GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Lombard Gradually Phasing Out LayerZero, Plans to Migrate Over $1 Billion in BTC Collateral Assets to Chainlink

following the $292 million exploit of Kelp DAO's LayerZero bridge, the security of cross-chain infrastructure has once again come under scrutiny. DeFi protocols Kelp DAO, Solv Protocol, Re, and crypto exchange Kraken have all taken similar migration measures, with the total value of this outflow reaching approximately $4 billion.Decentralized finance protocol Lombard has become the latest project to join the migration wave, announcing a gradual phase-out of LayerZero and the migration of over $1 billion in Bitcoin collateral assets to Chainlink's Cross-Chain Interoperability Protocol (CCIP). Bitcoin-related tokens issued by Lombard include LBTC and BTC.b. It is reported that Lombard's initial migration assets cover the Solana, Etherlink, Berachain, Corn, and TAC chains, while the use of LayerZero on Morph and Swell will also be terminated. As of now, LayerZero has not responded to requests for comment. (CoinDesk)

Euler takes over operations of HypurrFi's Mewler market, HypurrFi to gradually shut down and complete migration

Euler Finance announced it will take over the maintenance and operation of the Euler contract stack known as Mewler under HypurrFi on the Hyperliquid EVM. The relevant infrastructure is undergoing a smooth transition, with Clearstar Labs continuing to serve as the risk manager for the Prime, Yield, and Earn vaults. HypurrFi Scale and Pooled Markets are scheduled to gradually wind down and undergo orderly liquidation over the coming weeks. However, all existing markets remain solvent and fully operational, with no security vulnerabilities or emergency parameter adjustments.During the migration process, new borrowing functionality for some Pooled assets has been frozen, but HYPE, USDC, and USDT0 can still be used for liquidity provision to allow borrowers to gradually unwind their positions. Euler emphasized that its isolated lending architecture on HyperEVM will continue to serve as core infrastructure, jointly maintained by Euler and Clearstar Labs.The HypurrFi team stated that user deposits, positions, and collateral assets remain fully secure. This adjustment is an active strategic migration, not a security incident or protocol failure. According to the plan, Euler Prime and Yield markets will become the primary entry points for lending and yield markets on HyperEVM moving forward. The HypurrFi brand will be gradually phased out, with related support services closing after May 28. Full market liquidation is expected to be completed by July 15, 2026.HypurrFi also reminded users to be aware of risks and fraudulent links during the migration process, to operate only through official channels, and to use the built-in migration tools to transfer Pooled positions to Euler Prime or Yield markets.

THORChain: Asgard Vault Breach Results in Approximately $10.7 Million Loss; User Cross-Chain Transactions Unaffected for Now

According to Odaily, THORChain has issued an emergency announcement stating that after discovering a suspected breach of an Asgard vault, the network has suspended trading operations to respond to the security incident. Preliminary information indicates that user funds remain unaffected, with losses primarily concentrated on the protocol's own capital.The official statement noted that the system automatically detected anomalous behavior and halted signing operations, thereby alerting the community and preventing further asset outflow. The investigation is currently ongoing to determine the root cause of the vulnerability and the full scope of the impact.Known information indicates that this incident involves one of the six Asgard vaults, with estimated losses of approximately $10.7 million. Meanwhile, staked RUNE on the affected nodes has been slashed due to a penalty mechanism triggered by unauthorized outgoing transactions. The network has paused churn operations and delayed the launch of new chains and related features until system stability is restored.THORChain stated that no user cross-chain transactions have been affected so far and has requested node operators to thoroughly inspect their infrastructure, secure key management, and anomalous behavior, and to submit relevant logs to assist the investigation.

ZachXBT: Suspected Address in 185 BTC Social Engineering Theft Transfers Another $2.59 Million in Crypto Assets

on-chain detective ZachXBT stated that the hacker "Dritan Kapplani Jr" transferred approximately $2.59 million in assets today, including 1.99 million DAI and 259 ETH. The funds were moved from address 0x4487...bba6 to address 0x67ec...125d. The stolen funds currently remain dormant.ZachXBT stated that on May 12, they published an investigation detailing the connection between Dritan Kapplani Jr and Trenton (Trent) Johnson in a social engineering theft involving 185 Bitcoin (approximately $13 million).

