GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Gate Security Team Alerts Users to FomoPeek App Risks

Odaily News: According to monitoring and analysis by the Gate security team, the FomoPeek App contains malicious code with high security risks. It may exploit iOS system vulnerabilities to attack other apps and is capable of dangerous operations such as accessing the clipboard, scanning sensitive phone data, and obtaining login credentials. Based on the security team's analysis, no attack losses caused by the FomoPeek App have been found among Gate App or its users so far, and Gate's existing risk control mechanisms are operating normally.Gate reminds users to upgrade their iOS system to the latest version as soon as possible and check whether the FomoPeek App is installed on their devices. If it is already installed, please uninstall it immediately and restart the phone. After that, it is recommended to log in again to the Gate App and other important applications; if using a Web3 wallet, it is advisable to promptly check the wallet's security status and transfer relevant assets if necessary to reduce potential security risks.

Fetch.ai and NuNet Hacked, Losing Approximately $2 Million

According to PeckShield monitoring, the same attacker transferred approximately 8.7 million FET from Fetch.ai, worth about $1.53 million, and illicitly minted around 408.5 million NTX on NuNet, valued at approximately $462,700. As a result, the NTX price dropped by roughly 65%. Currently, the attacker has converted part of the involved assets into approximately 546.36 ETH, worth about $1.44 million.

An attack cluster stole $1.54 million in FET from the Fetch AI token converter and obtained $452,000 in NTX, with cumulative involvement of approximately $2.01 million

According to Onchain Lens monitoring, an attack cluster transferred approximately $1.54 million worth of FET from the Fetch AI token converter on Ethereum; the cluster also received approximately $452,000 in newly minted NTX from the Nunet Global deployer. As of now, the total confirmed amount involved is approximately $2.01 million.

Iran Conveys Three Ceasefire Conditions to the US, Awaits Trump's Response

Rezaei, Secretary of Iran’s Supreme National Security Council, stated that he has conveyed three conditions via Qatar to Washington: ending the war, releasing assets, and lifting the naval blockade, and is awaiting a response from the U.S. side. He also emphasized that Iran’s nuclear policy remains unchanged and warned that any attack would trigger strikes against U.S. military bases in the Middle East.

Blink Suspends Service to Investigate Security Incident

Bitcoin News posted on X that attackers accessed a small number of Blink custodial accounts and withdrew funds. Blink stated that the vast majority of funds remain safe, and non-custodial wallets were not affected; the Bitcoin payment protocol Spark, which it uses, supports multiple Lightning Network wallets, but it has not yet been confirmed that Spark was the source of this security incident.

Over $500,000 in Assets Stolen, Attackers Forge Uniswap-Related ENS Names to Execute Arbitrage Bot Scam

Odaily Report: According to on-chain detective Specter, the attackers behind this campaign provided so-called arbitrage bot tutorials and code through YouTube videos, and guided victims to use a counterfeit Remix development interface to compile and deploy contracts. The attackers registered ENS names containing "Uniswap" to disguise the related addresses as legitimate incoming fund sources from DeFi activity, leading victims to believe that the deployed arbitrage bot was profiting through Uniswap. After victims injected their own assets into the contracts, the funds were transferred away by the attackers. The attackers currently appear to still be active and hold a substantial portion of the stolen funds in two addresses.

ZachXBT Slams zkSNARKs: Calls It an Ordinals Scam, Raised $17 Million With Zero Practical Utility

On-chain analyst ZachXBT (@zachxbt) disclosed that the recently launched 10K PFP NFT project zkSNARKs on the Zcash chain is allegedly a rug pull. The project attracted a total of 16,971 bids via a blind auction, ultimately completing the allocation of 8,000 items at a clearing price of 1.5 ZEC (approximately $2,190). Total trading volume reached 25,305 ZEC (approximately $36.94 million), and refunds totaling 13,309 ZEC (approximately $19.43 million) have been progressively returned. ZachXBT noted that the project raised approximately $17 million, while incorporating a 10% team allocation, 5% royalties, and a minting fee of around $2,000, yet offered zero utility. This mirrors the typical "rug pull" strategy commonly seen in Ordinals-style projects.

SlowMist Warning: FomoPeek App v1.1-1.2 contains malicious code that can steal user private keys and assets.

