BTC $77,466.20 +0.31%
ETH $2,501.94 -0.76%
BNB $722.40 -0.77%
XRP $1.36 -0.46%
SOL $100.68 -1.33%
TRX $0.3387 -0.47%
DOGE $0.0838 -1.47%
ADA $0.2073 -0.29%
BCH $224.11 -0.66%
LINK $11.34 -1.57%
HYPE $78.95 -0.48%
AAVE $126.03 -0.87%
SUI $0.7125 -2.03%
XLM $0.1800 -0.09%
ZEC $1,099.94 -2.40%
AAPL $329.00 -1.25%
AMZN $255.10 -0.76%
GOOGL $336.05 -1.65%
MSFT $494.22 -0.30%
META $641.71 -1.03%
NVDA $215.19 -1.24%
TSLA $361.16 -1.77%
SNDK $1,567.96 -3.56%
INTC $98.97 -2.48%
SPCX $148.77 -1.02%
MU $941.82 -2.65%
AMD $501.86 -2.42%
BTC $77,466.20 +0.31%
ETH $2,501.94 -0.76%
BNB $722.40 -0.77%
XRP $1.36 -0.46%
SOL $100.68 -1.33%
TRX $0.3387 -0.47%
DOGE $0.0838 -1.47%
ADA $0.2073 -0.29%
BCH $224.11 -0.66%
LINK $11.34 -1.57%
HYPE $78.95 -0.48%
AAVE $126.03 -0.87%
SUI $0.7125 -2.03%
XLM $0.1800 -0.09%
ZEC $1,099.94 -2.40%
AAPL $329.00 -1.25%
AMZN $255.10 -0.76%
GOOGL $336.05 -1.65%
MSFT $494.22 -0.30%
META $641.71 -1.03%
NVDA $215.19 -1.24%
TSLA $361.16 -1.77%
SNDK $1,567.96 -3.56%
INTC $98.97 -2.48%
SPCX $148.77 -1.02%
MU $941.82 -2.65%
AMD $501.86 -2.42%

ism

All
Article
Flash

first_img The Curve soft liquidation mechanism allows hundreds of loans to survive in a liquidation state for several weeks

According to CoinDesk, data from Curve Finance shows that its lending market has recorded a total of 704 "soft liquidation" events, involving 602 borrower addresses, with a median duration of 14.5 days, of which a quarter lasted at least 38.9 days, and some positions remained within the liquidation range for several months. Of these soft liquidations, 476 began in the first half of 2026. Unlike traditional lending protocols such as Aave and Compound, Curve's LLAMMA system does not sell off collateral all at once after the price drops below a threshold, but gradually converts collateral into borrowed assets within a price range. If the price rebounds before the loan completely fails, some or all of the conversions may be reversed. This means that borrowers are not in a grace period; their collateral has been partially liquidated during the loan's duration, but they still have the opportunity to restore their positions if the price reverses. However, soft liquidations are not without costs. Data shows that borrowers may still incur losses due to transaction fees, conversions, rebalancing, interest, and bid-ask price fluctuations, and if the market remains unfavorable, positions may still fall into hard liquidation. Curve Finance is a mainstream DeFi protocol focused on stablecoin exchanges and crvUSD lending, currently holding approximately $1.35 billion in deposits, with a DEX trading volume of about $3.4 billion over the past 30 days and active loans of about $46 million.

first_img Ukrainian police dismantle cryptocurrency scam, with monthly thefts reaching 1 million USD

