GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Data: Cases of hackers using open-source AI to implant malicious on-chain instructions increased by 440% in a year

Odaily reports: Blockchain analytics firm Chainalysis has released a report stating that hackers are increasingly leveraging open-source artificial intelligence (AI) to implant malware control instructions into on-chain transactions and smart contracts, with such cases surging approximately 440% in less than a year. Data shows that these incidents have risen from roughly 2 per day to approximately 11 per day. Attackers write malicious instructions on-chain to manipulate infected devices into stealing passwords and funds, and redirect assets to designated wallets; since on-chain records cannot be deleted, defense and interception are becoming increasingly difficult.The report notes that state-sponsored hackers from countries such as North Korea and Iran have become the primary drivers of such activity. Open-source models support local independent operation and modification, allowing them to directly bypass cloud-based defenses. However, the public and transparent nature of blockchain also leaves critical evidence for tracing attack infrastructure. (Bloomberg)

S&P Global Announces Acquisition of Blockchain Security Company OpenZeppelin

According to PR Newswire, S&P Global (NYSE: SPGI) announced on September 17 that it signed an agreement to acquire OpenZeppelin, a company specializing in on-chain financial security standards. Founded in 2015, OpenZeppelin's open-source smart contract library has collectively supported over $37 trillion in value transfers, covering global mainstream stablecoins and tokenized funds. The company has completed more than 900 security audits and identified over 10,000 vulnerabilities. This acquisition will expand S&P Global's assessment capabilities in the on-chain technology risk layer, helping it develop next-generation on-chain security assessment and benchmark products. OpenZeppelin will continue to operate as an independent business unit, with CEO Demian Brener remaining in his position and reporting to Yann Le Pallec, President of Ratings at S&P Global. Financial terms of the deal were not disclosed, and the transaction is expected to have no material impact on S&P Global's financial results.

Revolut Responds to Multiple Extortion Attempts: No Direct Contact Received, Italian Authorities Have Intervened

Odaily News: Following a customer data breach at Revolut, multiple hacker groups have publicly demanded ransom. A group calling itself "IAmNotAVillain" demanded that Revolut pay 6,000 Monero (XMR, approximately $3 million) within 24 hours, or it would sell customer data to other criminal organizations; another group, "Revolut Smilik," had earlier demanded 10,000 Bitcoin (approximately $780 million).In response, a Revolut spokesperson stated that the company has not received any direct contact or extortion demands from any of the aforementioned individuals or organizations. Meanwhile, Italy's Anti-Mafia and Anti-Terrorism Directorate has launched an investigation, with Italian prosecutors investigating unauthorized access to government computer systems, and Italy's privacy regulator has also asked banks to urgently review the security of their access systems. (Cointelegraph)

Formerly lost $23.75 million, Ostium's $15 million loan dispute goes to court today

According to court documents, a federal court in New York will hold a hearing today in the case brought by ESS Frontier and Hong Kong lender Minghui Zheng against Ostium, involving a $15 million loan dispute. The two parties are asking the judge to freeze Ostium's assets and refer the dispute to arbitration; Ostium previously lost $23.75 million in an exploit in July.

Paradigm Co-founder: Zcash Developer Fund Is Crucial, Pure Coin-Holder Voting May Undermine Long-Term Trust

Paradigm co-founder Matt Huang posted on the X platform outlining some views on Zcash. He stated that blockchain ecosystems generally face the challenge of long-term funding sources, especially for public goods financing, and that funding developer funds through an inflation mechanism is a viable approach. He believes that amid the backdrop of AI-enhanced cyberattack capabilities and the rapid development of quantum technology, the Zcash developer fund remains highly significant.Matt Huang also stated that as Zcash gains greater acceptance and adoption as a privacy supplement to Bitcoin, governance relying purely on coin-holder voting may introduce unpredictability and affect its ability to build long-term trust as a monetary asset. Therefore, Zcash is better suited to combining coin-holder voting with other governance approaches. Matt Huang also disclosed that Paradigm is an investor in ZEC and ZODL.In the early hours of today, ZEC briefly broke above $1,385, setting a new all-time high.

