 million stolen MANTRA remained frozen in the attacker’s wallet, but 94.7% of the stolen tokens had already been transferred to one centralized exchange deposit address through 15 transactions.

The chain remained unable to process transactions for roughly 30 hours. Crypto.news reported during the interruption that MANTRA halted transactions while engineering and security teams investigated the incident and exchanges suspended deposits and withdrawals.

Validators later deployed patched software and resumed block production without rolling back the chain or altering user balances. Version 8.4.0 included the Cosmos EVM security fix.

MANTRA had added native EVM support to its mainnet in September 2025 alongside CosmWasm compatibility, allowing Solidity applications and Cosmos-native smart contracts to operate on the network.

Advertisement

No stolen MANTRA tokens had been recovered as of Aug. 28, according to the project.

Its circulating supply increased by about 720.9 million tokens because assets held in accounts previously classified as unspendable, including the burn address, became tradable after being moved by the attacker.

TAC and KiiChain were hit after MANTRA

The same method was used against TAC on Aug. 22, according to Cosmos Labs. Nearly 3 billion TAC were taken from the network’s staking pool.

TAC is designed to bring decentralized finance applications to TON and Telegram users. Around 1.2 billion of the stolen tokens were sold on BNB Chain for roughly $950,000.

Advertisement

KiiChain was attacked that evening, losing approximately 148 million KII. About 64.6 million tokens were sold for roughly $1.6 million.

Cosmos Labs estimated that around 54% of the stolen KII remains recoverable onchain if the network is restored.

In its Aug. 23 technical post-mortem, KiiChain criticized how the vulnerability had been communicated to downstream networks. The project said Cosmos Labs did not provide advance notice, identify the release as security critical or initially tell affected chains to halt.

“A patch takes days to review, build, test and roll out across a validator set. A halt takes minutes,” KiiChain wrote. “The only measure that would have contained the risk immediately was a clear instruction to stop producing blocks, and that instruction came after the damage was done.”

Cosmos Labs recommended that vulnerable networks halt on Aug. 22, after MANTRA, TAC and KiiChain had already been hit.

Advertisement

KiiChain disputed part of the technical assessment as well, saying three upstream defects were needed to carry out the exploit and that only the underflow had been publicly patched.

MANTRA reached a different conclusion after testing the fix against a working reproduction of the exploit. Its post-mortem described the underflow repair as “the control that closes this attack path.”

Cosmos Labs described two chained vulnerabilities but did not address KiiChain’s claim that another upstream defect remains unresolved.

Three other Cosmos EVM networks were attacked

Three further chains were exploited with the same method, though Cosmos Labs did not identify them in its report.

Advertisement

Nesa may have been one of the affected networks. Bitvavo suspended NES deposits and withdrawals on Aug. 24, citing a critical consensus vulnerability that had been exploited to make vulnerable nodes accept invalid blocks.

Blockchain analytics firm Bubblemaps identified Nesa as one of the affected chains in an Aug. 26 analysis. The firm said an attacker bought about $250,000 worth of NES, bridged it to Nesa, used the flaw to increase the balance about 200-fold and transferred roughly $50 million in NES back to Ethereum.

Most attempted swaps suffered extreme slippage as liquidity was removed from trading pools, leaving the attacker with about $60,000 in profit, according to Bubblemaps.

The wallet had originally been funded through Monero. Bubblemaps said differences in the funding method and the attacker’s behavior meant a separate party may have been responsible for the Nesa exploit.

Advertisement

The remaining two affected chains have not been publicly identified.

Cosmos Labs said it coordinated with 40 networks during its response and worked with 13 others to patch the vulnerability or halt before they were attacked.

The firm said it does not maintain a complete registry of the more than 115 public blockchains operating across the Cosmos ecosystem. Its response uncovered 11 Cosmos EVM deployments that had not previously been registered with the team.

MANTRA, meanwhile, is being acquired by existing backer Inveniam Capital Partners, which had made a $20 million strategic investment in the project in August 2025. The transaction is expected to close in the third quarter of 2026, with MANTRA Chain, its token and related infrastructure set to continue operating under Inveniam’s ownership.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Berlin probes cyberattack as hackers demand 30 Bitcoin for stolen data

Published

on

Berlin probes cyberattack as hackers demand 30 Bitcoin for stolen data

Berlin authorities have refused to meet an alleged 30 Bitcoin ransom demand after a cyberattack hit two state agencies, while officials have yet to confirm the amount of data claimed to have been stolen.

