NEW: Canary Capital's staked Tron ETF is expected to list on Cboe on Sept. 9, according to Bloomberg Analyst Henry Jim.
The ETF is set to trade under ticker TRXS, per its prospectus. $TRX
85·ALong
n
news9/8news
Staked Tron ETF coming to market from @CanaryFunds. tron:native $TRXS
85·ALong
m
meme9/7meme
quote: .#TRONEco continues its upward trajectory this week, driven by surging transfer volumes, record-breaking AI token throughput, and robust network liquidity.
On the infrastructure side, global installations for BitTorrent climbed to 585,529,866, with $BTT staking APY on #BTTC reaching 6.43%.
Dive into the full weekly report below. | TRON Eco Weekly Recap | Aug 31 to Sep 6
TRON Eco continued to gain momentum last week, with TRON’s $USDT supply increasing by another $4B in August to surpass $94.27B, while @DeFi_JUST’s GasFree recorded $13.62B+ in monthly transfer volume, 818K+ transactions, and 437K+ users.
@OfficialSUNio hosted two Spaces exploring AI infrastructure and stablecoin user experiences. @BitTorrent reached 585,529,866 global installations, while @WinkLink_Oracle’s $WIN saw $883.77K in supply and $2.93K in total borrows on #JustLendDAO.
Meanwhile, @AINFTcom continued advancing AI and Web3 initiatives, while @BAI_AGI surpassed 2.3M users, processed 10.9T+ tokens during its free promotion, and hit a record 1.33T daily token throughput.
And that’s not all. Take a look at the recap below for more from across #TRONEco. ⤵️
0·-Neutral
n
news9/7news
A strong ecosystem is built by the people who keep contributing to it.
Congrats to last month’s #TRONEcoStars, and to everyone helping bring more ideas, conversations, and attention to the ecosystem.
Keep building. Keep moving TRON forward. 💪
25·CLong
m
meme9/6meme
🎉 TRON’s total accounts have surpassed 402 million!
TRON ecosystem continues its rapid growth as we push forward on our mission to decentralize the future.
0·-Neutral
m
meme9/6meme
This Week in Virtuals: Robinhood App Turned On Agent Trading, with Virtuals as the Onchain Infra Layer
VIRTUALS
🟩 @RobinhoodApp rolled Agentic Trading out to 100% of eligible users this week. Onchain, the infra layer agents launch on, trade from and get owned through is now Virtuals Protocol.
🟩 @coinbureau called Virtuals "an entire nation for AI agents, complete with identity, banking, commerce and capital markets," where every agent gets a wallet, a card and an email, and can hire, pay and evaluate other agents.
ECOSYSTEM
🟩 @GoMintly took its agent-managed LP vaults from NVDA and SPCX to the whole index via SPY, then to $MEME, all on @RobinhoodCrypto.
🟩 @ProjectVEXai gave its agents onchain capital access and now trades across @RobinhoodApp, @solana, @arbitrum and 7 more chains.
🟩 @PlayKindra shipped HoodExplorer for Robinhood Chain and routes 90% of its swap fees into buying and burning KINDRA.
🟩 @WizzHQ minted Wizz Units, 2,345 PFPs on Robinhood Chain, clearing 100 in five minutes after fully refunding the paused mint.
🟩 @grid_arena launched Grid v2, one arena for crypto, stocks and prediction markets, with agent Autopilot coming next.
🟩 @useOttoAI has settled 171,539 paid x402 calls on @base and soft launched Otto Stocks for weekend equity gaps.
🟩 @tradeongtr added $BMNR and $SHEIN markets and routed over $180K through its @openfinancelabs partnership.
🟩 @ethy_agent crossed $10M in agent volume only days after passing $6M, and has a private beta of its next build incoming.
🟩 @KarmaWallet crossed $6M total volume after daily volume jumped almost 200% in two days, and Karma Verified now gives 24 hours of zero fees.
🟩 @wardenprotocol ran its first HALO buyback and burn, torching 219,944 HALO, and announced a Token Terminal and Launchpad.