慢雾安全团队(@SlowMist_Team)与 OKX 安全团队联合调查,FomoPeek App 1.1–1.2 版本被证实含有恶意代码。该应用内置 iOS 内核漏洞利用框架,共包含 8 种攻击方式,可根据设备型号及 iOS 版本自动选择攻击路径,成功后可逃逸 iOS 沙箱、解密 Keychain 数据,并读取其他应用文件,导致私钥、助记词、登录凭证、聊天记录等敏感信息泄露。受影响 iOS 版本为 12.0–18.7 及 26.0–26.1,攻击功能当前处于激活状态并定期自动运行。 已安装该应用的用户建议立即采取以下措施: 1. 检查账户及资产是否有异常活动 2. 在未安装过 FomoPeek 的可信设备上创建新账户并生成新私钥/助记词 3. 尽快将资产转移至新账户 4. 将设备 iOS 更新至最新版本 5. 停止使用并卸载 FomoPeek

CLARITY Act Stumbles in Senate, SEC and CFTC Continue Push for Crypto Regulation

According to Crypto in America, the US Senate failed to advance the crypto market structure bill known as the "Clear Act" this week with a 49-50 vote, with Democrats voting as a bloc against it and Republican Senators Collins, Hawley, and Moran joining the opposition. Following the setback, the focus of crypto regulation shifted from Congress to regulatory agencies: the SEC subsequently issued innovation exemption measures, paving a limited pathway for on-chain trading of tokenized US stocks, while the CFTC adopted a no-action stance regarding passive software providers and submitted a broader proposal for crypto market rulemaking to the White House. Meanwhile, Visa announced the closure of a loophole that allowed purchasing memecoins with credit cards in exchange for standard loyalty points, with related processors granted a grace period expected to expire next week. Some Democratic senators involved in the negotiations stated that the "Clear Act" is not "dead," with efforts to restart talks still underway.

Crypto tech service provider Haruko hit by cyberattack, 15 clients affected

Odaily News: Crypto technology service provider Haruko suffered a targeted cyberattack, with 15 clients affected. Read-only API information and trading data from some exchanges were leaked.Haruko stated that smaller hedge fund clients with weaker security controls may have lost a small amount of funds. The company has patched the vulnerability and updated its server-side keys. (CoinDesk)

Crypto technology service provider Haruko hit by targeted cyberattack, impacting 15 institutional clients

According to CoinDesk, London-based crypto institutional technology services provider Haruko was targeted by a cyberattack earlier this week, affecting a total of 15 clients. Attackers exploited vulnerabilities in Haruko’s infrastructure to extract user access tokens, gaining access to clients’ read-only exchange API information and trading data. A small amount of client funds were stolen, and smaller hedge funds with weaker security controls face a higher risk of loss. Haruko co-founder and CTO Adam Carlile confirmed that the attack specifically targeted Haruko itself. The vulnerability has been patched, and the company plans to release a complete technical post-incident report. Haruko serves over 80 institutional clients globally and connects to more than 100 centralized exchanges and 30 blockchains.

DeBot Reports Security Incident Update: Confirms APT Attack, Fund Isolation Ongoing

DeBot team member Cat has released a security incident update, confirming that the previous wallet security incident was an APT (Advanced Persistent Threat) attack. No related fund losses have been identified so far. According to the announcement, analyses by multiple security teams and cloud service providers revealed traces of intrusion in the system, and the relevant private keys remain at security risk. Therefore, the platform will continue to implement automatic fund isolation. Currently, DeBot is operating in a fully isolated environment. Users can still trade and withdraw normally, but other operations involving private keys have been suspended and will be gradually restored after the security audit is completed.A new security solution is being upgraded and is being audited by the SlowMist team and cloud service providers. DeBot stated that this incident exposed security issues in the project, and the team will further upgrade security measures.

Japan and U.S. Jointly Expose North Korean Hacker Campaign: 30,000 Devices Infected, Associated Wallets Received at Least $10.71 Million

Odaily News: Japan's National Police Agency, together with the U.S. FBI and other agencies, released a report stating that the North Korea-backed hacker group WaterPlum infected more than 30,000 devices across over 100 countries and regions worldwide between December 2025 and July 2026, stealing more than 7,000 pieces of crypto wallet information, with wallets under its control receiving at least approximately $10.71 million in crypto assets.The group's tactics include impersonating recruiters at crypto companies to trick job seekers into running malicious code to carry out attacks. Japanese police also for the first time seized a "laptop farm" within the country that assisted North Korean IT personnel in working remotely, and disclosed that a suspected North Korean IT worker had applied for an engineer position at bitFlyer but was not hired.