Summary

  • Hackers reportedly demanded 30 Bitcoin, worth roughly €2 million, after a cyberattack affected two Berlin state agencies.
  • The attackers threatened to publish stolen information, while Berlin officials have refused to pay and have not confirmed the reported ransom amount.
  • Berlin initially said only public information was compromised but later acknowledged that non-public data had been affected.
  • Rhysida reportedly claimed responsibility for the attack and said it obtained sensitive files, though Berlin authorities have not verified the full extent of the alleged theft.

The Berlin Senate Chancellery said it would not disclose details about the attackers, their demands or the information potentially taken from government systems while the investigation remains active. A Senate spokesperson told German news agency dpa that officials could not comment “for investigative reasons” at this stage.

The position leaves several details of the attack unconfirmed by the state government, including reports that the ransomware group Rhysida obtained sensitive files and threatened to publish them unless Berlin paid roughly 2 million euros in Bitcoin.

Advertisement

Berlin has refused the reported 30 Bitcoin demand

Berlin Mayor Kai Wegner confirmed after a special Senate meeting on Friday that the state was facing an extortion attempt following the cyberattack.

“The state of Berlin will not allow itself to be blackmailed,” Wegner said.

He did not publicly identify the attackers or disclose the amount demanded. Interior Senator Iris Spranger joined Wegner in briefing the public following the meeting, while authorities continued examining what information had left government systems.

German magazine Der Spiegel reported that Rhysida was behind the attack, citing information posted by the ransomware group on its dark web leak site. Security sources cited by the publication reportedly identified Rhysida as the group responsible for the extortion attempt.

The attackers demanded 30 BTC and threatened to release the information if Berlin did not pay, according to the report. At current prices, the demand was worth roughly 2 million euros.

Advertisement

Rhysida reportedly claimed to have taken almost six terabytes of data. The alleged files include information from tens of thousands of administrative offense proceedings, contracts, passwords, login credentials, emergency plans and documents related to critical infrastructure.

Berlin authorities have not independently confirmed the amount of data claimed by the group or the full list of compromised records.

The distinction has become important to the official account of the incident because the government’s assessment changed after the attack was discovered. Officials initially said only publicly accessible information had been taken before the Senate Chancellery acknowledged last Wednesday that non-public data was affected.

Cyberattack forced two Berlin agencies off the state network

The attack became public on Aug. 14 and affected Berlin’s Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Climate Protection and the Environment.

Advertisement

Both agencies were temporarily disconnected from Berlin’s state network as officials worked to contain the incident.

The separation lasted for about a week and disrupted some administrative services. German reports said residents were temporarily unable to apply for or receive housing benefits while the affected systems remained isolated.

Investigators are still determining when the intrusion began and how much information left the network. Reports citing the investigation said data may have been extracted between Aug. 7 and Aug. 12, several days before officials detected the attack.

Advertisement

The Berlin State Criminal Police Office and prosecutors are investigating the breach. Wegner said state and federal security authorities were working to identify the perpetrators while officials continued checking which files had been accessed or removed.

Spranger said the attack had not compromised preparations for Berlin’s Sept. 20 state election, describing the election infrastructure as fully secured.

The ransomware case follows another government cyberattack involving a Bitcoin demand reported by crypto.news in July. Hackers took control of Kenyan President William Ruto’s official website and demanded 5 BTC while threatening to disclose unspecified information.

Kenyan authorities temporarily restricted access to the website and opened an investigation. The country’s ICT Authority said at the time that investigators had found no evidence that sensitive information had been accessed, stolen or lost.

Advertisement

Rhysida has operated as a ransomware group since 2023

Rhysida emerged in 2023 and has been linked to attacks against government bodies, healthcare organizations and other institutions in several countries.

The group has previously targeted organizations including the British Library and the Chilean Army. Its operations generally combine network intrusion with demands for payment, while the threat of publishing stolen information can be used to pressure victims.

Bitcoin and other cryptocurrencies have repeatedly featured in ransomware cases because attackers can direct payments to blockchain addresses without using conventional bank accounts.

Public blockchain transactions can still be followed. A crypto.news report on blockchain forensics detailed how investigators can trace cryptocurrency movements between addresses and use transaction patterns and other information to connect funds with services or individuals.

Advertisement

Law enforcement agencies have recovered cryptocurrency from ransomware operations in previous cases. In August 2025, U.S. authorities seized $1.09 million in cryptocurrency linked to the BlackSuit ransomware group alongside four servers and nine domains.

BlackSuit had been linked to more than 450 known U.S. victims and over $370 million in ransom demands since 2022. One victim paid 49.3 BTC in 2023 after an attack, with investigators later recovering part of the payment, according to the Justice Department.

