GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Yuga Labs Vice President: PPv2 Exploit Ongoing, Urges Users to Revoke Token Approvals Immediately

Yuga Labs Blockchain Vice President Quit (0xQuit) warns that the security vulnerability associated with PPv2 remains actively exploited, leaving even previously unaffected users at risk. Monitoring shows that an address was drained within a single block after accepting a quote and receiving 0.15246 WETH; attackers directed 99% of the illicit proceeds to block builders (Titan Builder), making conventional fund recovery via frontrunning extremely difficult.

Attack ongoing, Yuga Labs VP reminds users to revoke PPV2-related approvals immediately

— According to Quit monitoring, the Payment Processor V2 (PPV2) exploit attack is still ongoing. Even if users were not affected in the September 25 incident, as long as they have not revoked the relevant approvals, their assets may still be at risk. Users are advised to revoke approvals immediately.About 1 hour ago, an address lost 0.15246 WETH in the next block after accepting a quote and receiving funds. The attacker paid 99% of it as a tip to Titan Builder and kept only about 0.0015 ETH, making it nearly impossible to rescue the funds through frontrunning.Quit suggests that OpenSea could check whether a user still has risky approvals before they accept a quote and require them to revoke them first; when transferring NFTs, it should also check whether the receiving address has any related approvals remaining.

Balancer Community Votes to Pass BIP-928 Orderly Liquidation Proposal

Decentralized exchange protocol Balancer announced that community voting has approved the BIP-928 ordered liquidation proposal, while the fork proposal BIP-929 was not approved. The protocol's liquidity pools will operate normally until October 30, after which they will transition to a "withdrawal-only" mode and the bug bounty program will be simultaneously terminated. V3 vaults are expected to pause on November 30. Due to the non-custodial nature of the smart contracts, liquidity providers can withdraw funds at any time, and relevant withdrawal guidelines will be published prior to October 30.

$900,000 Bitcoin Theft Case: US Seeks Forfeiture of 110,300 USDT

Odaily News: The U.S. Attorney's Office for the District of Massachusetts filed a civil forfeiture lawsuit on September 28, seeking the forfeiture of 110,300 USDT seized from a Binance account. The case involves phishing text messages impersonating Coinbase, which led to the theft of 33.7 bitcoins, worth approximately $900,000 at the time, from a beneficiary and their family trust held in the same Coinbase account.Investigators said that between June 5 and June 15, 2023, 11.2 of the stolen bitcoins were traced to the Binance account and were quickly converted into Monero. When the FBI requested the account be frozen, it held approximately 758.55 Monero; Binance transferred 110,300 USDT to a government-controlled wallet on August 3, 2026. (Bitcoin.com News)

Zano Completes 30-Day Blockchain History Rollback and Releases Hotfix, Network Now Running Stably on Updated Chain

Odaily reports: The privacy-focused public chain Zano team has stated that in response to the inflation vulnerability discovered last Friday, a hotfix has been deployed, and the network is now running stably on the updated chain. The chain previously rolled back the block height to 3,833,000, erasing 30 days of previously confirmed transaction records.The Zano team stated that third-party wallets, exchanges, and payment service providers must first update their own nodes to the updated chain before they can safely resume transfers of ZANO and Zano-issued assets. Service providers will announce recovery progress through official channels, and recovery procedures for affected users are being prepared.The native asset ZANO has dropped 32% in price this week and 40.6% since the start of 2026. Zano's official X account stated that users can update their iOS, Android, and desktop wallets, and the team will soon release more details on the recovery process. (Bitcoin.com News)

