GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Gate Research: Crypto Market Warms Up in April with RWA and On-Chain Capital Flow in Focus

Odaily Odaily News Gate Research recently released its "April 2026 Cryptocurrency Market Review" report, indicating that the overall cryptocurrency market saw a volatile upward trend in April, with total market capitalization significantly higher than in March. BTC and ETH ETF trading volumes maintained high volatility overall. The report shows continued divergence in activity across major public chain ecosystems. Solana's daily transaction volume remained in the range of approximately 90 million to 110 million transactions, maintaining its leading position.Regarding trending sectors, the report notes that Pokemon TCG RWA has become one of the fastest-growing on-chain RWA sub-sectors, entering a second explosive growth phase in April. Major trading platforms saw monthly trading volumes exceed $220 million, with weekly revenue briefly approaching $6 million, setting new historical records. Meanwhile, Aave experienced its most severe liquidity crisis ever in April, with TVL outflows reaching tens of billions of dollars within a few days and net outflows exceeding $9 billion for the entire month.In terms of fundraising and security incidents, the Web3 industry completed 51 financing rounds in April, totaling approximately $834 million, with capital further concentrating on leading financial and infrastructure tracks. Among these, Payward ranked first for the month with a $200 million financing round. On the security front, Web3 security incidents in April resulted in losses of approximately $306 million, a month-over-month increase of about 858%, primarily driven by a single cross-chain infrastructure attack on Kelp DAO worth approximately $293 million. The report suggests that against the backdrop of a recovering market, on-chain activity and capital liquidity are both increasing simultaneously. However, the security risks associated with cross-chain infrastructure and high-leverage protocols remain worthy of continued attention.

T3 Financial Crime Unit Freezes Over $450 Million in Illicit Crypto Assets

According to The Block, the T3 Financial Crime Unit (T3 FCU), jointly established by Tether, TRON, and TRM Labs, announced that since its founding in 2024, it has frozen over $450 million worth of illicit crypto assets globally. In 2025, the unit’s interception of illicit proceeds increased by 43.9% year-on-year, covering 23 jurisdictions including the United States, Spain, and Germany, and has been recognized by the Financial Action Task Force (FATF) as “a critical resource for global law enforcement agencies.” The T3 FCU has participated in investigations across multiple crime categories, including exchange hacks, North Korea–related activities, terrorist financing, and violent crimes, and assisted Brazil’s Federal Police in freezing over $5.989 billion in assets—including 4.3 million USDT.

A New York judge postponed the hearing on Aave’s application to unfreeze $71 million worth of ETH, requesting both parties to submit additional explanations.

According to Cointelegraph, a New York judge has postponed the hearing on Aave’s emergency motion to unfreeze approximately $71 million worth of ETH and ordered Aave and Gerstein Harrow LLP to submit additional case briefs. A new hearing is scheduled for June 5. The court noted that Aave previously failed to adequately explain why users’ funds would suffer “derivative losses” if the restraining order remained in effect. The assets in question are linked to the Kelp DAO hack, which involved approximately $293 million and was previously frozen by Arbitrum. The judge also directed both parties to further clarify several legal issues, including the applicable law governing the hacker’s transactions, the legal distinction between fraud and theft, the priority ranking of creditors’ claims, the applicability of constructive trust, and whether assets can be proportionally returned to victims.

GoPlus Security: A user mistakenly transferred 100,000 DAI due to an address poisoning attack.

GoPlus Security reported that a user fell victim to a typical address poisoning attack: the user mistakenly sent 100,000 DAI to a spoofed address after copying a visually similar address from their transaction history. In this incident, the user had previously sent 300,000 DAI to the legitimate target address; the attacker then sent 0.0003 DAI to the user from a malicious address with characters nearly identical to the legitimate one—before and after the address—thereby tricking the user into selecting the wrong address during their subsequent transfer. GoPlus Security advises users not to copy wallet addresses from transaction history, always verify the full address before sending funds, and conduct a small test transaction prior to any large transfer.

TAC: If Attacker Returns Approximately $2.8 Million in Assets, 10% White Hat Bounty Will Be Offered

the L1 blockchain TAC team stated they have confirmed a security incident on the cross-chain layer resulted in approximately $2.8 million in assets being transferred, involving assets such as USDT, BLUM, and tsTON.TAC stated that if the attacker returns the relevant funds to the designated multi-signature address, the team will consider this incident a "white hat rescue" and will not take legal action against the operator of the involved ETH/BSC, ZEC, and TON addresses.As a reward, the attacker can receive an approximately 10% bounty, equivalent to about 13 ETH and 300 ZEC.

