GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Core Lightning Warns Users to Upgrade, Unupgraded Nodes Should Be Taken Offline

: Bitcoin News posted on X that Core Lightning developers have received a large number of AI-generated CVE reports over the past 10 days, and have verified the existence of vulnerabilities that need to be fixed. The team has now escalated its response, will release signed binaries, and will keep vulnerability details confidential for a two-week period. Core Lightning strongly urges all users to upgrade during this period; users who have not upgraded should take their nodes offline. Previous versions, including 26.04, will no longer be supported.

6 dormant bitcoin wallets inactive for over 10 years transferred 553.59 BTC, worth $40.15 million, within 10 days

Odaily News reported that Galaxy Research tracking found that 6 bitcoin wallets, dormant since 2011, 2012, and 2014, transferred a total of 553.59 BTC between August 16 and 26, valued at $40.15 million at the time of transfer. Two of the wallets carry the "Salomon Client Dusted" tag linked to a New York lawsuit involving Noah Doe.One of the transfers involved 40 BTC from a wallet dormant since May 28, 2012, with the funds moved on August 26 to German crypto custodian bank Boerse Stuttgart Digital. Calculated at a cost of approximately $5, the funds appreciated by roughly 1,535,911%.The remaining transfers included 212 BTC, 150 BTC, and 132.31 BTC, originating from wallets inactive since 2012, 2014, and 2011, respectively. The Noah Doe lawsuit seeks to declare 39,069 dormant bitcoin addresses in New York State as lost property. Additionally, several long-term holding addresses moved funds following the July Coldcard hardware wallet vulnerability incident. (Decrypt)

Coldcard incident boosts BitBox credit card sales by ~10x, while Trezor and OneKey see rising demand

Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)

NES holdings inflated to $50 million, Cosmos EVM exploit attacker actually profited about $60,000

According to Odaily, an investigation into the security vulnerability exploit of the Cosmos EVM module reveals that the primary attacker (0x9AE7) purchased $250,000 worth of NES and bridged it to Nesa Chain, exploiting a balance vulnerability to inflate holdings to 200 times their original size, then bridged approximately $50 million worth of NES back to Ethereum. The attacker's initial funding for the wallet originated from Monero. Through multiple wallets, the attacker exchanged NES for ETH on DEXs and deposited the proceeds into centralized exchanges. Due to rapid liquidity withdrawal, most exchanges suffered extreme slippage, and the attacker ultimately sold for only $315,000, netting a profit of approximately $60,000 after deducting costs.

Kraken Says It Was Hit by a "Dust Attack," Some Customer Accounts Temporarily Locked

According to Bloomberg, digital asset exchange Kraken stated that some customer accounts were temporarily locked after receiving small cryptocurrency transfers from wallets linked to the sanctioned exchange HTX. Kraken refers to such transfers as "dust attacks," which involve sending tiny involuntary transactions to disrupt or manipulate other cryptocurrency users. In this incident, Kraken believes the attackers' objective was likely to trigger the platform's compliance review by spreading sanctioned funds.

Grayscale launches Zcash ETF, trading on NYSE Arca following key privacy vulnerability fix

Odaily News - Digital asset manager Grayscale's Zcash ETF began trading on NYSE Arca on Tuesday under the ticker ZCSH. The product is the world's first exchange-traded product offering spot exposure to Zcash, allowing investors to track ZEC prices through securities accounts without needing to directly purchase or store the token.ZCSH was formerly known as the Grayscale Zcash Trust, established in October 2017 through a private placement. Grayscale filed an application with the U.S. Securities and Exchange Commission in November 2025 to convert the trust into an ETF, with shareholders holding shares that track the fund's ZEC holdings rather than holding ZEC directly.In May of this year, security researcher Taylor Hornby, using Anthropic's Claude Opus 4.8, discovered a vulnerability in Zcash's Orchard shielded pool that had existed for four years, which could potentially allow attackers to mint counterfeit ZEC. Developers deployed an emergency patch on June 1, but due to privacy mechanisms, it was not possible to cryptographically confirm whether the vulnerability had been exploited.Zcash activated the Ironwood upgrade in July, replacing Orchard with a new shielded pool and introducing accounting rules that limit the amount of ZEC exiting the old shielded pool to no more than the amount entering. Grayscale stated it will monitor the adoption of the Ironwood upgrade, network security, exchange support, and regulatory conditions for privacy assets. (Decrypt)

Galaxy: 1,789 Bitcoin Stolen in Coldcard Hack, 87% of Funds Remain Untransferred

According to Cointelegraph, the latest statistics from Galaxy Research show that the Coldcard hack involved 8,865 addresses, resulting in the theft of 1,789.28 Bitcoin valued at approximately $114.7 million based on the price at the time of the incident. Of this amount, 1,561 Bitcoin, representing roughly 87.3% of the stolen funds, have not yet been transferred and remain in aggregation or holding addresses controlled by the attackers.

