BTC $76,931.08 -0.41%
ETH $2,490.36 -1.31%
BNB $718.53 -1.08%
XRP $1.34 -1.43%
SOL $100.15 -1.40%
TRX $0.3406 +0.21%
DOGE $0.0830 -1.99%
ADA $0.2049 -0.91%
BCH $221.69 -1.69%
LINK $11.26 -2.15%
HYPE $77.78 -2.28%
AAVE $124.63 -0.71%
SUI $0.7075 -2.03%
XLM $0.1779 -1.18%
ZEC $1,073.52 -4.43%
AAPL $330.40 -0.85%
AMZN $254.10 -1.06%
GOOGL $336.97 -1.32%
MSFT $491.04 -0.91%
META $644.40 -0.64%
NVDA $214.82 -1.64%
TSLA $361.96 -1.47%
SNDK $1,566.79 -3.58%
INTC $98.62 -3.29%
SPCX $149.01 -0.71%
MU $935.57 -3.23%
AMD $500.04 -3.13%
BTC $76,931.08 -0.41%
ETH $2,490.36 -1.31%
BNB $718.53 -1.08%
XRP $1.34 -1.43%
SOL $100.15 -1.40%
TRX $0.3406 +0.21%
DOGE $0.0830 -1.99%
ADA $0.2049 -0.91%
BCH $221.69 -1.69%
LINK $11.26 -2.15%
HYPE $77.78 -2.28%
AAVE $124.63 -0.71%
SUI $0.7075 -2.03%
XLM $0.1779 -1.18%
ZEC $1,073.52 -4.43%
AAPL $330.40 -0.85%
AMZN $254.10 -1.06%
GOOGL $336.97 -1.32%
MSFT $491.04 -0.91%
META $644.40 -0.64%
NVDA $214.82 -1.64%
TSLA $361.96 -1.47%
SNDK $1,566.79 -3.58%
INTC $98.62 -3.29%
SPCX $149.01 -0.71%
MU $935.57 -3.23%
AMD $500.04 -3.13%

cross-chain

All
Article
Flash

Galaxy Research: Coldcard attackers continue to transfer funds, approximately 45% of the stolen assets have entered mixing or cross-chain pathways

Galaxy Research published that the attackers in the Coldcard "Wave 3" attack are still continuously transferring the stolen funds. During this phase, the attackers created 293 2-of-2 multi-signature wallets for each victim's assets. The first batch of funds was transferred across chains to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attackers are processing the largest amounts of stolen funds in order of the stolen amount, having sequentially transferred the funds from wallets ranked 1 to 11. The next 10 wallets that have not yet been transferred hold a total of 30.81 BTC, while wallets ranked 61 to 293 hold a total of 33.77 BTC. So far, the attackers have transferred about 45% of the stolen assets from this exploit, with funds flowing to Ethereum (via THORChain) or entering CoinJoin mixing transactions. Additionally, this fund transfer has revealed a previously unknown wallet: 58 addresses jointly spent in a 2-of-2 multi-signature format identical to that of Wave 3, and these were further transferred by the Wave 3 attackers to a jump address that funds CoinJoin.The on-chain analysis team currently marks this wallet as "cause = open," but believes it likely also belongs to Coldcard victims, which means the number of wallets involved in Wave 3 may increase to 294, raising the previously reported total amount stolen from the Coldcard vulnerability to approximately 1806 BTC. Currently, about 82% of the stolen BTC remains in addresses initially controlled by the attackers, while about 18% has been transferred, with the flow of funds indicating that it may be undergoing laundering processes.

first_img Cross-chain infrastructure Router Protocol announced its closure and will destroy 303 million ROUTE tokens

Router Protocol, a cross-chain infrastructure project supported by Coinbase Ventures, announced that it will cease all operations by September 30 and plans to permanently destroy 303,333,198 ROUTE tokens held in its treasury, accounting for about 30% of the total supply of nearly 1 billion tokens. The team released a statement on X, stating that over the past year, they attempted commercialization, licensing, and acquisition negotiations, but failed to achieve sustainable operational results.Router identified the flow of funds from the cryptocurrency sector to artificial intelligence and the decline in cross-chain asset transfer fees as core challenges facing its operations. As activities concentrated on fewer networks and standardized infrastructure, the demand for its services has decreased. The team noted that bridging economic profits are thin, fees have been compressed, and costs have never stopped. As part of the closure, Router will negotiate with centralized exchanges to stop supporting ROUTE tokens, and the delisting arrangements and withdrawal processes may vary across exchanges.Router raised $4.1 million from investors including Coinbase Ventures and Polygon in 2021 and launched the proof-of-stake Layer 1 blockchain Router Chain in July 2024, but it was shut down in September 2025 due to infrastructure costs, validator expansion, and security risks. The team also disclosed two security incidents in 2025: in February, approximately 80% of the value was recovered through negotiations after a vulnerability incident, while losses from a chain-level vulnerability in July could not be recovered.

Slow Mist Reveals Details of the Allbridge Cross-Chain Bridge Attack: Forged CCTP Messages, Flash Loans, Insufficient Minting Result Verification

The Slow Mist security team disclosed that the cross-chain bridge project Allbridge was attacked on August 19, 2026, resulting in a loss of approximately $190,000. Notably, this attack was not executed instantly; the attacker had begun laying the groundwork nearly a month prior and bypassed the verification mechanism by forging cross-chain messages. According to Slow Mist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as a CCTP style message, claiming that a transfer of 1 million USDC existed, but in reality, no USDC destruction operation took place. Subsequently, Circle generated a valid verification proof (attestation) for this complete message according to normal procedures.About 24 days later, on August 19, the attacker waited for the Base Router to receive a real CCTP deposit, increasing the balance to approximately 191,000 USDC, and initiated the attack just 6 seconds later. The attacker utilized the previously forged message and verification proof to call Allbridge's receiveCctpMessage function. Due to the project's lack of critical verification, the system mistakenly recognized the false cross-chain message as a real deposit and recorded a limit of 1 million USDC. The attacker then temporarily borrowed approximately 809,000 USDC through an Aave flash loan, matching the Router balance with the forged amount, and used the internal credit record to call the transfer function, ultimately transferring out approximately 999,000 USDC (after a 0.1% fee). After repaying the flash loan and fees, the attacker netted a profit of about $189,800. The root cause of this vulnerability lies in Allbridge's failure to verify the identities of the sender and receiver of the cross-chain message, as well as not confirming whether USDC was genuinely minted and whether the balance actually increased, instead directly trusting the amounts and message hash data constructed by the attacker. Slow Mist emphasizes that on-chain message verification does not equate to the actual arrival of real assets. Cross-chain protocols not only need to verify the authenticity of messages but must also ensure that the message source is trustworthy, that the receiver is Circle's official TokenMessengerV2, and that asset accounting can only proceed after confirming the actual minting of assets and changes in balance. This incident once again highlights the security risks of cross-chain bridges in the message verification and asset settlement processes.
app_icon
ChainCatcher Building the Web3 world with innovations.