GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Sentient officially launches the latest season of its hackathon, Challenge 0

Sentient has officially launched the latest season of its hackathon, Challenge 0. This event offers a $6,000 prize pool and MiniMax points.

Drift Protocol: Insurance Fund Unaffected by Attack; Users Can Withdraw Staked Shares After Recovery

Drift Protocol stated on X platform that after the protocol resumes operation, users who have staked in the Insurance Fund will be able to withdraw their corresponding shares normally. The Insurance Fund is designed to maintain the protocol's solvency during liquidation or bankruptcy scenarios. Since the protocol was paused before losses were realized through normal liquidation or bankruptcy processes, the Insurance Fund was not affected by the relevant vulnerability or attack.Drift Protocol added that the protocol's own Insurance Fund assets will be used to support system restart and user recovery, and it plans to disclose the relevant on-chain addresses to allow the community to track fund usage and subsequent deployment.

LayerZero Releases KelpDAO Attack Report: North Korean Hackers Suspected of Involvement, Security Policies to Be Adjusted

LayerZero Labs has released a recent incident report stating that on April 18, 2026, the KelpDAO rsETH cross-chain bridge, built on its cross-chain communication protocol, suffered an attack resulting in the theft of approximately 116,500 rsETH (around $292 million). Multiple security organizations, including Mandiant, CrowdStrike, and independent researchers, have attributed this attack to the North Korea-linked hacker group TraderTraitor (UNC4899).According to the report, the attack began on March 6, 2026. The attackers compromised a LayerZero developer account through social engineering, obtained session keys, and penetrated the RPC cloud environment. They further contaminated internal RPC node data and manipulated the returned results to deceive monitoring systems and the Decentralized Verification Network (DVN). Subsequently, the attackers launched a denial-of-service attack against external RPC providers, forcing the verification system to rely on the compromised nodes to generate forged cross-chain proofs, thereby successfully extracting the funds.LayerZero pointed out that the core vulnerability of this incident lay in the affected application adopting a "single-verifier" configuration. This allowed the target contract to execute asset releases upon receiving only a single valid signature, leading to the theft of rsETH.Following the incident, LayerZero Labs announced an adjustment to security policies. This includes no longer allowing its own DVN to act as the sole signer in a single-verifier configuration, rebuilding the affected cloud infrastructure, and introducing short-term credentials, instant permission upgrades, and multi-party approval mechanisms to enhance security. Additionally, zeroShadow and law enforcement agencies have initiated investigations and asset tracing. LayerZero stated it will continue to collaborate with ecosystem partners to strengthen the cross-chain security framework to address increasingly sophisticated nation-state attack threats.

GitHub Updates Security Incident Investigation: Employee Compromised by Malicious VS Code Plugin, Approximately 3,800 Internal Repositories Stolen

GitHub posted on X platform, sharing more investigation details regarding the unauthorized access incident to its internal repositories. Yesterday, GitHub detected and contained an attack on an employee's device involving a malicious VS Code plugin. GitHub has removed the malicious plugin version, isolated the endpoint, and immediately initiated an incident response.Current assessment indicates that this activity only involved the theft of GitHub's internal repositories. The attackers' claim of approximately 3,800 repositories aligns with GitHub's investigation direction so far. GitHub has taken swift action to mitigate risks, rotating critical keys yesterday and overnight, and prioritizing the most impactful credentials. GitHub will continue analyzing logs, verifying key rotations, and monitoring subsequent activities. A more comprehensive report will be released upon completion of the investigation.

Bankr Platform Suffers Attack on 14 Wallets, Approximately $385,000 Stolen

According to an announcement by Bankr’s official X account (@bankrbot), on May 20, 2026, Bankr—a blockchain-based financial infrastructure platform—confirmed it had suffered a cyberattack. A total of 14 user wallets were compromised. The platform has urgently suspended its trading functionality and pledged to fully compensate all losses. Blockchain analyst @99barzzz tracked the incident, revealing that the losses amounted to approximately $385,000. The hacker’s EVM-compatible address has been identified.

Bankr multiple user wallets compromised, involving Grok's interaction with Bankrbot leading to unauthorized transaction signatures

According to monitoring by SlowMist's Cosan, multiple user wallets of Bankr have been compromised. @bankrbot responded that the incident is a social engineering attack targeting the trust layer between automated agents, specifically involving the interaction between Grok and Bankrbot, which led to unauthorized transaction signatures.

