GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Liquidity Collapses After Attack, Solana Tokenized Silver Project Dominion Announces Shutdown

Odaily News: Solana tokenized silver project Dominion has announced its shutdown. The team stated that a September security incident led to a large amount of SILV being exploited and sold off, followed by a liquidity collapse, loss of operating capital, and damage to market structure. The capital required for rebuilding now exceeds the project's remaining resources. Dominion has allocated most of its remaining liquid funds to a refund plan, allowing eligible pre-attack SILV holders to exit at $63 per token. SILV was originally designed as a Solana token backed 1:1 by physical silver, with each token corresponding to 1 troy ounce of silver. On September 11, attackers gained control of its 3/5 multisig keys and dumped approximately 46,900 SILV into a DEX with thin liquidity. The notional value before the attack was approximately $3 million, but only about $238,000 was ultimately cashed out.

Base Vault Suffers ~$6M Exploit, Still Holds $31.7M in Assets

Odaily reports: Gonçalo Magalhães, Head of Security at Immunefi, stated that an unnamed Base vault suffered an approximately $6 million exploit, while still holding around $31.7 million in assets at the time of the incident. According to a briefing, the attacker used a Safe multisig wallet to add a malicious contract to the vault's lending whitelist, then withdrew 1,783 aBaswstETH and swapped it for approximately 1,783 wstETH via AaveV3. Gonçalo Magalhães noted that while whitelisted addresses may appear secure, approved addresses can withdraw assets without collateral, constituting a vulnerability; this whitelist weakness had been discovered the previous week, but researchers lacked a clear disclosure channel. More than 24 hours after the incident, no team had publicly claimed responsibility or disclosed remediation measures.

$4 Million in Assets Suspected Stolen, @frogmanhaha Wallet Dispersed Funds to ETH, BNB, and SOL Approximately 5 Hours Ago

Odaily News — According to on-chain analyst Yu Jin's monitoring, trader @frogmanhaha's wallet (0x14...5794, 9wMS...ov8z) was suspected of being hacked approximately 5 hours ago, with 9 types of assets worth about $4 million transferred, sold, and swapped into ETH, BNB, and SOL, then dispersed through tools such as Privacy Cash and Chainflip. The stolen assets mainly include 1.43 million BP, worth approximately $1.77 million; 13.96 million MarsCoin, worth approximately $1.55 million; and 3.7 million Cash Cat, worth approximately $510,000.

Trump Faces Bipartisan Criticism After Calling Iranian Attack on Los Angeles "A Small Price"

Trump defended the cost of war, claiming that Iran's attack on the U.S. West Coast was merely a "small price," sparking strong bipartisan opposition in California and prompting an urgent clarification from the White House.

US Government Transfers 264.863 BTC Seized in Bitfinex Hacking Case to New Address

According to on-chain monitoring, the U.S. government has just transferred funds seized in the Bitfinex hacker case, with approximately 264.863 BTC (worth around $22.87 million) moved to a new address.

Loss of approximately $538,000: A dormant MakerDAO liquidation bot proxy was drained of 200 WETH

a new address funded via Tornado Cash extracted 200 WETH on October 6 from a dormant MakerDAO ETH-A liquidation bot proxy, causing losses of approximately $538,000. The upgradeable proxy had won 4 ETH-A liquidation auctions in 2020, namely auctions #1457 through #1460, earning 50 WETH each, but never called deal(), leaving the collateral stuck in the Flipper. The implementation contract's exit function was not protected by ds-auth, allowing any caller to trigger it: first calling deal() on the aforementioned old auctions, then transferring the collateral to the keeper via Vat.flux, and subsequently calling GemJoin.exit to send the 200 WETH to a caller-specified address and unwrap it into ETH. The MakerDAO core contracts operated as designed; the vulnerability lies in the third-party bot's exit function lacking access controls.