A separate U.S. case in July involved a suspected member of the Scattered Spider hacking group. Federal prosecutors charged 19-year-old Peter Stokes over an alleged corporate intrusion and an unsuccessful $8 million cryptocurrency ransom demand.

The Justice Department said Scattered Spider-linked intrusions had resulted in more than $100 million in ransom payments, with attackers using techniques including phishing and impersonating employees when contacting corporate help desks.

Advertisement

Berlin has not confirmed Rhysida’s data claims

Berlin’s investigation remains focused on establishing the extent of the breach while the government withholds details that officials say could affect the inquiry.

Rhysida’s claims about the stolen material originate from the group’s dark web communications and have not been fully verified by the Berlin government. Officials have confirmed that non-public information was affected, reversing the initial assessment that the compromised material was limited to publicly accessible data.

The Senate Chancellery has not disclosed whether investigators have verified the reported 30 BTC demand, the nearly six terabytes allegedly taken or the individual categories of information Rhysida claims to possess.

Wegner said authorities at the state and federal levels were working to identify the group responsible, while the Berlin State Criminal Police Office and prosecutors continued their investigation into the attack.

Advertisement

Source link

Continue Reading

Crypto World

Blockaid Reports $9.3M Lending Reserve Depleted Across More Markets

Published

on

Crypto Breaking News

DeFi lending infrastructure has suffered another high-value breach on Flow EVM, with Blockaid reporting that the protocol More Markets lost roughly $9.3 million in assets from a lending reserve. The incident, described in a Monday post by Blockaid on X, centers on an overborrow strategy using a liquid staking token.

Blockaid said the attacker drained about 15.5 million Wrapped Flow (WFLOW) tokens—valued at approximately $9.3 million—from the mFlowWFLOW lending reserve. The exploit reportedly involved Ankr Staked FLOW (ankrFLOW), together with Aave V3’s “efficiency mode” (E-mode), to expand borrowing capacity beyond what the reserve should allow.

Key takeaways

  • Blockaid attributes the More Markets Flow EVM reserve drain to an overborrowing approach using Ankr Staked FLOW (ankrFLOW) and Aave V3 E-mode.
  • About 15.5 million Wrapped Flow (WFLOW), worth around $9.3 million, were taken from the mFlowWFLOW lending reserve.
  • The month-to-date total losses from crypto hacks reached $139.7 million in August, placing the month as the third-largest by stolen value so far in 2026.
  • The August figure is sharply lower than July’s $254 million in stolen funds, suggesting either fewer major breaches or reduced impact from exploits.
  • Cronos paused its network on Sunday following a separate reported $75 million exploit tied to the Tectonic DeFi lending protocol.

How the More Markets reserve was drained

According to Blockaid’s account of the event, the attacker targeted More Markets’ lending reserve that holds mFlowWFLOW. Blockaid said the stolen amount consisted of 15.5 million Wrapped Flow (WFLOW) tokens, which it valued at approximately $9.3 million based on blockchain data it shared publicly.

Blockaid further claimed that the exploit depended on two linked mechanisms: the use of Ankr Staked FLOW (ankrFLOW) and Aave V3’s E-mode. E-mode is designed to increase borrowing power for specific asset groups when their values are expected to move together—commonly a liquid staking token and its corresponding underlying token.

In practical terms, this means that when the protocol’s configuration treats certain pairs as sufficiently correlated, the borrowing limits can become more permissive. Blockaid’s report indicates the attacker leveraged that increased borrowing power to overextend against the reserve, resulting in the loss of WFLOW tokens from mFlowWFLOW.

Advertisement

E-mode designed for correlation—what this incident suggests

E-mode in Aave V3 is intended to make capital more efficient by rewarding users when asset prices track each other closely. Blockaid’s description of this exploit highlights a recurring risk in DeFi: when an attacker can obtain collateral exposure through a token wrapper or staking derivative, the assumed relationship between the assets may be insufficiently protective during the exploit window.

Blockaid specifically tied the strategy to Ankr Staked FLOW (ankrFLOW) in combination with E-mode for correlated assets. While E-mode is not inherently wrong—its goal is to reflect genuine market linkage—incidents like this underscore that protocols still need robust defenses around liquidation mechanics, borrowing limits, and whether the collateral’s behavior under stress matches the assumptions baked into risk parameters.

For investors and users, the takeaway is not that E-mode should be avoided, but that reliance on correlated asset groups can raise the stakes for monitoring. Protocol teams typically need to ensure that their accounting, oracle choices, and validation logic remain resilient when liquidity conditions change quickly.

