GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

738,600 USDC Transferred Out, Hyperliquid User Account Compromised with Over 10,000 HYPE Unstaked

Odaily News – A Hyperliquid user's account was compromised through unauthorized access, with approximately 738,600 USDC transferred out and an additional 10,287 HYPE unstaked. The affected account is identified by a specific address, with some of the stolen funds flowing to an address suspected to be associated with Bitget. As of the time of verification, the 10,287 HYPE remained in the staking balance and had not yet entered the withdrawal queue. If the attacker proceeds to initiate cWithdraw, the affected assets would be further transferred after a 7-day waiting period. In two similar recent cases, staked assets were stolen a second time due to the lack of a user-triggerable emergency pause mechanism, resulting in losses exceeding $1.1 million. Relevant recommendations include introducing a Guardian or Recovery mechanism that users can pre-enable, which would only temporarily pause withdrawals, transfers, and authorization changes. The pause would expire automatically, and restoration would require a time lock and evidence review, with all actions recorded on-chain.

Alby Hub old versions have critical vulnerability, publicly exposed management API could lead to fund transfer

Bitcoin News posted on X platform that Alby has confirmed a critical vulnerability in Alby Hub v1.7.0 through v1.18.5. If the management API is exposed to the public internet, attackers could gain unauthorized access and transfer funds. Currently, 1 user is known to be affected, and Alby Hub v1.19.0 and later versions are not affected. Alby recommends affected users restrict public access to the management interface, update to v1.24.0 immediately, and change their unlock password after updating. Multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers have also been fixed in the latest version.

ZachXBT Accuses Austin Fine of Allegedly Facilitating Money Laundering of Stolen Crypto Assets

On-chain detective ZachXBT posted allegations accusing user "Mr Austin Fine" (handle "@xmrfine") of helping Malone Lam, the mastermind behind a $245 million crypto fraud case, exchange funds for luxury goods and launder a portion of the stolen cryptocurrency, while also raising suspicions that he acted as an informant. ZachXBT has already traced on-chain, revealing that a portion of the funds flowed through Monero to Los Angeles luxury car dealer TBTFW for vehicle purchases.

Singaporean man pleads guilty to orchestrating $245 million cryptocurrency theft and money laundering crimes.

The U.S. Department of Justice stated that 22-year-old Singaporean national Marlon Ram pleaded guilty in federal court in Washington, D.C., admitting to participation in a conspiracy under the Racketeer Influenced and Corrupt Organizations Act. Prosecutors said the criminal network began operating around October 2023, obtained victims' information through social engineering and individual burglaries, and stole and laundered over $245 million in cryptocurrency.

Liquid Network: In discussions with white hat to recover remaining 598.5 BTC, network restoration efforts also underway

Liquid Network's official security incident report: On September 6, a vulnerability related to the range proof verification method in Liquid node caching within the open-source software Elements was exploited, resulting in the creation of approximately 4,000 LBTC tokens not backed by bitcoin reserves. The exploiter subsequently exchanged them for approximately 4,000 BTC via SideSwap and the Liquid standard Peg-out mechanism. Prior to the incident, Liquid's reserves stood at approximately 4,205 BTC. After the relevant Peg-out and other withdrawals completed before the network halt, reserves fell to 197 BTC.According to the official statement, the incident did not involve the compromise of Functionary nodes or private keys, and other issued assets on Liquid such as USDT were also unaffected by the vulnerability. The exploiter claimed to be a white hat security researcher and returned 3,400 BTC to the Liquid Federation Peg wallet on September 7. Approximately 598.5 BTC (about 15% of the funds involved) remain unrecovered, and Blockstream is in communication to recover the remaining assets.At present, the top priority is to recover the remaining funds and restore Liquid Network to normal operation as quickly and safely as possible. A fix for the vulnerability has been developed and is currently undergoing multiple rounds of internal and external review. Blockstream is preparing to urgently release Elements v23.3.4, which is expected to be rolled out as soon as preparations are complete, with a target launch within approximately 48 hours. Following the software update, Liquid Network Functionary operators will make further adjustments to restore full network functionality and resume a corrected network state, including rejecting previously invalid Peg-outs.

Coldcard thief prioritizes emptying third wave of vaults, has moved 97.09 BTC worth approximately $7.7 million

according to Bitcoin News monitoring, the Coldcard thief is prioritizing emptying the largest portion of the third wave of vaults. Galaxy Research stated that these wallets have transferred out 97.09 BTC, worth approximately $7.7 million, accounting for about 45% of the assets in this batch. The attacker created 293 2/2 vaults themselves and previously moved some tokens via THORChain on September 2, followed by multiple rounds of CoinJoin over the weekend. The vulnerability stems from a 2021 firmware flaw that reduced seed entropy to a minimum of 40 bits. Of the tokens stolen in this exploit, approximately 82% remain unmoved.