Qilin ransomware gang core member arrested in Japan and extradited to Germany, involved in extorting approximately $165,000 in Bitcoin

Odaily News: A 28-year-old Russian national identified as a core member of the globally notorious ransomware gang Qilin was arrested in Japan and lawfully extradited to Germany on October 2. Reports state that the man is suspected of illegally breaching a German logistics company's systems in September 2024, encrypting its data, and demanding and extorting approximately $165,000 (about 26 million yen) in Bitcoin. Investigations show that within the Qilin criminal network, he was responsible for building attack systems and received a proportional cut of the ransom payments collected by various affiliate execution teams.Japanese police took him into custody in late May of this year while he was traveling in Osaka, and he was subsequently handed over to German authorities after the Tokyo High Court ruled that the conditions for extradition were met. Qilin operates on a "ransomware-as-a-service" (RaaS) model and previously claimed responsibility in 2025 for a cyberattack on Japan's Asahi Group. (Nada News)

AI security company Hadrian completes $40 million funding round, co-led by SmartFin and others

Odaily News: AI security platform Hadrian has announced the completion of a $40 million funding round, co-led by Forgepoint Capital International and SmartFin, with participation from existing investors including HV Capital, Motive Partners, Picus Capital, and Oetker Ventures.Following this funding round, Hadrian's cumulative funding has reached $65 million. The funds will be used to expand into European and American markets, grow its engineering and research teams, and further develop its AI-driven cybersecurity platform.Hadrian states that with the rapid advancement of AI technology, cyberattack methods are evolving — attackers are beginning to use AI agents to automate attack processes, while many enterprise security teams still rely on manual penetration testing. The company cites data showing that 87% of organizations still use manual penetration testing, and more than 70% of security teams struggle to determine whether vulnerabilities are truly exploitable.Hadrian combines Continuous Exposure Management with AI agent penetration testing to simulate an attacker's perspective for enterprises, helping them discover external attack surfaces, verify real risks, and optimize remediation priorities. (businesswire)

CertiK Report: From Assistive Tools to "AI Employees," Agentic AI Reshapes Security and Compliance Work

Odaily News — Web3 security firm CertiK today officially released its Intel3D report, "The Rise of AI Employees: How Agentic AI Is Reshaping Cybersecurity, Anti-Money Laundering, and Compliance." The report notes that AI is transitioning from an assistive tool that helps analysts identify issues to a member of the working team capable of conducting investigations, making judgments, and executing remediation tasks within defined permissions. This shift is reshaping security and compliance processes across traditional finance and Web3, and is also raising new requirements for how enterprises supervise AI, define permission boundaries, and allocate responsibility.The report also cautions that model misjudgments, prompt injection, and adversaries' exploitation of AI may introduce new risks. As AI begins to hold and trade digital assets, its own behavior must also be subject to audit. CertiK recommends that enterprises establish governance mechanisms covering permission boundaries, human approval, decision records, and division of responsibilities, and conduct regular red-team testing; these mechanisms must be improved in tandem with AI's execution capabilities to support "AI employees" in continuously creating value for security and compliance work under supervision and accountability.

ZachXBT Goes Undercover in Lazarus Group-Linked Money Laundering Ring: Invested Nearly $3.5 Million in OTC Trades with Counterparty Using the Alias Jimmy Green