Broader hack landscape: August losses mount

Blockaid’s reported loss adds to a fast-moving set of crypto-security events. DefiLlama’s data on hacks shows that total cryptocurrency losses from hacks reached $139.7 million in August, making it the third-largest month by value stolen so far in 2026.

Advertisement

The same DefiLlama dataset cited in the reporting indicates a meaningful change from earlier in the year: July saw approximately $254 million stolen. While August has a lower total than July, the ongoing frequency of incidents—spanning multiple ecosystems and chains—suggests that attackers remain active and that DeFi lending remains a frequent target.

Another DeFi lending event: Cronos halts after Tectonic exploit

Alongside the More Markets issue, the market also digested another major DeFi lending-related disruption. On Sunday, Cronos halted its blockchain network following a reported $75 million exploit targeting the DeFi lending protocol Tectonic.

That earlier incident, reported by Cointelegraph, involved a sizable compromise that prompted an emergency network pause by Cronos. Together, the two stories emphasize how quickly lending platforms can become central points of failure—especially when borrowing configurations intersect with token derivatives and liquidity-linked assumptions.

At the time of publication, More Markets had not publicly confirmed the incident or disclosed whether users suffered losses. Cointelegraph said it contacted Blockaid for more details but did not receive a response by publication, and it was unable to reach More Markets for comment.

Advertisement

Readers should watch for follow-up disclosures from More Markets regarding the affected reserve, whether funds were fully recovered, and any post-incident changes to collateral or E-mode configuration. For the wider DeFi community, the key uncertainty is how closely future risk models will account for real-world token behavior during fast-moving market or liquidity conditions.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Crypto World

Zcash private transactions could fall below 200ms

Published

on

Shielded Labs warns Ironwood delay could disrupt Zcash upgrade

Zakura released an open-source cryptography toolkit on Aug. 29 that it says can reduce the time required to construct some private Zcash transactions from more than three seconds to below 200 milliseconds.

Summary

  • Zakura Common cuts transaction construction from over three seconds to under 200 milliseconds, developers claim.
  • Mobile proof generation improved more than fourteenfold, while desktop benchmarks showed gains exceeding fivefold overall.
  • Sinsemilla hashing accelerated more than twenty-onefold, while proof verification improved between fourfold and eightfold overall.
  • Wallet developers can adopt the open-source libraries without requiring a coordinated Zcash network upgrade first.
  • Zakura version 1.3.0 uses the stack, while Vizor Wallet is among its earliest confirmed adopters.

The toolkit, called Zakura Common, replaces several cryptographic components used by wallets and full nodes. The developers said the changes improve proof generation, transaction verification, wallet scanning and hashing without altering Zcash’s consensus rules.

Zakura released the software under dual MIT and Apache 2.0 licenses. Wallet and node developers can therefore integrate the libraries without waiting for a hard fork or synchronized network upgrade.

Advertisement

Zcash wallets generate privacy proofs faster

Zcash shielded transactions conceal the sender, recipient and transferred amount. A wallet must create a zero-knowledge proof showing that the hidden transaction follows the network’s rules before broadcasting it.

That computation happens on the user’s device. Slow proof generation can therefore delay a payment before validators or nodes begin processing it.

Zakura’s benchmarks showed mobile proof generation running more than 14 times faster under the new stack. Desktop performance improved by more than five times.

Advertisement

The developers said those gains could bring transaction construction below 200 milliseconds “in many cases.” The figure is a benchmark result rather than a guaranteed time for every device, wallet or transaction.

Hardware, operating systems, transaction complexity and wallet implementations may produce different results.

Zakura Common improves more than proof generation

The toolkit also made Sinsemilla hashing more than 21 times faster, according to Zakura. Zcash uses Sinsemilla within its Orchard shielded protocol for cryptographic commitments and related operations.

Trial decryption improved by more than 1.5 times. Wallets use that process while scanning blockchain data to identify shielded transactions belonging to their users.

Advertisement

Zakura also reported fourfold to eightfold gains in zk-SNARK verification. Faster verification could help full nodes validate transactions sooner and reduce the risk of block-processing delays.

“Shielded wallets that use Zakura Common, and full nodes like Zakura itself, all benefit,” Zcash co-founder Sean Bowe said.

The release does not shorten Zcash block production or settlement on its own. It primarily targets the cryptographic work performed before broadcasting and while checking transactions.