TAC Cross-Chain Layer Attacked on TON Side, Suffering ~$2.8M Loss

TAC stated that its cross-chain layer on the TON side was exploited by external attackers, resulting in approximately $2.8 million in losses involving USDT, BLUM, and tsTON. TAC confirmed that the TAC token, TON, and all ERC-20 tokens bridged from Ethereum remain unaffected. The bridge has been temporarily suspended, and the team is conducting forensic analysis and implementing fixes. Additionally, the team plans to legally structure a sale of the foundation’s TAC token treasury reserves to restore bridge liquidity and compensate affected users. A post-mortem report and further details will be released within the next 48 hours.

Code4rena to Shut Down, Immunefi to Take Over Its Bug Bounty Clients

the smart contract auditing platform Code4rena has announced it will gradually cease operations. All ongoing audit contests and bug bounty programs will still be completed as normal.Web3 security platform Immunefi subsequently stated that it will collaborate with Code4rena to take over its bug bounty clients and security researchers, assisting in the migration of bounty scope, rules, and reward structures.Code4rena was known for its "competitive audit" model, allowing independent security researchers to earn rewards by discovering smart contract vulnerabilities. The platform secured $6 million in funding from Paradigm in 2023 and was acquired by blockchain security firm Zellic in 2024.

Transit Finance: Historical TRON Contract Vulnerability Exploited; Affected Users to Receive Full Compensation

According to the official announcement by Transit Finance, an outdated smart contract—originally deployed on the TRON blockchain and deprecated in 2022—was recently exploited via a historical vulnerability, affecting a small number of users. The team completed its investigation, isolation, and remediation efforts on May 12, 2026; no action is required from users. The current version of the smart contract remains unaffected, has been operating securely for over four years, and continues to undergo regular security audits and monitoring. Affected users will receive full compensation; details of the compensation plan will be announced separately via official channels. The team also reminds users to remain vigilant against impersonator accounts and never disclose private keys or mnemonic phrases to anyone.

PeckShield: Transit Finance Hacked, Suffering ~$1.88M Loss

According to on-chain analyst PeckShield (@PeckShieldAlert), Transit Finance appears to have been hacked, resulting in losses of approximately $1.88 million. The stolen funds are currently held in DAI at the address 0x8a634DfA2609358849D7D65FFA270C8A57a8abA5.

Avant Delays TGE to Mid-September; Points Accumulation to End on May 15

Avant announced that, based on comprehensive market feedback and its own assessment, it has decided to postpone the Token Generation Event (TGE) to mid-September. Avant stated that the broader decentralized finance (DeFi) token market is currently under pressure, and multiple protocols have recently suffered security incidents—conditions unfavorable for launching a token sale. Avant Rewards points will cease accruing on May 15; however, users’ already-earned points will be preserved and remain eligible for participation in the upcoming TGE. During the postponement period, Avant will advance partnerships, expand total value locked (TVL), and enhance its product suite. It also plans to host a public Space this Thursday at 2:00 PM Eastern Time.

Aave: First Phase of rsETH Technical Recovery Plan Completed, Including Burning Attacker's rsETH on Arbitrum

Aave posted on X, stating that the first phase of the rsETH technical recovery plan has been completed, including the burning of the attacker's rsETH on Arbitrum.In the coming days, funds will be gradually replenished for the LayerZero OFT adapter, and rsETH-related operations will be restored.

Hackers Inject Malicious Code into Mistral AI Software Package

According to Decrypt, Microsoft’s Threat Intelligence team disclosed that attackers had injected malicious code into Mistral AI packages distributed via the PyPI platform. This malicious code automatically executes when developers use the packages on Linux systems, downloading and running a malicious file named <code>transformers.pyz</code> in the background—the filename deliberately mimics the widely used Hugging Face Transformers library to evade detection. Microsoft noted that the malware primarily steals developers’ login credentials and access tokens. It avoids execution on Russian-language systems and includes logic that can randomly delete files on devices located in Israel or Iran. This attack is linked to the “Shai-Hulud” supply-chain campaign launched in September. In response, Mistral stated that its investigation found the attack originated from compromised developer devices, and its corporate infrastructure was not breached.

