Blockchain security firm SlowMist issued urgent warnings about AI coding assistant vulnerabilities that trigger automatic malware execution during routine operations like "Open Folder," with Cursor users facing severe exposure to attacks embedding malicious instructions in markdown files invisible to developers.
An attacker exploited IPOR Labs' legacy USDC vault on Arbitrum for $336,000 by hijacking an administrator account through Ethereum's new EIP-7702 delegation feature, with the protocol confirming all affected depositors will receive full refunds while newer vaults remain secure with enhanced validation.
A sophisticated attacker laundered $19.4 million of stolen funds through Tornado Cash following a $27.3 million multi-signature wallet exploit, while concurrent attacks including pig-butchering scams and contract exploits pushed 24-hour losses above $36 million across multiple platforms.
Get dialed in every Tuesday & Friday with quick updates on the world of crypto