News linked to this event type.
Odaily News, According to a disclosure by the SlowMist security team, they have detected an attack campaign disguised as a free VPS service, specifically targeting iPhone Safari browsers running iOS versions 18.4 to 18.6.2. The attackers exploited a chain of six vulnerabilities codenamed DarkSword to form a complete attack sequence, covering WebKit remote code execution, sandbox escape, and kernel read/write operations. This allows them to access app container files and keychain data without user awareness, and record keyboard inputs while wallets such as imToken, TokenPocket, or TronLink are in the foreground.The SlowMist team stated that all six aforementioned vulnerabilities have been patched by Apple, and the current attack constitutes reuse of an n-day vulnerability chain. Merely visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen, and device forensics is still required for confirmation. iOS/iPadOS users are advised to upgrade their systems to version 18.7.3 or 26.3 and above as soon as possible.
According to the official ZKsync X account (@zksync), ZKsync has announced a security upgrade for its EraVM chain. Core measures include introducing an instant upgrade framework, extending the proving delay from 3 hours to 24 hours, and deploying a second prover, EraBender, to defend against AI-driven vulnerability attacks. Over the next six months, all Boojum/EraVM chains will gradually phase out the legacy execution environment, with each chain formulating and publishing its own transition schedule. Users who hold funds directly in EOAs do not need to take any action at this time. Users who hold funds through smart contracts such as multisigs, smart accounts, DEXs, and lending protocols must take action as required once the transition plans for their respective chains are finalized. The ZKsync Atlas chain remains unaffected by this upgrade.
According to CoinDesk, OpenAI said it will provide subsidized access to the $1 billion Daybreak cybersecurity model over the next six months, along with training and technical support, to help organizations defend against AI-driven cyberattacks, including potential zero-day exploits. Daybreak is divided into two tiers, Blue and Red, tailored for routine defense and more sensitive cybersecurity tasks, respectively, with about 2,000 organizations already using it.
According to PeckShieldAlert citing Specter's monitoring, Notional Finance's custody contract may have been exploited, resulting in approximately $1.7 million in DAI and USDC losses. The attacker has converted the stolen funds into 689.2 ETH and deposited them into Tornado Cash.
PeckShieldAlert monitoring shows that an address flagged as the TectonicFi attacker has deposited 2,658.9 ETH into Tornado Cash, valued at approximately $6.65 million.
US Vice President Vance stated that the conflict with Iran is not a war, emphasizing that Iran must stop attacking merchant ships before negotiations can begin. He also publicly called for the Federal Reserve to cut interest rates, noting that the White House is pushing for lower rates.
U.S. Vice President Vance stated that shipping in the Strait of Hormuz has returned to pre-conflict levels, but the U.S. will not engage in dialogue with Iran unless it stops attacking merchant vessels. No major combat operations are currently underway.
According to CriptoNoticias, Argentina's Public Prosecutor's Office (MPF) conducted a specialized training course titled "Virtual Assets: Financial Analysis, Tracking, Detection and Confiscation" via Zoom on August 19 and September 2, 2026, for internal staff, officials, and judges. Led by anti-money laundering specialist Carmen Chena, the curriculum covered digital wallet asset analysis, domestic and international legal frameworks, the cryptocurrency ecosystem, and practical case studies on preservation measures. Previously, Argentina's judiciary had already accumulated extensive experience in cryptocurrency-related cases, including the freezing of 3 million USDT in December 2024 and the 2022 ruling ordering Binance to return stolen BTC.
As reported by Securityweek, AI security company HiddenLayer has announced the completion of a $100 million Series B funding round. This round was led by Delta-v Capital, with participation from Booz Allen Ventures, Microsoft’s M12, Morgan Stanley, and Ten Eleven Ventures. To date, the company’s cumulative funding has exceeded $155 million. HiddenLayer specializes in full-lifecycle security for Generative AI, Predictive AI, and AI Agents. Its enterprise platform features capabilities including AI asset discovery, AI supply chain security, attack simulation, and runtime protection. The newly raised capital will be primarily directed toward expanding AI Agent runtime security capabilities, particularly for AI coding agents.
Odaily News, September 3 — WEEX Exchange announced that the WEEX Hackathon Season 2, themed "AI Wars II: The Algorithm Era," is now officially live. Global AI developers, quantitative traders, Web3 builders, teams, and individuals are invited to join Team AI or Team Human to compete in five rounds of live market trading battles, vying for rankings and rewards based on PnL% performance. The total prize pool stands at 600,000 USDT, with multi-tiered incentives designed to accommodate different participation methods.The early registration phase runs from September 3 to 6, during which the first 2,000 registrants can share in the 100,000 USDT Early Bird prize pool. Additionally, users who register early can complete event tasks ahead of time to accumulate activity points for the upcoming competition.
The LayerZero research team, in collaboration with Oblivious Labs and researchers from Carnegie Mellon University, has published a paper introducing OTTER, a novel automated market maker mechanism designed to enhance resilience against maximum extractable value (MEV). OTTER employs a batch clearing mechanism modeled after Vickrey-Clarke-Groves (VCG) auctions, making truthful reporting of valuations and budgets a dominant strategy for traders, while diminishing block builders' ability to profit from transaction ordering, sandwich attacks, or injecting false bids.
