GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Coldcard Wave 3 Attacker Has Transferred Approximately 45% of Stolen Bitcoin

According to Galaxy Research, in the Coldcard wallet attack incident, the Wave 3 attacker has transferred approximately 45% of the stolen Bitcoin, with the related funds routed to Ethereum via THORChain or entering CoinJoin transactions to increase tracking difficulty. Galaxy stated that the attacker previously created 293 2-of-2 multisig vaults to hold victim funds, draining them from largest to smallest amount, and the funds in the 11 largest vaults have now been fully transferred out.

Loss of approximately $104,000: Secured Finance lending market suffers attack

Odaily News: The decentralized lending protocol Secured Finance's lending market was attacked on September 5, resulting in a loss of approximately $104,000. The root cause was that collateral was priced based on the average execution price of the order book for the current block, allowing attackers to influence the price through self-trading, causing fraudulent lending positions to be counted as valid collateral. The attacker initially deployed the contract but did not execute immediately, then used flash loans and self-trading to inflate the price and withdraw USDC. The original attacking wallet was rolled back due to insufficient gas fees; approximately 48 seconds later, the general-purpose sandwich bot coffeebabe took about 0.9 WBTC, worth approximately $72,000, and transferred about 28.8 ETH of it to the ultra sound money builder, keeping only about $29 for itself. Subsequently, another bot took part of the USDC.

Cozy Finance Suffers Ongoing Attack on Optimism, Approximately $170,000 in Assets Stolen

Odaily News DeFi risk management protocol Cozy Finance is currently facing an ongoing attack on its Optimism deployment, with attackers having stolen approximately $170,000 in assets so far. Blockaid has subsequently released preliminary attack information and flagged the attacking transactions along with related attacker addresses. Multiple attacker addresses have now been confirmed, along with a token address suspected to have been exploited in the attack. It remains unclear whether the attack is still ongoing, and users should exercise caution when interacting with contracts associated with Cozy Finance.

Vitalik refutes Silicon Valley investor's "AI will kill BTC" argument: The probability of hash algorithms or PoW being broken is extremely slim

Odaily News Silicon Valley angel investor Liron Shapira (@liron) posted on X this morning: "I predict (with 50% confidence): due to AI shaking the security and stability guarantees people once believed Bitcoin possessed, BTC's price will plummet more than 50% within the next two years."Ethereum co-founder Vitalik Buterin rebutted this, stating: "I hold the exact opposite view. My basic reasoning is that, in the long run, I am quite optimistic about network security. I believe the main challenge lies in smoothly navigating the transition period. Moreover, I think BTC can at least properly handle all problems that do not require social consensus (such as upgrading clients, mining pools, etc., to counter network-level attacks — these fall into this category). Additionally, I believe the probability of hash algorithms or proof-of-work mechanisms being genuinely broken is extremely slim. I would have wanted to bet with you, but considering my current asset allocation (I guess you hold the same view regarding Ethereum ETH), I have already staked about 90% of my net worth on this bet."

After fixing the vulnerability, Liquid's white hat hacker said they would return most of the 4,000 BTC

According to Odaily, monitoring by Galaxy's Head of Research revealed that Liquid's white hat hacker stated they would return most of the 4,000 BTC after the Liquid Network vulnerability is patched. The hacker communicated with Blockstream through OP_RETURN messages and PGP-encrypted text: In block 965,822, a Blockstream address sent 1,000 satoshis with the message "Please contact the security team via the Blockstream website"; in block 965,865, the hacker sent an encrypted message to their own key, accompanied by a detached PGP signature that can be verified using the key published by Blockstream; in block 965,869, the hacker sent 1,000 satoshis to the Liquid federation peg-in wallet via a self-spend transaction with the message "Can we return the majority of the funds to the federation address?"; in block 965,875, the hacker conducted another self-spend transaction, sending 1,000 satoshis to the federation peg-in wallet and leaving an OP_RETURN message: "Please fix the vulnerability first. As of the latest commit, there is risk on-chain. Please ensure every node completes the patch update. Once the fix is confirmed, we will securely transfer the funds back." Relevant technical details were encrypted via PGP messages to the key published by Blockstream, readable only by Blockstream.

SlowMist Alert: Two Attackers Are Replicating the Notional Finance Vulnerability on BSC

According to monitoring by blockchain security firm SlowMist (@SlowMist_Team), two attackers are replicating the recent Notional Finance vulnerability exploit on the BSC chain. Having completed the pre-attack phase, they have created malicious fCash positions using the same vulnerability pattern. The attack has not yet been fully executed; the malicious positions are currently awaiting maturity. Once mature, the attackers may settle the positions and withdraw assets from the protocol. The potentially vulnerable address is 0x0795E2cd771788572b61BeA45Abd6E9a8FC8D9F0. SlowMist strongly recommends that relevant projects take immediate mitigation measures before the positions mature. Previously, the Notional Finance V1 contract was exploited on September 5, resulting in approximately $1.7 million in user funds lost. The affected contracts have been paused.

