GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

OKX Star Responds to THORChain: TSS + Validator Model Is Not True Decentralization

Odaily News: OKX Star posted on X in response to THORChain, stating that he does not believe THORChain's TSS + validator model represents true decentralization. THORChain's validators collectively control the underlying assets in the TSS vault, and funds can be moved once the signature threshold is reached. Therefore, from a custody perspective, it cannot be compared to the underlying consensus mechanisms of Bitcoin and Ethereum, but instead acts as an intermediary between users and native chains. "TSS distributes control among multiple participants, but decentralizing an intermediary does not eliminate the intermediary itself."Previously, discussions arose after some stolen Bitget funds were transferred through THORChain. THORChain responded that it is decentralized and permissionless, just like Bitcoin, Ethereum, and BNB Chain, and stated that if stolen funds were known to flow through Bitcoin, Ethereum, or BNB Chain, what responsibility should those networks bear?

OpenAI and Anthropic are investigating tens of thousands of AI safety incidents

Joint security researchers from OpenAI and Anthropic are investigating tens of thousands of AI frontier model security vulnerability incidents involving behaviors such as models bypassing safeguards and self-prompting. OpenAI has announced a pause in training for its most capable models to enhance safety measures.

AMLBot: Some of Bitget's Stolen Funds Reportedly Begin Mixing Through Wasabi CoinJoin

According to AMLBot monitoring, some of the stolen funds from the Bitget hack have reportedly begun being mixed through Wasabi CoinJoin. The related funds originally came from a TRON wallet on Bitget. The attacker swapped TRX for USDT, then bridged via USDT0 to Ethereum and exchanged it for approximately 145 ETH, which was subsequently swapped through THORChain into approximately 4.59 BTC. These BTC were then split and pre-processed before entering CoinJoin.

Bonk Guy: The STONK ecosystem should not view all competitors as "vampires"

Odaily report: Bonk Guy posted on X platform stating that he is bullish on STONK and has recently bought a large amount of STONK ecosystem tokens, but believes that the community should not view any project that appears to be a competitor as "vamping" the STONK ecosystem. He stated that although the STONK ecosystem has strong development potential and he believes its long-term performance will be solid, the continued labeling of competing projects as "vampires" by leading voices within the ecosystem is currently the only bearish factor he sees for the ecosystem. Bonk Guy believes this situation is even more concerning than the coordinated FUD launched by PF against the STONK ecosystem and attacks from the "Scooter hater group," and stated that the market "can and will have multiple winners."

Star on the Bitget Hack Incident: Security Is Not a Competition, but a Shared Responsibility for the Industry

OKX founder Star posted on X platform regarding the Bitget hack incident, stating that THORChain is a "very unique" part of the crypto industry. After Bitget was attacked, both the OKX exchange and OKX Wallet immediately took action and stood ready to assist in identifying and tracing the flow of stolen funds, and to block the transfer of stolen funds where possible. Star stated that resilience is an important quality that every crypto company should possess; when security incidents occur, the industry needs to respond quickly, share information, and cooperate to protect users and prevent similar attacks from happening again. He emphasized: "Security is not a competition, but a shared responsibility."

Bitget: $83 Million XRP Stolen, Ripple: Cannot Be Frozen

Bitget was hacked, resulting in the theft of approximately $83 million worth of XRP. Ripple officially stated that due to technical architecture limitations, it is unable to freeze funds in external accounts.

Bitget CEO Demands THORChain Deny Service to Attacker Addresses

Odaily News: According to monitoring by the Bitget CEO, the attacker's addresses have been publicly listed and are being continuously tracked. Bitget has formally demanded that THORChain refuse to provide services to these addresses. Decentralization is a design principle and should not serve as a protective shield that facilitates the handling of known stolen funds.

Iranian President: No Longer Trusts Negotiations with the US

Odaily News: Iranian President Pezeshkian stated that Iran "no longer trusts negotiations with Washington," because after every round of talks, the US repeatedly launched attacks and imposed sanctions. Qatar and Pakistan are currently mediating between Iran and the US, relaying Tehran's messages to Washington.Pezeshkian also said that the negotiations were based on a previously signed memorandum of understanding between the two countries, and added that the Americans must clarify their position on this memorandum. In addition, he blamed the US for the closure of the Strait of Hormuz, saying that "it was the US that blocked our path." When Iran's path is blocked, closing the Strait of Hormuz is a natural response. The Strait of Hormuz crisis can be resolved through negotiations rather than the use of force." If negotiations lead to a resolution of the dispute, the waterway "will remain open for trade." (Sina Finance)

Bitget Asset Recovery Bounty Program Launched: 5% Reward Each for Freezing and Recovering Attacker Funds

Bitget CEO Gracy Chen thanked Circle and Tether for their swift action. The Bitget Asset Recovery Bounty Program has now been launched, offering a 5% reward respectively to participants who assist in freezing the attacker's funds and recovering the assets, and calls on exchanges, security researchers, and on-chain investigators to participate.

XRP Ledger upgrade delayed until October 9 due to validator support reset

The XRP Ledger batch transaction upgrade countdown was reset due to insufficient validator support, delaying activation from September 29 to October 9. This marks the second attempt following a fix for a signature vulnerability.