$388 Million in Crypto Assets Stolen, Bitget CEO Says Full Recovery Unlikely

Odaily News — Gracy Chen, CEO of cryptocurrency exchange Bitget, said the company is not optimistic about recovering the $388 million in crypto assets lost in last week's security incident. Citing the Bybit hack in 2025 as a reference, she noted that approximately one year after that incident, only about 3.5% of the stolen funds had been frozen, and that this does not equate to a completed recovery.Bitget has set up a bounty program offering 5% rewards for frozen funds and recovered funds respectively. The NEAR Intents team said it has intercepted over $50 million in assets related to the attack and frozen approximately $500,000. Tether and Circle have blacklisted the relevant wallets, freezing $318,000 worth of USDT and USDC.Gracy Chen stated that preliminary investigations indicate the attack may match VPN addresses used by North Korea-linked groups, but Bitget has not yet fully ruled out the possibility of an insider job. Bitget has resumed withdrawals in phases, starting with Bitcoin transactions on Monday and continuing with ETH transactions on Tuesday. (Cointelegraph)

Bitget Suffers $350 Million Security Breach, CEO: Funds Fully Secured

Bitget confirmed a hack of approximately $351.6 million, with CEO Gracy Chen stating that attackers stole funds by forging transfer requests, and that user assets are fully covered by a protective fund of over $464 million.

Bitcoin Pioneer Adam Back's Multiple Ventures Hit Setbacks: BSTR Ordered to Pay $15 Million Breakup Fee

Odaily News — Multiple Bitcoin ventures associated with Bitcoin pioneer and Blockstream co-founder Adam Back have recently suffered a series of setbacks: the merger between BSTR Holdings, the Bitcoin treasury project he championed, and a SPAC under Cantor Fitzgerald has been terminated, with BSTR ordered to pay a $15 million breakup fee; Blockstream Mining, the Bitcoin mining operation he co-founded and in which he holds a minority stake, along with its partner Exacore, has faced multiple lawsuits following its spin-off from Blockstream, accused of owing equipment payments, electricity bills, and customer deposits, with related financing totaling approximately $2 billion; meanwhile, Liquid Network, the Bitcoin sidechain initiated by Blockstream, suffered a hack in which approximately 4,000 BTC were stolen, of which 3,400 have been returned, with the hacker still retaining approximately $47 million worth of Bitcoin. (Bloomberg)

About 50 BTC Unable to Be Redeemed, User Claims Their Address Remains Restricted After Solv Protocol Restored Functionality

according to monitoring by neil lee (@neillee99), they claim to have withdrawn approximately 50 BTC from Binance on July 8, converted it into SolvBTC and BTC+ to earn approximately 3% annualized yield, after which BTC+ minting and redemption functionality was suspended. On July 22, Solv Protocol publicly disclosed the related security incident and stated that assets were not affected; on July 31, the project team said functionality had been restored, but their address remained restricted, and approximately 50 BTC still cannot be redeemed to this day. They claim to have submitted proof of fund sources and wallet control, and called on Binance and investors to pay attention.

SlowMist's Cos: Chainflip bridge blocks North Korean hacker money laundering, but AML/KYT speed lags behind

Odaily report: According to monitoring by SlowMist's Cos, the Chainflip bridge is attempting to block North Korean hacker money laundering, but the response speed of AML/KYT lags behind the speed of money laundering. Money laundering groups use automation to split funds into large numbers of small amounts, transferring them across chains through various bridges; if funds are intercepted or returned by risk controls, they immediately try the next money laundering path, ultimately converting to BTC and continuing to obfuscate the source of funds through CoinJoin. This money laundering operation is still continuously evolving.

BlockTower founder accuses Coinbase of concealing over $1 billion hack

Ari Paul, founder and chief investment officer of digital asset investment firm BlockTower Capital, stated on social media that Coinbase caused his firm to lose $25 million several years ago. Paul accused Coinbase of concealing large-scale, repeated security breaches and refusing to return the related funds.

Bitget Attackers Attempted to Transfer Stolen Funds via Cross-Chain Protocol Chainflip But Were Rejected

MistTrack monitoring indicates that a Bitget attacker recently attempted to transfer stolen funds through the cross-chain liquidity network Chainflip, but the deposit was rejected by the relevant broker (Broker). The platform did not freeze the funds, but instead executed a return to the originating address. MistTrack stated it will continue to track the subsequent flow of the stolen funds.

