GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Balancer Co-Founder Proposes Phasing Out the Protocol, Says v3 Revenue Growth Fell Short of Expectations

Odaily Report: Balancer Labs co-founder Marcus Hardt posted on X that he has proposed a governance proposal to gradually shut down Balancer. Balancer had previously completed a restructuring, including halting token emissions, transferring all protocol fees to the DAO, cutting the operational budget by one-third, and reducing the team from approximately 25 people to 12.5 full-time equivalents.Marcus stated that the restructuring was completed on the cost side as planned, but revenue performance fell short of expectations. Currently, most of Balancer's protocol revenue still comes from v2, and v3 revenue has not grown enough to replace v2. Previous security incidents have also continued to affect partners' willingness to adopt v3. Marcus said he can no longer see a funded path that could change the situation, and continuing to burn through treasury funds is not reasonable. Therefore, he has proposed gradually shutting down Balancer and will not lead efforts to develop a plan for continued operations. The Balancer code will remain open source, and other teams can fork it and continue development. The relevant proposal has been submitted to the governance forum, and the final decision still rests with token holders.

Eight Banking Trade Associations: CLARITY Act Circuit Breaker Is Not a Safeguard

Odaily News: According to crypto reporter Eleanor Terrett, eight banking trade groups have stated that the deposit outflow "circuit breaker" mechanism added to the new version of the CLARITY Act is not an effective safeguard, because the mechanism would only be triggered after large-scale deposit outflows have already occurred.In a letter to Senate leaders, these groups called for further tightening of provisions related to stablecoin rewards, in order to close loopholes that could allow stablecoin balances to earn interest-like payments.

Liquid Network hit by major exploit, Bitcoin News publishes security incident newsletter

Odaily News: According to Bitcoin News monitoring, its latest newsletter reviewed multiple security incidents over the past eight weeks involving projects that Bitcoin users rely on in their daily activities, with a focus on the latest major exploit targeting Liquid Network.

The EU Cyber Resilience Act officially takes effect, requiring crypto wallet vendors to report vulnerabilities within 24 hours.

According to Cointelegraph, the EU Cyber Resilience Act (CRA) officially entered into force, requiring cryptocurrency hardware and software wallet providers to submit an early warning within 24 hours of discovering a serious security vulnerability or an actively exploited vulnerability, a complete notification within 72 hours, and a final report within 14 days after remediation measures are implemented. The regulation applies to all "products with digital elements" sold in the EU market. Violating companies face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing false or misleading information will result in an additional fine of up to €5 million. Previously, Trezor and BitBox have both disclosed user data breach incidents and warned users to be vigilant against phishing emails disguised as security notifications.

EU's Cyber Resilience Act Takes Effect: Crypto Wallet Vulnerabilities Must Be Reported Within 24 Hours

The EU's Cyber Resilience Act has taken effect. Cryptocurrency hardware and software wallet providers must submit an initial early warning within 24 hours after discovering actively exploited vulnerabilities or severe security flaws in their products, and submit a full notification within 72 hours.Manufacturers must submit a final report within 14 days after corrective or mitigating measures become available; serious incidents must be reported within one month. Companies that violate the relevant regulations may face fines of up to €15 million or 2.5% of global annual turnover, whichever is higher; providing false, incomplete, or misleading information may result in fines of up to €5 million. (Cointelegraph)

Symbiosis Recovers 15 BTC From Bitcoin Bridge Exploit, Offers 20% Bounty for Leads

According to Cointelegraph, cross-chain liquidity protocol Symbiosis announced that it has recovered 15 BTC (approximately $1.1 million) from its Bitcoin bridge exploit and deposited them into a team-controlled multisignature wallet. The vulnerability occurred last Friday, as the attacker exploited the protocol flaw to mint 46.1 billion uncollateralized tokens, ultimately realizing profits of 4.3 WBTC (approximately $336,000). Symbiosis had previously offered the attacker a 20% white-hat bounty in exchange for returning the assets, but the deadline has passed without any response. The protocol is now offering a 20% bounty to anyone who provides leads to assist in recovering the assets, while committing to announce a compensation plan for affected liquidity providers. The impacted Bitcoin bridge feature remains paused.