Bloomberg: AI threats are increasing, with over half of blockchain attacks in 2025 theoretically automatable by AI

in April 2026, two major DeFi attacks on Drift Protocol and Kelp DAO resulted in losses of nearly $600 million, triggering approximately $9 billion in capital outflows from protocols like Aave. TRM Labs investigator Nick Carlsen stated that a hacker group suspected to be linked to North Korea has allegedly used AI to assist in target selection and attack path design. Failsafe CEO Aneirin Flynn said that AI has compressed the time for discovering blockchain vulnerabilities from months to days or even hours. The report noted that Anthropic has not fully opened its AI model Mythos due to cybersecurity risks, claiming the model has the capability to discover large-scale zero-day vulnerabilities. Its research indicates that over half of blockchain attacks in 2025 could theoretically be completed autonomously by AI. (Bloomberg)

PeckShield: THORChain Suffers Attack, Losing Approximately $10 Million in Cryptocurrency Assets

According to on-chain analyst PeckShield (@PeckShieldAlert), THORChain has been hacked, resulting in losses of approximately $10 million in crypto assets, including 36.75 BTC (around $3 million) and roughly $7 million in assets from BNB Chain, Ethereum, and Base.

THORChain Suspected of Suffering an Attack, Losses Exceed $7.4 Million

On-chain investigator ZachXBT stated that THORChain appears to have been attacked on the Bitcoin, Ethereum, BSC, and Base networks, resulting in losses exceeding $7.4 million.

THORChain Suffers Attack, Losses Exceed $7.4 Million

According to on-chain detective ZachXBT, THORChain has suffered an attack across multiple chains, resulting in losses exceeding $7.4 million.

Signal says it may exit the Canadian market if Bill C-22 takes effect.

According to Cointelegraph, privacy-focused messaging app Signal stated it may exit the Canadian market if required to comply with Canada’s proposed lawful access bill, Bill C-22. Udbhav Tiwari, Signal’s Vice President of Strategy and Global Affairs, said the bill could compel service providers to build technical surveillance capabilities and retain certain user metadata for up to one year—potentially undermining end-to-end encryption and increasing the risk of cyberattacks. The report notes that Bill C-22 has not yet entered into force and still requires parliamentary review and royal assent. In addition to Signal, VPN provider Windscribe has also indicated it may follow suit and withdraw from Canada if the bill is passed.

OpenAI Suffers Supply Chain Attack with Leaked Signing Certificates, macOS Client Mandatory Update Next Month

OpenAI has confirmed a supply chain attack targeting a malicious TanStack NPM package in its internal environment, infecting two employees' devices. While user data and core code were not affected, the attackers stole access credentials for some internal code repositories, including code signing certificates used for iOS, macOS, and Windows products.To prevent hackers from exploiting the stolen certificates to distribute counterfeit applications, OpenAI has initiated defensive certificate rotation and announced that all macOS users of ChatGPT desktop, Codex, and Atlas browsers must upgrade to the latest version by June 12, 2026. After this deadline, old certificates will be revoked, and system-level blocks will prevent the launch of older versions and new installations.OpenAI stated that the company had previously deployed stricter code package blocking policies, but the infected devices had not yet synchronized the latest configuration, allowing the malicious component to successfully infiltrate. Currently, the iOS and Windows clients are unaffected, and core data such as user account passwords and API keys have been confirmed secure.

SlowMist: DarkSword attack program leaked in the wild; older iOS users’ crypto wallets at risk

SlowMist’s Yu Xian stated that some in-the-wild attack samples have been obtained. It is currently confirmed that the attacks primarily target iPhones running older versions of iOS, Safari browsers, and users holding cryptocurrency wallets. He noted that malicious JavaScript exploit code may be embedded in fake websites—such as those impersonating adult live-streaming platforms, TRON energy stations, refund procedures, or vulnerability alerts. If users of older iPhone models open such websites using Safari and leave them open, while simultaneously unlocking their wallet apps in preparation for use, their plaintext private keys could be stolen.