Four people killed in Mexico, suspects accused of stealing a cold wallet holding millions of dollars in Bitcoin

Odaily News: The State Attorney General's Office of Mexico (FGJEM) stated that two suspects are accused of killing four people in search of a cold wallet believed to contain millions of dollars in Bitcoin. The two are scheduled to appear in court on Wednesday, where a judge will determine whether there is sufficient evidence to continue criminal proceedings.The surnames of suspects Diego Sebastián and Gerardo have not been disclosed. Prosecutors allege that the pair killed Jonathan Meléndez, keyboardist for the rock band Camilo Séptimo, his pregnant wife, their daughter, and an employee at a residence in the city of Atizapán de Zaragoza. The family's golden retriever was also killed.Mexico's Secretary of Security, Omar García Harfuch, stated that one of the suspects was a business partner of the victim and allegedly used that relationship to gain entry into the residence. If convicted, the two could face sentences ranging from 25 to 70 years in prison for each victim.Blockchain security firm CertiK reported that 52 violent coercion attacks against cryptocurrency holders were recorded globally in the first half of 2026, a 33.3% increase from 39 during the same period in 2025. Blockchain analysis company Chainalysis estimates that the value of stolen cryptocurrency from related attacks exceeded $30 million. (Cointelegraph)

The Sandbox Launches SAND Compensation Claims

The Sandbox stated that it will provide full compensation to affected users for the SAND vulnerability incident on Base and BNB Smart Chain that occurred on August 22. Any wallet that legitimately held cross-chain SAND at the time of the snapshot prior to the incident will receive SAND compensation on the Ethereum network at a 1:1 ratio.

Suspected collective theft incident hits Lootbot subscribers, losses surpass $600,000 and continue to grow

Odaily News On-chain analyst SomaXBT stated on the X platform that suspected Lootbot users have experienced a collective wallet theft incident, with losses now exceeding $600,000 (approximately 245 ETH). Preliminary information shows that about 50% of the victims are Lootbot subscribers.It is worth noting that Lootbot is one of the projects founded by dexter, the founder of gm.ai, a project previously involved in a soft rug pull. Lootbot was originally a trading bot platform within the Telegram ecosystem.

SlowMist: Approximately 62.28 BNB Lost in Attack on a Router on BNB Chain

According to Odaily, as monitored by SlowMist, per the SlowMist TI security alert, a Router contract has been exploited due to security flaws in its Swap entry point and uniswapV3SwapCallback, resulting in losses of approximately 62.28 BNB. The Router fails to verify whether the caller is a legitimate V3 Pool, nor does it bind the payer in the callback to the original transaction context. The attacker forged a V3 Pool/adapter and injected a victim's address as the payer, exploiting users' existing ERC-20 approvals granted to the Router to execute transferFrom() and transfer assets. Users who have previously granted sufficient token approvals to this Router may see their approved assets transferred out, even without further interaction on their part.

Tectonic hit by oracle manipulation attack, $120.4 million in assets stolen

According to the post-incident report released by Tectonic, the Cronos blockchain lending protocol Tectonic suffered an oracle manipulation attack at 12:49 UTC on August 30, 2026. By repeatedly borrowing and re-collateralizing TONIC tokens 98 times within a single transaction, the attacker drove up the TONIC collateral price by approximately 195 times. Leveraging this artificially inflated value, they subsequently extracted assets with a nominal value of $120.4 million from nine lending markets, spanning USDC, USDT, WBTC, WETH, and other assets. The attacker then bridged the stablecoins to Ethereum and converted them to ETH, while selling the remaining assets for CRO on the Cronos chain before withdrawing them. Approximately $9.19 million in total successfully escaped before the network halt. At 14:32 UTC, Cronos validators emergency-paused the network, rolling back the on-chain state to pre-attack conditions and restoring assets still held on Cronos. Currently, Tectonic's supply and borrowing functions remain suspended, while withdrawal and repayment capabilities continue normally. Tracing efforts for the stolen funds are being coordinated by blockchain forensics firms, law enforcement agencies, and stablecoin issuers, with freeze requests already filed with the relevant issuers.

Biden’s Son Meme Coin LAPTOP: No Utility or Development Roadmap, Foundation Signs Loan Agreement with G20 and GSR

According to disclosures from the Phoenix Veritas Foundation, the Hunter Biden laptop-themed cultural token, LAPTOP, has been issued on the Base chain with a total supply of 1 billion tokens and an initial circulating supply of 350 million tokens (35%) at TGE. Token allocation consists of 30% for founders (including Hunter Biden), 30% for the prediction mechanism, 20% for the community airdrop, 10% for liquidity, 10% for the foundation treasury, and 5% for charity. Founder tokens are subject to a six-month lock-up period followed by linear unlocking over 24 months. LAPTOP provides no utility, positioned strictly as a cultural digital collectible with its value driven entirely by community sentiment. The token contract underwent a security audit by Hacken in April 2026, revealing no major vulnerabilities. Regarding market maker arrangements, the foundation has entered into a lending agreement with G20 and GSR totaling 20.5 million tokens.