Trader loshmi bought STONK at a $1 million market cap, earning $327,400 in 30 days

Odaily News: Trader loshmi stated that he closed all positions on September 13, realizing $327,400 in profits from 30 days of public trading. He said he began buying when STONK had a market cap of approximately $1 million over a month ago and continued to add to his position as the price declined.Stonkfun is a Solana token launch platform that went live on August 3, allowing creators to pair new tokens with tokenized stocks. STONK is the platform's native token.loshmi disclosed that his portfolio once rose from $5,000 to over $25,000 before falling back to $4,000; during this period, he also lost over $6,000 due to a hack. He cited fatigue from intensifying competition in recent market trading as the reason for closing his positions. (Bitcoin.com News)

US Congress Considering Making AI Kill Switch a Legal Requirement

According to Forbes, the US Congress continues to debate a federal bill establishing an "AI kill switch," but AI scientist Lance Eliot warns of potential "backfire effects." From a technical standpoint, distributed AI systems are difficult to effectively shut down with a single switch; legally, disputes remain over activation authority and definitional boundaries; internationally, this initiative could deter other countries from adopting US AI technology and trigger reciprocal retaliation; domestically, mandatory shutdowns of AI within critical infrastructure could cause widespread social chaos while providing hackers with new attack vectors. Moreover, advanced AI systems may even bypass the kill switch itself, casting doubt on the legislation's practical impact.

Ampleforth Faces Malicious Governance Proposal Attack, $2.5 Million USDC Treasury Funds at Risk

The GoPlus Chinese community released a security alert stating that on September 12, a newly activated external account address submitted a malicious governance proposal to Ampleforth. Under the guise of applying for funding for completed work on the SPOT ecosystem analytics tool, the proposal attempted to transfer 2.5 million USDC from the treasury to the proposer themselves, an amount that nearly comprised all of the treasury's liquid funds.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

Chainflip Hit by Attack, 736,442 USDT Stolen, Recovery Expected Around Monday

Odaily reports: Cross-chain protocol Chainflip has disclosed that an attack targeting Tron USDT occurred yesterday. It has been confirmed that 736,442.17 USDT was stolen through 6 unauthorized payments, while another 115,654.41 USDT in user swaps remained in the vault due to failed payments. All other funds were unaffected.Chainflip stated that the attacker exploited a vulnerability in the Tron transaction memo mechanism by attaching custom memos to transactions already signed by validators, causing the system to identify the same deposit as separate swaps and issue refunds again, ultimately resulting in duplicate payments. The attacker carried out 8 operations over approximately 90 minutes, gradually increasing the amounts. Chainflip said it has completed a fix and has flagged the stolen funds to relevant authorities in an attempt to recover them. The protocol is expected to resume operations as early as Monday and will be responsible for compensating affected users for their losses.

US Department of Justice Has Frozen Approximately $938 Million in Fraud-Related Crypto, With About $52 Million Added in a Single Day

Odaily News: In an operation targeting the Telegram crypto escrow trading platform Xinbi Guarantee, the U.S. Department of Justice's Scam Center Strike Force restricted the handling of approximately $52 million in fraud-related cryptocurrency in a single day, bringing the cumulative total to approximately $938 million. Previously, the cumulative amount frozen, seized, or recovered had already exceeded $580 million.The U.S. Department of the Treasury stated that since its founding around 2022, Xinbi Guarantee has processed over $24 billion in transactions, involving digital assets and fiat currency, primarily serving Southeast Asian transactions. North Korean hackers and sanctioned entities are alleged to have used the platform, including entities under Jin Bei Group and Prince Group.A U.S. federal court approved the seizure on September 7 of the Telegram channel operated by Xinbi Guarantee. Law enforcement authorities also seized two payment wallets totaling approximately $12 million and applied to freeze another 47 cryptocurrency wallets suspected of being used for money laundering or associated with fraud-related service providers.The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) added Xinbi Guarantee and its two supporting companies, Safew Technology and Anwen Technology, to its sanctions list on September 9. The U.S. Department of Justice also dispatched investigators to Madagascar to assist local law enforcement in cracking down on 13 scam compounds operated by Chinese nationals and to process over 3,200 electronic devices. (Bitcoin.com News)

Solana Mobile Third-Party Email Service Provider Brevo Hacked, Accounts Experience Unauthorized Access

Solana Mobile stated that its third-party marketing email service provider Brevo experienced a security incident, resulting in unauthorized access to its Brevo account. To date, no emails have been sent through the account, and the company is currently investigating the scope of information that may have been accessed.