Tezos Launches TzEL, a Post-Quantum Privacy Payment Prototype on Testnet

According to Cointelegraph, Tezos ecosystem developers have launched the quantum-resistant privacy payment prototype TzEL on the testnet. TzEL employs post-quantum cryptography and zk-STARK proofs to defend against “harvest now, decrypt later” attacks, safeguarding transaction data and encrypted payment metadata. The prototype also integrates Tezos’ data availability layer to handle the relatively large size of post-quantum proofs. According to the whitepaper, the quantum-resistant zk-STARK proofs used by TzEL are approximately 300 KB in size. TzEL is currently running on the Tezos testnet, and the Tezos ecosystem’s transition to post-quantum cryptography remains in its early stages.

Ranger Finance Announces Gradual Shutdown Due to Funding Difficulties and Drift Vulnerability

Ranger Finance co-founder cobra stated that Ranger Finance is winding down operations. Some personnel and vendors who collaborated with, built, and supported the project have not received full payment. He explained that during periods of cash shortage, the founders personally injected funds to keep operations running and advanced fundraising efforts within MetaDAO; however, the delayed fundraising led to an accumulation of unpaid bills. After the fundraising was completed, the project only secured approximately two months of runway before the funds were returned. Ranger Finance noted that treasury liquidation exceeded expectations, negatively impacting employees, vendors, and growth budgets. Subsequently, the Drift vulnerability further hampered project progress. Vault users affected by the Drift vulnerability will receive recovered tokens when distributed by the Drift team.

CertiK CEO: AI Is Turning DeFi Defense into an "Unfair Game"

Ronghui Gu, co-founder and CEO of CertiK, stated that AI tools are exacerbating the imbalance between attack and defense in DeFi security, making it easier for attackers to discover vulnerabilities and replicate attack paths across different protocols.He pointed out that the DeFi security situation was particularly severe in April of this year, with only 3 days that month free from hacker attacks, resulting in cumulative losses exceeding $690 million for DeFi protocols. Excluding the Bybit attack in February 2025, April has become the month with the highest losses from DeFi hacks since March 2022.Ronghui Gu believes that attackers can concentrate significant computing power to repeatedly test a single protocol, whereas security companies need to serve multiple clients simultaneously with dispersed resources, putting the defense side at a natural disadvantage. Meanwhile, the focus of recent attacks is also shifting from smart contract vulnerabilities to operational security and weak points in the supply chain.He emphasized that even if AI fails to find vulnerabilities over an extended period, it does not prove the code is completely secure; under current technical conditions, formal verification remains a more reliable method for ensuring security.

AaveLabs: Updates Bug Bounty Program, Core Aave V3 Maximum Reward Raised to $5 Million

that, according to official sources, AaveLabs has proposed restructuring the Aave DAO bug bounty framework into multiple specific subsystem programs, operating on the Immunefi, Sherlock, and Cantina platforms respectively. Core Aave V3, Core Aave V2, GHO, and non-liquidity protocol infrastructure will be covered by Immunefi; Aave V4 and the Aave App Stack will be covered by Sherlock; and Aave V3 on Aptos will be covered by Cantina.The proposal suggests adjusting the bounty scale for each system. The maximum reward for critical vulnerabilities in Core Aave V3 is $5 million, while the maximum reward for critical vulnerabilities in Aave V4 is $2.5 million. Additionally, the funding source for the Aave V3 bug bounty on Aptos will be transferred from Aave Labs to the Aave DAO. This ARFC proposal has currently been passed.

Aave Updates Its Bug Bounty Program: Core Aave V3 and Other Modules to Launch Separate Bug Bounty Programs

Aave announced that its bug bounty program has been updated to better align rewards with the risk profile of each component within the ecosystem and to streamline the review process. The reward cap for critical vulnerability fixes in Aave V4 and Core Aave V3 has now been increased fivefold.