Approximately 2,077.97 DCR were minted due to a vulnerability, and Decred has decided not to roll back

Odaily News, L1 blockchain Decred stated that between August 16 and 17, its mainnet inflation vulnerability was exploited, resulting in the generation of approximately 2,077.97 DCR. This vulnerability has existed in the consensus code since the mainnet launch in February 2016, stemming from improper handling of edge cases when the regular transaction tree interacts with the stake transaction tree, allowing for double-spending of inputs. The vulnerability was submitted via a bounty program on August 12, but was exploited before a fix could be implemented. Decred has decided not to roll back to minimize the impact on users. The approximately 2,000 DCR minted through this exploit do not affect the 21 million hard cap and are far lower than historical shortfalls in subsidies due to missed votes and other causes, which exceed 215,000 DCR. Currently, the team has developed an additional double-spend monitoring service and plans to improve the emergency upgrade signaling mechanism.

Kylie Jenner's X Account Allegedly Hacked to Promote Same-Named Meme Coin; Market Cap Surges Then Drops 68%

According to BeInCrypto, Kylie Jenner’s X account appears to have been compromised, with an attacker posting the ticker and Pump.fun page link for the Solana-based memecoin kylie before the post was subsequently deleted. The token’s market cap briefly spiked to approximately $1.19 million before retreating by around 68%; at press time, it stood at roughly $378,500.

Term Labs attacker deposited 300 ETH into Tornado Cash, worth approximately $741,000.

According to monitoring by PeckShield, the Term Labs attacker address deposited 300 ETH into Tornado Cash, worth approximately $741,000.

Cosmos Labs: A security incident occurred in the Cosmos EVM module, and its security and engineering teams are addressing it.

Cosmos Labs stated that a security incident is occurring in the Cosmos EVM module and has already affected relevant users. Its security and engineering teams are addressing the situation and have advised the contacted Cosmos EVM chains to require validators to suspend chain operations. Cosmos Labs has not yet disclosed vulnerability details, the affected chains, or specific losses, stating that an incident report will be published after the matter is resolved.

ZachXBT: BitcoinIRA and iTrustCapital Suspected of Experiencing Data Breaches This Year That Have Not Yet Been Publicly Disclosed

According to a post by ZachXBT, after reviewing relevant evidence, he stated that two U.S. investment platforms, BitcoinIRA and iTrustCapital, are suspected of having suffered data breaches this year, though neither appears to have publicly disclosed the incidents to date. The compromised data reportedly includes user profiles, portfolio holdings, banking information, custodian details, and verification statuses. ZachXBT noted that in June 2026, an attacker leveraged information from the relevant database to target a BitcoinIRA user, stealing more than $1.2 million in assets.

TAC was attacked due to a vulnerability in the Cosmos EVM precompile layer, with approximately 2.986 billion TAC tokens transferred.

TAC tweeted that on August 22, an attacker exploited a vulnerability in the Cosmos EVM precompile layer, transferring 2,985,651,403 TAC from a single account on the TAC network. The project team subsequently paused the network at block height 24,671,475 to halt the attack.

Coldcard vulnerability incident causes 1,789.28 BTC losses, affecting 8,865 addresses

Odaily News According to Galaxy's head of research, the Coldcard vulnerability incident involved 8,865 addresses, resulting in total losses of 1,789.28 BTC, valued at $114.7 million at the time of theft and currently valued at $138.8 million.By address, the median loss per address was 0.00152 BTC, with an average of 0.20184 BTC; the median dormancy period for affected addresses was 3.2 years, with an average of 3.6 years.Among 221 victim reports, the median loss was 1.04272 BTC, with an average of 3.57792 BTC; the median dormancy period was 3.25 years, with an average of 2.99 years. The losses reported by victims amount to 790.72 BTC, accounting for 44.2% of total losses. If medium-confidence losses are included and related losses remain unconfirmed, total losses would reach 1,824 BTC, valued at $140 million based on prices at the time of the incident.

Over $40 million in cryptocurrency was stolen across 3 incidents last week, with each victim suffering losses in the tens of millions of dollars

Odaily News: According to on-chain detective Specter's monitoring, three separate incidents last week involved over $40 million in stolen cryptocurrency, with each victim suffering losses in the tens of millions of dollars. Specter noted that a large amount of capital flowed into the market last week, while social engineering, phishing links, and wallet-draining scams also persisted. Specter reminded that cryptocurrency is not an industry where you can simply buy assets and stop paying attention; asset security is part of the investment. It's important to stay updated on the latest attack incidents, wallet exploits, and phishing campaigns. If you're not active on crypto Twitter or security forums, you should at least follow one reliable source that continuously publishes security updates.