Crypto brokerage platform Cascade announces shutdown

Odaily reports: Crypto brokerage platform Cascade (formerly Perennial) announced on X that it is officially ceasing operations after approximately 5 years.Cascade stated that this was a difficult decision. Users can claim remaining funds from Cascade CLS and their trading accounts through the officially designated page, and users are reminded to only use the official claim portal.Previously in July, the Cascade CLS vault was suspected to have suffered a security exploit, resulting in approximately $1.3 million in user fund losses.

North Korea uses third-country IT workers to pass interviews at US companies, then takes over the positions after hiring

North Korea is using remote IT workers from third countries such as Iran and Lebanon to infiltrate US companies in order to obtain funding to support its weapons programs. After the relevant individuals pass interviews, their positions are usually taken over by North Korean personnel.The US government and multiple foreign agencies issued warnings in July stating that North Korean IT workers seek contracts and send salaries back to their affiliated North Korean organizations, while also posing insider threats to companies, involving data leaks, cryptocurrency theft, and the theft of sensitive information.Some third-country IT workers are recruited through LinkedIn, and some of them work part-time as "interview facilitators," earning $500 in cryptocurrency per month.Data from cybersecurity company CrowdStrike shows that in 2025, cryptocurrency losses caused by North Korea state-linked hackers and threat actors exceeded $2 billion, an increase of 51% year over year. South Korea's central bank estimates that North Korea's GDP grew 3.5% in 2025. (Cointelegraph)

North Korean hackers exploit third-country nationals to infiltrate US companies and acquire cryptocurrency.

North Korea leverages foreign technicians from Iran and Lebanon to infiltrate US companies through an "interview assistant" model, involving data theft and crypto asset theft. CrowdStrike data shows it caused over $2 billion in crypto losses last year.

US House Ways and Means Committee Schedules September 16 Markup of Cryptocurrency Tax Rules

The U.S. House Ways and Means Committee is scheduled to hold a markup on September 16 of a series of digital asset tax bills, moving crypto tax legislation toward a full House vote. The markup focuses on two core issues: when miners and stakers should be taxed on newly created tokens, and whether wash sale rules applicable to stocks should extend to digital assets.The two key bills are the "Mining and Staking Tax Clarity Act" H.R. 9175 and the "Applying Existing Tax Anti-Abuse Rules to Digital Assets Act" H.R. 9172. The former provides that miners and stakers need not pay tax immediately upon receiving new tokens, and can instead pay tax as ordinary income when the tokens are actually sold; the latter extends wash sale and constructive sale rules to actively traded digital assets, closing a tax loophole that crypto traders have exploited for years.

SlowMist Discloses Liquid Vulnerability Details: Attacker Minted 3,998.5 L-BTC Without Collateral, Approximately 598.5 BTC Still Not Returned

SlowMist has disclosed that the Liquid Network was attacked on September 6 via a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without collateral — with no corresponding BTC peg-in — and then within minutes converted them to BTC on the Bitcoin mainnet via peg-out. After the incident, approximately 3,400 BTC was returned to the Liquid Federation peg wallet, but approximately 598.5 BTC remains under the attacker's control.SlowMist noted that the root cause of the vulnerability lies in the fact that the Rangeproof verification cache key in Elements did not include length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to potentially generate the same cache key. The attacker triggered a cache collision by constructing transactions, causing nodes to hit a "verification passed" cached result, thereby bypassing secp256k1_rangeproof_verify and the minimum amount check, ultimately accepting outputs not backed by real assets and completing the L-BTC minting. SlowMist stated that it has traced the fund flows on the Bitcoin side and completed its analysis of the incident.

SlowMist: ether.fi Attacked, Losing Approximately 15.45 ETH

SlowMist issued a security alert stating that it had previously privately contacted the ether.fi team to disclose the relevant issues. This incident resulted in a loss of approximately 15.45 ETH. The root cause was that AtomicQueue.solve() lacked access control for the solver provided by the caller, failing to verify solver == msg.sender, and did not perform signature, registration, or consent verification.

74% drop after SILV incident, sunrise warns users not to interact with tokenized silver asset issued by Dominion_Market

According to SolanaFloor monitoring, sunrise has warned users not to interact with SILV, the tokenized silver asset issued by Dominion_Market, after a previous attack led to the compromise of Dominion's treasury wallet, causing SILV to drop 74% following the incident.