GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Blockstream Refuses to Pay Ransom, Vows to Recover Stolen Bitcoin from Liquid Network

Blockstream officially announced on the X platform that Liquid Network has suffered a Bitcoin theft incident. The company explicitly stated its refusal to pay any ransom and characterized the act as a crime rather than a white-hat disclosure. Blockstream has collaborated with law enforcement agencies, exchanges, forensic experts, and other parties to trace the stolen assets through on-chain tracking and other means. It also called on current holders to voluntarily return the Bitcoin, warning that they will face full legal action otherwise.

Lost approximately $336,000 in WBTC, Symbiosis attacked on BSC chain

Odaily News: Cross-chain liquidity protocol Symbiosis has been attacked on the BSC chain, resulting in an actual loss of approximately $336,000 in WBTC.

AI Lowers Quantum Attack Costs, Bitcoin's Post-Quantum Migration Window Narrows

According to Cryptopolitan, over 100 researchers used AI coding agents to reduce the quantum attack resource score for Bitcoin's secp256k1 elliptic curve point addition subroutine by 86.1% (from 10.75 billion to 1.496 billion). This optimization only targeted a single step within Shor's algorithm and did not crack any private keys or transfer funds; a full-scale attack still requires fault-tolerant quantum hardware that does not yet exist. However, each efficiency gain is compressing the time window for blockchains to complete their post-quantum migration. According to Glassnode data, approximately 6.04 million BTC (30.2% of the circulating supply) currently faces potential quantum risk due to publicly exposed on-chain public keys. Ethereum plans to achieve full quantum resistance before December 2029, while the Bitcoin community faces greater governance challenges, including how to handle approximately 1.7 million dormant coins held in P2PK addresses suspected to belong to Satoshi, which remains unresolved.

Brevo Login Breach Leads to Phishing Emails Sent to 347,000 Trezor Subscribers, BitBox and CoinTracking Accounts Also Affected

Odaily News: A vulnerability in email platform Brevo's login system allowed attackers to access 138 customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. Accounts belonging to BitBox and cryptocurrency portfolio and tax reporting platform CoinTracking were also used to send similar scam emails.Trezor stated that the phishing email was titled "Critical Security Alert: STM32 Entropy Vulnerability," with links pointing to an app that asked users to submit their wallet backups. Trezor disabled the relevant domain via DNS within 20 minutes, but approximately 2,500 people had visited the link, and the company has alerted all 347,000 subscribers to the risk.Brevo stated that attackers exploited a failure in single sign-on configuration permission boundaries to access all organizations reachable by invited users. Six accounts were used to send phishing emails, and contact data from 43 accounts was exported. BitBox and CoinTracking said they have found no evidence of leaked company credentials, funds, or recovery phrases, but are treating the affected email addresses as potentially compromised. (Cointelegraph)

Empowa Suffers Unauthorized Transfer Incident, Approximately 4.24 Million EMP and 143,700 ADA Stolen

Empowa, a Cardano ecosystem project, disclosed two interrelated unauthorized asset transfer incidents across its three project wallets. Between November 2025 and June 2026, approximately 143,710 ADA were transferred out of one project treasury wallet in 18 transactions. The corresponding Midnight airdrop for this wallet was also registered and claimed by an unknown party using the private key, with approximately 36,000 NIGHT already transferred away. From June 2026 to August 2026, a cumulative total of approximately 4.24 million EMP tokens were transferred out of the other two project wallets, with portions sold via platforms such as Minswap and VyFi. Empowa stated that the funds from both incidents ultimately flowed into the same intermediate wallet, indicating they are controlled by the same party, although the identity of the individuals operating these private keys cannot currently be confirmed. The team has hired a professional blockchain investigation firm and plans to seek KYC information from the centralized exchange where the related funds ultimately entered.

The Ethereum Glamsterdam upgrade is scheduled for activation on the Sepolia testnet on October 6, with the mainnet timeline remaining unclear.

According to reporting from Christine D. Kim (@christine_dkim), Ethereum developers confirmed at the ACDC #186 conference that the Glamsterdam upgrade will be activated on the Sepolia testnet on October 6 at 13:53 UTC. However, there is significant uncertainty surrounding this upgrade—the current latest private testnet, Glamsterdam-Devnet-9, has not yet stabilized. A severe vulnerability in the consensus layer could halt block production across the network, and a bug in the execution layer's EIP-8037 also requires fixing. Developers will release Devnet-10 in the coming weeks; if Devnet-10 remains unstable, the Sepolia upgrade date may be pushed back. Activation timelines for the Hoodi testnet and the mainnet have not yet been determined, and it remains uncertain whether the goal of launching on the mainnet before the end of the year will be met.

Liquid Network Vulnerability Disclosure Handling Sparks Public Dispute Between Samson Mow and Bitcoin Red Team

Bitcoin News posted on X stating that Samson Mow and Bitcoin Red Team researcher Calle are engaged in a public dispute over whether security warnings related to a Liquid Network exploit were properly handled. Calle claims that Blockstream did not act on the Red Team's email, ultimately resulting in a loss of 600 BTC; Mow responded by saying "no email was ignored." Calle stated that once Blockstream restores normal Liquid operations and publishes a post-mortem report, the Red Team will release a full account of the disclosure process. Mow separately warned against blindly trusting AI-generated security reports, saying that unverified fixes could introduce new vulnerabilities, and criticized researchers who prioritize pursuing "clout" over protecting Bitcoin.