454,000 USDC Loss Compensation Method Faces Five Questions from D2 Finance

according to D2 Finance monitoring, derivatives strategy protocol D2 Finance has raised five public questions regarding Tori Finance's operations to cover the shortfall after the Term Finance incident. These include: why 250,500 trUSD tokens were minted in advance instead of directly using existing USDC reserves; the source of the collateral used for minting; the other half of the funds coming from Kraken's hot wallet; the transparency page showing a buffer range of only approximately $17,600, or roughly 3 basis points, far below the scale of the incident's impact; as well as Delta Neutrality verification, high-yield money market positions, and hedging methods. Previously, the Term Finance governance vulnerability incident affected RockawayX Tori USDC Vault, resulting in a loss of approximately 454,000 USDC. RockawayX and Tori Finance subsequently stated that the loss has been fully covered by both parties.

Besu fixes 5 security vulnerabilities, version 26.7.1 released on July 27

Odaily News: Ethereum client Besu has fixed 5 security vulnerabilities discovered by blockchain security firm CertiK in version 26.7.1 released on July 27, and published 4 detailed security advisories on August 14. Vulnerability details were disclosed after a delay to allow node operators to complete upgrade deployments.Jialiang Chang, Director of Security Engineering and Senior Audit Partner at CertiK, stated that the arrangement of releasing patches first and details later provided an 18-day buffer period, allowing node operators to identify affected deployments, test new versions, and coordinate with validators or consortium participants to complete upgrades.The vulnerabilities involve block broadcast handling, caching of future-height consensus proposals, WebSocket subscription limits, and JSON-RPC filter creation. If left unpatched, attackers could exhaust node memory or thread resources, impacting node availability and consensus processing.Using the Chain Scan methodology, CertiK conducted adversarial testing on peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi-node test network, and provided reproducible testing tools to the Besu team. CertiK is updating Chain Scan to expand round-the-clock multi-node testing on public chain networks. (Bitcoin.com News)

Peter Schiff: Artificial intelligence is not bullish for Bitcoin, but rather a threat.

Renowned gold bull and economist Peter Schiff posted on social media to refute Bitcoin advocates' strategy of bundling artificial intelligence (AI) with Bitcoin for speculative trading, bluntly stating that AI poses a threat to Bitcoin rather than offering any benefits. Schiff pointed out that AI and Bitcoin compete directly for speculative capital, electricity, and data center resources. More critically, AI could uncover vulnerabilities in Bitcoin's code, cryptographic algorithms, wallets, or network that remain undetected by humans, thereby undermining the foundations of its security and scarcity.

Term Labs:Term Meta Vault 已关闭,DAO 治理角色已被撤销

Term Labs 发文更新漏洞事件进展。目前所有 Term Meta Vault 已关闭,DAO 治理角色已被撤销。此关闭不可逆,永久禁止进一步存款,但提款仍开放。本次事件涉及 Term Vault 治理。底层 Term 协议及其直接借贷市场尚未受到影响,团队正在继续核实影响范围。若仍存在资金缺口,团队将寻找解决途径。 此前消息,据 CertiK 监测,Term Finance 于昨日遭遇治理攻击,损失约 850 万美元。

SafePal Updates Security Incident Progress: Launches Anti-Phishing Initiative, Will Commission Third-Party Agency to Review Order System

Odaily News: Cryptocurrency wallet project SafePal has released an update on the security incident, stating that it is continuously tracking phishing websites and impersonating accounts. The company plans to bring in a professional anti-phishing security firm to expedite the takedown of malicious information, aiming to protect user asset security.SafePal stated that it is currently in the final selection process among 4 professional anti-phishing security firms. Once a partner is chosen, it will further enhance the efficiency of handling threats such as imitation websites and fraudulent accounts. The team is also continuously monitoring whether affected data has been sold or made public, including channels such as dark web forums and trading markets. In the event that any signs of data leakage are detected, affected users will receive risk alerts as a top priority.In terms of security auditing, SafePal stated that it is making a final selection among 3 established independent security agencies, which will conduct a comprehensive security review of the order system. Meanwhile, the team is re-evaluating the order and logistics processes to reduce the scale of data that needs to be stored during the initial phase of the system, thereby lowering potential risks at the source.For affected users, SafePal stated that it will continue to provide one-on-one assistance through official support channels and will keep updating its fraud prevention page with event progress, frequently asked questions, and analysis of scam cases.SafePal once again reminds users: The official team will never ask users for their Seed Phrase. Users should not disclose their seed phrase to anyone, should not scan unknown QR codes or click on suspicious links, and should verify information sources through official channels.