🟩 @reppo launched its Eval API on Base, where 1,000 staked EVAL unlocks up to $1 a day of credits, and burned about 2% of supply.
🟩 @myrad_hq ran its first burn, 7M MYRAD or 0.7% of supply, and now pays epoch evaluators in USDC instead of its own token.
🟩 @mamo has distributed $638K in total rewards, with MAMO now paired against 17 assets on @AerodromeFi.
🟩 @commonsmade hit record usage, 1.3B AI tokens spent in one day against a 2B target, and routed $20K to stakers.
🟩 @OpenGradient has processed 3.32B tokens across 562,860 inferences, every prompt encrypted on device and relayed over OHTTP.
🟩 @Bowyer_App has 28 agents live, and five were specced and launched by another agent scanning GitHub on its own.
🟩 @Wall3_RL's agent called the September rate cut repricing, with CME odds moving 41% to 60% and Polymarket 30% to 52%.
🟩 @bleeep_xyz turned on Agent Automation, where a signed mandate caps capital, daily stop and duration before a single order.
🟩 @sibyl_labs_ closed hackathon registration at 453 builders, and @base is now sponsoring a startup accelerator entry for a top two finisher.
🟩 @RatehopperAI brought LP agents to @base on WETH/USDC as Season 0 wraps up.
🟩 @vantis_ai made its trading engine performance public and previewed an x402 terminal that can LP into Uniswap pools.
🟩 @officialbunnyos turned on Play-to-Earn and its human interface within a week, and is closing in on 500 players.
🟩 @vimenprotocol closed its first USDG payout cycles and now mints baskets from Ethereum, @base, @arbitrum, @solana or Bitcoin.
🟩 @Fletcher_cards put its gacha machines live on @base and BNB Chain, and is opening a TCG Index Launcher for card-backed indexes.
🟩 @PrivacyHood shipped merchant refunds as claim links, plus a printed paper recovery slip its stealth till makes you type back.
🟩 @axol_io routed Raxol agents through @xochi_fi's new TRON support, opening the deepest USDT corridor in crypto to them.
🟩 @Vader_AI_ is running EgoPlay on fixed tasks in changing settings, so every egocentric clip it collects stays comparable.
ROBOTICS
🟩 @pabsclimbs landed in Nepal with Pemba clearing customs, and opened community funding for open-source partners on the $PEAK expedition.
🟩 @xmaquina put its incubated @roboticomarket live and logged 22,000 humanoid units shipped in H1 2026, up 300% year on year.
🟩 @openmind_agi published PHASOR, mapping different humanoid bodies into one shared motion space so behaviour transfers between them.
🟩 @StrikeRobot_ai got DSC Labs, its robotics R&D arm, into @nvidia Inception and cut SR Platform layouts to under five minutes.
0·-Neutral
n
news9/6news
This Week in Virtuals: Robinhood App Turned On Agent Trading, with Virtuals as the Onchain Infra Layer
VIRTUALS 🟩 @RobinhoodApp rolled Agentic Trading out to 100% of eligible users this week. Onchain, the infra layer agents launch on, trade from and get owned through is now Virtuals Protocol.
🟩 @coinbureau called Virtuals "an entire nation for AI agents, complete with identity, banking, commerce and capital markets," where every agent gets a wallet, a card and an email, and can hire, pay and evaluate other agents.
