GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Bitget Launches the "Companion Plan": V1 to V7 Users Can Receive a 30-Day Tier Protection Trial Pass

According to the official announcement, Bitget has launched the "Companion Program," offering trading rewards, asset rewards, and exclusive benefits across different user segments, designed to reward those who have consistently provided trust and support throughout the recent security incident.

NVIDIA Releases AI Security Software, Says It Could Have Prevented the Hugging Face Hack

Odaily News NVIDIA has launched a suite of software security tools for AI agents, claiming that these tools could have prevented the hacking incident involving Hugging Face. Hugging Face is an AI programming hub, and NVIDIA acquired it for $13 billion months after it was breached by OpenAI's rogue AI agent. The tool, called OpenShell, leverages NVIDIA CPU hardware features to constrain AI agents and is partnering with Arm and Intel to ensure compatibility. Another system, Sentry, can cut off rogue agents attempting to escape their containers. NVIDIA CEO Jensen Huang has refused broad AI security regulation, treating rogue agents as an engineering problem. (Reuters)

ZachXBT: Gang Suspected of Assisting North Korean Hackers with Money Laundering is Transferring Stolen Bitget Funds and Publicly Seeking Technical Support

On-chain investigator ZachXBT disclosed that illicit actors assisting a suspected North Korean hacker group with money laundering are currently publicly seeking order processing support on the Discord public servers and Telegram channels of relevant service platforms. The laundered funds originate from the $387 million security breach previously suffered by Bitget.

First such security incident in 8 years of operations, Bitget publishes attacker addresses and tracing data

Odaily News: According to Bitget monitoring, Mandiant and SlowMist are continuing to support the investigation and on-chain tracing of this incident. Bitget has published the identified attacker addresses and related tracing data to support industry collaboration and asset recovery efforts.Bitget expects to complete its internal security report this week and will release further updates once the investigation findings are verified. Bitget stated that the September 24 incident was the first such security event in its 8 years of exchange operations.

MEXC 回应用户账户被盗事件:已成立专项小组跟进处理

加密货币交易平台 MEXC 官方就近期相关事件做出回应,表示平台已成立专项小组,并安排专人跟进相关账户情况及后续处理工作。MEXC 表示将持续推进处理流程,以保障用户的资产安全与相关权益。

Stealing $351.6 Million: Bitget Hacker Swaps ETH for BTC via THORChain

Odaily reports, according to Lookonchain monitoring, the Bitget hacker (0xf7bC...96C3) swapped ETH for BTC via THORChain, having stolen $351.6 million.

MEXC Users Suffer Account Takeover, API Backdoor Leads to $340,000 in Stolen Assets

According to a post by user @shuangfei8, their MEXC account was compromised on September 25 when attackers used forged identification documents to complete a security reset and breach the account within 10 minutes. Although MEXC subsequently froze the account and assisted in its recovery, it failed to revoke the API key created by the attacker during the period of unauthorized control. At 04:12 on September 27, merely 27 minutes after the 24-hour withdrawal restriction was lifted, the attacker exploited this residual API to bypass Google verification and email verification, draining 322,110 USDT and 9,133,999 ONE (totaling approximately $340,000) from the account across six separate transactions. The user has submitted a formal compensation claim to MEXC and attempted to report the incident to the police, demanding that the platform preserve logs, provide a written response regarding the security vulnerability, and return the stolen assets. Furthermore, multiple MEXC users have recently reported receiving suspicious emails resembling a "request to reset security settings," prompting users to immediately navigate to 【API Management】 to check for any unknown API keys.

The Zano network was attacked due to a gateway address vulnerability, forcing it to restart the blockchain.

According to The Block (@TheBlockCo), the Zano network was recently subjected to a Gateway Address vulnerability attack, resulting in the unauthorized minting of ZANO and fUSD that have since entered the market. To contain the losses, the team has urgently restarted the blockchain. The team is currently actively negotiating with affected projects and relevant counterparties regarding compensation for losses, and will publish a formal compensation and claims process in the near future.

Control over Nano Labs founder Jack Kong's X account has been restored.

Control over the X account of Jack Kong, founder of Nano Labs, a US-listed BNB crypto treasury company, has been regained. Previously, attackers sent a phishing email to a publicly used email address of his. AI misidentified the link in the email as an official X third-party verification link, and after the verification code sent by X to the linked email was entered into the spoofed page, the account was compromised. Scam content was briefly posted during the account takeover.

国家安全部发文揭示虚拟货币"匿名神话":区块链全程留痕,链上身份终可溯源

据国家安全部微信公众号发文,虚拟货币所谓"匿名交易""不可追踪"的特性不过是表象。区块链技术具备公开透明、数据不可篡改等核心特点,任何交易均永久留存于"公共账本",专业机构可通过链上数据分析与大数据比对等手段溯源钱包地址背后的真实身份,还原资金流转全过程。 文章指出,虚拟货币已成为洗钱犯罪、网络攻击、境外间谍窃密等违法活动的重要工具。2026年 2 月,中国人民银行等多部门重申,比特币、以太币、泰达币等虚拟货币不得作为货币在市场流通,相关业务活动属非法金融活动,一律严格禁止。

DYORSWAP Responds to Fake GIWA Incident: Approximately 766 ETH Transferred Out, Over 200 ETH Already Compensated

DYORSWAP has released an "Official Statement Regarding the Fake GIWA Mainnet 9134 Incident," stating that the incident was not a DYOR contract vulnerability, but rather was caused by a fraudulent network impersonating GIWA Chain 9134. This network had a bridge and batcher similar to OP Stack, deployed on September 27, 2026, at 02:10:59 (UTC+8). Approximately 8.5 hours before deployment, the address received about 0.045 ETH from a ChangeHero-related address. Data shows that a total of 1,335 addresses bridged approximately 767.65 ETH to it, of which about 766.25 ETH was ultimately transferred out from the cross-chain bridge.DYORSWAP stated that it has already used its own funds to compensate affected users with over 200 ETH. Additionally, the team is still tracking the cross-chain bridge deployer, the source of funds, early test wallets, and the subsequent flow of the transferred funds.

