More than $8.17 million stolen in phishing attack targeting Uniswap users

In a successful, broadly-targeted phishing campaign, more than 70,000 addresses connected to Uniswap were airdropped tokens that baited users into approving transactions that allowed attackers to control their wallets. After some initial confusion that there might be a vulnerability in Uniswap itself, it was determined that the thefts were being perpetrated through the airdrop, which also linked users to a website that resembled the authentic Uniswap site. Users were tricked into signing the contract, and cryptocurrency and NFTs were stolen from wallets.

One single wallet targeted by the phishing attack lost more than $6.5 million worth of Ether and Bitcoin, and another targeted by attackers lost around $1.68 million worth of those currencies.

Vauld is short around $70 million

Crypto lending firm Vauld, which suspended withdrawals and announced they were considering restructuring on July 4, have disclosed to their creditors a shortfall of around $70 million. They explained this was due to mark-to-market losses relating to the declining pricess of Bitcoin, Ether, and Polygon, as well as exposure to the now-collapsed Terra stablecoin UST. They also attributed some of the shortfall to longterm loans that can't be called back for another 3–11 months.

Several weeks prior, Vauld had cut 30% of staff, slashed executive salaries, and began various other cost-cutting measures.

Rival firm Nexo has said it is considering acquiring Vauld, though some have expressed skepticism that Nexo is in a position to afford such an acquisition.

Report claims that Binance served Iranian customers in violation of sanctions

The latest Reuters investigation into Binance has alleged that the company processed transactions for Iranian users, despite U.S. sanctions and the company's claim to be compliant with them. Iranian traders interviewed by Reuters stated that they were able to take advantage of Binance's poor KYC checks to use the service despite the sanctions.

The usage of the exchange by residents of sanctioned countries could draw the attention of US regulators. It's also the latest in several investigative reports by Reuters into Binance, in addition to a June report that the exchange facilitated $2.35 billion in illicit transfers from 2017–2021, and an April report that Binance supplied the Putin regime with information about crypto donors to opposition leader Alexei Navalny.

More than $2.25 million stolen from Bifrost's BiFi platform

Bifrost is a platform that allows developers to create dApps across multiple blockchains. They run the service BiFi, which is a defi platform built atop Bifrost. On July 10, they inadvertently exposed the key to their Bitcoin address-issuing server. An attacker was able to use this to self-sign their own deposit address, then make a fake deposit into the BiFi Bitcoin lending service in exchange for 1,852 ETH ($2.25 million).

Bifrost wrote in their post-mortem analysis that because the attack was limited to the BTC address registration server, and the hack didn't exploit any smart contract or protocol vulnerabilities, a security audit performed by Theori "is still valid" — leading one to wonder why anyone should trust an "audited" platform if $2.25 million in assets can be stolen without invalidating an audit.

Hackers steal $1.43 million from Omni NFT lending platform

Hackers used a flash loan attack to steal around 1,300 ETH ($1.43 million) from the NFT lending platform Omni. Omni allows users to borrow cryptocurrency against their NFTs.

Hackers used NFTs from the popular Doodles collection as collateral to borrow wETH, then withdrew all but one of the NFTs, allowing them to perform a re-entrancy attack. The attacker then laundered the funds using the Tornado Cash cryptocurrency tumbler.

According to Omni, only funds belonging to the platform that were being used for testing were taken by the attacker.

CoinFLEX sues Roger Ver to try to recover claimed $84 million debt

Portrait of Roger VerRoger Ver (attribution)
When CoinFLEX suspended withdrawals on June 23, they blamed "continued uncertainty involving a counterparty".

Although they initially dodged naming the counterparty, CEO Mark Lamb eventually publicly stated that this counterparty was Roger "Bitcoin Jesus" Ver, who he said failed to meet a $47 million margin call. However, Ver publicly refuted this claim, stating that CoinFLEX in fact owed him money. Both parties went back and forth, each accusing the other of misrepresenting the situation.

On July 9, the company stated that they would be seeking arbitration to recover $84 million from Ver — an updated figure that they said factored in the "significant loss in liquidating his significant FLEX coin positions".

Vauld seeks protection against creditors

Cryptocurrency exchange Vauld, who suspended withdrawals on July 4, filed for a moratorium against creditors in Singapore, a process that's conceptually similar to Chapter 11 bankruptcy proceedings in the U.S.

In late June, the exchange laid off 30% of staff and took other measures to cut costs. They later disclosed they were short $70 million, partly from exposure to the Terra ecosystem which collapsed in May.

Three Arrows Capital founders are nowhere to be found

Kyle Davies and Zhu Su, the founders of Three Arrows Capital, have apparently disappeared after the firm entered bankruptcy proceedings. Although lawyers for the duo have said they intend to cooperate with the proceedings, their whereabouts are unknown, and the liquidators' lawyers stated they had "not yet received any meaningful cooperation" from either. Those lawyers have expressed concerns that the pair might make off with the remaining funds — a substantial portion of which are cash, cryptocurrencies, and NFTs, and could be easily transferred.

Hypernet Labs shuts down shortly after being hit with a fraud lawsuit

Ivan Ravlich, founder of the nebulous crypto firm called Hypernet Labs, announced on Twitter that "Hypernet's road has reached an end". "Hypernet was impacted by the same market headwinds that have touched millions around the world since May. Unfortunately, the treasury was also held in Ethereum, which disproportionately exacerbated the bear market's impact on our balance sheet", he wrote.

What he didn't mention was the lawsuit that had just been filed against the company, by investors who allege that Ravlich and his co-founders lied to investors and never created any usable product or service. Investors claim to have lost millions in cryptocurrency, and one alleged that Ravlich and his compatriots used a shell company in the Cook Islands to make it harder for him to recoup his losses.

Hypernet initially promised to build a system for renting unused computing power, and in 2018 raised around $20 million in an initial coin offering. In late 2021, Hypernet "pivoted hard" into NFTs, which one investor stated was a "knee jerk reaction to the flavour of the day" and a "last-ditch attempt to find a non-existent market for a non-existent product".

Blockchain.com faces a $270 million loss from their loan to Three Arrows Capital

Crypto exchange Blockchain.com announced in a letter to shareholders that they could lose the $270 million in cryptocurrency and USD they loaned to Three Arrows Capital, a now-insolvent crypto fund that is pursuing bankruptcy. The ripple effects of the 3AC implosion have been felt throughout the crypto ecosystem, contributing to liquidity issues and the outright failure of some other platforms. Blockchain.com assured customers that they would not be one of those platforms, writing that the company "remains liquid, solvent and our customers will not be impacted", but they also would not be the first crypto company in recent weeks to assure customers that everything is fine shortly before being forced to reveal that everything is not fine at all.

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.