Odaily News: On-chain detective ZachXBT posted on X that he once posed as a client to infiltrate a criminal group suspected of laundering money for the North Korea-backed hacker organization Lazarus Group, and assisted in freezing funds related to the 2025 Bybit attack.ZachXBT stated that after Bybit suffered a $1.5 billion attack in February 2025, he discovered that more than 15 accounts in public Telegram and Discord groups were seeking help processing transactions related to the stolen funds. He subsequently contacted one of the Telegram users using the alias "Jimmy Green" and built trust through multiple transactions. According to his disclosure, on March 6, 2025, he transferred $3.497 million in USDC to an Ethereum address for a USDC-to-TRON-chain USDT exchange transaction with the counterparty. The source of gas funds for that address can be traced back to the Bybit attack funds and was publicly flagged as a Bybit attack blacklisted address.ZachXBT said that in subsequent communications, the counterparty revealed that their team had been involved in processing the stolen Bybit funds and disclosed in advance that the funds would be moved across chains including Solana. By matching transaction timing, amounts, and on-chain data, he identified a wallet cluster involving more than $12 million in Bybit attack funds, with fund paths spanning multiple networks including BTC→ETH→SOL→TRON. Approximately 442,000 USDT was frozen by Tether, and the group also attempted to launder money through Uniswap liquidity pools and low-liquidity tokens. Additionally, the counterparty disclosed having helped other clients process approximately $3 million in fraudulent proceeds, and ZachXBT traced the related funds to wallets associated with the sanctioned Huione Guarantee.ZachXBT revealed that in this investigation, he initially invested $3.497 million and bore a loss risk of approximately 5% per transaction. The intelligence ultimately obtained was provided to relevant investigative agencies and law enforcement authorities at the earliest opportunity. Since 2022, he has assisted in freezing over $75 million in funds related to North Korea-linked incidents.

Drift Foundation: DFX is not pegged to 1 USDT; the current recovery pool covers only approximately 1% of claims.

The Drift Foundation has outlined the compensation plan following the protocol hack: users will receive 1 DFX token for every 1 USDT lost, with redemption amounts depending on the recovery pool balance that currently covers only about 1% of total claims; Tether has committed to providing up to $127.5 million USDT to support protocol restart and user compensation, with funds matched against Velocity's net protocol revenue rather than disbursed as a lump sum; the claims deadline is January 1, 2028, allowing users to choose to hold DFX or trade it on secondary markets such as Raydium, with the only official link being dfx.drift.trade.

Drift Hack Victims Begin Redemptions, $3.11M Recovery Pool Pays Out Only About 1 Cent per Dollar

victims of the Drift hack, a perpetual contract exchange on Solana, began filing claims on October 1. The recovery pool's initial funding stands at approximately $3.11 million against nearly $295.4 million in verified losses. Victims can redeem USDT through DFX tokens, with each $1 of loss converting to roughly 1.04 cents at launch, meaning a $1,000 loss corresponds to about $10.40.The total supply of DFX is fixed at 299,500,810.998 tokens, with each token corresponding to $1 of verified loss from the April incident, and no additional tokens will be minted. Holders can choose to burn DFX to redeem USDT, sell on secondary markets such as Raydium, or continue holding their claims. Completed redemptions are irreversible, and unclaimed tokens will expire after the claims window closes on January 1, 2028.Future funding for the recovery pool includes a portion of daily net protocol revenue from Velocity, the rebranded exchange rebuilt by Drift, up to $127.5 million in USDT committed by Tether, $20 million in USDT committed by strategic partners, and recovered stolen assets. On the first Friday after claims opened, approximately 216,480 DFX tokens were redeemed for about 2,250 USDT, with Velocity's first revenue transfer amounting to 31 USDT; approximately 13,025.9 ETH is spread across 4 Ethereum wallets, another approximately 2,309.4 ETH passed through Tornado Cash, and about $9.2 million in assets have been frozen at other addresses. (Bitcoin.com News)

Over $6 Million in Assets Stolen from Base Anonymous Multisig Vault, 7 Signer Identities Unknown

A crypto asset vault on Base had approximately 1,783 wstETH transferred out on October 4, resulting in losses exceeding $6 million. On-chain records show that the vault is controlled by a 3-of-7 Safe, and the identities of the seven signers have not yet been made public.Security firms stated that the attacker borrowed aBaswstETH from the vault and swapped it for wstETH through Aave. Neither the Base chain itself nor Aave's core contracts have been identified as being exploited, and the specific authorization vulnerability remains unconfirmed. (Bitcoin.com News)

Safe early investor Greenfield has filed a complaint with Swiss regulators, alleging that a foundation director used tokens to threaten and exert pressure.