Grafana: Suffered a supply chain attack, but the security incident did not affect customer production systems or operations

Grafana Labs posted on X, stating that it confirmed a targeted hacker attack on May 16. The attacker gained unauthorized access to its GitHub repository and downloaded the codebase through a TanStack npm supply chain attack (Mini Shai-Hulud campaign), subsequently issuing a ransom threat.Investigations indicate that this incident was strictly limited to Grafana Labs' GitHub environment, with no evidence suggesting it affected customer production systems, operations, or the Grafana Cloud platform. The downloaded content, in addition to source code, also included the names and email addresses of some internal business contacts. Although the attacker downloaded the codebase, it was not tampered with. Grafana Labs has decided not to pay the ransom and has notified federal law enforcement authorities. It is currently implementing defensive measures, including enhancing CI/CD pipeline security.

Threshold Network: Successfully Thwarted Attempt to Maliciously Mint tBTC

Threshold Network posted on platform X, stating that on May 18, 2026, a malicious attacker attempted to mint tBTC without depositing the underlying Bitcoin. The attempt was unsuccessful; no invalid tBTC was issued, and user funds were not at risk.As a precautionary measure against high-frequency malicious activity in the broader crypto ecosystem, Optimistic Minting has been temporarily suspended. Currently, minting operations are conducted through the liquidation mechanism, with typical minting times increasing from approximately 1.5 hours to around 6 to 7 hours.

Echo Protocol: Management key control has been regained, and the attacker’s remaining 955 eBTC have been destroyed.

Echo Protocol announced that the team has now regained control of the administrative keys and destroyed the remaining 955 eBTC held by the attacker. Additionally, the current exposure on Aptos is limited to approximately $71,000 in the Echo lending market and the Hyperion liquidity pool, and the team has observed no fund losses on Aptos. As a precautionary measure, the team has fully suspended Aptos bridge operations while the review remains ongoing. Echo Aptos Lending remains unaffected but has been paused for security reasons.

Echo Protocol confirms security incident on Monad cross-chain bridge, cross-chain transactions suspended

Odaily Echo Protocol posted on X platform, confirming a security incident on the Monad cross-chain bridge. An investigation is currently underway, and all cross-chain transaction functions have been suspended. The protocol stated that it will continue to provide updates through official channels once the investigation progresses.

Kelp: rsETH Recovery Achieves Key Progress, Multiple DeFi Protocols Jointly Liquidate Attacker Positions

Odaily  Kelp announced on X platform that it has coordinated with multiple DeFi protocols to complete the liquidation of the attacker's positions, achieving key progress in the rsETH recovery process. Among them: Compound participated in coordination multiple times over the past four weeks, providing approximately 3,000 ETH in support, and jointly completed the liquidation with Aave, recovering a total of approximately 17,426.20 rsETH; Euler Finance liquidated the attacker's positions within its protocol and plans to return the excess ETH to the DeFi ecosystem fund.

Data: ETH lending protocol TVL has dropped from its year-to-date high of $32 billion to $23 billion.

According to CoinDesk, the total value locked (TVL) in ETH lending protocols has declined from a year-to-date high of $32 billion to $23 billion—a drop of approximately 28%. The oracle vulnerability incident involving KelpDAO triggered a market confidence crisis, and combined with overall bearish market sentiment, led to roughly $9 billion in outflows from the DeFi lending sector.

Curvance: Anomaly detected in Echo eBTC market, related market has been suspended

Curvance posted on platform X, stating that at approximately 6:00 PM EST today (Beijing time), it noticed an anomaly in the Echo eBTC market on the Curvance platform. Currently, there are no indications that the Curvance smart contract has been attacked or compromised. Due to its fully isolated market architecture, other markets remain unaffected. As a precautionary measure, the team has suspended the affected market and is investigating the cause of the incident together with ecosystem partners. Further updates will be announced as more information becomes available.

Casa Co-founder Warns of New Phishing Attack: Using Google Account Recovery Forms to Conceal Malicious Links

Casa co-founder Jameson Lopp has warned of a new phishing attack, where attackers leverage legitimate Google account recovery forms to hide malicious links within large amounts of blank space. This technique involves embedding "invisible" or overlooked whitespace characters within long text, making the malicious link less noticeable to users, thereby tricking them into clicking and exposing their account information.Lopp advises users to remain vigilant when handling account recovery emails or forms, and to avoid clicking on links that are from unknown sources or intentionally hidden. (Cointelegraph)

Mining of cryptocurrencies will be banned in Russia’s Kursk border region.