Liquid Network preparing to restart, Blockstream has deployed updated software

Odaily News, according to Bitcoin News, Blockstream stated that Liquid Federation members are preparing to coordinate a network restart, with the updated software already deployed. Previously, a security incident occurred on the Liquid Network, resulting in fund transfers. Blockstream noted that its team remains focused on further strengthening the network and ensuring asset restitution. Blockstream thanked the Bitcoin community for its patience, support, suggestions, and assistance, and stated that more updates will be released in the future.

Liquid Network white hat hacker returns 3,400 BTC, keeps about 598 BTC as bounty

According to on-chain monitoring by analyst PeckShield (@PeckShieldAlert), the Liquid Network was targeted by white-hat hackers. Approximately 4,000 BTC (roughly $320 million) were transferred from a Liquid Federation wallet. The funds were consolidated into address bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, accompanied by an on-chain message: "We are white hats, please contact us on-chain." Subsequently, the hackers completed on-chain negotiations with Blockstream, returning 3,400 BTC (approximately $315 million, or 85% of the total) while retaining around 598.5 BTC (about $47.38 million) as a bug bounty.

Harmony's preliminary ONE shortage narrows to 6.581 billion after cross-exchange reconciliation

: Harmony has released an update on the exchange reconciliation progress following the August 11 incident. It has verified on-chain deposits/withdrawals and cross-platform fund flows with Binance, Gate, KuCoin, MEXC, OKX, and Binance.US, prioritizing the coordination of restoring ONE deposits, withdrawals, and trading, with specific timelines to be announced separately by each exchange.Harmony stated that after matching 295 cross-exchange transfers totaling approximately 3.493 billion ONE and adjusting for circular transfers and returned funds, the preliminary shortage has been reduced from approximately 10.234 billion ONE to 6.581 billion ONE, a decrease of about 3.653 billion ONE. This change reflects an adjustment in reconciliation methodology and does not equate to newly recovered funds.Among these, Binance's data remains a preliminary upper-bound estimate, while some data from Gate and OKX are still pending final verification. Exchange teams have already frozen significant ONE balances and hacker proceeds. These efforts will be coordinated with the ONE migration and validator transition proposal, and validators may cease operations starting 22:00 Beijing time on September 10.

CZ clarifies X account was not hacked: Unfollowed accounts inactive for over 30 days

CZ retweeted on X platform to clarify that his account was not hacked, stating that he had simply unfollowed some accounts that had been inactive for over 30 days, adding "that's all."

Binance Wallet Saves Users from $540 Million in Potential Losses in H1

Odaily News: Binance stated that in the first half of 2026, the Binance Wallet Security Center helped users avoid approximately $540 million in potential losses, filtering about 206 million spam transfers, identifying 4.93 million high-risk transactions, and approximately 996,000 malicious authorizations during the period. Binance noted that AI is being used by attackers to mass-generate malicious code, phishing websites, and fake identities, shifting attacks from broad-based approaches to more targeted fraud.

U.S. Department of Justice Prosecutes Group in $240 Million Bitcoin Theft Case, Ringleader Expected to Plead Guilty

According to the Associated Press, the U.S. Department of Justice has charged Ma Long Ram and 17 other defendants in connection with a Bitcoin theft scheme valued at over $240 million. Prosecutors allege that the group carried out a social engineering attack on a Washington resident by impersonating employees of Google and cryptocurrency exchange Gemini, thereby gaining control of their accounts and security codes to steal more than 4,100 Bitcoin. The suspects subsequently laundered the proceeds through multiple trading platforms and spent the money on sports cars, mansions, luxury watches, private jet services, and nightclub expenses.

Blockstream notifies white hat hackers that vulnerability has been fixed, approximately 4,000 BTC pending return

Odaily News: Blockstream has notified white hat hackers that the vulnerability fix is complete and the approximately 4,000 BTC can be safely returned. The hacker who previously withdrew funds from the Liquid network expressed willingness to return them, but requested that the vulnerability be fixed first. Both parties have been negotiating publicly through Bitcoin OP_RETURN messages.The hacker initially proposed returning "most" of the BTC, but later changed their stance, demanding that the vulnerability be fixed first: "Ensure every node has been patched, and once the fix is confirmed, we will securely return the funds." The hacker also sent encrypted vulnerability details to Blockstream. About two hours ago, Blockstream responded via a PGP-signed OP_RETURN message stating that nodes have been patched. Currently, 3,998.5 BTC remain under the hacker's control.

Coldcard Wave 3 Attacker Has Transferred Approximately 45% of Stolen Bitcoin

According to Galaxy Research, in the Coldcard wallet attack incident, the Wave 3 attacker has transferred approximately 45% of the stolen Bitcoin, with the related funds routed to Ethereum via THORChain or entering CoinJoin transactions to increase tracking difficulty. Galaxy stated that the attacker previously created 293 2-of-2 multisig vaults to hold victim funds, draining them from largest to smallest amount, and the funds in the 11 largest vaults have now been fully transferred out.