Relay suffered a sandwich attack due to an API vulnerability and will compensate affected users with approximately $312,000.

Cross-chain payment and transaction protocol Relay disclosed that a vulnerability in its API interface led to the exposure of pending transaction data. Between September 12 and 26, Maximal Extractable Value (MEV) searchers exploited this flaw to execute sandwich attacks, accumulating approximately $136,000 in profits.

SlowMist Yu Xian: Vulnerability in iOS Versions Prior to iOS 27 Exploited to Steal Crypto Wallets from iPhone Users

According to Odaily, SlowMist founder Yu Xian posted on X platform that vulnerabilities in iOS versions prior to iOS 27 are being exploited by certain criminal groups to steal crypto wallets from iPhone users. He reminded users to promptly update their iPhone, iPad, Mac and other devices to the latest versions, exercise caution when installing apps from unknown sources, and be careful when opening unknown links through Safari and in-app browsers.

Bitget Suffers $387.5 Million Exploit, NEAR Intents Freezes $503,000 in Stolen Funds

Odaily News: According to monitoring by Bitget CEO, Bitget was hacked on September 24, with approximately $387.5 million in funds stolen, a large portion of which was transferred across chains and primarily consolidated on Ethereum. A report released by NEAR Intents shows that its risk intelligence layer SHIELD detected over $50 million in suspected money laundering transfer attempts; of this, $166,000 in funds went through, while $503,000 was frozen during execution. The frozen funds remain restricted pending subsequent legal and recovery proceedings.

MEXC: Has reached an agreement with relevant users regarding the asset security incident, and the incident has been properly resolved.

MEXC officials stated that following a recent user asset security incident that drew community attention, the platform promptly established a special task force and contacted the user to follow up on the resolution process. To date, MEXC has reached an agreement with the user regarding all related matters, and the incident has been properly resolved.

MEXC Responds to User Asset Security Incident: Agreement Reached with User and Issue Properly Resolved

MEXC posted on X in response to a recent user asset security incident that drew community attention, stating that it immediately set up a dedicated task force after the incident occurred, got in touch with the user, and followed up throughout the entire process. Currently, MEXC has reached an agreement with the user on the relevant matters, and the incident has been properly resolved. MEXC stated that it will continue to prioritize user asset security and rights, responding promptly and properly handling related issues whenever users need assistance.

Chainlink Releases CCIP 2.0, Allowing Large Crypto Apps to Customize Cross-Chain Security Verification

Odaily News: Cross-chain protocol Chainlink has released CCIP 2.0, allowing enterprises to add their own security checks for cross-blockchain transfers on top of its default network of 16 operator validators.The upgrade comes after Kelp DAO suffered a $292 million hack in April, an incident attributed to a LayerZero cross-chain bridge setup using a single validator; Kelp DAO subsequently migrated its rsETH token to Chainlink.Chainlink's risk management network no longer operates as a standalone security safeguard, and users who do not add their own validators will rely on one validation network rather than two. (CoinDesk)

Bitget Launches the "Companion Plan": V1 to V7 Users Can Receive a 30-Day Tier Protection Trial Pass

According to the official announcement, Bitget has launched the "Companion Program," offering trading rewards, asset rewards, and exclusive benefits across different user segments, designed to reward those who have consistently provided trust and support throughout the recent security incident.

NVIDIA Releases AI Security Software, Says It Could Have Prevented the Hugging Face Hack

Odaily News NVIDIA has launched a suite of software security tools for AI agents, claiming that these tools could have prevented the hacking incident involving Hugging Face. Hugging Face is an AI programming hub, and NVIDIA acquired it for $13 billion months after it was breached by OpenAI's rogue AI agent. The tool, called OpenShell, leverages NVIDIA CPU hardware features to constrain AI agents and is partnering with Arm and Intel to ensure compatibility. Another system, Sentry, can cut off rogue agents attempting to escape their containers. NVIDIA CEO Jensen Huang has refused broad AI security regulation, treating rogue agents as an engineering problem. (Reuters)