Revolut Hit by Ransom Attack: Hackers Demand 3 Million Monero or Threaten to Leak Data

The hacker group "iamnotavillain" attacked Revolut and demanded 6,000 Monero as ransom, threatening to sell the data of at least 680 customers to the black market if the payment is not made.

HBO Max Reddit Account Hijacked, 108 Malicious Ads Pushing Infostealer Malware Deployed Over 48 Hours

Odaily reports: Earlier this month, the verified Reddit account of streaming service HBO Max was hijacked by hackers, who deployed 108 malicious ads over approximately 48 hours, tricking Mac and Windows users into executing commands to install infostealer malware.The malware can steal browser credentials, Telegram data, Apple Notes, saved passwords, and crypto wallet recovery phrases, and may also alter wallet addresses in the clipboard. Reddit has suspended the relevant ads and launched a security investigation. The number of infections and crypto asset losses have not yet been confirmed. (Decrypt)

Flamingo Finance legacy contract suffers flash loan attack, attacker profits approximately $345,900

According to Blockaid monitoring, Flamingo Finance's legacy Flamincome contract was attacked. The attacker borrowed approximately 18 million USDT via a flash loan, staked USDP LP into the Strategy contract to inflate the VaultYUSDT share price, and subsequently redeemed aUSDT liquidity, currently realizing profits of approximately $345,900.

Bitcoin Core 32.0 entered the final testing phase on September 14, with the official release date set for October 10.

According to CoinDesk, Bitcoin Core 32.0 entered its final testing phase on September 14, with its official release scheduled for October 10. This update adds a transaction fee estimator based on real-time mempool status, enabling fee estimates to be lowered more quickly once network congestion subsides. It also enables multi-threaded parallel reading of transaction data to speed up node blockchain synchronization, defaulting to 8 threads. Security-wise, it resolves a wallet naming vulnerability on non-Windows systems since version 24.0 that allowed attackers to execute arbitrary commands on the node host via a specially crafted wallet name. Additionally, it patches an out-of-memory vulnerability in the newly added built-in web server; testing indicates that 16 unauthenticated connections can spike node memory usage from 46MB to roughly 3GB in approximately one minute. This update does not include any changes to Bitcoin's consensus rules.

Bitcoin Core 32.0 enters final testing, official release scheduled for October 10

Odaily News: Bitcoin Core 32.0 entered its final testing phase on September 14, with the official version planned for release on October 10.This version will improve fee estimation, speed up block processing, and make PSBT version 2 the default option for multiple wallet commands, without changing Bitcoin's consensus rules.Developers also fixed a command execution vulnerability affecting certain wallet configurations, as well as a memory exhaustion vulnerability in the new web server. (CoinDesk)

AI-Driven Vulnerability Operations Center Hackuity Announces Completion of €16 Million Funding Round

According to EU-Startups, Lyon-based AI-driven Vulnerability Operations Center (VOC) Hackuity has announced the completion of a €16 million funding round (approximately $19 million), led by Forgepoint Capital International alongside Bright Pixel, Bpifrance, and Seventure Partners, bringing its cumulative funding to €32 million. The funds will be allocated toward product innovation, AI capability enhancements, and expansion into European and Asian markets. Hackuity’s platform integrates data from over 130 security tools, automating vulnerability prioritization and remediation through a proprietary risk scoring engine. It currently serves more than 6,000 users, protects over 2 million assets, and manages 1 billion security findings, with enterprise clients including ENGIE, BPCE, and Orange Cyberdefense.