The Ukrainian police and the Security Service of Ukraine (SBU) recently dismantled a scam network that used a fake investment platform to steal cryptocurrency. This network disguised itself as an investment platform website, luring users to connect their main cryptocurrency wallets and approve a small test transaction when withdrawing funds. Subsequently, it used a "wallet stealer" hidden within the website to automatically transfer user funds to wallets controlled by the operators, kicking victims off the platform. Investigators have currently confirmed 62 victims, with over 46 Ukrainian citizens involved, and the network could steal up to $1 million per month.The police stated that the false profits displayed on the platform are part of the scam, with operators manually creating transactions and adjusting user account balances to create the illusion of investment growth. In addition to cryptocurrency, the platform also collected victims' passport information, phone numbers, email addresses, login credentials, and photos during the registration and identity verification process. The main organizer of the network is a 25-year-old IT expert who recruited over 46 Ukrainian citizens and operated multiple offices in Kyiv and surrounding areas, with members responsible for building and maintaining fake websites, contacting potential victims, and providing security.Victims come from multiple countries, including Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada, and Israel. The police traced the gang's server equipment located in the Netherlands and obtained a database stored there, which included a list of victims, cryptocurrency wallet addresses, suspected stolen amounts, internal communications, and platform operation information. The Ukrainian police and SBU subsequently executed 34 searches in Kyiv and surrounding areas, seizing over 100 computers, more than 100 mobile phones, 79 SIM cards, documents, cash, and 15 vehicles.

first_img Ukrainian police dismantled a gang in Kyiv that stole cryptocurrency wallets, with a monthly turnover reaching up to 1 million USD

On Tuesday, the Ukrainian National Police and Security Service announced the dismantling of a fake investment platform network based in Kyiv. This gang stole cryptocurrency from users in over 20 countries through built-in wallet theft tools. Investigators have currently confirmed 62 victims, including citizens from Germany, Poland, Lithuania, Latvia, Spain, France, the UK, Canada, and Israel. The organizers recruited more than 46 Ukrainians, operating multiple offices in Kyiv and surrounding areas, where developers were responsible for building the fake platform and resisting bans, while other members handled customer service and security.According to the Ukrainian Security Service, the organizer is a 25-year-old IT expert, and the gang's peak monthly revenue reached up to $1 million. The scam began with advertisements for cryptocurrency investment projects on Telegram. After users registered, they connected their wallets and invested funds, while gang members manually forged transactions to show a continuously increasing balance in the user backend. When users requested withdrawals, the platform required them to connect their main wallet and approve a small "test" transaction under the pretext of verification. This authorization immediately triggered the built-in theft tool on the website, transferring assets to wallets controlled by the gang and locking the victims' accounts.Investigators tracked down server equipment storing the gang's database in the Netherlands, which recorded victim information, wallet addresses, stolen amounts, internal communications, and platform operation data, as well as user passports, phone numbers, emails, login passwords, and photos. Police executed 34 searches in Kyiv and surrounding areas, seizing over 100 computers, more than 100 mobile phones, 79 SIM cards, one GSM gateway, cash, and 15 vehicles.

first_img The U.S. Department of Justice and CrowdStrike teamed up to dismantle the Sality botnet, which had been operating for over 20 years

According to Decrypt, CrowdStrike and the U.S. Department of Justice announced on Tuesday that they have dismantled the Sality peer-to-peer botnet, which has been active since 2003.This botnet primarily hijacked cryptocurrency payments through the EggJagger malware over the past eight years, which monitored the cryptocurrency wallet addresses in victims' clipboards and replaced them with the operator's own address, causing victims to send funds to strangers.CrowdStrike estimates that the operator has stolen at least 12.1 million rubles (approximately $150,000) solely through the EggJagger payload. Most of the stolen cryptocurrency has not been spent, and CrowdStrike assesses that these unspent assets were worth about 147 million rubles (nominally around $1.35 million) at their peak in January 2025. The reason Sality has survived to this day is that it does not have a central server that can be seized; infected machines communicate directly with each other.This multinational operation involved the United States, Bulgaria, Hungary, and Romania. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service seized Sality-related domains within the United States, and police from multiple European countries also seized other domains.CrowdStrike isolated more than 15,000 infected machines to its controlled honeypot by exploiting its architectural vulnerabilities. The operator has been tracked as SALTY SPIDER, which launched a denial-of-service attack against the Russian cryptocurrency exchange AvanChange in September 2023.
app_icon
ChainCatcher Building the Web3 world with innovations.