BTC $80,010.12 +2.12%
ETH $2,504.65 +1.58%
BNB $709.91 +1.65%
XRP $1.45 +6.09%
SOL $109.12 +13.10%
TRX $0.3378 +0.70%
DOGE $0.0885 +4.42%
ADA $0.2139 +4.41%
BCH $269.91 +3.46%
LINK $11.88 +5.67%
HYPE $84.94 +6.03%
AAVE $128.02 +4.43%
SUI $0.7761 +5.41%
XLM $0.1874 +4.74%
ZEC $818.05 +4.42%
BTC $80,010.12 +2.12%
ETH $2,504.65 +1.58%
BNB $709.91 +1.65%
XRP $1.45 +6.09%
SOL $109.12 +13.10%
TRX $0.3378 +0.70%
DOGE $0.0885 +4.42%
ADA $0.2139 +4.41%
BCH $269.91 +3.46%
LINK $11.88 +5.67%
HYPE $84.94 +6.03%
AAVE $128.02 +4.43%
SUI $0.7761 +5.41%
XLM $0.1874 +4.74%
ZEC $818.05 +4.42%

cati

All
Article
Flash

The Sandbox: Compensation will be carried out based on the on-chain snapshot before the attack, and the compensation application process is expected to open within two weeks

The Sandbox released an update on the security vulnerability attack incident involving the SAND cross-chain bridge, stating that the attacker modified the verification mechanism to forge cross-chain deposit messages and mint unbacked SAND. This incident resulted in approximately 14.7423 million SAND being withdrawn, valued at about $697,000. Additionally, some uncollateralized SAND was profited through market trading, leading to an overall economic impact of approximately $1.497 million, of which the attacker actually obtained about $987,000.The Sandbox stated that the attack did not affect the supply of SAND on Ethereum and Polygon, with the total amount of SAND on Ethereum remaining unchanged at 3 billion. There were also no super administrator privileges stolen, and the attack stemmed from a vulnerability caused by the combination of the general call function in the token contract and the design of bridge permissions. Currently, the related addresses have been marked, and collaboration has begun with exchanges, security agencies, and the LayerZero team.For affected users, The Sandbox promises to compensate wallets holding legitimate bridged SAND with a 1:1 ratio of SAND on the Ethereum chain based on an on-chain snapshot taken before the attack. The compensation application process is expected to open within two weeks and will last for two weeks.

first_img Unstoppable Domains abandons ICANN application, refunds Web3 domain names

Matthew Gould, the founder of Unstoppable Domains, stated that the company did not submit an application for its Web3 top-level domains in ICANN's 2026 expansion round and will refund customers who purchased related domains. Gould mentioned that the compliance, application, and bidding costs of incorporating Web3 domains into the ICANN system exceeded the company's expected recoverable sales. This move ends the company's commitment since 2019 that domains like .crypto and .wallet would eventually be resolvable in standard browsers.The application window for this round of ICANN opened on April 30 and closed on August 12, receiving over 1,600 major applications. Gould stated that customers have been notified via email, but the list of affected extensions and refund terms have not been disclosed. Some holders questioned the scope of the refunds, claiming they held the domains based on Unstoppable's commitment to advance the ICANN application. Gould responded that Web3 domains will still serve as on-chain assets for cryptocurrency transactions.Unstoppable continues to participate in ICANN activities as a service provider and previously announced a partnership with Telegram to apply for the .gram domain. Meanwhile, ENS has chosen a different path, with token holders approving the restructuring of the ENS Foundation to pursue the .ens top-level domain in ICANN, but ENS will not apply for .eth, as it is reserved for ISO 3166-1 country codes.

Slow Mist Reveals Details of the Allbridge Cross-Chain Bridge Attack: Forged CCTP Messages, Flash Loans, Insufficient Minting Result Verification

The Slow Mist security team disclosed that the cross-chain bridge project Allbridge was attacked on August 19, 2026, resulting in a loss of approximately $190,000. Notably, this attack was not executed instantly; the attacker had begun laying the groundwork nearly a month prior and bypassed the verification mechanism by forging cross-chain messages. According to Slow Mist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as a CCTP style message, claiming that a transfer of 1 million USDC existed, but in reality, no USDC destruction operation took place. Subsequently, Circle generated a valid verification proof (attestation) for this complete message according to normal procedures.About 24 days later, on August 19, the attacker waited for the Base Router to receive a real CCTP deposit, increasing the balance to approximately 191,000 USDC, and initiated the attack just 6 seconds later. The attacker utilized the previously forged message and verification proof to call Allbridge's receiveCctpMessage function. Due to the project's lack of critical verification, the system mistakenly recognized the false cross-chain message as a real deposit and recorded a limit of 1 million USDC. The attacker then temporarily borrowed approximately 809,000 USDC through an Aave flash loan, matching the Router balance with the forged amount, and used the internal credit record to call the transfer function, ultimately transferring out approximately 999,000 USDC (after a 0.1% fee). After repaying the flash loan and fees, the attacker netted a profit of about $189,800. The root cause of this vulnerability lies in Allbridge's failure to verify the identities of the sender and receiver of the cross-chain message, as well as not confirming whether USDC was genuinely minted and whether the balance actually increased, instead directly trusting the amounts and message hash data constructed by the attacker. Slow Mist emphasizes that on-chain message verification does not equate to the actual arrival of real assets. Cross-chain protocols not only need to verify the authenticity of messages but must also ensure that the message source is trustworthy, that the receiver is Circle's official TokenMessengerV2, and that asset accounting can only proceed after confirming the actual minting of assets and changes in balance. This incident once again highlights the security risks of cross-chain bridges in the message verification and asset settlement processes.
app_icon
ChainCatcher Building the Web3 world with innovations.