Italian authorities investigate government email security incident linked to Revolut customer data breach

Odaily reports: Italian cybercrime police are investigating a government email security incident linked to a Revolut customer data breach, involving suspected unauthorized access to computer systems and computer fraud.The accounts involved are said to belong to Italy's Certified Email System (PEC). Revolut did not confirm which government agency the compromised accounts belonged to, but said it has reported the incident to Italian authorities and that its systems, databases, and customer funds were not affected.Italy's CERT-AGID cybersecurity agency warned in June that PEC only certifies email delivery and does not guarantee the security of email contents. The agency said it has handled over 650 cases of abused or illegal PEC accounts since the beginning of 2026. (Cointelegraph)

Busan Integrated Shopping Center SMS Account Compromised, 260,000 Receive Crypto Wallet Phishing Messages

According to Yonhap News Agency, the Busan Metropolitan Police Agency revealed that on the morning of September 12, an unauthorized individual breached the SMS agency account used by the marketing department of a mixed-use shopping complex in Sasang-gu, Busan. The attacker bulk-sent scam messages to over 260,000 unspecified recipients, claiming "your cryptocurrency wallet has been updated" and urging quick installation. Once users clicked the attached links, they could fall victim to a smishing attack, potentially resulting in the theft of their virtual assets. Police have since blocked access to the relevant accounts and are actively investigating the intruders.

KOL @cladzsol lost approximately $600,000, meme coin display pages disguised verification links to carry out phishing

Odaily News: According to monitoring by @insidecalls and @cladzsol, recently multiple popular meme coin display pages have been directing users to phishing pages disguised as "Cloudflare verification." After users follow the prompts, their computer systems download and execute malicious scripts, resulting in on-chain asset theft. The relevant display pages directly reference the official website or social media links in the token metadata, and these fields can be updated by the token creator or individuals later claiming "community takeover."

Indra hit by denial-of-service attack, forward swaps temporarily disabled

According to Bitcoin News monitoring, JAN3 has stated that its newly launched swap infrastructure Indra has suffered a denial-of-service attack, and the team has temporarily disabled forward swaps while investigating. Swaps already in progress may experience delays. Indra, developed by JAN3, is designed to replace Boltz in Aqua, enabling users to move Bitcoin between Lightning and Liquid, though Liquid peg operations remain restricted.

Liquid hacker may receive a bounty if remaining stolen funds are returned

Bitcoin News posted on X platform stating that Samson Mow said Blockstream refuses to pay a ransom and does not rule out offering a bounty if the hacker returns the remaining stolen funds. Mow stated that the stolen funds belong to Liquid users, and Blockstream cannot negotiate over these funds; any bounty would need to be an independent and reasonable arrangement.

Gnosis Safe Wallet Hacked, $7.8M Worth of rsETH Stolen

According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.

A user's Safe wallet on Ethereum was attacked, resulting in the loss of approximately $7.73 million worth of rsETH.

Blockaid stated that its vulnerability detection system identified that a Safe wallet belonging to an unidentified user on Ethereum was compromised, resulting in confirmed losses of approximately $7.73 million in rsETH. The attacker leveraged a public keeper's multi-call to route the custom Uni V4 LP Safe module to a hook-enabled liquidity pool they created, causing the associated hook to unwrap aEthrsETH into rsETH. The exploit was extracted via MEV within the block.

Lazarus Group hacker sold 911 ETH worth $2.28 million within 2 hours

according to Lookonchain monitoring, the Lazarus Group hacker (0x0EBA...C22C) sold at an average price of $2,499 over the past 2 hours.

Warren to Slam CLARITY Act in Senate, Says New Ethics Provisions Still Have Major Loopholes

Odaily News: U.S. Senate Banking Committee ranking Democrat Elizabeth Warren will deliver a speech on the Senate floor Monday evening, attacking the ethics provisions in the latest revised text of the CLARITY Act. Warren will call the provision a "weak fig leaf," arguing that it still contains major loopholes and fails to effectively restrict U.S. President Trump from profiting through crypto ventures such as World Liberty Financial.Previously, Senate Republicans unveiled the latest revised text of the CLARITY Act on Sunday evening, adding new ethics rules that include allowing state attorneys general to enforce the relevant provisions and prohibiting the president and other senior government officials from issuing digital assets. The Senate is expected to hold a key procedural vote Tuesday afternoon to advance the bill, which requires at least 60 votes in favor to move forward. (CNBC)