Wallet developers can adopt the toolkit immediately

Zakura version 1.3.0 has moved to the new cryptography stack. Vizor Wallet is among the first wallet projects adopting the libraries, according to the development team.

Advertisement

Other wallets must integrate and test Zakura Common before their users receive the same performance gains. Adoption will therefore depend on individual development schedules rather than a single network activation date.

The update arrives as Zcash wallet development becomes more distributed. In January, former Electric Coin Company developers formed CashZ to continue work based on the Zashi wallet code.

Wallet integrations have also expanded access to shielded transfers. A previous ShapeShift wallet integration added Zcash privacy support across its non-custodial platform.

ZEC briefly rose before the broader pullback

ZEC initially rose about 5% following the Zakura Common announcement and traded near $839. The timing indicates a market reaction but does not prove the software release caused the entire move.

Advertisement

CoinGecko subsequently placed ZEC near $829 on Aug. 31, down about 0.8% over 24 hours. The token traded between approximately $808 and $888 during that period.

The next evidence will come from real wallet deployments. Developers will need to confirm whether the benchmark gains persist across consumer devices, larger shielded transactions and different operating environments.

Zakura is also preparing for the proposed NU7 upgrade, which could reduce Zcash block times to about 25 seconds. The team says its current software can already operate under that target, although NU7 requires a separate network governance and activation process.

Advertisement

Source link

Continue Reading

Crypto World

Live updates: Bitcoin holds $78,000 as yen breaks 160 and rate-hike bets lift the dollar

Published

on

Live updates: Bitcoin holds $78,000 as yen breaks 160 and rate-hike bets lift the dollar


Bitcoin is holding just under $78,000 as August closes. The dollar strength that pushed the yen past its intervention line is the same force capping crypto.

Source link

Continue Reading

Crypto World

More Markets Lending Reserve Drained for $9.3M: Blockaid

Published

on

More Markets Lending Reserve Drained for $9.3M: Blockaid

Decentralized finance (DeFi) vault infrastructure protocol More Markets had a lending reserve drained of about $9.3 million in digital assets on Flow EVM, according to Web3 security platform Blockaid.

The attacker drained about 15.5 million Wrapped Flow (WFLOW) tokens, valued by Blockaid at approximately $9.3 million, from the mFlowWFLOW lending reserve, according to blockchain data shared by Blockaid in a Monday X post.

Blockaid said the attacker used Ankr Staked FLOW (ankrFLOW), a liquid staking token, alongside E-mode to overborrow from the reserve.

E-mode, short for efficiency mode, is an Aave V3 feature that increases borrowing power for assets whose prices are expected to move together, such as a liquid staking token and its underlying asset.

Advertisement

The exploit pushed total losses from cryptocurrency hacks to $139.7 million for August, making it the third-largest month by value stolen so far in 2026. However, it marks a significant decrease from $254 million stolen during July, according to DefiLlama data.

On Sunday, Cronos halted its blockchain network after a reported $75 million exploit targeting DeFi lending protocol Tectonic.

More Markets had not publicly confirmed the incident or disclosed whether users suffered losses at the time of publication. Cointelegraph contacted Blockaid for more details but did not receive a response by publication and was unable to reach More Markets for comment.

Related: Humanity Protocol to prioritize operational security following $36M hack

Advertisement
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Source link

Continue Reading

Crypto World

U.S. jobs report, Russia’s digital ruble rollout: Crypto Week Ahead

Published

on

Bank of Russia speeds up digital asset rules following fresh western sanctions


Your look at what’s coming in the week starting Aug. 31.

Source link

Continue Reading

Crypto World

Ripple mints 11M RLUSD as supply tops $2.3B

Published

on

Ripple wins EU-wide access as ESMA adds it to MiCA register

Ripple recorded another round of RLUSD treasury activity on Aug. 31, including an 11 million-token mint and a separate 11 million-token burn.

Summary

  • 11 million RLUSD was minted and 11 million burned at treasury addresses on August 31.
  • CoinGecko placed RLUSD’s circulating supply and market capitalization near $2.37 billion on August 31.
  • Ripple reported $1.87 billion circulating against $1.98 billion in reserves as of August 20.
  • Treasury mints create tokens but do not independently confirm circulation, customer demand or completed issuance.
  • Ethereum and XRP Ledger remain RLUSD’s main networks, although Ripple supports several additional blockchain deployments.

The transactions were reported by the Ripple Stablecoin Tracker. They followed several large operations on the XRP Ledger and Ethereum during the final days of August.

CoinGecko placed RLUSD’s circulating supply and market capitalization at approximately $2.37 billion on Aug. 31. The stablecoin continued trading close to its intended $1 peg, meaning supply growth rather than price appreciation drove the higher valuation.