CLARITY Act Hearing Live: AI Regulatory Sandbox Amendment Passes, Amendment to Block High-Risk Assets from Retirement Accounts Rejected

the deliberation of the "Cryptocurrency Market Structure Act" (i.e., the CLARITY Act) has commenced in the U.S. Senate Banking Committee. As of now:1. An amendment proposed by Senator Mike Rounds to create an AI regulatory sandbox was passed with 15 votes in favor and 9 against, indicating some bipartisan support, despite Senator Elizabeth Warren urging Democratic members to vote against it.2. An amendment proposed by Elizabeth Warren, aimed at "preventing high-risk assets from entering retirement accounts," was rejected with 11 votes in favor and 13 against.3. An amendment previously proposed by Senator Katie Britt of Alabama, which would have allowed certain retirement accounts to invest in pooled investment vehicles, was withdrawn before the vote.It is reported that one of the most contentious amendments comes from Elizabeth Warren, concerning the strengthening of sanctions authority over cryptocurrency mixers. In her remarks, she referenced the U.S.-sanctioned mixing protocol Tornado Cash, stating it has been used to launder over $7 billion for criminal organizations and North Korean hacker groups, including over $450 million in related funds. Warren argued that the current bill does not grant the U.S. Treasury Department sufficient legal authority to isolate or restrict mixer services, potentially creating loopholes in anti-money laundering oversight. In response, Cynthia Lummis countered that the illegal financial activities are already covered in Parts Two and Three of the bill.

Kraken: Will Replace LayerZero with Chainlink as Cross-Chain Infrastructure

Kraken announced on X platform that Chainlink CCIP will become the sole cross-chain infrastructure for kBTC and future wrapped assets, replacing the original LayerZero protocol. This decision followed last month's $292 million LayerZero cross-chain bridge exploit incident at Kelp.Currently, a total of over $3 billion in total value locked has migrated from LayerZero. The migration covers blockchains including Ethereum, Ink, Unichain, and Optimism. The current market cap of kBTC is approximately $260 million. Kraken stated that it will continue to be responsible for the issuance and custody of assets, while Chainlink CCIP will handle cross-chain asset transfers. (coindesk)

Gate Research: Crypto Market Warms Up in April with RWA and On-Chain Capital Flow in Focus

Odaily Odaily News Gate Research recently released its "April 2026 Cryptocurrency Market Review" report, indicating that the overall cryptocurrency market saw a volatile upward trend in April, with total market capitalization significantly higher than in March. BTC and ETH ETF trading volumes maintained high volatility overall. The report shows continued divergence in activity across major public chain ecosystems. Solana's daily transaction volume remained in the range of approximately 90 million to 110 million transactions, maintaining its leading position.Regarding trending sectors, the report notes that Pokemon TCG RWA has become one of the fastest-growing on-chain RWA sub-sectors, entering a second explosive growth phase in April. Major trading platforms saw monthly trading volumes exceed $220 million, with weekly revenue briefly approaching $6 million, setting new historical records. Meanwhile, Aave experienced its most severe liquidity crisis ever in April, with TVL outflows reaching tens of billions of dollars within a few days and net outflows exceeding $9 billion for the entire month.In terms of fundraising and security incidents, the Web3 industry completed 51 financing rounds in April, totaling approximately $834 million, with capital further concentrating on leading financial and infrastructure tracks. Among these, Payward ranked first for the month with a $200 million financing round. On the security front, Web3 security incidents in April resulted in losses of approximately $306 million, a month-over-month increase of about 858%, primarily driven by a single cross-chain infrastructure attack on Kelp DAO worth approximately $293 million. The report suggests that against the backdrop of a recovering market, on-chain activity and capital liquidity are both increasing simultaneously. However, the security risks associated with cross-chain infrastructure and high-leverage protocols remain worthy of continued attention.

T3 Financial Crime Unit Freezes Over $450 Million in Illicit Crypto Assets

According to The Block, the T3 Financial Crime Unit (T3 FCU), jointly established by Tether, TRON, and TRM Labs, announced that since its founding in 2024, it has frozen over $450 million worth of illicit crypto assets globally. In 2025, the unit’s interception of illicit proceeds increased by 43.9% year-on-year, covering 23 jurisdictions including the United States, Spain, and Germany, and has been recognized by the Financial Action Task Force (FATF) as “a critical resource for global law enforcement agencies.” The T3 FCU has participated in investigations across multiple crime categories, including exchange hacks, North Korea–related activities, terrorist financing, and violent crimes, and assisted Brazil’s Federal Police in freezing over $5.989 billion in assets—including 4.3 million USDT.