GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

PeckShield: WUSD/GLOVE attacked, losses amount to approximately $207,000

According to PeckShield’s monitoring, the WUSD/GLOVE pool on Ethereum was attacked, resulting in losses of approximately $207,000. The attacker has swapped the stolen assets for roughly 98 ETH and deposited them into Railgun.

SlowMist Discloses Cross-Registry Supply Chain Attack Targeting Crypto and AI Developers

According to on-chain analyst PeckShield (@PeckShieldAlert), SlowMist’s threat intelligence system MistEye has detected a cross-registry supply chain attack targeting developers. Malicious packages have spread across three major registries—npm, PyPI, and Crates.io—comprising over 34 malicious packages and more than 384 related versions. The attack targets developer communities in cryptocurrency, DeFi, Solana, Sui/Move, and AI. It may lead to the theft of cryptocurrency wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, and other sensitive developer information. Some malicious payloads also attempt persistence via mechanisms including `.cursorrules`, `CLAUDE.md`, Git hooks, cron, systemd, and SSH. SlowMist recommends immediately removing affected packages, isolating compromised systems, rotating exposed credentials, rebuilding CI environments and developer machines from clean images, and conducting comprehensive reviews of GitHub, cloud, SSH, and wallet-related activities.

Data: StabIR's EURR and USDR suffer losses exceeding $10 million after attack, over $100,000 in stolen funds frozen

according to monitoring by crypto KOL Yusuf, two contracts of European stablecoin issuer StabIR, EURR and USDR, were attacked yesterday, resulting in losses exceeding $10 million. Following the incident, over $100,000 in stolen funds have been frozen, with the de-pegging range of USDR and EURR exceeding 20%.

TrapDoor Cryptocurrency Theft Campaign Spans npm, PyPI, and Crates.io, Involving Over 34 Malicious Packages

According to research by security firm Socket Security, a cryptocurrency-stealing supply chain attack dubbed “TrapDoor” spans npm, PyPI, and Crates.io, involving over 34 malicious packages and 384 related versions and artifacts. The attack targets cryptocurrency, DeFi, Solana, Sui, Move, and AI developers. Attack samples can steal sensitive information including SSH keys, wallet data, AWS credentials, GitHub tokens, browser data, and environment variables. Specifically, npm packages execute the shared payload `trap-core.js` via the `postinstall` hook; PyPI packages execute remote JavaScript upon import; and Crates.io packages steal local keystores via `build.rs`. Socket has flagged all related packages as malicious and reported them to the respective package registries.

Analysis: AI Will Accelerate Quantum Computing Threats, Crypto Industry May Enter an Era of Persistent Security Arms Race

multiple blockchain and post-quantum cryptography researchers have warned that artificial intelligence (AI) is accelerating the development of quantum computing and could potentially impact the security systems of mainstream blockchains, including Bitcoin and Ethereum, earlier than anticipated.Alex Pruden, CEO of Project Eleven, a firm focused on quantum-resistant infrastructure, stated that the combination of AI and quantum computing is fundamentally reshaping the future security landscape. "People will no longer be able to rely on existing security assumptions as they have in the past," he said.Researchers point out that AI is already being used to optimize quantum error correction, which is one of the key technical bottlenecks in the development of quantum computing. Illia Polosukhin also noted that AI has been accelerating scientific breakthroughs for years, and in the future, there may even be a circular acceleration effect where "AI helps build the next generation of quantum computers."One of the industry's biggest current concerns is the "Harvest Now, Decrypt Later" strategy, where governments or advanced attackers begin mass-collecting encrypted data now, waiting to decrypt it all at once once quantum computing matures. Polosukhin warned that if quantum computers become viable within a few years, "most of today's important data on the internet could be decrypted in the future."Given that most blockchain networks and internet infrastructure currently rely on elliptic curve cryptography (ECC), a sufficiently powerful quantum computer could theoretically derive a private key from a public key, directly breaking wallets and on-chain systems. Simultaneously, AI itself is strengthening hacking capabilities. Pruden stated that AI models are becoming increasingly adept at discovering software vulnerabilities and cryptography implementation flaws, and may even be able to crack some encryption algorithms directly in the future.However, AI is also being used by developers for code auditing, formal verification, and testing post-quantum security systems, creating a "long-term security arms race" with simultaneous upgrades on both the offensive and defensive sides. Researchers believe the most significant change brought by AI and quantum computing together is that the core assumption of "long-term cryptographic reliability" in the digital age is being challenged. Future security systems may shift from "static upgrades" to continuous dynamic evolution. (CoinDesk)

StablR stablecoin depegs after attack, attacker nets approximately $2.8 million

stablecoin issuer StablR suffered a sustained attack, causing its euro stablecoin EURR and dollar stablecoin USDR to depeg.Blockchain security firm Blockaid stated that the attacker allegedly gained control by obtaining the private key of one of the owners of the minting multi-signature account. Exploiting the 1/3 signature threshold mechanism, the attacker replaced other administrators and minted an additional 8.35 million USDR and 4.5 million EURR.Subsequently, the attacker swapped tokens worth approximately $10.4 million for about 1,115 ETH on a DEX, yielding an actual profit of around $2.8 million. Following the incident, EURR fell to around $0.88, while USDR dropped to approximately $0.7.Blockaid noted that the incident was not caused by a smart contract vulnerability but rather by a failure in key management and governance mechanisms. (Cointelegraph)