Bitget Hacked, THORchain Refuses to Cooperate

Bitget announces that approximately $387.5 million has been stolen; the CEO's request for THORchain to compromise addresses was denied; Vitalik Buterin states that Ethereum is evolving into a "cryptographic world computer".

Zano rolls back to before the 6th hard fork, deleting about a month of on-chain transaction records

privacy blockchain project Zano has rolled back its blockchain to block height 3,833,000, before the 6th hard fork, deleting approximately one month of on-chain transaction records in order to address an inflation vulnerability involving Gateway Addresses.The vulnerability allowed unauthorized minting of the native token ZANO and the USD-pegged stablecoin fUSD. Zano stated that the core consensus protocol, wallet spending keys, and ordinary transaction privacy were not affected, and that nodes, miners, stakers, and service providers need to adopt the update.Freedom Dollar stated that millions of dollars in assets held by the project had been swapped into counterfeit fUSD, and that the related losses will be borne by the project. Freedom Dollar has asked fUSD holders to suspend economic activity involving the token until the stabilized Zano chain is confirmed after repairs. (Bitcoin.com News)

Bitget Hacked, Loses $351 Million and Suspends Withdrawals

Cryptocurrency exchange Bitget has been hacked, losing approximately $351 million. Bitget CEO Gracy Chen stated that the platform's protection fund will cover the losses, and the exchange has temporarily suspended withdrawals. (Bitcoin.com News)

Senator Lummis accuses the Democratic Party of vetoing the offshore money laundering oversight bill.

Senator Cynthia Lummis (@SenLummis) posted that the U.S. Senate voted on the "Clarity Act," which aims to empower the Treasury Department to cut off money laundering activities conducted through offshore exchanges such as Binance. Lummis accused Democrats of voting against the bill, claiming they are unwilling to protect American citizens from the threat of offshore money laundering. Critics, however, pushed back, citing constitutional concerns and a corruption loophole targeting the current president as reasons for its defeat.

1830 BTC Stolen: COLDCARD Seed Entropy Theft Affects 256 Victims

according to Galaxy's head of research, the COLDCARD Seed Entropy theft incident has resulted in 1,830 BTC being stolen, involving 3 rounds of attacks and more than 30 smaller related indicators. A total of 256 victims have reported their situations to GLXY Research, with a median loss of 1.1 BTC, and efforts to track the attackers are still ongoing.

THORChain Earns Nearly $10 Million in Fees in 10 Days, Accused of Funneling Most of Bybit's Stolen Funds

Odaily News: According to on-chain analyst Yu Jin, over 90% of the funds swapped cross-chain through THORChain are illicit or grey-market funds. Yu Jin stated that most of the funds stolen from Bybit last year were transferred through THORChain, which collected nearly $10 million in fees within 10 days. Recently, some of the funds stolen from Bitget have also been transferred through THORChain, generating $1 million in fee revenue.

Slow Mist's Cosine Talks About THORChain: Decentralization Is Not Just a Slogan, and "Decentralized, No Right to Interfere" Should Not Be Used to Respond to Industry Security Incidents

Slow Mist's Cosine posted on X platform, stating that the Bitget hack incident has spread widely, involves a huge amount of funds, and the related funds were quickly linked to North Korean hackers. Institutions such as Circle and Tether promptly assisted in freezing the related funds, with Circle freezing the USDC held by the hackers.Regarding THORChain, Cosine pointed out that when THORChain itself previously suffered a hack, it also quickly intervened in its so-called "decentralized" platform; but this time, when facing a major industry security incident, it responded on the grounds of being "decentralized and having no right to interfere," likened itself to Bitcoin and Ethereum, and continued to earn fees from the hackers' large cross-chain transactions.He stated that decentralization should not just be a slogan. After major security incidents occur, the key is to distinguish which issues need to be solved jointly by the industry. He also believes that platforms such as THORChain should not be easily mentioned in the same breath as Bitcoin and Ethereum, as there are clear differences in the degree of decentralization and mechanisms among different systems.

THORChain addresses questions regarding the Bitget security incident, emphasizing the permissionless nature of decentralized protocols.

MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.

"Money Laundering Dedicated Network" THORChain Official Cries Foul: As Decentralized and Permissionless as BTC, ETH, and BNB Chain, Not Responsible for Bitget Hack Money Laundering Process, Previously Suspended Services for 39 Days Due to Hacker Attack

Odaily News: Today, THORChain officially posted on X platform stating, "We have noticed the recent Bitget hack and are deeply saddened by it. We can imagine this is a difficult time for everyone in the industry. (However,) THORChain is as decentralized and permissionless as Bitcoin, Ethereum, and BNB Chain. When dealing with known stolen funds, what responsibility should Bitcoin, Ethereum, and BNB Chain bear?" Subsequently, it called out OKX CEO Star and Bitget CEO Gracy.However, crypto community members in the comments pointed out that when THORChain previously suffered an attack, it once suspended services for 39 days, and they are deeply ashamed of the differentiated treatment between the two situations.