News linked to this event type.
Ripple与XRP Ledger基金会(XRPLF)联合成立新组织XRP Asia,旨在推动亚太地区XRP Ledger(XRPL)生态发展,总部位于新加坡,由前Hedera基金会亚太及金融科技/支付业务负责人Sabrina Tachdjian领导,该组织将支持开发者培训、黑客松、合作伙伴计划、创业支持以及生态活动,并对接基础设施服务商、孵化及资助项目,以及连接投资者和生态合作伙伴。
Odaily reports, according to Bitcoin News monitoring, Core Lightning stated that attackers are targeting nodes still running version 26.06.7 and earlier. The 26.06.8 patch released on September 22 fixes a channel closure issue that could jeopardize funds, as well as vulnerabilities that cause crashes and memory exhaustion. The project has not yet disclosed the name of the vulnerability used by attackers, nor has it reported any stolen funds. Node operators who have not yet upgraded are becoming attack targets.
According to the Arbitrum Security Council report, Arbitrum took emergency action at around 23:30 Beijing Time on October 2 to temporarily halt the activation of new Stylus contracts on Arbitrum One and Nova, in order to mitigate the risk of AI-assisted attacks utilizing custom WebAssembly programs.
According to Yonhap News Agency, South Korea's five major commercial banks were all targeted by suspected AI-driven cyberattacks, with customer information leaked at three of them. The simultaneous attack on all five banks marks a first in South Korea's financial industry. According to reports, BNK Busan Bank suffered a breach that exposed the personal information of 11 outsourced employees; KB Kookmin Bank had the personal information of 119 customers leaked, while Hana Bank also confirmed that data belonging to 89 clients was compromised.
Revoke.cash issued a reminder stating that, following last week's Magic Eden security incident, Ultimate subscribers must ensure their wallets meet two conditions for the Auto-Revoking feature to properly protect assets: first, granting Auto-Revoking permissions for the wallet in MetaMask; second, the wallet has been upgraded to a MetaMask Smart Account on the corresponding network. The second step is normally completed automatically during the authorization process, but if the address had already been upgraded to a Smart Account via another wallet application, the upgrade may fail.
Alex Shevchenko, General Manager of NEAR Intents, stated that just hours after issuing a 48-hour return deadline to the identified attacker, the $3.8 million stolen from NEAR Intents has been fully refunded. The team has halted its investigation and is calling on security researchers to report issues through a bug bounty program in the future, rather than disrupting network services.
Consensys founder Joseph Lubin stated in a post that the team has recently addressed and resolved a security incident impacting some infrastructure. Based on current investigation results, there is no indication that the MetaMask wallet or user funds within it were affected. The mnemonic phrase, private keys, and wallet assets were not compromised in this incident, and users retain full control over their assets.
According to Decrypt, Spanish police arrested a 16-year-old Romanian suspect in Alicante for allegedly serving as an administrator and primary operator of the KillSec ransomware group. The operation is part of "Operation KillSwitch," with law enforcement agencies from across Europe taking control of five of the organization's core servers and its data leak site, and securing at least 110 TB of stolen data.
Odaily News: Spanish police have arrested a 16-year-old Romanian national in Alicante on suspicion of being the administrator and primary operator of the KillSec ransomware group. Europol stated that law enforcement agencies have seized control of the group's servers and leak site, and preserved at least 110 TB of stolen data.The operation involved searches at 8 residences across Spain, Greece, Romania, and the United Kingdom, investigating approximately 1,000 suspected attacks worldwide, of which about 500 have been confirmed successful. Two other suspects in their 20s were arrested in the UK and Romania respectively, while a Dutch national residing in the UK was indicted and arrested in Puerto Rico, awaiting extradition.KillSec has been active since around 2024, often demanding ransoms in cryptocurrency and carrying out double extortion through encrypted servers and threats to publish stolen data. Investigators are tracing the group's proceeds, including cryptocurrency; Europol's European Cybercrime Centre provided cryptocurrency tracing and digital forensics support. (Decrypt)
according to monitoring by Stani Kulechov, Aave founder Stani Kulechov stated that what was exploited was a third-party external adapter built on top of Aave v3, and the Aave v3 contracts themselves were not affected. The FlashLoopAdapter in the Aave v3 Loop Safe module involved had access control vulnerabilities in its open() and close() functions. The attacker forged Safe authentication and arbitrary module execution to steal approximately 114.09 ETH from two Safe multisig addresses, and repaid approximately 1,300 WETH in debt to unlock collateral.
the Core Lightning team, which develops the Bitcoin Lightning Network node software, is warning node operators running version 26.06.7 or earlier to upgrade to the latest version as soon as possible. The team said it has received reports of attackers targeting unpatched nodes, but did not disclose the vulnerability exploited by the attackers or the potential impact.Core Lightning said on September 16 that it was investigating an issue that could affect experimental features and user funds, and on September 22 released version 26.06.8 to fix the vulnerability and update the software. This announcement did not state whether the previously reported attacks were related to the vulnerability fixed in this version. (Cointelegraph)
SlowMist has issued a security alert stating that a vulnerability has been discovered in the Aave V3 Loop Safe Module. Attackers exploited forged Safe authentication and arbitrary Module execution to steal approximately 114.09 ETH from two Safe multisig wallets.The attackers bypassed authentication by forging a Safe that always returns true, and leveraged an arbitrarily controllable router and calldata to execute module transactions, transferring weETH and Aave collateral. The attackers repaid approximately 1,300 WETH in debt to unlock the collateral.