Five people in the UK sentenced for “wrench attacks” against cryptocurrency holders, victims forced to transfer crypto assets

UK police announced that five individuals have been sentenced in a “wrench attack” case targeting cryptocurrency holders. The suspects met the victim at a Shoreditch pub in London in July 2025 and forcibly took him to his home, where they used violence and threats—including coercing facial recognition verification—to compel him to access his bank and cryptocurrency accounts, stealing over £10,000 in cash, cryptocurrency, and watches. During the investigation, cryptocurrency exchange Coinbase reported suspicious activity on the victim’s account to the police, who subsequently identified and arrested the suspects. The court sentenced four principal offenders to prison terms ranging from three-and-a-half to six-and-a-half years, while a fifth individual received a community service order for money laundering. Police stated that the incident inflicted long-term psychological trauma on the victim and his family, highlighting the rising risk of offline violent crime targeting cryptocurrency asset holders.

MARA spent $4.3 million on CEO security last fiscal year amid rising cryptocurrency-related physical attacks

According to Cointelegraph, Bitcoin mining company MARA Holdings spent $4.3 million on CEO Fred Thiel’s personal security in 2025, including $430,780 for vehicle armor, as well as residential and personal security expenses. Filings show related spending for 2024 totaled $191,040. In the same year, MARA also spent $3.9 million on CFO Salman Khan’s personal security. The report notes that personal safety costs for companies are rising amid an increase in “wrench attacks” targeting cryptocurrency executives and investors.

Polymarket: ZachXBT Reports Security Incident Related to Internal Operational Wallet Private Key Leakage; User Funds and Market Settlement Secure

Polymarket staff member Shantikiran Chanal posted on platform X, stating that they have taken note of the security reports related to reward distribution, and that user funds and market settlements remain safe. The investigation indicates that a private key leak occurred in a wallet used for internal operations, and the issue is not related to contracts or core infrastructure. Further updates will be provided.Previous report: ZachXBT stated that the Polymarket UMA CTF Adapter contract allegedly came under attack on Polygon, with over $520,000 having been drained.

ZachXBT: Polymarket’s UMA CTF Adapter contract疑似 attacked, over $520,000 stolen

According to on-chain investigator ZachXBT, Polymarket’s UMA CTF adapter on the Polygon network appears to have been attacked, resulting in losses exceeding $520,000 so far.

THORChain Releases Security Incident Update: Losses to Be Absorbed Through Protocol-Owned Liquidity, Attacker Node Fully Slashed

THORChain has released its fourth update regarding the Asgard vault intrusion incident, publishing the ADR028 proposal and opening voting for node operators. The proposal indicates that the protocol will first absorb losses through its Protocol-Owned Liquidity (POL), with the remaining portion to be borne by synthetic asset holders. The exact proportion is still under evaluation. The POL will be reduced to zero as a result, and the proposal suggests allocating a portion of system revenue over time to gradually replenish it. This plan does not involve minting new RUNE, selling RUNE, or diluting holder equity.On the technical side, the GG20 version will be temporarily retained with a patch upgrade. Trading will resume after the vulnerability is fixed and a successful node rotation is completed. A slower, more security-focused release cadence is planned for the future.Regarding the slashing mechanism, unrelated nodes sharing the same vault as the attacker will be protected, while the attacker's node will be fully slashed. The recovered RUNE will be paired with recoverable assets from the affected vault, and any excess RUNE will be burned.Additionally, THORChain has offered a white-hat bounty to the attacker to recover funds. If a portion of the funds is recovered, the recovery plan will be adjusted proportionally. THORChain emphasizes its commitment to remaining neutral and permissionless, stating it will not censor the attacker's swap transactions after trading resumes.Currently, node operators are voting on the overall direction and principles of the proposal. The specific figures in the ADR are indicative and will be adjusted later via the Mimir mechanism. The goal is to restart the network as soon as possible. A "yes" vote means developers can proceed further along this path.

Bankr: Expects to Restore Full Functionality by Next Week, Trading Features Remain Suspended

Bankr posted on platform X, stating that the team is currently working with external partners such as zeroShadow to continue the investigation and restoration efforts. It is expected that full functionality will be restored by next week after completing additional security reviews and monitoring measures.Bankr stated that in the short term, it may gradually restore token issuance and some "read-only" features, allowing users to view account information such as balances. However, wallet transaction functions, including swap and transfer, will remain suspended during the review period.Previously, Bankr disclosed that an attacker had gained access to 14 Bankr wallets. The platform subsequently suspended related functions and promised full compensation for user losses.

PeckShield: The VerusCoin cross-chain bridge attacker has returned 4,052.4 ETH to the project team’s address.