Advertisement

RLUSD minting does not necessarily show net demand

A stablecoin mint creates tokens at an issuer-controlled address. Those tokens may remain in treasury, move to an institutional customer or support transfers between networks.

A mint therefore does not prove that an equivalent amount entered public circulation. Likewise, a burn removes tokens from supply and can accompany customer redemptions, treasury management or network rebalancing.

The matching 11 million-token mint and burn on Aug. 31 illustrate that distinction. Viewed separately, the mint suggests expansion. Considered together, the two transactions produced no net increase from those specific operations.

Advertisement

Ripple did not identify the customer, purpose or economic relationship behind either transaction. The ledger records establish that the transactions occurred, but they do not establish new institutional demand.

As crypto.news previously reported, Ripple minted another 10 million RLUSD on XRPL on Aug. 17. Ripple also did not disclose the receiving customer or intended use of that issuance.

RLUSD supply moved above $2 billion in August

RLUSD crossed $2 billion in market capitalization during August, less than two years after its December 2024 launch. Ripple confirmed the milestone on Aug. 25 and said close to $1 billion had been issued on the XRP Ledger.

In related coverage, RLUSD approached an even split between XRPL and Ethereum when it crossed the threshold. Ethereum held a modestly larger amount at that time.

Advertisement

Available data now show continued supply expansion. CoinGecko reported approximately 2.37 billion circulating tokens on Aug. 31. XRP Ledger trackers placed the network’s portion above 1 billion tokens after several late-August mints.

Ethereum remains another major venue for RLUSD. Ripple has also extended the stablecoin to Base, Ink, Optimism, Unichain and the XRPL EVM sidechain. Public dashboards do not always provide synchronized supply totals for every network, which can produce differences between data providers.

Ripple’s reserve report trails the latest mints

Ripple’s transparency page reported $1.866 billion in circulating RLUSD and $1.981 billion in reserve funds as of Aug. 20. That official snapshot predates the latest issuance and the $2 billion milestone.

Standard Custody & Trust Company, a Ripple subsidiary supervised by the New York State Department of Financial Services, issues RLUSD. Ripple says reserves consist of cash and permitted cash equivalents held in segregated accounts.

Advertisement

Deloitte prepares monthly attestations covering the reported circulation and reserve balances. However, those reports are retrospective. They do not provide real-time confirmation of reserve changes after every mint or burn.

The next attestation should offer a clearer view of whether reserve assets increased alongside the late-August supply expansion.

What happens next for RLUSD

Further treasury transactions will show whether the latest mints move into circulation or are offset by additional burns. Transfers from treasury accounts to exchanges, custodians or institutional counterparties could provide more context, although wallet movements alone may not reveal their purpose.

The next reserve report will be the more important disclosure. It should show whether Ripple maintained reserve assets above circulating liabilities as RLUSD moved beyond $2 billion.

Advertisement

No verified XRP price movement could be directly attributed to the RLUSD transactions. RLUSD growth may add dollar liquidity to the XRP Ledger, but it does not automatically create equivalent demand for XRP.

Source link

Advertisement
Continue Reading

Crypto World

Navigating the Noise: HTX Turns 13 with Resilience in Action

Published

on

Navigating the Noise: HTX Turns 13 with Resilience in Action

Amid recent discussions in the crypto space, HTX has drawn significant attention.

Like many other exchanges, regulatory scrutiny has become subjects of discussion on this exchange.

However, activity on the HTX platform presents a contrasting picture.

The HTX 13th Anniversary Carnival is now well into its second half, with more than 120,000 rewards already distributed.

Advertisement

Every day, users set their alarms for 13:13 (UTC+8) to make sure they don’t miss the anniversary red packets. Some are lighting up 9, 11, or 13 Future Gems to unlock rewards, while others have already received their $HTX rewards and shared their wins on social media.

The market has also begun to warm up. Amid price movements in major assets such as BTC, trading activity across both spot and futures markets on the platform has surged.

Furthermore, the 13th Anniversary celebration extends far beyond a single Carnival Month.

Futures traders can participate in the HTX Trading Championship, spot traders can join the Spot Trading Carnival, and users seeking yield opportunities can take part in the HTX Earn Bonanza. In addition, a series of campaigns focused on $HTX, referrals, P2P, and margin trading are being launched in rapid succession.

For users, one way to assess whether an anniversary event is truly engaging is to look beyond its headline prize pool.

Prize pool figures may attract attention, but actual reward distribution is a much more direct measure of the true user experience.