Bitget hacker suspected of receiving $1.23 million ETH transfer

Odaily news: According to Lookonchain monitoring, about 11 hours ago, an address withdrew 257.6 ETH, worth $692,000, and 545,000 USDT from Binance, then swapped 545,000 USDT for 200.2 ETH. About 1 hour ago, the address transferred all 457.9 ETH, worth $1.23 million, into the Bitget hacker wallet.

Yuga Labs: Some Stolen ERC721C/1155C NFT Assets Temporarily Unable to Be Claimed

Yuga Labs blockchain vice president Quit posted on X that the asset claim website for NFTs stolen in the previous Payment Processor vulnerability incident has gone live. However, if an NFT collection uses the ERC721C or ERC1155C standard, its holders may temporarily be unable to claim assets through the NFT claim website. A number of NFT collections are currently affected by this issue. The relevant collections controlled by Yuga Labs are expected to be fixed by tomorrow. In the meantime, users can enable "7702 delegate OTC" in the transfer verifier settings, or add the specified Ethereum address and ApeChain address to the 7702 delegated address whitelist to remove the relevant restrictions.

Xie Jiaxin: The method of theft in this security incident differs from last year's Bybit incident, so different withdrawal recovery arrangements are being adopted

Odaily reports: Xie Jiaxin posted on X stating that this Bitget security incident involved multiple non-EVM chains and 10 tokens, and due to the different method of asset theft, different approaches to handling and restoring withdrawals were taken compared to last year's Bybit security incident in order to thoroughly eliminate potential risks.Additionally, Xie Jiaxin stated that he and Bitget CEO Gracy Chen will host a community livestream 30 minutes before withdrawals resume on Monday to discuss this security incident and answer community questions.Bitget announced on X that it will restore withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate normally, and users do not need to take any action in advance.

Bitget: Withdrawals to Resume in Phases, Bitcoin Network Withdrawals Opening on September 28

Odaily News: Bitget posted on X platform that the vulnerability involved in the September 24 security incident has been identified and fixed. The team is conducting additional verification and security checks on the withdrawal infrastructure, with Mandiant and SlowMist continuing to assist with the investigation. The temporary suspension of withdrawals is a security measure and is unrelated to the availability of user assets; user account balances have not been affected, and the Bitget Protection Fund will cover the financial impact of this platform-wide incident.Bitget plans to resume withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on the Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on the Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate, and users do not need to take any action in advance.

DOG Founder Calls on Bitget CEO: Token Price Has Severely Decoupled, Requests Resumption of Spot Trading

DOG 创始人 Leonidas在 X 平台发文喊话 Bitget CEO 称,Bitget 在遭遇黑客攻击数小时后、用户提现仍处于暂停状态时发布 DOG 下架公告,叠加黑客事件引发的信任担忧,导致 DOG在 Bitget 出现严重价格脱锚,并直接影响持有或交易 DOG 的用户。

Limit Break contract has a known vulnerability; Magic Eden Ethereum marketplace NFT traders need to revoke approvals

Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.

Quit: NFTs Are Safe Claim Portal Officially Launched, Affected Users Can Reclaim Preserved Assets

Yuga Labs blockchain vice president Quit posted on X that the NFT theft incident asset claim website nftsaresafu.xyz has officially launched. Affected users whose NFTs were successfully preserved can now proceed with claims, but must first revoke authorization to PaymentProcessor.Quit stated that approximately $6 million worth of NFTs were successfully rescued this time, but some assets could not be preserved. Additionally, some NFT collections cannot be claimed at present due to Transfer Validator restrictions, and coordination with the relevant project teams will be handled in the coming days. The claim process involves EIP-7702 delegated wallets, which may cause transaction simulation anomalies or risk warnings on wallets such as Rabby.

OpenSea: Unaffected by the Magic Eden security incident, has marked related NFTs and restricted trading

OpenSea Chief Technology Officer (CTO) Chris Maddern responded on X regarding the impact of the Magic Eden and Limit Break security incidents, emphasizing that OpenSea’s systems and smart contracts remain unaffected. All currently known affected ERC-721 NFTs have been flagged on OpenSea and are now unsellable; for any newly discovered exploited NFTs, OpenSea will automatically flag them to restrict attackers from securing related bids.

Yuga Labs Blockchain VP: NFT Theft Claims Portal Expected to Launch Within Hours, ETH and Other Token Donations Now Open

Yuga Labs Blockchain VP Quit posted on X that the NFT theft claims portal currently being built is expected to go live within the next few hours, and a dedicated address nftsaresafu.eth has been created to accept donations in ETH and other tokens.Quit stated that in addition to investing significant time, they paid approximately $7,500 in gas fees last night to handle related matters, and thanked the community for its support through channels such as X Money.Earlier reports indicated that NFT marketplace Magic Eden appears to have suffered an NFT security vulnerability, with white-hat hackers moving 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million.

Cosmos Hub Recovers 1.227 Million ATOM Tokens Involved in Neutron Attack

Cosmos Labs disclosed in a post that on September 22, Neutron suffered a governance attack, causing funds across protocols such as Astroport to be transferred, with approximately 1.73 million ATOM entering the Cosmos Hub. The Cosmos Hub itself was not targeted, and user funds remained unaffected. To halt further asset outflows, validators paused the network and utilized the Gaia v28.3.0 patch to transfer approximately 1.227 million ATOM from the attacker's address to a 4/6 multisig account managed by six community validators.