Crypto wrench attacks reach 52 as financial exposure hits $124M: CertiK
The attack did not appear to stem from a direct breach of Ostium’s smart contract code. Instead, the validated source material points to manipulation of price feed reports through a compromised oracle private key. That distinction matters because it shows the risk was not only in on-chain contracts, but in the off-chain infrastructure feeding data into the system.
Perpetuals exchanges depend on accurate prices. If the price feed can be manipulated, the entire trading venue becomes exposed.
Ostium’s response was to halt trading while investigating the incident.
Perpetuals markets need reliable prices.
A trader’s collateral, liquidation level, profit and loss, funding exposure, and settlement value all depend on price data. If that data is wrong, the market can be exploited even if the core trading contracts behave exactly as designed.
That is why oracle infrastructure is one of DeFi’s most sensitive layers.
It sits between real-world or market data and on-chain execution. A protocol may have audited contracts, but if the data feeding those contracts can be manipulated, the system is still vulnerable.
In Ostium’s case, the issue appears to involve a compromised off-chain oracle key. That means the attacker was able to interfere with the trusted reporting path rather than simply finding a normal contract bug.
That kind of failure can be harder for users to understand because the problem is not always visible in the same way as a contract exploit.
The blockchain may record the transactions, but the weak point may be the infrastructure behind the data.
The distinction between smart contract risk and oracle risk matters.
Crypto users often ask whether a protocol’s contracts are audited. That is important, but not sufficient. A trading protocol also depends on pricing systems, administrative keys, keeper networks, bridges, liquidation bots, front ends, and operational security.
Any one of those layers can become a weak point.
If an oracle private key is compromised, attackers may not need to break the smart contract. They can feed the contract bad information and profit from how the system reacts.
That is why DeFi security has to be broader than code review.
Protocols need key management, monitoring, alert systems, circuit breakers, fallback feeds, and clear emergency procedures. The faster a venue can detect abnormal prices and pause dangerous operations, the more damage it may prevent.
Ostium’s trading halt shows that emergency controls are still essential.
Arbitrum remains one of the most active Ethereum layer-2 ecosystems for DeFi.
That activity brings liquidity, traders, and innovation, but it also attracts attackers. Perpetuals venues are especially attractive because they concentrate collateral and rely on real-time pricing.
An $18.4 million exploit is large enough to matter for the ecosystem, even if it does not threaten Arbitrum itself.
The incident should not be framed as an Arbitrum network failure. The issue is specific to Ostium’s oracle infrastructure. But for users, every exploit adds to the broader question of how safe layer-2 DeFi venues are in practice.
That question matters as more capital moves to faster and cheaper networks.
Layer-2 scaling lowers transaction costs, but it does not remove application-level risk. Users still need to evaluate each protocol’s design, security model, and operational controls.
The immediate priority is investigation, containment, and user communication.
Ostium needs to explain what happened, which systems were affected, whether user balances are recoverable, how trading will restart, and what controls will change before reopening.
For traders, the most important question is whether the oracle system has been rebuilt or secured enough to prevent a repeat.
A trading venue can survive an exploit if the response is transparent and the fix is credible. It becomes much harder if users are left unclear about where the failure occurred or whether the same path remains exposed.
The broader market should also pay attention.
Oracle key risk is not unique to one exchange. Any protocol relying on off-chain signing, price feeds, or privileged reporting paths needs to think carefully about compromise scenarios.
The lesson is straightforward: DeFi systems are only as strong as the weakest trusted component.
Ostium’s contracts may not have been directly breached, but the market still suffered a major exploit. That is why oracle security remains one of the most important issues in on-chain trading.
This article is based on Ostium’s public statement and Arbiscan transaction data.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released in official primary source disclosures at primary source documentation.
If you run a WordPress site and haven’t updated it in the last week, stop reading this and go do that first. Seriously. I’ll wait.
Reference: GitHub
Bitcoin developers have introduced BIP-361, a draft proposal designed to prepare the network for a future migration away from legacy signature schemes that could become vulnerable in a post-quantum environment.
The proposal, titled “Post Quantum Migration and Legacy Signature Sunset,” was authored by Jameson Lopp and others. It lays out a phased approach for moving Bitcoin users away from older cryptographic signature types and toward quantum-resistant alternatives.
This is not a panic signal. Quantum computers are not suddenly breaking Bitcoin tomorrow. But BIP-361 matters because Bitcoin moves slowly by design, and cryptographic migrations can take years to plan, debate, test, and adopt.
If the network ever needs to retire vulnerable signature schemes, the planning has to start long before the emergency arrives.
Bitcoin relies on cryptographic signatures to prove ownership of coins.