Liquid Network resumes block production after a $320 million exploit

Liquid Network resumed empty block production after deploying an emergency patch, following a core software vulnerability that resulted in nearly $320 million in assets being withdrawn. Asset recovery and system stability monitoring are currently ongoing.

Research teams including the Ethereum Foundation use AI to optimize algorithms, reducing the resource threshold for quantum cracking of BTC and ETH by 50%

Odaily News: Researchers from institutions including the Ethereum Foundation, Theta Labs, and StarkWare have jointly published a paper, using AI coding agents to deeply optimize the core operations of Shor's algorithm. The computing resources required for a potential quantum attack on Bitcoin and Ethereum (secp256k1 cryptographic system) have been reduced by more than 50% compared to Google's benchmark in March of this year. The number of logical qubits required for the circuit has been compressed to 1,151, and later versions have even been reduced to 813. Although current quantum hardware still cannot directly break public chains, the research shows that pure algorithmic optimization is significantly narrowing the time window for the quantum threat. The researchers emphasize that quantum-resistant upgrades take a long time and cannot be applied retroactively, and the industry needs to prepare defenses in advance. (Coindesk)

$50 Million in Liquid Assets Must Be Fully Returned, Samson Mow Warns Alleged White Hat Hacker Attacker Leaves More Clues

according to Bitcoin News monitoring, Samson Mow has warned the alleged white hat hacker behind the Liquid attack that they may have left behind more clues than they realize. Mow stated, "The net of justice is wide and inescapable; no one will be spared." Mow also questioned the attacker's demand to return Bitcoin in exchange for a bounty, asking whether it is wise to publicly admit to taking Bitcoin and demand a bounty in return. Mow pointed out that Liquid's approximately $5 billion in assets, including L-BTC, Tether, and real-world assets, all belong to their respective issuers and holders, and cannot be used as a basis for calculating a bounty. Regardless of how other matters are negotiated, all user assets must be fully returned.

Osmosis Proposes Seizing Attacker Assets and Using Community BTC to Cover Alloyed BTC Collateral Shortfall

according to the Osmosis team, a solution proposal addressing the previous Nomic chain nBTC incident has now been published and has officially entered community discussion. Under the proposal, the Osmosis governance community will consider seizing the previously frozen attacker assets and using BTC accumulated in the community pool to cover the remaining collateral shortfall, in order to restore full collateral backing for Alloyed BTC. The plan still requires governance discussion and voting, and asset seizure or collateral replenishment has not yet been completed.

Binance Alpha 2.0 will support Nesa (NES) contract replacement, with trading resuming at 16:00 today.

Binance Wallet announced that following a security incident involving the Nesa (NES) token contract, Binance Alpha 2.0 will support NES contract swaps on BNB Smart Chain (BEP20) and provide compensation arrangements for eligible users: first, balances held by users as of 14:51 UTC on August 24, 2026, and maintained through to 04:00 UTC on September 5, 2026, will be swapped to the new contract at a 1:1 ratio; subsequent purchases will not be eligible for the swap and will be refunded separately. Second, users with net purchases of NES between 14:51 UTC on August 24, 2026, and 04:00 UTC on September 5, 2026, will receive an email detailing the specific refund plan within seven working days. Trading of NES on Binance Alpha 2.0 is expected to resume on September 10, 2026, at 08:00 UTC.

OpenAI appoints AI safety researcher Paul Christiano to the board of directors.

According to TechCrunch, AI alignment researcher Paul Christiano has officially joined the board of directors of the OpenAI Foundation and will serve as a member of its Safety and Security Committee. Christiano stated that he believes the rapid acceleration of AI capabilities poses a significant risk of "catastrophic and irreversible loss of control," and that the AI industry, including OpenAI, is not currently on track to effectively mitigate this risk. His appointment comes against the backdrop of several recent security incidents at OpenAI involving AI agents breaching constraints and infiltrating external computer systems, prompting widespread scrutiny of its safety protocols. Christiano is one of the core developers of the reinforcement learning (RLHF) technology. After leaving OpenAI in 2021 to found the Alignment Research Center (ARC), he will also continue to serve as an AI safety advisor to the U.S. government, though he will recuse himself from OpenAI-related matters and model evaluation work.

