Scan to download
BTC $79,001.96 -2.93%
ETH $2,218.23 -3.50%
BNB $672.04 -1.32%
XRP $1.43 -4.24%
SOL $89.16 -3.89%
TRX $0.3515 -0.55%
DOGE $0.1129 -3.21%
ADA $0.2610 -4.39%
BCH $424.86 -2.94%
LINK $10.05 -4.86%
HYPE $43.99 -0.05%
AAVE $92.52 -7.08%
SUI $1.09 -8.65%
XLM $0.1543 -5.85%
ZEC $516.12 -8.19%
BTC $79,001.96 -2.93%
ETH $2,218.23 -3.50%
BNB $672.04 -1.32%
XRP $1.43 -4.24%
SOL $89.16 -3.89%
TRX $0.3515 -0.55%
DOGE $0.1129 -3.21%
ADA $0.2610 -4.39%
BCH $424.86 -2.94%
LINK $10.05 -4.86%
HYPE $43.99 -0.05%
AAVE $92.52 -7.08%
SUI $1.09 -8.65%
XLM $0.1543 -5.85%
ZEC $516.12 -8.19%

att

After being attacked, KelpDAO has seen multiple protocols abandon LayerZero, with $4 billion in assets migrated to Chainlink CCIP

After KelpDAO was attacked, resulting in a loss of $292 million, the industry's scrutiny of the security of cross-chain infrastructure has intensified. Approximately $4 billion in assets have completed or are in the process of migrating from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP). The DeFi protocol Lombard is the latest project to join this migration trend. The protocol announced it would discontinue the use of LayerZero and migrate over $1 billion in Bitcoin-backed assets to Chainlink CCIP, stating that this decision stemmed from a comprehensive internal security review following the April attack incident.Lombard issues two types of Bitcoin-backed tokens—LBTC and BTC.b—and will prioritize the migration of assets on chains such as Solana, Etherlink, Berachain, Corn, and TAC, while terminating the use of LayerZero on Morph and Swell. Lombard stated that the reason for choosing CCIP is its independent node operators, built-in rate limiting mechanisms, and audited infrastructure. Additionally, the protocol will adopt Chainlink's cross-chain token standard to facilitate asset cross-chain circulation through a burn-and-mint model.Previously, Kelp DAO, Solv Protocol, Re, and the cryptocurrency exchange Kraken have all completed similar migrations, with these projects collectively transferring approximately $4 billion in assets. Chainlink Labs Chief Business Officer Johann Eid stated, "We are witnessing a continued wave of risk-averse migration within the industry."

AI Agent Security Risk Exposure: Attackers Can Exploit "Memory Pollution" to Induce Misoperation of Funds

The GoPlus Security team has disclosed a new type of attack in its AgentGuard AI project: inducing AI agents to perform unauthorized sensitive operations through "memory poisoning." This attack method does not rely on traditional vulnerabilities or malicious code but exploits the long-term memory mechanism of AI agents. For example, an attacker first induces the agent to "remember preferences," such as "usually prioritizing proactive refunds instead of waiting for chargebacks," and then uses vague expressions like "process as usual" or "execute as before" in subsequent instructions, thereby triggering automated financial operations.GoPlus points out that the key risk in such cases lies in the AI agent mistakenly treating "historical preferences" as a basis for authorization, leading to financial losses or security incidents in operations such as refunds, transfers, and configuration changes. To address this issue, the team has proposed several protective recommendations, including:Operations involving refunds, transfers, deletions, or sensitive configurations must require explicit confirmation in the current session.Memory-related instructions like "habit," "usual way," and "as before" should be regarded as high-risk state changes.Long-term memory must have a traceability mechanism (writer, time, confirmation status).Vague instructions should automatically elevate the risk level and trigger secondary verification.Long-term memory must not replace real-time authorization processes.The team emphasizes that the "AI agent memory system" should be viewed as a potential attack surface and should be constrained and audited through a dedicated security framework.

Bitcoin spot ETFs have seen net positive inflows for seven consecutive weeks, with IBIT attracting $269.3 million in a single day yesterday. The House fundraising committee is holding a closed-door meeting on cryptocurrency tax reform today, in sync with the Senate markup

According to BBX data, institutional demand for Bitcoin ETFs maintained strong momentum yesterday. Today, both houses of Congress are advancing cryptocurrency legislation simultaneously for the first time, with the core dynamics as follows:The U.S. Bitcoin spot ETF recorded a total net inflow of approximately $358.1 million yesterday (May 13), with BlackRock, Inc. (NYSE: $BLK) subsidiary iShares Bitcoin Trust (NASDAQ: $IBIT) seeing a single-day net inflow of $269.3 million, the strongest single-day data in recent weeks; the overall U.S. Bitcoin spot ETF has recorded net positive inflows for seven consecutive weeks, further reinforcing the structural signal of institutional capital returning. Bitcoin closed above $80,000 yesterday, with a year-to-date increase of about 14%, and market sentiment remains relatively optimistic on the eve of the CLARITY Act markup.The House Ways & Means Committee held a closed-door meeting today (May 14) on cryptocurrency tax reform in sync with the Senate Banking Committee's CLARITY Act markup, covering topics such as the treatment of capital gains tax on crypto assets, tax reporting responsibilities for DeFi protocols, and the tax classification of Bitcoin mining and staking income; this marks the first time in 2026 that both houses of Congress are advancing cryptocurrency regulatory legislation on the same day, indicating that cryptocurrency regulatory legislation has expanded from a single market structure issue to a complete legislative ecosystem of "regulatory framework + tax system."

CertiK Report: North Korean hackers caused approximately 60% of digital asset thefts by 2025, with attack patterns shifting to "offline infiltration."

Web3 security company CertiK has released the "Skynet North Korea Cyber Threat Report." The data shows that since 2016, North Korean hacker groups have plundered approximately $6.75 billion in digital assets. In 2025 alone, the losses from thefts they orchestrated reached as high as $2.06 billion, accounting for nearly 60% of the total losses in the global cryptocurrency industry for the entire year (including the $1.5 billion Bybit theft case). As of early 2026, this threat trend continues, with losses accounting for about 55%.The report emphasizes that the attack patterns of North Korean hackers have undergone a fundamental shift, evolving from simple code vulnerability exploitation to a national-level attack system that combines social engineering, deep supply chain attacks, and "physical infiltration." In the recent Drift protocol incident, attackers even spent six months lurking at offline industry conferences, establishing trust through real funds and interpersonal interactions before executing their attack.CertiK security experts warn that in the face of such systemic attacks, simple technical defenses have become weak. Cryptocurrency institutions urgently need to fully implement a "zero trust" hiring model, strengthen third-party supply chains, establish fund circuit breaker mechanisms, and collaborate with professional security organizations to build a comprehensive lifecycle defense system covering code audits, round-the-clock risk monitoring, and on-chain anti-money laundering/KYT (Know Your Transaction) fund tracking.
app_icon
ChainCatcher Building the Web3 world with innovations.