According to on-chain analyst PeckShield (@PeckShieldAlert), the VerusCoin cross-chain bridge attacker has returned 4,052.4 ETH (approximately $8.5 million) to the project team’s address (0xF9AB...C1A74), representing 75% of the total stolen amount. The remaining 25% (1,350 ETH, approximately $2.8 million) is retained in the attacker’s wallet as a white-hat bounty.

Bithumb Suspends Virtual Asset Deposit and Withdrawal Transactions Related to Heleket

According to an official announcement, South Korean cryptocurrency exchange Bithumb has announced the immediate suspension of all virtual asset deposits and withdrawals related to the overseas payment platform Heleket, effective May 21, 2026. The announcement states that Heleket is suspected of involvement in illegal activities such as money laundering and terrorist financing. Bithumb stated that this measure is taken to comply with relevant regulations, including the Act on Reporting and Using Specified Financial Transaction Information and the Virtual Asset User Protection Act, and to safeguard users’ assets. Bithumb also warned that using unverified overseas services may expose users to risks such as hacking attacks and disruptions to deposit and withdrawal services.

A whale suffered an alleged personal intimidation attack, resulting in losses of $6.7 million

according to monitoring by Specter Analyst, a high-net-worth investor holding significant assets on Kraken and Coinbase exchanges fell victim to an alleged personal intimidation attack, resulting in total losses of approximately $6.7 million across various assets.The attacker withdrew 1,554 ETH (approximately $3.3 million) and 10.5 BTC from the user's Kraken account. Simultaneously, the attacker also breached the user's Coinbase defenses, withdrawing 34.1 cbBTC. Subsequently, the attacker directly deposited over $5.3 million of the stolen funds into the privacy protocol Tornado Cash to obfuscate the transaction trail. (financefeeds)

Syndicate Labs Decides to Shut Down Due to Severe Market Contraction

Syndicate Labs stated that after five years of developing on-chain infrastructure for customizable Ethereum Rollups and sequencers, the company has decided to shut down due to a drastic contraction in the Rollup market. Syndicate Labs previously completed a $20 million Series A funding round led by Andreessen Horowitz in 2021.This decision caused the SYND token price to drop 21% in the past three hours, hitting an all-time low of $0.012, a 99.5% decline from its peak of $2.61 in September 2025.Additionally, Syndicate Labs stated that the Syndicate Network Collective operates independently of Syndicate Labs, so the governance of the SYND token will not be immediately affected. The decision to shut down was not influenced by the previous hacking incident involving bridged assets.

Transit attacker has deposited 832.9 ETH into Tornado Cash, worth approximately $1.8 million

According to CertiK monitoring, the attacker of cross-chain aggregation protocol Transit Finance has deposited 832.9 ETH into Tornado Cash, valued at approximately $1.8 million.

Syndicate Development Company to Gradually Cease Operations, SYND Governance Unaffected in Short Term

Syndicate, a DAO infrastructure service provider, has announced it will gradually cease operations. It stated that after five years of continuously building on-chain developer infrastructure, the Rollup market has undergone fundamental changes. Currently, the Rollup market has significantly shrunk, some Rollup projects are gradually shutting down, and the market has shifted from EVM Rollups to custom chains built from scratch by consulting teams, leading to a notable decline in reusable technology and network value.Syndicate stated that its system consists of two parts: Syndicate Labs, responsible for development, will be closed, while the independent entity Syndicate Network Collective (Wyoming DUNA), which holds SYND tokens and has governance rights, will continue to exist. SYND governance will not be affected in the short term.Furthermore, Syndicate emphasized that this decision to cease operations is unrelated to recent cross-chain security incidents. Affected users and SYND holders have been fully compensated through the treasury reserves, and team and investor tokens are currently still in a lock-up period.

PeckShield: RetoSwap was hacked via a vulnerability in the Haveno trading protocol, resulting in the theft of 7,000 XMR.

According to on-chain analyst PeckShield (@PeckShieldAlert), RetoSwap—a peer-to-peer, decentralized exchange for Monero (XMR)—was exploited by hackers leveraging a vulnerability in the Haveno trading protocol, resulting in the theft of users’ funds totaling 7,000 XMR (approximately $2.7 million). Following the incident, the RetoSwap team responded swiftly, blacklisting the attacker’s onion address at 02:33 UTC and pausing all platform trading by enforcing an upgrade to client version 2.0.0. The attack has now been contained.

Trump insists on diplomatic solution to Iran issue, Netanyahu strongly opposes

According to the Wall Street Journal, US President Donald Trump had a tense and heated phone call with Israeli Prime Minister Benjamin Netanyahu on Tuesday evening. According to sources, Netanyahu strongly criticized the agreement aimed at ending the war with Iran during the call, while Trump defended the diplomatic process. Israel has long been skeptical about whether Iran will adhere to any agreement to dismantle its nuclear program and halt attacks on regional countries. According to insiders, Netanyahu reiterated these positions to Trump during calls on both last Sunday and Tuesday. However, Trump was not convinced. He told Netanyahu that he would continue to push for an agreement to prevent Iran from acquiring nuclear weapons. Trump also stated that if Iran fails to show greater flexibility in negotiations, it may face a new round of strikes. (Golden Ten)