According to Cointelegraph, Alex Shevchenko, General Manager of NEAR Intents, stated that the team has identified the hackers behind the previous security incident and given them a 48-hour deadline to return the stolen funds through a "responsible disclosure." NEAR Intents previously suspended its services due to a vulnerability in the interaction between the Omni deposit and withdrawal infrastructure and its smart contracts. Initial investigations revealed that approximately $3.8 million in user funds were stolen in the incident, and the team has committed to fully compensating affected users. On-chain detective ZachXBT stated that the stolen funds were subsequently transferred to KuCoin and cross-chain converted into Bitcoin.
Odaily News: NEAR Intents has stated that it has identified the attacker responsible for the loss of user funds and has demanded the return of $3.8 million within 48 hours through a "responsible disclosure" mechanism, after which the window will be closed.NEAR Intents suspended services on Thursday after discovering a vulnerability in the interaction between the Omni deposit and withdrawal infrastructure and its smart contracts. A preliminary investigation showed that the attack resulted in the theft of $3.8 million in user funds, and the platform has committed to fully compensating affected users.On-chain investigator ZachXBT disclosed that the related funds were transferred to the KuCoin exchange and subsequently bridged to Bitcoin. (Cointelegraph)
Odaily News: A new proposal has been submitted on the NEAR governance forum by Sal Ternullo, CEO of Svrn AI, recommending that the NEAR token issuance rate be reduced from 2.5% to 1.6% over 24 months, with a long-term push toward a fixed total supply. The proposal is currently open for discussion among validators, House of Stake representatives, and the broader NEAR community.The NEAR team stated that the NEAR Intents incident did not involve any vulnerability in NEAR Protocol or the native NEAR token. The network continued producing blocks and processing transactions without downtime during the period.
NEAR Protocol announced on the X platform that Sal Ternullo, CEO of NEAR Treasury Company SVRN, has introduced a new proposal on the NEAR Governance Forum to reduce NEAR's annual maximum token issuance rate from 2.5% to 1.6% over a 24-month period, and lower the staking yield from the current approximately 5.4% to around 3.5%. The proposal is currently soliciting feedback from validators, House of Stake delegates, and NEAR community members, with a complete plan expected to be published next week for voting. Following the earlier NEAR Intents security incident, NEAR Protocol further clarified that the blockchain network is operating normally. The incident was not caused by any vulnerabilities in NEAR Protocol or its native NEAR token. The NEAR Protocol network continues to produce blocks and process transactions without experiencing downtime.
Zano disclosed a validation flaw in the Gateway Addresses introduced by Hard Fork 6. An attacker minted approximately 18.4 million ZANO in a single transaction on August 29, then minted an equal amount again on September 25, and minted fUSD in the same manner.The project team stated that the value of the illicit tokens involved exceeds $200 million, with potentially affected activity involving 117,941 outputs and 65,301 transactions. Zano has restored the chain state from block 3,833,000 and disabled Gateway Addresses. All affected balances will be fully restored, and the ZANO supply and issuance schedule will remain unchanged. (Bitcoin.com News)
Odaily News — According to monitoring by Drift Foundation, DFX claims and redemption are now live. Users with verified losses from the April 1 incident can claim 1 DFX per 1 USDT lost. Each DFX corresponds to a claim on the Recovery Pool, which currently holds approximately 3.11 million USDT. The funding sources include a portion of Velocity's daily protocol net revenue, up to 127.5 million USDT in matching funds from Tether, up to 20 million USDT from strategic partners, and assets recovered subsequently.DFX can be redeemed for USDT at a redemption amount calculated as "Recovery Pool balance ÷ DFX outstanding supply." Redeemed DFX will be burned, and transactions are irreversible. The claims window will close on January 1, 2028, at 00:00 UTC, at which point unclaimed DFX will be burned.Yesterday, Drift Foundation released an update on fund recovery efforts related to the April 1 security incident, in which approximately $295 million in user assets were stolen. The Foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct investigations and trace funds, with Mandiant identifying the attacker as North Korean threat group UNC6862.
Illia Polosukhin stated that the attack involving approximately $3.8 million only affected USDT on BSC. NEAR Intents and near.com are now back online, and affected users will receive full compensation.
According to PeckShield monitoring, the NEAR Intents attacker has transferred the stolen funds to KuCoin and bridged them to BTC; the associated address had previously interacted with addresses flagged as Lazarus Group.