Advertisement

To date, more than 120,000 rewards have been distributed to users.

The anniversary celebration has only just passed its midpoint.

01 | How Are 120,000 Rewards Being Distributed?

For its 13th anniversary, HTX designed a distinctly crypto-native interactive framework.

Thirteen Future Gems correspond to 13 specific tasks.

Advertisement

Rather than forcing users to complete every challenge at once, they can progress step by step, starting with the simplest tasks.

Posting a 13th Anniversary wish, completing a Learn & Earn quiz, and purchasing 50 USDT worth of $HTX are among the early-stage milestones. As users progress, the tasks gradually extend into core areas such as spot and futures trading, Earn, fiat deposits, margin trading, and TradFi.

The second half of the progression introduces higher-tier incentives.

At 9 Gems, you can start drawing rewards and receive up to 130 USDT worth of $HTX. At 11 Gems, you can claim an anniversary red packet every day at 13:13 (UTC+8). Light up all 13 Gems for a chance to win up to 1,300 USDT worth of $HTX and unlock the grand prize.

Advertisement

02 | A Particular 13th Anniversary Period

HTX’s 13th anniversary coincides with a notable period of market and operational backdrop.

There’s a lot of noise in the industry.

Like many other exchanges, HTX is subject to public discussion and scrutiny regarding issues such as regulation and compliance. However, beyond social media commentary, underlying operational metrics provide a far clearer view of the platform’s performance.

According to recent operational statistics disclosed by HTX, the daily average number of deposit and withdrawal orders has remained at tens of thousands since August 23. HTX stated that core services, including spot, futures, deposits, and withdrawals, continue to operate normally.

Advertisement

In addressing market questions, HTX has maintained open communication regarding its operations and platform stability while encouraging continued public observation. Thus far, these external developments have not interrupted the platform’s operations. User trading activity, capital flows, and anniversary events have continued during this period. These operational indicators provide a more concrete basis for assessing the platform.

03|For an Exchange, Money Is More Honest Than a Tweet

A week ago, Justin Sun, Advisor to HTX, responded to external inquiries with a concise statement:

“Everything is fine.”

This is very much in line with his style of expression.

Advertisement

However, whether an exchange holding user assets is genuinely operating normally cannot be determined by a single tweet alone.

Money is more honest than a tweet. Operational data provides a more substantive basis for assessment than statements alone.

Key operational metrics provide a more substantive view: whether deposits and withdrawals proceed smoothly; whether trading activity and liquidity remain stable; and whether platform infrastructure can support increased trading volume when market opportunities emerge. These are the core indicators of an exchange’s operational resilience.

Against this backdrop, the theme of HTX’s 13th anniversary—”Resilience Reveals the Future”—takes on greater significance.

Advertisement

Without recent events, “resilience” might have been nothing more than an anniversary tagline.

Industry narratives frequently reference 13 years of experience, multiple bull and bear cycles, the ability to weather market cycles, and a long-term approach.

Yet operational resilience for an exchange relies on clear fundamentals.

Operational resilience means keeping systems stable during periods of high market volatility, maintaining seamless deposit and withdrawal processing amid external turbulence, addressing issues promptly as they arise, and maintaining system capacity as market volumes recover.

Advertisement

True resilience is not the absence of problems, but the ability to maintain momentum when problems arise.

Routine deposit and withdrawal processing, together with the distribution of 120,000 rewards, does not imply the absence of operational risk, nor does it replace long-term regulatory resolution.

HTX still needs to address the relevant issues and consistently provide verifiable data to users and market participants.

Resilience can help a company navigate periods of uncertainty, but it should not substitute for addressing underlying issues.

Advertisement

At least for now, these external developments have not interrupted the platform’s operations.

The post Navigating the Noise: HTX Turns 13 with Resilience in Action appeared first on BeInCrypto.

Source link

Advertisement
Continue Reading

Crypto World

Ripple’s (XRP) Sharpe Ratio Just Did Something It Hasn’t Done In a Year

Published

on

XRP has seen a notable improvement in its risk-adjusted returns. The Ripple token’s Sharpe Ratio on Binance has now reached its highest level since August 2025.

The indicator is currently stabilizing at around 0.207, according to CryptoQuant, while the price hovers close to $1.40.

Risk-Reward Profile

Over the past few months, XRP’s Sharpe Ratio stayed around negative or neutral levels and fell significantly during the crypto asset’s broader price decline. The recent increase suggests that returns have improved relative to the amount of volatility investors are facing.