Today, that system is secure against known practical attacks. But a sufficiently powerful quantum computer could threaten some widely used public-key cryptography. That is why researchers and developers across the technology sector have been preparing for post-quantum security.
For Bitcoin, the challenge is especially complicated.
A bank can update internal systems. A software company can push patches. Bitcoin is a decentralized network with users, wallets, miners, developers, exchanges, custodians, and old addresses spread across the world.
Changing cryptographic assumptions is not simple.
Coins sit in different address types. Some coins have not moved in years. Some users may no longer have access to their keys. Some wallets may be slow to upgrade. Exchanges and custodians need time to support new formats. Any migration plan has to balance security, usability, and social consensus.
That is why BIP-361 is important even though it is only a draft.
It starts mapping the problem.
BIP-361 focuses on a phased sunset for legacy signatures.
The idea is not to suddenly invalidate large parts of Bitcoin. Instead, the proposal looks at how the network might gradually move away from signature schemes that could become risky in a quantum future.
A phased approach matters because Bitcoin cannot afford chaos around address formats and wallet compatibility. Users need time to migrate. Infrastructure providers need time to support new tools. The ecosystem needs clear milestones.
That kind of transition would be one of the most sensitive upgrades Bitcoin has ever considered.
It would involve not just technical safety, but also fairness. What happens to coins in old address types? How long should users have to move? What about dormant wallets? What about coins believed to be lost? At what point does protecting the network outweigh preserving indefinite spendability from legacy formats?
Those are difficult questions.
BIP-361 does not make them easy, but it gives the community a structured starting point.
Some people will see the proposal and ask why Bitcoin needs to discuss quantum security now.
The answer is that Bitcoin’s upgrade process is slow because it has to be.
A controversial protocol change can take years to reach consensus, and many never do. That can frustrate developers who want faster progress, but it is also part of why Bitcoin has remained stable. The network avoids rushed changes that could damage trust.
Quantum migration would require even more caution.
It touches the deepest layer of Bitcoin ownership: signatures. A mistake could be catastrophic. A rushed proposal could divide the community. A poorly communicated migration could leave users confused or exposed.
That is why early discussion is healthy.
The proposal does not mean activation is near. It does not mean quantum computers are already a practical threat to Bitcoin. It means some developers believe the community should begin preparing before the pressure becomes urgent.
That is a reasonable position for a system designed to last for decades.
For traders, BIP-361 should not be read as a short-term price event.
Bitcoin is not suddenly insecure because a quantum-migration proposal exists. In fact, the opposite reading may be more useful: serious networks plan for long-term threats before they become immediate crises.
The draft shows that Bitcoin’s developer community is thinking about future-proofing the protocol.
The market should also remember that draft proposals can change, stall, or fail to gain consensus. BIP status does not equal activation. A proposal must be reviewed, debated, implemented, tested, and accepted by a broad set of stakeholders before it becomes part of Bitcoin’s rules.
Still, the topic is worth watching.
Bitcoin’s long-term credibility depends on its ability to handle risks without compromising its core values. Quantum migration may eventually test that ability. The network will need to balance security upgrades with decentralization, user sovereignty, and conservative governance.
BIP-361 puts that conversation back on the table.
Not because Bitcoin is broken, but because Bitcoin is important enough that its hardest problems need to be discussed early.
This article is based on the BIP-361 draft in the Bitcoin BIPs repository.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released by GitHub. at GitHub

A hacker tied to the Trusted Volumes exploit has returned 1,122 ETH to the protocol, closing part of a security incident that began with a multi-million-dollar exploit earlier this year.
The on-chain recovery is unusual because the attacker did not return everything. Instead, the wallet linked to the exploit sent back roughly $2 million worth of ETH while retaining another large amount as what now looks like a de facto bounty. That kind of outcome is familiar in DeFi, where projects sometimes negotiate with attackers after an exploit rather than risk losing the full amount forever.
The returned funds matter because they reduce the damage for the protocol and its users. But the structure of the settlement also shows how messy DeFi security remains. When smart contracts fail, the market often ends up relying on public pressure, wallet tracking, and informal negotiation rather than a clean legal process.
Reference: Etherscan
The exploit traces back to a vulnerability in Trusted Volumes’ RFQ swap proxy. According to the on-chain evidence, the May 7 attack drained approximately $5.9 million in assets through a signature-check bypass.
That is the kind of vulnerability that can be especially damaging in DeFi because it sits close to the execution layer of a protocol. If a swap proxy accepts an invalid or improperly checked instruction, an attacker may be able to move funds in a way the system was never meant to allow.
