GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Polygon Fixes Multiple Security Vulnerabilities, Austin and Kyoto Forks Go Live

Polygon disclosed multiple hidden security vulnerabilities affecting its PoS network and implemented preventive fixes through a recent fork, with no evidence of actual exploitation.

Refi Hub Co-founder Hit by Malicious Claude Link Attack, Contaminated Skill File Attempts to Steal Credentials

Odaily News: Numa Lunah, co-founder of the crypto project Refi Hub, stated that he was hacked after using a download link provided in a Claude chat window to install a transcription application. The link pointed to a fake website bundled with malware, which attempted to steal all information from his device upon execution.Numa Lunah said he wiped and reinstalled the affected laptop and found no signs of sensitive data leakage. Subsequently, he discovered a contaminated Claude Code skill file named SKILL.md in his backups. The file was disguised as a style guide written by himself and contained instructions to re-download malware and steal credentials every time it was loaded.Microsoft Defender Experts previously warned that attackers have shifted from search engine optimization poisoning to large language model response poisoning. These tactics include recommending attacker-controlled download links, AI-branded fake installers, and contaminated code repositories and agent skills. Individuals working in the crypto industry may hold irrevocable credentials such as mnemonic phrases, private key files, hot wallet JSONs, exchange API keys with withdrawal permissions, and deployer keys. (Bitcoin.com News)

Starkware completes quantum-resistant transaction on Bitcoin mainnet without soft fork

: Blockchain technology company Starkware stated that on August 26, a transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) scheme was mined on the Bitcoin mainnet, without requiring a soft fork, hard fork, or modification of consensus rules.The transaction consumed 10,000 sats and was processed through MARA Foundation's Slipstream service, as the non-standard format typically cannot propagate through Bitcoin's public mempool. The test consumed several hours of GPU computation, costing approximately $150 to $200.QSB employs hash-based quantum-resistant spending conditions and reduces quantum attack risks through signature trial mining, but still requires users to proactively migrate funds and cannot protect assets whose public keys have already been exposed. Starkware CEO Eli Ben-Sasson still supports introducing a protocol-level solution via a soft fork. (Bitcoin.com News)

Ajna v2 Suffers Liquidation Accounting Manipulation Attack, Losing Approximately $775,000

Decentralized lending protocol Ajna tweeted that Ajna v2 was exploited and is investigating abnormal fund flows, advising users to withdraw all funds, repay loans, and pause interactions with the protocol. The incident caused approximately $775,000 in losses across pools including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI, attributed to a liquidation accounting manipulation attack.

1685 users affected, Avici will fully refund card balances of $500,900

Odaily News, Avici announced that its card partner Rain discovered today a vulnerability in an old Solana card contract used by Avici and a few other projects. The relevant contract has now been upgraded across all projects, and no further unauthorized activity has been detected. This incident only affected the standalone Solana contract used to hold post-deposit card balances; users' Avici wallets and card balances are isolated from each other, and funds in Solana and EVM self-custody wallets are safe and unaffected. Upon review, a total of 1,685 users were affected, with combined card balances of approximately $500,900. Avici has committed to fully refunding card balances to all affected users and has filed a report with the FBI's Internet Crime Complaint Center (IC3). Previously reported, Avici, a crypto banking project, saw its native token AVICI allegedly suffer a hacker attack, with losses of approximately $1.02 million. The attacker transferred 10,000 SOL stolen from the project to another wallet, converted it into approximately $1.02 million USDC, and then swapped the funds into approximately 418 ETH via cross-chain operations.

A loss of $82,400: An address's assets have shrunk by 90.7% after investing over $90,000 total in GOLD

Odaily News: According to monitoring by on-chain analyst Ai Yi, address Emxhs...euZMP spent $72,700 to build a position during GOLD's market cap surge, when GOLD's market cap was below $40 million. After the tweet was deleted and theft rumors circulated, the address added another $18,100, bringing its total investment to over $90,000. Currently, the address has a loss of $82,400, with its assets shrinking by 90.7%.