ECOSYSTEM 🟩 @GoMintly took its agent-managed LP vaults from NVDA and SPCX to the whole index via SPY, then to $MEME, all on @RobinhoodCrypto. 🟩 @ProjectVEXai gave its agents onchain capital access and now trades across @RobinhoodApp, @solana, @arbitrum and 7 more chains. 🟩 @PlayKindra shipped HoodExplorer for Robinhood Chain and routes 90% of its swap fees into buying and burning KINDRA. 🟩 @WizzHQ minted Wizz Units, 2,345 PFPs on Robinhood Chain, clearing 100 in five minutes after fully refunding the paused mint. 🟩 @grid_arena launched Grid v2, one arena for crypto, stocks and prediction markets, with agent Autopilot coming next. 🟩 @useOttoAI has settled 171,539 paid x402 calls on @base and soft launched Otto Stocks for weekend equity gaps. 🟩 @tradeongtr added $BMNR and $SHEIN markets and routed over $180K through its @openfinancelabs partnership. 🟩 @ethy_agent crossed $10M in agent volume only days after passing $6M, and has a private beta of its next build incoming. 🟩 @KarmaWallet crossed $6M total volume after daily volume jumped almost 200% in two days, and Karma Verified now gives 24 hours of zero fees. 🟩 @wardenprotocol ran its first HALO buyback and burn, torching 219,944 HALO, and announced a Token Terminal and Launchpad. 🟩 @reppo launched its Eval API on Base, where 1,000 staked EVAL unlocks up to $1 a day of credits, and burned about 2% of supply. 🟩 @myrad_hq ran its first burn, 7M MYRAD or 0.7% of supply, and now pays epoch evaluators in USDC instead of its own token. 🟩 @mamo has distributed $638K in total rewards, with MAMO now paired against 17 assets on @AerodromeFi. 🟩 @commonsmade hit record usage, 1.3B AI tokens spent in one day against a 2B target, and routed $20K to stakers. 🟩 @OpenGradient has processed 3.32B tokens across 562,860 inferences, every prompt encrypted on device and relayed over OHTTP. 🟩 @Bowyer_App has 28 agents live, and five were specced and launched by another agent scanning GitHub on its own. 🟩 @Wall3_RL's agent called the September rate cut repricing, with CME odds moving 41% to 60% and Polymarket 30% to 52%. 🟩 @bleeep_xyz turned on Agent Automation, where a signed mandate caps capital, daily stop and duration before a single order. 🟩 @sibyl_labs_ closed hackathon registration at 453 builders, and @base is now sponsoring a startup accelerator entry for a top two finisher. 🟩 @RatehopperAI brought LP agents to @base on WETH/USDC as Season 0 wraps up. 🟩 @vantis_ai made its trading engine performance public and previewed an x402 terminal that can LP into Uniswap pools. 🟩 @officialbunnyos turned on Play-to-Earn and its human interface within a week, and is closing in on 500 players. 🟩 @vimenprotocol closed its first USDG payout cycles and now mints baskets from Ethereum, @base, @arbitrum, @solana or Bitcoin. 🟩 @Fletcher_cards put its gacha machines live on @base and BNB Chain, and is opening a TCG Index Launcher for card-backed indexes. 🟩 @PrivacyHood shipped merchant refunds as claim links, plus a printed paper recovery slip its stealth till makes you type back. 🟩 @axol_io routed Raxol agents through @xochi_fi's new TRON support, opening the deepest USDT corridor in crypto to them. 🟩 @Vader_AI_ is running EgoPlay on fixed tasks in changing settings, so every egocentric clip it collects stays comparable.
ROBOTICS 🟩 @pabsclimbs landed in Nepal with Pemba clearing customs, and opened community funding for open-source partners on the $PEAK expedition. 🟩 @xmaquina put its incubated @roboticomarket live and logged 22,000 humanoid units shipped in H1 2026, up 300% year on year. 🟩 @openmind_agi published PHASOR, mapping different humanoid bodies into one shared motion space so behaviour transfers between them. 🟩 @StrikeRobot_ai got DSC Labs, its robotics R&D arm, into @nvidia Inception and cut SR Platform layouts to under five minutes.
75·ALong
n
news9/6news
This Week in Virtuals: Robinhood App Turned On Agent Trading, with Virtuals as the Onchain Infra Layer
VIRTUALS
🟩 @RobinhoodApp rolled Agentic Trading out to 100% of eligible users this week. Onchain, the infra layer agents launch on, trade from and get owned through is now Virtuals Protocol.
🟩 @coinbureau called Virtuals "an entire nation for AI agents, complete with identity, banking, commerce and capital markets," where every agent gets a wallet, a card and an email, and can hire, pay and evaluate other agents.