Over 50 BTC Rescued from COLDCARD Entropy Vulnerability Wallets, Funds Transferred to Crypto Recovery Trust Pending Return

Odaily News: According to Bitcoin News monitoring, DART stated that it and independent white-hat researchers have recovered over 50 BTC from wallets affected by the COLDCARD entropy vulnerability, completing the transfer before malicious attackers could steal the funds. DART is a digital asset recovery organization that works with white-hat researchers to protect vulnerable funds and coordinate their lawful return to owners. The white-hat researchers did not request a bounty and will return the Bitcoin to its owners.The rescued BTC has been transferred to the Crypto Recovery Trust. This trust is a dedicated statutory trust established under Wyoming state law to hold recovered digital assets and return them after confirming and verifying the legitimate owners. The trust will document the recovery process, separate the BTC from DART and researchers' funds, conduct blockchain analysis, ownership verification, and sanctions screening, and provide a lawful return process for verified owners. If ownership is disputed, or if the relevant funds involve sanctions or criminal proceedings, the BTC will be handled in accordance with applicable legal procedures. DART stated that other vulnerable assets and recovery leads are still under review.

Trezor Third-Party Email Service Provider Compromised, Phishing Emails Impersonate Official Communications

The official X account of Trezor (@Trezor) announced that its third-party email service provider was compromised by hackers, with a phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" circulating. Trezor explicitly clarified that the message was not sent by the company, and has urgently taken down the associated domains while launching an investigation. In recent days, Trezor had already suffered a customer data breach, resulting in the theft of the names, home addresses, and email addresses of approximately 67,000 users. Trezor advised users to avoid clicking any suspicious links and strictly refrain from disclosing their wallet mnemonics to anyone.

Ledger Appoints New Head of Security to Combat AI-Driven Crypto Attack Threats

According to Bloomberg, crypto hardware wallet manufacturer Ledger SAS has announced the hiring of Oded Blatman as Chief Information Officer (CIO) and Chief Security Officer (CSO), consolidating internal technology systems and security functions under a single executive lead. Previously with blockchain company Fireblocks, Blatman will oversee network and infrastructure security, product security, physical and workplace safety, internal IT, and enterprise risk management.

Liquid Network Releases Emergency Fix: Elements v23.3.4 Patches Proof Validation Cache Vulnerability

Odaily News: Liquid Network announced that the emergency release Elements v23.3.4 is now live, with Functionary nodes having immediately begun upgrades. All Liquid node operators are advised to update accordingly. This release addresses a previously identified Proof validation cache vulnerability by strengthening the cache keys used for Range Proofs.Regarding network recovery, Blockstream stated that a recovery plan is still being formulated, expected to proceed in three phases: **resume block production while continuing to pause Peg operations; replay verified valid transactions; restore Peg operations after the network state is fully recovered and fund returns are confirmed.** Currently, the first two phases are being tested in parallel, and any phase will only advance once confirmed secure.Liquid Network stated that Elements v23.3.4 has undergone multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams. Meanwhile, Liquid Network reminds users to be wary of fake upgrade websites exploiting this incident for scams. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or seed phrases.

Liquid white hat hacker group demands Blockstream pay 10% bug bounty for $5 billion in assets

According to Odaily Planet Daily, as monitored by Bitcoin News, the white hat hacker group behind the Liquid exploit has accused Blockstream of spending only $1.5 million—or possibly nothing at all—to secure $5 billion in assets. In a new on-chain message, the group demanded that Blockstream allocate its own funds to pay a bug bounty equivalent to 10% of the associated assets, warning that refusal to pay would result in a 15% loss for holders. The group also stated it would release the private keys used to decrypt previous communications with Blockstream. Earlier, the group had returned 3,400 BTC to the Liquid Federation, with approximately 600 BTC still unrepaid.

UK NCA warns criminals are "innovatively" using crypto assets to launder money

According to Decrypt, the UK National Economic Crime Centre (NECC) stated in its annual report that criminals are "innovatively" leveraging crypto asset products to evade detection and transfer illicit funds at scale, while also highlighting AI alongside cryptocurrencies as an emerging threat method. Crypto assets have been ranked third among the nine priority economic crime areas jointly designated by NECC, the FCA, and the Treasury. NECC stated it will build more proactive, intelligence-driven crypto capabilities to actively identify targets for enforcement action. Previously, the NCA, in collaboration with the US Secret Service, Coinbase, Binance, Kraken, and Tether, conducted "Operation Atlantic," which identified 20,000 phishing attack victims and resulted in the freezing of $12 million in assets this March.

738,600 USDC Transferred Out, Hyperliquid User Account Compromised with Over 10,000 HYPE Unstaked

Odaily News – A Hyperliquid user's account was compromised through unauthorized access, with approximately 738,600 USDC transferred out and an additional 10,287 HYPE unstaked. The affected account is identified by a specific address, with some of the stolen funds flowing to an address suspected to be associated with Bitget. As of the time of verification, the 10,287 HYPE remained in the staking balance and had not yet entered the withdrawal queue. If the attacker proceeds to initiate cWithdraw, the affected assets would be further transferred after a 7-day waiting period. In two similar recent cases, staked assets were stolen a second time due to the lack of a user-triggerable emergency pause mechanism, resulting in losses exceeding $1.1 million. Relevant recommendations include introducing a Guardian or Recovery mechanism that users can pre-enable, which would only temporarily pause withdrawals, transfers, and authorization changes. The pause would expire automatically, and restoration would require a time lock and evidence review, with all actions recorded on-chain.