Coinbase internal tool Mux reveals AI coding paradigm shift: Engineers transition from "code writers" to "multi-agent orchestrators"

Coinbase, a cryptocurrency trading platform, has disclosed in a technical sharing session that its internal multi-agent development tool "Mux" is reshaping software engineering workflows, transitioning the engineer's role from traditional code implementers to task orchestrators for AI agents.With the widespread internal adoption of AI programming tools such as Cursor, Copilot, OpenCode, and Claude Code, code generation efficiency has significantly improved. However, development workflows have long remained stuck in a traditional "single-task, single-branch, sequential execution" mode, creating a new collaboration bottleneck.Mux was born as an internal tool against this backdrop. By assigning each AI agent an independent git worktree, branch, and terminal environment, the system enables parallel multi-task development and conflict-free collaboration, allowing engineers to simultaneously direct multiple agents to handle tasks such as API development, test writing, vulnerability fixes, and code refactoring.Data shows that as of April 2026, Mux has covered over 600 users within Coinbase (including engineers, product managers, and designers), with 335 actively using it and 197 being high-frequency users. It has facilitated over 5,000 PR merges across 461 code repositories and 10 organizations. Engineers using Mux achieved an average of 39.6 PR merges, approximately 3.5 times the baseline of 11.4.Coinbase stated that Mux's success relies on its internal infrastructure capabilities, including an LLM Gateway, secure model access, and a code flow deployment system, enabling deep integration of multi-agent tools into real development workflows. This trend marks a structural shift in the software engineering paradigm: as AI reduces the cost of code generation, the core value of engineers is transitioning from "implementation capability" to "problem definition and agent orchestration capability."

Depthfirst claims its code vulnerability detection has surpassed Anthropic's latest model Mythos

Odaily AI security startup Depthfirst has announced that its self-developed AI model outperforms Anthropic’s latest model, Mythos, in code vulnerability detection. It has discovered more critical security vulnerabilities at approximately one-tenth the cost, drawing attention from the cybersecurity industry.According to the company, a month before the launch of Mythos, it had previously claimed to have found a large number of severe vulnerabilities in key internet infrastructure code. Depthfirst now says its model has further identified multiple high-risk vulnerabilities that Mythos missed, all at a lower cost (approximately $1,000 compared to $10,000).Depthfirst CEO Qasim Mithani stated that the company has improved vulnerability detection efficiency through a “single-task-optimized AI model,” significantly reducing the cost of security analysis while enhancing coverage depth.The company completed $80 million in funding in March this year, achieving a valuation of $580 million. Alongside this, it launched the “Open Defense Initiative,” providing $5 million worth of AI detection credits to open-source developers and critical infrastructure projects for vulnerability scanning and security audits. (Forbes)

CertiK Report: North Korean Hackers Caused ~60% of Digital Asset Thefts in 2025, Attack Pattern Shifts Toward 'Offline Infiltration'

Odaily, Web3 security firm CertiK has released the "Skynet North Korean Crypto Threat Report." Data shows that since 2016, North Korean hacking groups have accumulated approximately $6.75 billion in stolen digital assets. In 2025 alone, their thefts amounted to $2.06 billion in losses, accounting for nearly 60% of the total annual losses in the global crypto industry (including the $1.5 billion Bybit hack). As of early 2026, this threat trend continues, with losses attributable to them making up about 55%.The report emphasizes that the North Korean hackers' attack patterns have fundamentally shifted, evolving from mere code vulnerability exploitation into a state-level attack system combining social engineering, deep supply chain attacks, and 'physical infiltration.' In the recent Drift protocol incident, attackers even spent six months infiltrating offline industry conferences, building trust through real financial transactions and personal interactions before launching the attack.CertiK security experts warn that in the face of such systemic attacks, purely technical defenses are proving inadequate. Crypto institutions urgently need to fully implement a 'zero-trust' hiring model, reinforce third-party supply chains, establish fund circuit breaker mechanisms, and collaborate with professional security firms to build a full lifecycle defense system covering code auditing, round-the-clock risk monitoring, and on-chain anti-money laundering/KYT (Know Your Transaction) fund tracking.

Monero GUI 0.18.5.0 "Fluorine Fermi" Released, Fixes Multiple Vulnerabilities and Upgrades P2Pool Component

privacy project Monero has released the graphical wallet software GUI version 0.18.5.0 "Fluorine Fermi". This update is a recommended upgrade version, primarily including numerous bug fixes and feature optimizations. Key highlights of this release include:Migration of the P2Pool installation path to LocalAppData on Windows systemsFix for an edge case in URI parsingProhibition of creating offline transactions in scenarios involving long payment IDsEscaping untrusted text during QR code scanning to enhance securityUpgrade of P2Pool to v4.15Numerous detail bug fixes and stability improvementsMonero officials stated that this version has been open-sourced on GitHub. Users can download and upgrade through official channels to obtain the latest security fixes and stability improvements.