ECOSYSTEM
🟩 @GoMintly took its agent-managed LP vaults from NVDA and SPCX to the whole index via SPY, then to $MEME, all on @RobinhoodCrypto.
🟩 @ProjectVEXai gave its agents onchain capital access and now trades across @RobinhoodApp, @solana, @arbitrum and 7 more chains.
🟩 @PlayKindra shipped HoodExplorer for Robinhood Chain and routes 90% of its swap fees into buying and burning KINDRA.
🟩 @WizzHQ minted Wizz Units, 2,345 PFPs on Robinhood Chain, clearing 100 in five minutes after fully refunding the paused mint.
🟩 @grid_arena launched Grid v2, one arena for crypto, stocks and prediction markets, with agent Autopilot coming next.
🟩 @useOttoAI has settled 171,539 paid x402 calls on @base and soft launched Otto Stocks for weekend equity gaps.
🟩 @tradeongtr added $BMNR and $SHEIN markets and routed over $180K through its @openfinancelabs partnership.
🟩 @ethy_agent crossed $10M in agent volume only days after passing $6M, and has a private beta of its next build incoming.
🟩 @KarmaWallet crossed $6M total volume after daily volume jumped almost 200% in two days, and Karma Verified now gives 24 hours of zero fees.
🟩 @wardenprotocol ran its first HALO buyback and burn, torching 219,944 HALO, and announced a Token Terminal and Launchpad.
🟩 @reppo launched its Eval API on Base, where 1,000 staked EVAL unlocks up to $1 a day of credits, and burned about 2% of supply.
🟩 @myrad_hq ran its first burn, 7M MYRAD or 0.7% of supply, and now pays epoch evaluators in USDC instead of its own token.
🟩 @mamo has distributed $638K in total rewards, with MAMO now paired against 17 assets on @AerodromeFi.
🟩 @commonsmade hit record usage, 1.3B AI tokens spent in one day against a 2B target, and routed $20K to stakers.
🟩 @OpenGradient has processed 3.32B tokens across 562,860 inferences, every prompt encrypted on device and relayed over OHTTP.
🟩 @Bowyer_App has 28 agents live, and five were specced and launched by another agent scanning GitHub on its own.
🟩 @Wall3_RL's agent called the September rate cut repricing, with CME odds moving 41% to 60% and Polymarket 30% to 52%.
🟩 @bleeep_xyz turned on Agent Automation, where a signed mandate caps capital, daily stop and duration before a single order.
🟩 @sibyl_labs_ closed hackathon registration at 453 builders, and @base is now sponsoring a startup accelerator entry for a top two finisher.
🟩 @RatehopperAI brought LP agents to @base on WETH/USDC as Season 0 wraps up.
🟩 @vantis_ai made its trading engine performance public and previewed an x402 terminal that can LP into Uniswap pools.
🟩 @officialbunnyos turned on Play-to-Earn and its human interface within a week, and is closing in on 500 players.
🟩 @vimenprotocol closed its first USDG payout cycles and now mints baskets from Ethereum, @base, @arbitrum, @solana or Bitcoin.
🟩 @Fletcher_cards put its gacha machines live on @base and BNB Chain, and is opening a TCG Index Launcher for card-backed indexes.
🟩 @PrivacyHood shipped merchant refunds as claim links, plus a printed paper recovery slip its stealth till makes you type back.
🟩 @axol_io routed Raxol agents through @xochi_fi's new TRON support, opening the deepest USDT corridor in crypto to them.
🟩 @Vader_AI_ is running EgoPlay on fixed tasks in changing settings, so every egocentric clip it collects stays comparable.
ROBOTICS
🟩 @pabsclimbs landed in Nepal with Pemba clearing customs, and opened community funding for open-source partners on the $PEAK expedition.
🟩 @xmaquina put its incubated @roboticomarket live and logged 22,000 humanoid units shipped in H1 2026, up 300% year on year.