According to Bits.media, Russia’s Government Legislative Committee approved, on May 18, a proposal to ban cryptocurrency mining in parts of the Kursk region along the border. Kursk Regional Governor Alexander Sinyutin announced the decision during a regional government meeting. The ban will cover eight districts and the city of Lgov, including Belovsky, Bolshesoldatsky, Glushkovsky, and others. The primary reason for the ban is that residents in these border areas are exempt from paying utility bills—including electricity—meaning that if mining were permitted, the associated electricity costs would fall on the federal budget, creating a fiscal burden. Additionally, ongoing attacks by Ukrainian armed forces and difficulties repairing infrastructure have strained local energy supplies. The governor stated that the ban could be lifted once the situation returns to normal, residents return home, and utility payments resume—but no specific timeline was provided.

Trump Announces Pause in Military Strike Against Iran; Diplomatic Negotiation Window Briefly Opens

According to JIN10 Data, U.S. President Trump announced on Monday that, at the joint request of the leaders of Qatar, Saudi Arabia, and the United Arab Emirates, he had canceled the planned military strike against Iran scheduled for Tuesday, in order to buy time for diplomatic negotiations. Trump stated that a key condition of any agreement would be Iran’s written commitment to abandon nuclear weapons, adding, “The chances of reaching an agreement appear quite high.” However, he also warned that he had directed the U.S. military to stand ready for an “immediate, full-scale, large-scale attack,” to be launched without delay if negotiations collapse—and emphasized that no deadline had been set. Currently, both the U.S. and Iran have rejected each other’s newly proposed plans; the main points of contention center on the disposition of Iran’s highly enriched uranium stockpile and the return of its frozen assets.

Monad Co-Founder: Security Incident Involving Echo Protocol Noted, Monad Network Unaffected

Odaily Odaily News Monad co-founder Keone Hon posted on the X platform, stating that the team has noted a security incident related to eBTC on EchoProtocol. Security researchers are currently investigating the matter. The Monad network itself has not been affected and is operating normally.Additionally, a preliminary review by security researchers determined that this exploit targeting EchoProtocol's eBTC has resulted in the theft of approximately $816,000 in assets.

PeckShield: EchoProtocol Hacked on Monad, ~$820,000 Drained to Tornado Cash

According to on-chain analyst PeckShield (@PeckShieldAlert), Echo Protocol was hacked on Monad. The attacker minted 1,000 $eBTC out of thin air (valued at approximately $76.7 million), then deposited 45 $eBTC (approximately $3.45 million) into Curvance and used it as collateral to borrow roughly 11.29 $WBTC (approximately $867,700). The attacker subsequently bridged the $WBTC cross-chain to Ethereum, swapped it for $ETH, and laundered 384 ETH (approximately $821,700) via Tornado Cash.

Trump: Gulf Allies Request "Two to Three Day" Delay in Military Strike Against Iran

Odaily News: Trump stated that Saudi Arabia, Qatar, the UAE, and several other countries requested that he delay a military strike against Iran by "two to three days," as they believe a US-Iran agreement is "very close to being reached." Speaking to reporters at a White House event, Trump said the US was prepared to launch a "very significant" attack on Iran on the 19th. "However, I postponed it for a short period of time, hoping it might be permanent, but it could also be temporary. Because we have been having very significant discussions with Iran, and we will wait to see the outcome of these discussions."Trump noted that there have been some "very positive developments" in the negotiations and that the aforementioned Gulf allies have an opportunity to help finalize an agreement. He added that the current situation is "slightly different" from previous instances when the US believed a deal with Iran was imminent. (Xinhua News Agency)

Echo Protocol attacked, attacker mints 1000 eBTC and then withdraws funds via Curvance

According to Onchain Lens monitoring, Echo Protocol on Monad has been attacked. The attacker minted 1000 eBTC, worth $76.7 million, and withdrew the funds through Curvance via a previously tested attack path.As of now, the attacker has deposited 45 eBTC as collateral into Curvance and borrowed approximately 11.29 WBTC, worth $867,700; the attacker then cross-chained this portion of WBTC to Ethereum, swapped it for ETH, and transferred 385 ETH (worth approximately $818,000) to Tornado Cash. The attacker currently appears to still control a large amount of the minted eBTC.