The important update now is the return of 1,122 ETH from the attacker wallet to protocol inventory. The primary source for the story is the wallet and transaction evidence on Etherscan, which shows the recovery leg of the movement.
This does not necessarily mean the protocol has been made whole. It means a meaningful part of the exploited funds has come back.
That distinction matters. A partial recovery can be better than nothing, but it still leaves users and the wider market asking why the vulnerability existed, how quickly it was detected, and whether the protocol has made changes to prevent a repeat.
Crypto has developed a strange pattern around major exploits.
In traditional finance, a theft usually leads to police reports, frozen accounts, and court processes. In DeFi, the first response is often public wallet tracking. The attacker’s address gets labelled. On-chain analysts follow the movement of funds. Protocol teams may publish messages offering a bounty if the money is returned.
Sometimes attackers accept. Sometimes they disappear into mixers, bridges, or exchange routes. Sometimes they return a portion and keep the rest.
That appears to be the shape of this case.
The reason this happens is simple: blockchains make funds visible, but not always recoverable. If an attacker controls the private keys, the protocol cannot simply reverse the transaction. The best practical outcome may be to offer a settlement before the funds are moved further away.
That is uncomfortable, but it is also realistic.
For users, the lesson is that code risk is not abstract. Even protocols with real activity can suffer from a small implementation flaw that becomes a major loss. For developers, the lesson is even sharper: signature validation, access controls, proxy logic, and upgrade paths need aggressive review because attackers only need one weak point.
The return of 1,122 ETH is clearly positive for Trusted Volumes, but it should not be treated as a full reset.
An exploit still happened. Funds were still removed. The attacker still appears to have kept a significant sum. The protocol still needs to show that the underlying issue has been addressed and that users can trust the system going forward.
That matters because DeFi confidence is fragile after security incidents. Users may forgive a protocol that responds quickly, communicates clearly, and recovers funds. They are less forgiving when teams stay vague, downplay the incident, or fail to explain what changed.
The strongest next step for Trusted Volumes would be a clear post-mortem: what failed, how the attacker used it, how the contract logic has been fixed, and whether any user balances remain affected.
Until then, the market can recognise the recovery without pretending the episode is over.
This is also a useful reminder for the wider sector. DeFi security is not only about preventing hacks. It is about incident response, transparency, on-chain monitoring, and whether projects can recover enough trust after something goes wrong.
Trusted Volumes got some funds back. The harder job is proving the system is safer than it was before the exploit.
This article is based on Etherscan wallet and transaction data.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released by Etherscan. at Etherscan

Sunday’s Close Was Wounded, Monday’s Price Improved, and Bitcoin Still Forces Discipline
Ethereum Research Thread Puts Sybil Resistance Back In Focus For Decentralized Networks is a useful reminder that crypto coverage is not only about token prices. Sometimes the more important story is the infrastructure, regulation, security, or product layer sitting underneath the market noise.
The immediate point is straightforward: an Ethereum Research post examines Sybil risks in the AUCIL framework. That gives readers something concrete to work with, rather than another vague sentiment update.
The timing matters because Ethereum is already part of a wider conversation across the market. Traders want to know whether the development changes liquidity or risk. Builders want to know whether it changes what can be deployed. Compliance teams want to know whether it changes how platforms operate.
In that sense, the story is bigger than one headline. It sits inside the ongoing shift from speculative crypto cycles toward more practical questions: who can use these systems, how safe are they, and whether the underlying incentives actually work.
The best way to read it is with discipline. It is not a guarantee of immediate upside, and it should not be treated as one. But it does add a fresh data point to the way the market is thinking about Ethereum.
For Ethereum, the important part is the specific mechanism. If this is a security issue, the risk sits in dependencies and user protection. If it is a listing or product launch, the question is access and liquidity. If it is a governance or research proposal, the question is whether the idea can survive implementation.
That is where this update becomes useful. It is not just a label attached to a trend. It gives readers a way to understand what might actually change if the development gains traction.
Crypto has a habit of turning every announcement into a broad market claim. This one deserves a narrower read. The value is in seeing how it affects the users, developers, institutions, or traders closest to the issue.
There is also a caution attached. Source material can confirm that a development exists, but it cannot prove that adoption will follow. A proposal still needs support. A product still needs users. A chart still needs confirmation. A compliance tool still needs integration.
That is why the responsible reading is not to oversell the story. The stronger takeaway is that this adds to a pattern. The crypto market is steadily becoming more professional, more technical, and more sensitive to real operational details.
Readers should also watch for follow-up signals. That could mean developer feedback, exchange support, regulatory response, wallet adoption, liquidity data, or simply whether market participants continue reacting after the first headline fades.