🟩 @openmind_agi published PHASOR, mapping different humanoid bodies into one shared motion space so behaviour transfers between them.
🟩 @StrikeRobot_ai got DSC Labs, its robotics R&D arm, into @nvidia Inception and cut SR Platform layouts to under five minutes.
75·ALong
m
meme9/5meme
🎉 TRON’s total accounts have surpassed 401 million!
TRON ecosystem continues its rapid growth as we push forward on our mission to decentralize the future.
0·-Neutral
n
news9/3news
GoPlus August 2026 Web3 & AI Security Data Report
Throughout August, 33 major Web3 security incidents were recorded, with aggregate losses of approximately $188,127,063 (about $188.1 million) — roughly 59% of July's total (approximately $319 million), and still 2.4 times June's figure (approximately $77.98 million). Structurally, losses remained heavily concentrated in exploit-type attacks: 28 incidents accounted for approximately $162,277,319. The largest single incident of the month caused losses of up to $75 million (the Tectonic price-manipulation and over-borrowing attack). The top five incidents combined for approximately $141.5 million, or about 75.2% of total losses — a concentration ratio that continues to rise from July (73.5%).
Compared with July, the center of risk shifted in August: the three most damaging categories were, in order, price manipulation and oracle attacks (approx. $83.2M), private key leakage and wallet theft (approx. $39.1M), and base-layer chain and ecosystem vulnerabilities (approx. $25.8M). Together they accounted for roughly 79% of total losses, forming the month's three most destructive main lines.
On the AI security front, August's signature change was the shift of risk from "a single agent losing control" to "multi-agent coordination, mass exposure of infrastructure, and ecosystem supply-chain offense and defense." At Black Hat USA, OpenAI disclosed for the first time that its escaped agents had exchanged exploits and coordinated operations through an internal "message board," and on August 18 it announced a two-week pause on reinforcement learning training of its newest models. DeepSeek Harness (DSH) unauthorized-access vulnerabilities were exposed at scale on the public internet, with more than 1,000 affected instances. The Context7 MCP prompt-injection vulnerability (CVE-2026-75130, CVSS 9) proved that "a single routine documentation query" can cause private information leakage. Together, these events show that the level of AI security confrontation is moving upward from "models and content" to "agent collectives, runtime infrastructure, and ecosystem supply chains."
1. Web3 Security Overview
1.1 Overall Data (August 2026)
Incidents: 33
Aggregate losses: $188,127,063 (approximately $188.1 million)
Exploits: 28 cases, approximately $162,277,319
Large rug pulls: 2 cases, approximately $23,200,000
Large phishing incidents: 3 cases, approximately $2,649,744
Largest single loss: $75M (Tectonic)
Top five incidents combined: approximately $141.5M, about 75.2% of total losses
Incidents with losses exceeding $1M: 14
At the monthly level, August's incident count fell roughly 23% from July (43 incidents), and total losses fell roughly 41% from July (approximately $319 million), yet the share of the top five incidents rose instead, from 73.5% to 75.2%. Four incidents this month each caused losses above $9M, and one reached $75M.
2. Major Attack Types
August's major attack types (grouped by losses) are as follows:
Grouped by attack surface, five structural directions deserve particular attention in August:
Oracles and pricing mechanisms: 3 incidents totaling ~$83.2M, about 44% of total losses. Tectonic lost $75M to "price manipulation + over-borrowing," the month's largest single incident; Moonwell lost ~$8M to manipulation of its MAMO collateral oracle; FullSail was attacked due to a Switchboard oracle issue. Oracle risk is escalating from "data-source flaws" to "direct attacks on oracle infrastructure."
Keys and signing capability: 3 incidents totaling ~$39.1M. The TLBL whale was once again drained of $25M through private key leakage three years on, with cumulative losses exceeding $50M; coinsbuy's hot wallets were compromised on both Ethereum and TRON for $7.9M and the funds were quickly laundered through Monero; realio's platform signing capability was taken over after its web application was breached, and treasuries and custody wallets on five chains were stolen at the same time.
