ART

BarnBridge
2026-07-15 05:17:21

BlockSec says BarnBridge may have suffered governance attack, with about $776,000 lost

BlockSec said Ethereum-based DeFi protocol BarnBridge may have been hit by a governance attack involving its SMART Yield (cUSDC) product. According to BlockSec’s monitoring, the attacker allegedly seized DAO control, upgraded the protocol with a malicious contract, and abused existing user approvals. Estimated losses were about $776,000. The disclosure was made through the source link provided in the input. No additional details on recovery, response measures, or affected user count were included in the source material.

930
BlockSec says BarnBridge may have suffered governance attack, with about $776,000 lost
BarnBridge
2026-07-15 05:26:04

BarnBridge SMART Yield exploit on Ethereum caused about $776,000 in losses

BlockSec Phalcon said BarnBridge SMART Yield (cUSDC) was attacked on Ethereum, with losses estimated at about $776,000. The monitoring data points to a suspected governance attack. According to the alert, the attacker first obtained DAO governance permissions, then upgraded the SmartYield/controller proxy to a malicious implementation contract. That contract later called CompoundProvider’s privileged _takeUnderlying function. BlockSec Phalcon said the attacker then used pre-existing USDC approvals from 50 user accounts and moved the pooled funds through transferFees. The incident centers on governance access, proxy upgrade control, and privileged contract execution inside the protocol’s architecture.

970
BarnBridge SMART Yield exploit on Ethereum caused about $776,000 in losses
MiCA
2026-07-12 10:23:53

MiCA transition ends in the EU as 279 CASP entities appear on ESMA register, with only 18 cleared to run trading platforms

The European Union’s transition period for Crypto-Asset Service Providers under MiCA ended on July 1, meaning crypto trading platforms without the required CASP authorization are, in principle, no longer allowed to keep serving users in the bloc. The change moves MiCA from a transition setup into active enforcement and redraws the compliance map for exchanges operating across the EU. The framework does not rely on a single catch-all exchange license. Instead, MiCA breaks crypto services into 10 categories, labeled a through j, covering custody, trading platform operations, fiat-to-crypto exchange, crypto-to-crypto exchange, order execution, placement, order transmission, investment advice, portfolio management, and transfer services. Separate from those service codes, MiCA groups firms into Class 1, Class 2, and Class 3 for minimum capital purposes, with thresholds of €50,000, €125,000, and €150,000. According to the article, ESMA’s register as of July 3, 2026 lists 279 authorized CASP entities. Around 222 can provide trading-related services such as exchange or order execution, but only 18 entities hold the key b-type authorization that allows operation of a crypto-asset trading platform. Firms listed in that group include OKX, Gate.io EU, Kraken, Bitstamp, Revolut Crypto, Bitvavo, One Trading, and others. Many large platforms, including Coinbase, Bybit EU, Crypto.com, Gemini, KuCoin EU, Robinhood Europe, and eToro Crypto, are shown mainly under Class 2 rather than the narrower group holding trading-platform permission.

1080
MiCA transition ends in the EU as 279 CASP entities appear on ESMA register, with only 18 cleared to run trading platforms