The sharp rise in the Sharpe Ratio also occurred alongside the recovery in XRP’s price, which is up by almost 30% over the past month. This indicates that the recent move was accompanied by stronger risk-adjusted performance rather than being only an isolated price increase, CryptoQuant explained.

Advertisement

However, the indicator’s move to its highest level in a year does not confirm that XRP has entered a steady uptrend. The Sharpe Ratio could reverse quickly if market volatility rises or the token undergoes a significant correction.

Zooming out, institutional demand for XRP-linked investment products was also hard to miss. Last week, US-based spot ETFs pulled in $110.49 million in five days.

CryptoPotato reported that it was the first weekly inflow above $110 million since early December 2025. All five sessions ended in positive territory, and each attracted more than $10 million. Monday saw $13.82 million come in, followed by $23.87 million on Tuesday. Wednesday led the week with $28.14 million, the funds’ strongest single-day showing since January 5.

Another $18.47 million arrived on Thursday, while Friday brought $26.2 million. The latest figures pushed total net inflows across the five ETFs to a record $1.66 billion. Bitwise remains ahead of the other issuers; its ETF now holds slightly more than $600 million in cumulative inflows.

Advertisement

What’s Next?

Regardless of how promising XRP’s setup may appear, a move toward $1.80 or $2 could remain out of reach until the token reclaims $1.54, according to crypto analyst ChartNerd. That level represents both a six-month resistance wall and the weekly 50 EMA. He further explained,

“Just to be clear, and to reaffirm. I am not suggesting XRP can’t push up towards $1.80/$2. I am suggesting we are under resistance, and if we do get the follow through, it will likely open up an even deeper retrace than what we would witness rejecting the weekly 50 EMA at $1.54.”

The post Ripple’s (XRP) Sharpe Ratio Just Did Something It Hasn’t Done In a Year appeared first on CryptoPotato.

Source link

Advertisement
Continue Reading

Crypto World

Alphabet: Five Months of Consolidation Reach Their Breaking Point

Published

on

Alphabet: Five Months of Consolidation Reach Their Breaking Point

Alphabet just had a genuinely turbulent month, and the whiplash tells its own story. Despite beating earnings expectations with profits of $9.11 per share, roughly triple what analysts had forecast, the stock actually sold off in the days following the report, weighed down by mounting concerns over AI spending. That mood shifted decisively on Monday, when shares jumped over 5% after Morgan Stanley reassured investors, highlighting Alphabet’s still-robust $53.3 billion in free cash flow over the past twelve months, even as cloud capital expenditure could exceed $1.2 trillion in 2027.

The underlying business remains genuinely strong: Google Cloud revenue surged 82% year-over-year to $24.8 billion in Q2, and the company has been actively defending its position, launching more budget-friendly AI pricing to compete directly with rivals. That said, not everything has gone smoothly. Alphabet agreed to pay £260 million to settle a UK class-action lawsuit this week, and a leadership shakeup within its AI division, including the departure of key figures, has added a layer of organizational uncertainty investors are still digesting.

The result: a company delivering genuinely impressive growth, but one whose massive AI bet keeps testing investors’ patience with every headline.

Technical Analysis of Alphabet (GOOGL)

As the GOOGL chart shows, the stock has been compressing into a symmetrical triangle since April, with a descending trendline from the 400 highs converging with an ascending trendline off the 269 low, both meeting right at the current price near 340–346, exactly where the 0.5 Fibonacci retracement and the 200-period EMA also sit.

Bullish Scenario

Should buyers defend this trendline-EMA confluence and break decisively above the descending trendline, the path would open toward the 0.382 retracement near 356.79, with a stronger move potentially targeting the 0 level at 382.88, the origin of the entire pullback.

Advertisement

Bearish Scenario

Conversely, a break below the ascending trendline and the 0.618 retracement near 340.66 would expose the 0.786 level near 329.19, with a deeper slide risking a retest of the 314.57 low that anchored this five-month structure.

With price coiled right at the apex of this triangle, sitting exactly on the 200-period EMA, Alphabet’s next move looks set to be decisive. Will the AI spending story finally translate into a genuine breakout, or does the stock settle back into its earlier range?

Buy and sell stocks of the world’s biggest publicly-listed companies with CFDs on FXOpen’s trading platform. Open your FXOpen account now or learn more about trading share CFDs with FXOpen.

This article represents the opinion of the Companies operating under the FXOpen brand only. It is not to be construed as an offer, solicitation, or recommendation with respect to products and services provided by the Companies operating under the FXOpen brand, nor is it to be considered financial advice.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025