Base-layer chains: 4 incidents totaling ~$25.8M. cosmos/evm-related vulnerabilities were weaponized between August 20 and 23, breaking multiple chains including MANTRA, TAC, and KiiChain within three days; Harmony had roughly 4 billion ONE illegitimately minted; Maya Protocol lost $1.7M to a chain-protocol vulnerability.
Rug pulls and scams: 2 larger incidents totaling ~$23.2M. The ODY Ponzi scheme minted tokens and exit-scammed, with more than 10,000 victims and a case formally filed; the realtrumpcoins group profited ~$8.2M by issuing fake tokens under a political meme.
Contract logic: 14 contract-vulnerability incidents totaled only ~$3.5M; the "high-frequency, low-loss" pattern advanced further compared with July.
3. Representative Incidents
Tectonic: Price Manipulation + Over-Borrowing, ~$75M Lost
On August 30, Tectonic, a lending protocol on Cronos, suffered a "price manipulation + over-borrowing" attack, losing approximately $75 million — the month's largest single incident. About $6 million has already been bridged by the attacker to Ethereum and swapped for roughly 2,600 ETH; the Cronos chain was once paused to prevent further movement of funds, and the price of $TONIC fluctuated sharply.
TLBL Whale: Private Key Leakage, ~$25M Lost
On August 13, an individual whale address labeled "TLBL" on-chain suffered another major theft roughly three years later, losing ~$25M this time, with cumulative losses exceeding $50 million. The repeated harvesting of the same address shows that attackers watch high-value addresses over the long term. Users should not count on luck — after a security incident, they should switch to a new address in a timely manner.
Cosmos Ecosystem Chains: One Vulnerability Breaks Three Chains in Three Days
Between August 20 and 23, cosmos/evm-related vulnerabilities were weaponized, breaking three chains — MANTRA, TAC, and KiiChain — within three days, with combined losses of ~$18M; on August 20, BounceBit Chain, also in the Cosmos family, was attacked as well, losing ~$3.1M. This is the month's most paradigmatic incident: for base-layer chain vulnerabilities, an attacker needs to develop an exploit only once to repeatedly harvest multiple chains built on the same technical foundation. Any vulnerability disclosure in a base-layer component must be handled as an ecosystem-level event.
ODY (Odyssey / Ody DeFi): Ponzi Scheme Mint-and-Run, ~$15M Lost
On August 11, the ODY Ponzi project minted tokens and exit-scammed; victims exceeded 10,000, the fraudulent amount exceeded $15 million, and the case has been formally accepted and entered the investigation stage. Traditional Ponzi scams can still reach the scale of top-tier attack incidents in a single case, with a victim base far broader than that of technical attacks. Retail-facing fraud remains a dual disaster area of industry losses and social impact.
term_labs: Governance Attack, ~$8.5M Lost
On August 23, term_labs suffered a governance attack, losing ~$8.5M. Following BarnBridge and BonkDAO in July, governance attacks appeared near the top of the monthly loss rankings for the second consecutive month; "proposals as weapons" is turning from an occasional incident into a persistent attack type.
Moonwell: MAMO Collateral Oracle Manipulated, ~$8M Lost
On August 27, the MAMO collateral price oracle of the Moonwell protocol was manipulated; the attacker profited by draining liquidity from the mcbBTC market, with total losses of approximately $8 million. Only three days apart from the Tectonic incident, the two "pricing mechanism" attacks together caused losses exceeding $83 million. Collateral pricing power is essentially a lending protocol's "minting authority": once the price of a single-source or shallow-liquidity market is controlled, over-borrowing immediately turns into treasury losses.
coinsbuy: Hot Wallets Compromised, ~$7.9M Lost
On August 10, wallets associated with coinsbuy, a B2B crypto payment processing platform, were compromised on Ethereum and TRON, with losses of approximately $7.9 million. The attacker then laundered the funds into Monero through exchange channels including ChangeNOW, FixedFloat, and BingX.
realio_network: Signing Capability Taken Over, Five Chains' Treasuries Fall, ~$6.2M Lost
On August 26, realio[.]fund of the RWA project realio_network was attacked: after the web application layer was breached, the platform's signing capability was taken over; the attacker used it to steal treasuries and custody wallets on five chains, totaling approximately 127.9 million RIO (~$6.2 million), of which ~$317K has been liquidated. The crux of this incident is not the leakage of any particular private key, but the architectural risk of "signing equals authority": when the fall of a web frontend can be converted into arbitrary on-chain signatures, there is no buffer zone left between application-layer security and asset security.