Approximately 45% of stolen assets have entered coin mixing or cross-chain paths, Coldcard attacker continues to move funds

Odaily News: The attacker behind the Coldcard "Wave 3" exploit continues to move stolen funds. In this phase, the attacker created 293 separate 2-of-2 multisig vaults for each victim's assets. On September 2, the first batch of funds was bridged to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attacker is processing the largest holdings in descending order by stolen amount, having already transferred vaults ranked 1 through 11 in sequence. The next 10 vaults yet to be transferred collectively hold 30.81 BTC, while vaults ranked 61 through 293 collectively hold 33.77 BTC.To date, the attacker has moved approximately 45% of the assets stolen in this exploit, with funds either flowing to Ethereum or entering CoinJoin mixing transactions. This latest transfer activity has also revealed a previously unknown vault: 58 addresses jointly spent funds via a 2-of-2 multisig setup in the same format as Wave 3, with the Wave 3 attacker subsequently routing them to a jump address that funds CoinJoin transactions.This vault is currently marked with "cause = open," but it is highly likely to belong to Coldcard victims as well, which could bring the total number of vaults involved in Wave 3 to 294 and push the previously disclosed total stolen in the Coldcard exploit to approximately 1,806 BTC. At present, roughly 82% of the stolen BTC remains in addresses initially controlled by the attacker, while approximately 18% has been moved, with fund flows suggesting it may be undergoing laundering.

White-Hat Hacker Withdraws Approximately 4,000 BTC from Liquid Network; Side Chain Suspends Operations

According to an announcement from the official Liquid Network X account (@Liquid_BTC), a suspected whitehat hacker withdrew approximately 4,000 BTC worth around $320 million from a Liquid Federation wallet using a SideSwap PAK (Peg-out Authorization Key). The official statement indicated that the key itself was not leaked, and the Blockstream team is attempting to contact the party through on-chain signed messages. Following the incident, exchanges have paused or are about to pause LBTC deposit and withdrawal services. Bridge nodes have been temporarily shut down, and the Liquid sidechain is currently suspended, unable to submit new transactions. Officials emphasized that other Liquid assets such as USDT, DePix, and RWA remain unaffected by this incident, while Federation members are actively working to resolve the issue to restore normal network operations as soon as possible.

Approximately 4,000 BTC transferred in a single transaction linked to Liquid Network, with an on-chain message calling it a "white hat" operation

Odaily News: According to Bitcoin News monitoring, out of 4,200 BTC associated with a peg-out transaction on the Liquid Network, approximately 4,000 BTC appear to have been moved simultaneously. A subsequent transaction included an OP_RETURN message stating: "We are white hats, please contact us on-chain." It remains unclear what the nature of this transaction is, and whether the funds were moved through an exploit.

Bitcoin fork asset BTCB2 once hit $1,799, with a fully diluted valuation of $20.9 billion calculated at a price of $1,000

Odaily News: Bitcoin fork asset BTCB2 hit an all-time high of $1,799 on September 5. Over the past 4 hours, its price has fluctuated between 750 and 1,000 USDC; the Neoxa USDC market recorded a 24-hour trading volume of approximately $1 million.BTCB2 originated from a chain split that occurred on August 8, 2026, at block height 961,632. The network subsequently changed its proof-of-work algorithm to Blake2 and reduced block size, and it can now be mined using Blake2-compatible ASIC miners.Neoxa Exchange and Nonkyc.io have listed BTCB2, with the former offering BTC, USDC, and USDT trading pairs, and the latter offering a USDT trading pair. Both platforms have limited liquidity, and CoinMarketCap and CoinGecko have not yet listed the asset.Based on a BTCB2 price of $1,000, its fully diluted valuation stands at approximately $20.9 billion. Since UTXOs need to be split from Bitcoin first, transactions may otherwise be vulnerable to replay attacks; the network's hash rate has risen by 30.41% over the past 7 days, reaching approximately 5.1 PH/s. (Bitcoin.com News)

Balancer V1 attack suspected to be ongoing, attacker has reportedly profited $250,000 so far

Odaily News According to on-chain detective Specter's monitoring, Balancer appears to have suffered a V1 attack. An attacker is continuously transferring funds and has profited $250,000 so far. The relevant address is 0x112...E0aE.

Jesse Pollak: X Account Hacked, Fraudulent Posts Removed and Control Restored

Odaily News, Base co-founder Jesse Pollak issued a statement on the X platform clarifying that his account was compromised. The attacker published a fraudulent token ticker through a third-party application connected to the account. Jesse stated that the related posts have been deleted, all third-party app connections have been removed, and full control of the account has been restored. He reminded users to stay vigilant.According to screenshots of the deleted posts, the attacker, after gaining control of Jesse Pollak's account, launched a token named BASEMEME, describing it as the "first Meme coin with real utility," while attaching a trading link to o1.exchange and the contract address. The Meme coin's market cap currently stands at $257,000.