The next stage will decide whether this remains a narrow update or becomes part of a larger market theme. In crypto, that difference matters. Plenty of stories look important for a few hours and then disappear. The ones that last usually show up again through usage, liquidity, enforcement, governance, or developer adoption.
For now, this gives the market another piece of information to weigh. It is specific enough to be useful, but still early enough that readers should keep the caveats in view.
That makes it worth covering without pretending it settles anything. The story is a signal, not a final verdict.
The key is not to confuse coverage with certainty. Ethereum stories can move quickly, especially when they touch security, regulation, listings, infrastructure, or price levels. The useful approach is to track the next confirming detail rather than assume the first update carries the whole market story. That is how traders avoid chasing noise and how readers separate a genuine development from another passing headline.
This report is based on information from ethresear.ch.
This article was written by the News Desk and edited by Samuel Rae.

Mantle’s Chainlink CCIP migration is the kind of infrastructure story that matters precisely because it is not flashy. Bridges are where crypto has lost billions over the years, and every major ecosystem has to treat that history seriously.
The move suggests Mantle wants to reduce reliance on more fragile bridge assumptions and lean on a cross-chain framework with a broader security model.
For more details, visit the official Chainlink platform.
Cross-chain transfers are powerful because they let liquidity move between ecosystems. They are dangerous because the bridge layer becomes a concentrated risk point. If something goes wrong there, the damage can be much bigger than a normal app exploit.
That is why migrating bridge infrastructure is a meaningful decision. It affects how users move assets and how much confidence they have in the network.
Chainlink’s CCIP is increasingly being positioned as a standard cross-chain messaging layer. Mantle adopting it adds another example of large ecosystems looking for more robust interoperability tools.
For users, the technical details may fade into the background. But if the result is safer transfers, the impact is very real.
The practical takeaway is that Chainlink stories now have to be read through both market structure and product execution. A headline can create attention, but the more durable signal is whether the underlying source points to real activity, a real filing, a real integration, or a measurable change in how users and institutions behave.
That is why this development is worth separating from ordinary market noise. It gives readers a specific point to track over the next few sessions rather than a vague reason to be bullish or bearish. If follow-up data confirms the direction, the story can build. If not, it still gives the market a clearer snapshot of where attention is concentrating today.
The cleaner way to read this story is not to force it into a simple bullish or bearish box. For Chainlink readers, the useful part is the change in context. A new filing, integration, market signal, or regulatory step can alter how traders think about the next few sessions even when it does not instantly change price.
That is especially true after the last few volatile weeks, when crypto has been dealing with a mix of ETF flows, legal updates, exchange listings, protocol upgrades, and shifting liquidity. The market is no longer reacting to one dominant theme. It is weighing several smaller signals at once, and that makes source-backed developments more important than ordinary chatter.
For Bitcoinist readers, the important question is what this changes from here. If follow-up data, filings, governance updates, or wallet movement confirm the direction, the story can develop into a larger market theme. If the next update is weak, delayed, or contradicted by new data, the market may quickly move on.
That is why the scope matters. This article is not treating the development as a guaranteed price trigger. It is treating it as a fresh signal inside a market that is trying to sort durable activity from short-term noise. The distinction is important because crypto narratives can move faster than the facts behind them.
The next thing to watch is whether this becomes part of a wider pattern. In some cases that means more institutional flows. In others it means stronger developer adoption, cleaner regulatory access, deeper exchange liquidity, or a clearer technical roadmap. Either way, the story is strongest if it is followed by measurable execution rather than another round of speculative headlines.
This article is based on information from Chainlink.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information from Chainlink. at Chainlink

Dogecoin does not always get taken seriously when the market is in meme mode, but infrastructure updates are where the joke stops and the network starts. Core 1.14.8 is one of those releases that matters because it focuses on security and stability, not sentiment.
That makes it relevant even for traders who never run a node. Healthy networks are built on boring work done properly.
For more details, visit the official GitHub platform.
The GitHub notes make clear that the new version includes critical security patches. That alone should be enough to get the attention of node operators and anyone responsible for infrastructure around DOGE.
Crypto markets often reward spectacle, but security updates are the difference between a network that looks active and a network that can actually be trusted. For Dogecoin, that means the conversation should be about resilience rather than memes.
Releases like this also help reinforce that Dogecoin is still maintained code, not just a ticker powered by online culture. That distinction matters whenever the asset is discussed as if it exists only on social momentum.
The immediate market impact may be limited, but the underlying point is straightforward: networks that keep patching, updating, and hardening themselves give holders and service providers more confidence over time.
This report is based on the Dogecoin GitHub release notes.
This article was written by the News Desk and edited by Samuel Rae.
Source: GitHub