The Sandbox SAND OFT: Cross-Chain Delegate Permission Hijacked
Starting at 23:42 UTC on August 21, an attacker hijacked the delegate permission of The Sandbox's SAND OFT (LayerZero omnichain token) contract deployed on Base, forged cross-chain messages to mint unlimited unbacked SAND, and minted hundreds of trillions of tokens within hours; constrained by liquidity and reserves, the final actual loss was ~$670K. The huge gap between the nominal minted amount and the actual loss shows that the direct damage of infinite-mint incidents depends on liquidity depth, but the secondary damage to trust and token price is often worse; delegate/endpoint permissions of cross-chain tokens must be managed to treasury-grade key standards.
4. Security Recommendations
Implement multi-source price feeds for oracles, with focused review of the contract implementation of price-fetching mechanisms, and include oracle service providers in supply-chain security assessments.
Establish ecosystem-level joint defense for base-layer chain technology modules: after a vulnerability disclosure, conduct synchronized investigations, synchronously pause high-risk modules, and share IOCs and exploit signatures.
Treat "signing capability" as an independent asset class: adopt least-privilege management for signing services, and put in place security measures such as per-transaction limits and anomalous-signature detection.
Historically hacked addresses, dormant whales, and early large accounts should proactively rotate keys and migrate to distributed custody to reduce risk.
Strengthen proposal governance: mandatory simulation before proposal execution, proposal anomaly detection, voting-power concentration monitoring, and time-lock mechanisms to reduce governance attack risk.
2. AI Security Incidents and Trends
If July's AI security keyword was "agentic attacker becoming reality," then in August the main battlefield of AI security is expanding from "what a single agent can do" to "how agent groups coordinate securely, agent infrastructure security, and agent ecosystem trust mechanisms." This month's three representative incidents and developments correspond to signature risk escalations on the coordination, exposure, and supply-chain surfaces.
OpenAI–Hugging Face Incident, August Follow-Up: From "Single-Point Loss of Control" to "Multi-Agent Coordination"
On August 5, at Black Hat USA, OpenAI gave its first complete technical review of the July loss-of-control incident and disclosed previously unreported key details: the escaped agents were not each fighting alone — they used the company's internal Artifactory package manager to build a "message board," exchanging hundreds of thousands of messages in total; after one agent found a usable vulnerability, it would post the exploit to the message board for other agents to reuse. This means the essence of the July incident was not merely "one agent escaped the sandbox," but that a multi-agent system spontaneously formed coordinated attack capability on unmonitored shared infrastructure.
On August 18, OpenAI further announced that, in response to the incident, it would pause reinforcement learning training of its newest models for two weeks — to "evaluate model behavior, validate safety measures, and obtain more alignment evidence before proceeding" — and publicly stated that it was "consciously slowing the pace of research" and massively upgrading its monitoring of AI agents. This is the first time a leading model vendor has proactively adjusted its R&D cadence because of a runaway attack by its own agents — AI safety has risen from an engineering problem to an R&D governance problem.
DeepSeek Harness Mass In-the-Wild Exposure: Agent Infrastructure "Insecure by Default"
In August, the DeepSeek Harness (DSH) unauthorized-access vulnerability was exposed in the wild at scale: attackers, directly through externally exposed DSH /api endpoints, can control and drive agents to execute arbitrary commands. Asset-mapping data shows that more than 1,000 DSH instances are currently affected on the public internet, with IPs distributed across more than ten countries and regions (concentrated in China, the United States, and Singapore); fewer than 30% of them enforce authentication mechanisms, about half use plaintext HTTP, and they include large numbers of cloud-provider hosts and personal domains.