Shivon Zilis' account suspected of being hacked, trader buys SLINK and loses approximately $250,000

Neuralink executive Shivon Zilis's X account was reportedly hacked, leading to the publication of two posts promoting the SLINK token. A trader subsequently bought approximately $250,000 worth of SLINK, nearly losing the entire investment as the token's price rapidly crashed to near zero.

G7 urges immediate migration to post-quantum cryptography; Bitcoin, Ethereum, and Solana developers have tested defense solutions

: The G7 cybersecurity working group stated in its latest report that quantum computing poses both a security threat and an economic threat to public and private institutions, and related organizations should immediately begin migrating to post-quantum cryptography (PQC).The working group noted that the migration process could take several years, as attackers can already collect and store encrypted data today and decrypt it once sufficiently powerful quantum computers emerge. Quantum computing could also break digital signatures, leading to identity theft and exposing companies and their supply chains.The report did not mention cryptocurrencies, but similar public-key cryptography is used for blockchain wallets and transaction authorization. Current quantum computers are not yet capable of breaking Bitcoin's cryptography, but developers are considering post-quantum solutions such as BIP-360.Ethereum researchers plan to replace multiple cryptographic components used by accounts, validators, and applications. The Solana Foundation has tested post-quantum signatures on its testnet and launched an optional hash-based vault. The G7 working group also urged governments to support related research, public-private cooperation, and national PQC strategies. (Decrypt)

Balancer sends on-chain message to V1 exploit hacker, demanding return of funds.

Balancer (@Balancer) officially announced that the Balancer team sent an on-chain message to known addresses involved in the Balancer V1 vulnerability incident on September 4. Following industry best practices, the message provides a contact channel for the hackers and requests the return of the stolen funds. The team stated that affected users are waiting for further updates, the investigation is ongoing, and related progress will continue to be disclosed.

At least 1,789 BTC stolen; Coldcard hacker begins swapping for ETH via THORChain, with approximately 10% of stolen BTC moved

Odaily News – According to Bitcoin News monitoring, hackers linked to the third wave of Coldcard wallet thefts have begun moving stolen funds for the first time, converting Bitcoin into ETH via THORChain. Galaxy Research's Alex Thorn stated that approximately 10% of the stolen BTC has been moved, while the remaining 90% remains untouched. The attacker reportedly encountered difficulties during the fund conversion, with multiple THORChain transactions being returned and retried. Researchers have traced the related swap activity to a new Ethereum address, which Alex Thorn noted has been shared with relevant authorities and cryptocurrency companies. Galaxy Research indicated that the broader Coldcard exploit has resulted in losses of at least 1,789 BTC across 8,865 addresses, valued at approximately $115 million based on prices at the time of the theft.

Term Labs hacker deposits 960 ETH cumulatively into Tornado Cash, latest deposit 400 ETH

Odaily News: Term Labs hacker deposited 400 ETH into Tornado Cash, bringing the cumulative total to 960 ETH.

SlowMist: iOS Safari DarkSword Attack Can Steal Wallet Inputs, Zero-Click Trigger with Six-Vulnerability Chain

Odaily News, According to a disclosure by the SlowMist security team, they have detected an attack campaign disguised as a free VPS service, specifically targeting iPhone Safari browsers running iOS versions 18.4 to 18.6.2. The attackers exploited a chain of six vulnerabilities codenamed DarkSword to form a complete attack sequence, covering WebKit remote code execution, sandbox escape, and kernel read/write operations. This allows them to access app container files and keychain data without user awareness, and record keyboard inputs while wallets such as imToken, TokenPocket, or TronLink are in the foreground.The SlowMist team stated that all six aforementioned vulnerabilities have been patched by Apple, and the current attack constitutes reuse of an n-day vulnerability chain. Merely visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen, and device forensics is still required for confirmation. iOS/iPadOS users are advised to upgrade their systems to version 18.7.3 or 26.3 and above as soon as possible.

ZKsync Announces EraVM Security Upgrade, Phasing Out Legacy Execution Environment Over the Next 6 Months

According to the official ZKsync X account (@zksync), ZKsync has announced a security upgrade for its EraVM chain. Core measures include introducing an instant upgrade framework, extending the proving delay from 3 hours to 24 hours, and deploying a second prover, EraBender, to defend against AI-driven vulnerability attacks. Over the next six months, all Boojum/EraVM chains will gradually phase out the legacy execution environment, with each chain formulating and publishing its own transition schedule. Users who hold funds directly in EOAs do not need to take any action at this time. Users who hold funds through smart contracts such as multisigs, smart accounts, DEXs, and lending protocols must take action as required once the transition plans for their respective chains are finalized. The ZKsync Atlas chain remains unaffected by this upgrade.

OpenAI will provide $1 billion in cybersecurity subsidies

According to CoinDesk, OpenAI said it will provide subsidized access to the $1 billion Daybreak cybersecurity model over the next six months, along with training and technical support, to help organizations defend against AI-driven cyberattacks, including potential zero-day exploits. Daybreak is divided into two tiers, Blue and Red, tailored for routine defense and more sensitive cybersecurity tasks, respectively, with about 2,000 organizations already using it.