Greenfield Capital has filed a complaint with the Swiss federal foundation regulator ESA regarding governance issues at the Safe Ecosystem Foundation, alleging that Safe Foundation directors instructed personnel to hand over a substantial amount of SAFE tokens following the Bybit hack, and threatened to force Gnosis to sell its holdings—which account for approximately 10% of the total SAFE supply—and sever ties with Safe.

Near Intents Recovers $3.8 Million in Stolen Funds, Ends Investigation

Odaily reports: Cross-chain swap service Near Intents announced that the $3.8 million in funds stolen in a previous exploit has been fully returned, and the team has closed its investigation. Near Intents General Manager Alex Shevchenko had previously issued a 48-hour return deadline to the attacker, providing Bitcoin, BNB, Ethereum, and Solana addresses.The attacker acknowledged wrongdoing in an on-chain message, stating that all funds had been returned and urging others to report issues through the bug bounty program. The incident stemmed from a vulnerability in the interaction between its Omni deposit and withdrawal layer and the main smart contract. Near Intents had suspended services and promised full compensation to users. (Decrypt)

24 accounts hacked, 6.61 BTC stolen; Blink releases attack post-mortem and offers a bounty of up to 3.3 BTC

Odaily News: According to Bitcoin News monitoring, Blink has released a full post-mortem of the September 19 attack: the attack resulted in the theft of a total of 6.61 BTC from 24 customer accounts. The company stated that the vulnerability had existed since October 2023, and any user with a free Blink account could potentially exploit it to gain customer-service-level privileges, take over customer accounts, and raise withdrawal limits. The attacker also obtained partial information from 3,817 accounts, including some phone numbers and email addresses; names, identity documents, addresses, passwords, and seed phrases were not leaked.None of the 24 stolen accounts had two-factor authentication enabled. The attacker attempted 18 withdrawals from 9 accounts protected by two-factor authentication, all of which failed. Blink shareholders have fully reimbursed all affected customers.About 5 of the stolen BTC were subsequently transferred through a cross-chain swap service. Blink is now offering a recovery bounty of up to approximately 3.3 BTC, with half of any successfully recovered funds to be distributed to those who provide valid leads and to the Bitcoin circular economy.

GoPlus: A User Suffers Address Poisoning Attack, Losing Approximately $305,000 in DAI

Odaily report: According to GoPlus Security monitoring, a user fell victim to an address poisoning attack, losing approximately $305,000 in DAI. The attacker generated a fake address with the same prefix and suffix as the victim's intended transfer address, and sent small amounts of dust funds to the victim to trick them into incorrectly copying the address from their transaction history. GoPlus Security stated that such attacks have achieved automation in target discovery, address forgery, and money laundering through mixers. Users should verify the full address and conduct a small test transaction before making large transfers.

A vault on the Base chain was hacked, with losses expanding to approximately $6 million.

According to Spot On Chain monitoring, a vault on the Base chain was attacked, with losses expanding to approximately $6 million, involving around 1,783 wstETH. The attacker added a new contract to the vault's whitelist, borrowed aBaswstETH, and transferred it to an attacker-controlled contract.

Losses Expand to Approximately $6 Million, Base Chain Vault Suffers Attack

According to Spot On Chain monitoring, the losses from the vault attack on Base chain have expanded to approximately $6 million, involving about 1,783 wstETH. The attacker added a new contract to the vault's whitelist, borrowed aBaswstETH from the vault, and transferred it to the attacker's contract. The attacker's address is a certain address. Spot On Chain stated that systemic risk is currently limited, but caution is needed regarding the potential short-term pressure on the peg of liquid staking tokens caused by the attacker selling off wstETH.

Approximately $2.02 Million in Assets Stolen, Vault on Base Chain Under Attack

According to Blockaid monitoring, a vault on the Base chain is currently under attack. The attacker added a brand-new contract to the vault's whitelist, then borrowed aBaswstETH and transferred it to the attacker's contract. The attack is still ongoing, and approximately 4 transactions have resulted in about $2.02 million in assets being stolen.