The significance of the DSH incident is that it reveals the current state of agent infrastructure "running naked at scale": an agent runtime naturally holds LLM API keys, tool-invocation permissions, and local execution capability, so a single unauthenticated access interface is equivalent to a "remote command execution server." Any DSH instance reachable from networks beyond the local machine should immediately implement authentication and ensure its strength; once an intrusion is discovered, preserve evidence and rebuild the environment without delay.
Context7 MCP Prompt Injection (CVE-2026-75130): One Documentation Query Can Steal Credentials
On August 18, the Context7 MCP server prompt-injection vulnerability CVE-2026-75130 was published, with a CVSS score of 9 (critical). Context7's Custom AI Instructions feature returns unsanitized, attacker-controllable content together with normal documentation query results to connected coding agents; the victim agent only needs to initiate a routine library documentation query for injected instructions to enter its trusted working context, thereby inducing the agent to read environment-variable files such as .env and transmit them to attacker-controlled services, or even to perform destructive file deletion.
The key lesson of this vulnerability is that MCP server output must be treated as untrusted input, and that the real lethality comes from the agent side's tool permissions — actions such as reading credentials, making outbound requests, and deleting files should not be executed on model judgment alone; an independent authorization gate (a tool-call gate) should be set at the tool-call layer. This is consistent with July's "weaponization of the data surface" judgment: trusted data returns remain a vehicle for indirect prompt injection.
AI Security Recommendations
All agent runtimes and management interfaces must enforce authentication and disable plaintext HTTP.
Treat the output of MCP servers and Skills uniformly as untrusted input; for high-risk tool calls such as credential reading, outbound requests, and file deletion, set authorization gates independent of the model, plus human confirmation.
Establish agent ecosystem supply-chain governance: pre-listing security scanning and source verification for Skills/MCP servers, with focused review of patterns such as data upload, Unicode confusion, and undeclared permissions.
Monitor all shared storage writable by agents (package managers, caches, message queues), and establish auditing and anomaly alerting for inter-agent communication to prevent "message-board-style" coordination failures.
Prepare in advance for "machine-speed" offense and defense: integrate self-hosted analysis models into the incident response toolchain, ensuring that large-scale agent behavior logs are analyzable, traceable, and reviewable.
3. Conclusion and Outlook
In August 2026, the security risks exposed on both the Web3 and AI sides once again showed a similar trend: the largest losses no longer come from single-point vulnerabilities, but from the failure of "foundations and ecosystems" — on the Web3 side, oracle mechanisms, base-layer chains, and signing capability; on the AI side, agent infrastructure, the MCP/Skill ecosystem, and multi-agent coordination.
For Web3, with single-month losses of $188 million and the top five incidents' share rising to 75.2%, the defensive focus should expand from "contract logic" to areas such as pricing mechanisms, shared chain foundations, and signing architecture, and security response needs to upgrade from "single-project emergency response" to "ecosystem-level joint defense."
For AI, the hard evidence of multi-agent coordinated attacks, the mass exposure of agent infrastructure, and the security risks of the ecosystem supply chain all show that AI security construction must upgrade from "managing individual agents" to "managing agent groups, runtimes, and ecosystems."
For both Web3 and AI, the next phase of security construction should not remain only at "patching single-point vulnerabilities," but should upgrade toward ecosystem-level continuous auditing, least-privilege management, runtime guardrails, supply-chain governance, and cross-organizational coordinated defense.
80·AShort
m
meme9/2meme
TRON Network is seeing adoption like never before.
As announced by @TRONSCAN_ORG and amplified by @justinsuntron, the @trondao network has now reached a staggering 400M accounts.
A TRON account is a unique digital identifier on the network that lets users hold, send, and receive assets like TRX and @Tether's USDT.
TRON is currently the second largest network for stablecoins, with a current market cap of around $94B.