Odaily News, lawyer Ariel Givner stated that hardware wallet manufacturer Ledger is facing a class action lawsuit in New York. The complaint alleges that a security incident in December 2023 exposed customers' personally identifiable information such as names, email addresses, and phone numbers, and that the company failed to disclose the breach in a timely and complete manner. Hackers subsequently used the contact information to impersonate official representatives, tricking customers into approving fraudulent transactions and stealing crypto assets. The compromised information was also circulated on the dark web.
Malwarebytes researchers discovered a website disguised as a Grand Theft Auto VI (GTA 6) fan countdown page that lured users into purchasing the so-called leaked version of the game and loaded a wallet drainer program after users connected their cryptocurrency wallets. The malicious code checks wallet balances, identifies tokens and NFTs, and transfers assets once users approve transactions or grant authorizations.
Odaily News: According to monitoring by Galaxy's Head of Research, the COLDCARD Wave 3 attacker has moved stolen funds for the first time, exchanging them for ETH via the THORChain cross-chain DEX. This marks the first on-chain transfer of funds from the original hacker address across Waves 1, 2, or 3.
Federal law enforcement agencies of the U.S. Department of Justice, in collaboration with organizations including CrowdStrike, have successfully disrupted the long-running Sality botnet. The group used malware to alter users' clipboard addresses, stealing approximately $150,000 in cryptocurrency.
According to CoinDesk, US cybersecurity firm CrowdStrike has partnered with federal law enforcement agencies to successfully dismantle the Russian botnet Sality, which has been operating for over two decades. Over the past eight years, the network has continuously stolen cryptocurrency through clipboard hijacking; its core payload, "EggJagger," resides on infected machines, monitoring the user's clipboard. Once a Bitcoin or Ethereum wallet address is detected, it is replaced with the attacker's address, causing victims to unknowingly complete transfers. Sality employs a decentralized P2P architecture with no central server, checking node online status every 40 minutes, and self-propagates via network-shared drives and USB devices. By exploiting an authentication vulnerability, CrowdStrike replaced legitimate node addresses with those of its own servers, successfully severing the network connections of over 15,000 infected machines. The operation was demonstrated live at the Day Zero summit in Las Vegas. Estimates indicate that the attackers stole at least 12.1 million rubles (approximately $150,000) over the eight-year period. Undisturbed crypto assets appreciated alongside the broader market, reaching a value of roughly $1.35 million by early 2025. Security experts advise users to always verify the first and last characters after pasting a wallet address to defend against such attacks.
According to The Block, the Wyoming Stable Token Committee announced the adoption of Chainlink Proof of Reserve to provide near-real-time on-chain reserve validation for its official stablecoin, Frontier Stable Token (FRNT). The Network Firm will audit FRNT reserves in accordance with AICPA standards, while Chainlink will post verification data on-chain in real time to bridge information gaps between reporting cycles. Previously, Wyoming fully migrated FRNT from LayerZero to Chainlink CCIP last month as its sole cross-chain infrastructure. The committee is also advancing the Chainlink Proof of Reserve Secure Mint feature, which requires verifying that reserves do not fall below FRNT's total supply before minting new tokens to prevent infinite minting attacks. FRNT launched in January this year and is the United States' first government-issued stable token, backed by U.S. dollars and short-term U.S. Treasuries.
Odaily News: CrowdStrike, in coordination with the U.S. Department of Justice, announced the dismantling of the Sality peer-to-peer botnet, isolating over 15,000 infected devices worldwide. The network has been active since 2003, and over the past eight years has primarily deployed a clipboard hijacking tool known as EggJagger to steal funds from Bitcoin and ETH transfers. EggJagger monitors cryptocurrency wallet addresses copied by victims and replaces them with addresses controlled by the attackers, redirecting transfer funds to the attackers. CrowdStrike estimates that this tool alone has stolen at least $150,000 in crypto assets; since most of the funds were not moved, the value of the associated holdings rose to approximately $1.35 million in January 2025. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service have seized related domains within the U.S., while police in Bulgaria, Hungary, and Romania have also shut down infrastructure in Europe. Currently, infected devices have been redirected to traffic reception servers controlled by CrowdStrike, but the original malware on the devices remains active until manually removed.
According to a report by the Securities Times, at the 4th Cyberspace Security (Tianjin) Forum, Zhou Hongyi, founder of the 360 Group, delivered a keynote presentation, stating that AI has reshaped the cyber attack and defense landscape, rendering traditional solutions unsustainable. It is essential to build a new automated cyber defense and offense system centered on "governing models with models," leveraging AI capabilities to mitigate AI risks, ensure the inherent security of large models, the reliability of generated content, and the trustworthiness of output results; and to implement full lifecycle management of AI agents, establishing control mechanisms that are auditable, subject to intervention, and capable of being blocked.
Odaily News: According to Defimon monitoring, YAM Finance has suffered a governance takeover attack. The attacker self-delegated approximately 504,000 YAM tokens, accounting for about 3.3% of the total supply, slightly above the legal voting threshold, and subsequently submitted proposal #45 to YamGovernorAlpha. The proposal description is empty and only contains an operation to call the setPendingAdmin method of the YAM Timelock contract, redirecting permissions to the attacker's address. If the proposal passes and is executed, the attacker will become pendingAdmin and can then fully control the Timelock through acceptAdmin, thereby gaining administrative access to all YAM protocol contracts and the DAO treasury, involving a risk amount of approximately $337,000. As the YAM protocol is currently in a dormant state, Defimon Alerts reminds YAM holders to vote against this proposal before block height 25897343, with approximately 34 hours remaining until that block.