Avici: Solana Card Contract Vulnerability Affects Approximately $500,900 in Card Balances; Affected Users Will Receive Full Refunds

Avici stated that its card-issuing partner, Rain, discovered a vulnerability in a specific version of the Solana card contract used by Avici and a few other projects. The relevant contracts have since been upgraded, and no further unauthorized activity has been detected to date. Avici clarified that user wallets and card balances are independent, meaning funds in Solana and EVM wallets remain unaffected; this incident only impacted the isolated Solana contract designated for storing card balances. Current reconciliations indicate that 1,685 users were affected, involving card balances totaling $500,859.22. All affected users will receive full refunds.

Approximately 400 Million FOGO Tokens Transferred, Fogo Foundation Suffers Attack

Odaily News: An unknown attacker breached the Fogo Foundation, resulting in the transfer of approximately 400 million FOGO tokens to a malicious address. The Fogo Foundation has notified major exchanges and is in communication with law enforcement and blockchain forensics experts. This incident will not affect the Fogo blockchain itself, and the network remains operational. The Fogo Foundation will provide further updates as more information becomes available.

CZ Comments on Justin Sun’s Emotional and Property Dispute: Industry Should Avoid Personal Attacks and Raise Its Own Standards

Binance founder CZ stated on social media that while marketing can be more aggressive, it should not involve exploitation or escalate into personal attacks that could even undermine others' future career prospects. He noted that directly addressing the issue through legal channels would be more appropriate than disclosing unnecessary details, and urged all parties to resolve the matter amicably and with mutual respect. CZ later added that the industry should hold itself to higher standards. In response, Justin Sun replied expressing his gratitude and agreement, stating, “With mutual respect and a proper resolution, the rest will be left to the courts. I have nothing further to say.”

CZ comments on Sun Yuchen's dispute: No need for personal attacks, better to resolve through legal means

Odaily News CZ recently commented on the emotional and property dispute involving Sun Yuchen, stating that while aggressive marketing is acceptable, there is no need to resort to personal attacks or affect others' future career development through such incidents. Compared to disclosing unnecessary details, it is better to resolve the matter directly through legal channels. He hopes both parties can handle the situation properly and show mutual respect.CZ further added that the crypto industry should hold itself to higher standards. In response, Sun Yuchen expressed agreement, saying, "Mutual respect, proper resolution, and leave the rest to the court—I will not say more."

Loss of approximately $1.02 million, AVICI attacked, attacker exchanged 10,000 SOL for about $1.02 million USDC and then cross-chain exchanged for 418 ETH

Odaily News, according to Onchain Lens monitoring, AVICI has been attacked, with losses of approximately $1.02 million. An address transferred 10,000 SOL to another wallet, exchanged it for approximately $1.02 million USDC, and then bridged the funds across chains to exchange for about 418 ETH.

Coldcard hacker still active, stealing keys generated by adding entropy from 5 dice rolls

Odaily News: According to monitoring by Galaxy's Head of Research, the Coldcard hacker remains active, with one hacker stealing a key generated by adding entropy from 5 dice rolls.

Core Lightning releases emergency security update, all node operators advised to upgrade immediately

Odaily News: Bitcoin News posted on X platform that Core Lightning version 26.06.7 has been released, fixing multiple vulnerabilities that were responsibly disclosed over the past three weeks. Recently, there has been an increase in AI-generated security reports targeting open-source Bitcoin projects. Specific vulnerability details will be kept confidential for two weeks to allow node operators to complete upgrades before technical details and source code are published. Developers warned that immediately disclosing the fixes could allow attackers to reverse-engineer the vulnerabilities and attack nodes that have not yet been updated. All Core Lightning node operators should upgrade immediately. Docker images are not yet available, and developers have explicitly warned users not to wait for the Docker image.

Lazarus Group hackers are active again, transferring 244.148 BTC worth $19.42 million an hour ago

Odaily News: According to Lookonchain monitoring, Lazarus Group hackers transferred 244.148 BTC, worth $19.42 million, an hour ago.