Dragonfly Partner Calls for Zcash Development Fund to End When It Expires in 2028

Odaily reports: Haseeb Qureshi, managing partner at crypto-focused venture capital firm Dragonfly, has proposed that under current rules, the Zcash development fund should cease operations after its expiration in 2028.Qureshi wrote: "I think this should be the last development fund." He stated that the current fund size is already sufficient to support Zcash's remaining development work, and as the fund's value approaches $100 million, it may face "politicization" risks in the future. According to ZecStats data, as of press time, the Zcash development fund holds 63,962 ZEC, worth approximately $95 million.These remarks come amid ongoing industry discussions about the growing size of the development fund. The previous rise in ZEC's price drove a significant increase in the fund's value. Some also argue that Zcash should continue to maintain the development fund. Paradigm founder Matt Huang said on Wednesday that against the backdrop of improving AI network attack capabilities and the rapid development of quantum computing, the fund is particularly important.

ZachXBT publicly questions the addresses implicated in the Raidparty $70 million rug pull incident.

According to on-chain analyst ZachXBT (@zachxbt), an address linked to user @7zarc previously received 4,870 ETH (approximately $15 million) from the $70 million Raidparty rug pull. These funds were subsequently transferred to a centralized exchange deposit address. ZachXBT noted that after @7zarc disappeared in 2022, he suddenly resurfaced in September 2026, and ZachXBT has publicly called on him to account for the movement of the funds.

Ethereum confirms Glamsterdam test date, developers warn of block builder attack risks

According to CoinDesk, Ethereum plans to launch Glamsterdam upgrade testing on the Sepolia testnet on October 6. Developers have warned that attackers could exploit free testnet ETH and numerous temporary block builder identities to win block auctions at high prices and then refuse to submit transaction payloads, thereby disrupting the testing process. This risk will not affect mainnet funds, but could hinder upgrade verification. Glamsterdam aims to increase the block gas limit to approximately 200 million, with the mainnet launch date remaining undetermined.

Glamsterdam Test: Attackers Could Exploit Free Testnet ETH to Win Sepolia Block Auctions and Withhold Transaction Payloads

Odaily reports: Ethereum developers have warned that attackers could exploit free testnet ETH and one-time builder identities to win Sepolia block auctions and withhold transaction payloads during the Glamsterdam testing period.This attack does not threaten mainnet funds, but it could disrupt infrastructure testing. The Sepolia public test is scheduled to launch on October 6, while the Hoodi test is tentatively set for October 27. The mainnet activation date remains undetermined. (CoinDesk)

Loss of approximately $3.5 million, Nostra hit by oracle attack

Odaily News: Nostra suffered an oracle attack. The manipulated NSTR oracle price allowed a single account to borrow approximately $3.5 million worth of ETH, STRK, USDC, USDT, WBTC, and DAI on Nostra's Starknet money market using NSTR as collateral. The attacker subsequently bridged approximately $1.92 million of the stolen funds—234.57 ETH and 1.3 million DAI—to Ethereum.

Relying on AI to find vulnerabilities first is not a sustainable security strategy, warns Bitcoin Core developer Niklas Gögge

Odaily reports: Bitcoin News posted on X platform that Bitcoin Core developer Niklas Gögge warned that recent AI-driven vulnerability scanning is changing the Bitcoin security landscape. Large language models have significantly reduced the cost of vulnerability discovery, and attackers may be able to find catastrophic vulnerabilities with only a few hundred dollars in computing costs. For Bitcoin Core, Project Loupe, Bitcoin Red Team, and individual contributors have generated over 1,000 reports, but so far no high-risk or critical vulnerabilities have been found. Gögge stated that relying on stronger models to find vulnerabilities before attackers do is not a sustainable security strategy. Developers should build testing infrastructure through automated testing, fuzzing, and property-based testing that can prevent entire classes of vulnerabilities in advance. Key components of Bitcoin Core have cumulatively completed over 100 years of CPU fuzzing and decades of Bitcoin node network simulation.

Liquid Network hacker still holds 598.5 bitcoins, L-BTC-to-bitcoin redemption channel paused for 11 days

Odaily News: The Liquid Network attacker has returned 3,400 bitcoins after the September 6 exploit, accounting for approximately 85% of the transferred assets; they currently still hold 598.50 bitcoins, worth over $45 million.Blockstream, the digital asset infrastructure company responsible for maintaining the Liquid Network, has refused to pay a ransom for the remaining assets and is demanding the return of the relevant bitcoins. The network shows 4,234.76 L-BTC in circulation, while the bitcoin reserves stand at only 3,632.23.The L-BTC-to-bitcoin redemption function has still not been restored, with Sideswap stating that redemptions are currently unavailable; Blockstream founder Adam Back said that L-BTC will be backed 1:1 by bitcoin reserves and reminded holders not to sell L-BTC off-market at a discount.As of now, Blockstream has not yet issued an announcement that "redemptions are live." The attacker's wallet continues to receive on-chain messages and has been subjected to address poisoning attacks and scam messages, with the related attacks inducing transfers by generating visually similar addresses. (Bitcoin.com News)