AI startup White Circle raises $11 million in seed funding, with OpenAI executives participating

According to Odaily, AI startup White Circle has completed an $11 million seed funding round, with participation from Romain Huet of OpenAI, Durk Kingma of Anthropic, and several other executives from prominent AI companies. The company provides a unified API for real-time monitoring of large model inputs and outputs, used to detect hallucinations, prompt injection attacks, harmful content, model drift, and malicious user behavior. It also supports custom security policies (such as rate limiting and banning) and automated governance. (Techfundingnews)

ZachXBT: US 18-Year-Old Hacker Dritan Allegedly Involved in $19 Million Crypto Theft and Money Laundering

on-chain detective ZachXBT has exposed US threat actor Dritan Kapllani Jr., alleging his involvement in social engineering thefts targeting crypto users, totaling approximately $19 million.ZachXBT stated that Dritan has long been flaunting luxury cars,名牌 watches, private jets, and nightclub lifestyles on social media. On April 23, 2026, during a "Band 4 Band (B4B)" voice call on Discord, in an attempt to prove he was wealthier than another hacker, he publicly displayed an Exodus wallet containing $3.68 million in assets.The relevant ETH address is: 0x4487db847db2fc99372a985743a26f46e0b2bba6ZachXBT's tracking revealed that this address is linked to a social engineering theft incident on March 14, 2026, involving 185 BTC (approximately $13 million). The following day, Dritan's Exodus wallet received about $5.3 million from that theft. By the time of the B4B call six weeks later, approximately $1.6 million had already been spent or laundered.On May 11, the US Department of Justice unsealed a criminal indictment against Trenton Johnson, charging him with participation in the theft of 185 BTC. He faces a potential maximum sentence of 40 years in prison. The indictment refers to "Co-Conspirator 1 (CC-1)," believed to be Dritan, who has not yet been formally charged.ZachXBT also noted that Dritan is connected to hacker John Daghita (Lick), who was previously arrested for stealing $46 million from the US government. John had previously exposed Dritan's old wallet address on Telegram. On-chain analysis shows that this address is linked to multiple high-confidence social engineering thefts in 2025, with a cumulative total exceeding $5.85 million.ZachXBT stated that Dritan has long been active in the "The Com" hacker circle and had seemingly avoided formal prosecution due to being a minor. Now that he has turned 18, his "borrowed time may finally be over."

SlowMist: High-Risk npm Worm “Mini Shai-Hulud” Detected, Capable of Stealing CI/CD Keys and Cryptocurrency Wallet Information

According to monitoring by MistEye, the threat intelligence monitoring system operated by blockchain security firm SlowMist (@SlowMist_Team), a highly sophisticated npm worm named “Mini Shai-Hulud” is spreading via well-known developer projects including TanStack, UiPath, and DraftLab. Attackers have hijacked GitHub credentials to publish malicious packages disguised as legitimate updates. These packages contain a hidden script—<code>router_init.js</code>—that executes silently within CI/CD environments such as GitHub Actions, specifically designed to steal CI/CD secrets, cloud infrastructure credentials, and cryptocurrency wallet information. Data exfiltration is conducted using GitHub’s own infrastructure. SlowMist has already shared this threat intelligence (IOC) with its clients. It recommends that projects using the affected packages immediately audit their CI/CD pipelines for the presence of <code>router_init.js</code>, rotate all exposed GitHub, cloud service, and cryptocurrency credentials, and continuously monitor development environments for anomalous background activity.

Meme stock king Roaring Kitty's X account suspected to be hacked, RKC market cap drops to $1.8 million after hitting $12 million

Roaring Kitty, the protagonist of the GameStop "Retail vs Wall Street" saga and the king of meme stocks, had his official X account allegedly compromised in the early hours of today. The hacker posted the contract address of the meme coin Red Kitten Crew (RKC), causing the token's market cap to briefly reach $12 million before plummeting to $1.8 million.Shortly afterwards, Roaring Kitty appears to have regained control of the account and deleted the tweet containing the contract address. Roaring Kitty himself has yet to issue a clarifying statement, with the community widely believing that the posting of the meme coin contract address was due to a brief account compromise.