Bitcoin ETFs See 8 Consecutive Days of Net Inflows Totaling $2.8 Billion, Strongest Inflow Streak in 10 Months

Odaily News: Bitcoin News posted on X platform that U.S. spot Bitcoin ETFs have recorded net inflows for 8 consecutive days, totaling $2.8 billion. August has become the strongest month for capital inflows since 2026.As Bitcoin and gold rise in tandem, investors are increasingly seeking to hedge against risks including a weakening U.S. dollar, persistent inflation, and the widening U.S. fiscal deficit. Gold funds have also seen record demand.This shift is beginning to reflect in ETF trading. IBIT and GLD have rejoined the list of the top 10 most-traded ETFs, after semiconductor funds dominated for most of the summer.BlackRock noted that another significant source of demand comes from existing Bitcoin holders moving their tokens into ETFs. The company has so far processed approximately $5 billion in deferred-tax Bitcoin transfers into ETFs, and the minimum conversion amount has recently been lowered from $25 million to $1 million."As we continue to expand access, this scale will continue to grow," said Robbie Mitchnick, Head of Digital Assets at BlackRock.Mitchnick pointed out that incidents such as kidnappings, ransomware attacks, and custody failures are driving some Bitcoin holders to shift toward ETF custody.Bitcoin and gold are once again aligning with the core of the same macroeconomic logic, as the currency debasement trade makes a comeback.

SlowMist: Malicious GitHub Repository Disguised as Qwen Model Discovered

Odaily News – SlowMist security team has disclosed the discovery of a GitHub repository impersonating the Qwen 3.8 27B local quantized model. The repository claims the model size exceeds 16 GB, but the actual downloaded content is only about 487 KB, containing disguised files, a LuaJIT interpreter, and obfuscated Lua scripts. SlowMist emphasized that the official Qwen project has not been compromised. According to SlowMist's analysis, once executed, the malicious program collects host data, captures screenshots, and sends them to the attacker's C2 server. When the hardcoded server becomes inactive, it reads a backup C2 address from a contract on the Polygon chain, allowing attackers to rotate infrastructure through on-chain transactions. Subsequent payloads can steal browser login credentials, cookies, browsing history, email accounts, WinSCP and Steam credentials, as well as wallet-related files and extension data. SlowMist also discovered at least 23 GitHub repositories and 29 similar archive files using the same Lua delivery chain.

MANTRA Discloses Security Incident Post-Mortem: ~721M MANTRA Tokens Transferred, Chain Offline for 30 Hours

MANTRA has released a complete review of the August 20 security incident. The incident stemmed from an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency, cosmos/evm. Without requiring privileged access, the attacker transferred a combined total of 720,923,967.99 MANTRA tokens from a burn address and a legacy genesis multisig address, amounting to approximately $3.6 million at pre-incident prices.

OneKey Reproduces Transaction Replacement Vulnerability in Legacy Ledger Ethereum App in the Lab

According to Cointelegraph, open-source wallet provider OneKey stated that its security team successfully reproduced a "transaction replacement attack" targeting the legacy Ledger Ethereum app version 1.22.1 in a laboratory environment. This vulnerability could allow attackers to replace transactions awaiting signature while users review legitimate ones, though successful exploitation requires controlling communication between the device and the host, such as through malware, compromised wallet software, or malicious websites.

Privacy Pools vulnerability fixed in March; 0xbow.io awards $5,000 bounty to researcher ross.wei

Odaily News: 0xbow.io, a privacy and regulatory compliance tool supported by the Ethereum Foundation, has awarded a $5,000 bounty to researcher ross.wei for disclosing a vulnerability in the Privacy Pools v1 SDK. The vulnerability reduced the entropy of user account master key generation and was fixed in March. The team has provided a migration process, and no user funds were lost.

The Sandbox plans 1:1 compensation, approximately $700K in SAND stolen in bridge vulnerability exploit

blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)