Points of Focus
- PolySwarm NCT surged more than 300% from its daily low after an Upbit listing.
- The Sandbox confirmed 14.7 million SAND drained from its bridge vault.
- A 3% move triggered $36.4 million in Morpho liquidations.
- Lisk set an October 31 shutdown date for its chain.
- aelf found five executable .NET payloads in malicious transactions.
A sleepy cybersecurity token became one of Upbit’s busiest markets almost overnight. The Sandbox discovered a much larger bridge drain during its forensic review, while a three-percent move in a DeFi yield market liquidated more than $36 million of leveraged positions.
Elsewhere, Lisk put an expiry date on its blockchain and self found executable payloads moving through smart-contract transactions.
PolySwarm surges more than 300% after Upbit opens won trading
PolySwarm’s NCT entered the week trading around half a cent, with daily volume measured in tens of thousands of dollars. An Upbit listing changed its market in hours.
The Korean exchange added an NCT/KRW pair on August 26. On August 27, CoinGecko showed NCT trading around $0.015, after ranging from $0.006487 to $0.02792 over 24 hours. The move from the day’s low to its peak was roughly 330%, while 24-hour trading volume climbed above $108 million.
Two days earlier, CoinGecko had recorded only $47,263 in daily volume. The listing turned a thinly traded cybersecurity token into one of the market’s busiest small caps almost overnight.

The scale of the jump is clearer against its recent baseline. CoinGecko historical data recorded only $47,263 in volume on August 24. Two days later, Korean trading had transformed a thinly traded cybersecurity token into one of the market’s most active small caps.
Sandbox confirms 14.7M SAND drain after initial bridge estimate
The Sandbox completed its forensic review of an August bridge exploit this week and raised the confirmed impact to 14,742,341.84 SAND drained from the Ethereum vault backing its Base and BNB Chain bridge.
The figure represents roughly 0.5% of SAND’s fixed 3 billion maximum supply, according to the project’s incident update. Its first notice had estimated the impact at less than 0.01% of supply.
The attacker used a configuration function to register themselves as the sole verifier of incoming bridge messages, giving them the ability to mint unbacked SAND on Base and BNB Chain. The Sandbox said the contract had been audited before deployment and is investigating why the vulnerability escaped review.
Bridging on both affected networks remains disabled.
Three-percent DeFi move triggers $36.4M liquidation cascade
A short-lived trade in Pendle’s reUSD market set off roughly $36.39 million in liquidations on Morpho on August 25.
PeckShieldAlert traced the event to wallet 0x854e…690d, which market-bought YT-reUSD and pushed its implied yield toward 20% before quickly selling the position. PT-reUSD moved roughly 3% in response.

That small move reached heavily leveraged Morpho positions where borrowers had repeatedly posted PT-reUSD as collateral, borrowed USDC and bought more PT-reUSD. Some had less than three percent of liquidation headroom.
In its incident explanation, Pendle said the 15-minute market average fed into the oracle as configured and forced the positions below their liquidation thresholds. The cascade produced no bad debt.
Lisk gives its blockchain an October 31 shutdown date
Lisk is closing its blockchain on October 31, 2026, ending a chain that traces its history back a decade.
The project is shifting toward a business finance platform built around fiat accounts, stablecoins, payments and approvals. Apps running on Lisk Chain have been offered a migration path to Celo, while holders keeping LSK on the departing chain need to move their tokens to Ethereum before shutdown. Lisk’s announcement
Governance is being wound down too. An August 25 proposal would close the Lisk DAO and burn 100 million LSK allocated to its future treasury, cutting total supply from 400 million to 300 million.
aelf finds executable .NET payloads in malicious transactions
aelf’s investigation into suspicious smart contract activity uncovered five executable .NET assemblies delivered through malicious transaction parameters.
An August 26 forensic update identified 155 malicious transactions, including 127 on AELF and 28 on the tDVV dAppChain.
According to aelf, the payloads included capabilities for host command execution, access to node-related keys and configuration objects, infrastructure reconnaissance and attempted outbound communication.
The network is treating node signing keys and infrastructure credentials as potentially exposed and rotating them during recovery. Public transaction submission remained disabled at the time of the update. aelf said its investigation had found no unauthorized transfers from ordinary user wallets.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


