GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

CertiK: Probability of Crypto-Related Violent Offline Crimes Rises, Families Becoming New Risk Points

a report from CertiK shows that in the first four months of 2026, 34 "wrench attacks" (offline violence or coercion to obtain crypto assets) have occurred globally, a 41% increase year-over-year, with cumulative losses of approximately $101 million.The report indicates that attack patterns are shifting towards being "data-driven," involving prior collection of victim information and incorporating "proxy targets," such as family members, into the threat scope to apply pressure.Regionally, Europe accounts for 82% of incidents, with France being the most concentrated. Industry insiders believe that such attacks have become a significant security risk for crypto asset holders.

The Mantle community, via MIP-34, proposes to provide Aave DAO with a loan of up to 30,000 ETH to address the rsETH incident’s bad debt.

The Mantle community has approved proposal MIP-34, authorizing the Mantle Treasury to extend a loan of up to 30,000 ETH to the Aave DAO to address the non-performing loan impact on Aave V3 resulting from the rsETH cross-chain bridge security incident on April 18, 2026. Per the proposal, the loan term is up to 36 months, with an annual interest rate of LIDO + 1%; the borrower may repay early without penalty. Regarding risk control, Mantle will hold a first-priority security interest in the relevant collateral assets. Additionally, Aave will provide supplementary collateral comprising no less than $11 million worth of AAVE tokens and protocol revenue, and delegate 130,000 AAVE tokens to Mantle for governance participation.

The Arbitrum DAO voted to release $70 million worth of ETH, but a court order has temporarily frozen the transfer.

According to The Block, the Arbitrum DAO voted to release 30,765.6 ETH (approximately $70 million), previously frozen, to support the DeFi United initiative—aimed at offsetting Kelp DAO’s $292 million exploit loss last month. The vote passed with 90.96% support (182.2 million votes). The attack was allegedly carried out by the North Korean Lazarus hacking group, which exploited a vulnerability in LayerZero’s OFT cross-chain bridge—a single-validator configuration—which allowed attackers to steal 116,500 rsETH and pledge most of the stolen assets as collateral on Aave, resulting in roughly $190 million in bad debt. DeFi United has secured contributions from multiple parties, including 30,000 ETH from Consensys and Joseph Lubin, a 30,000-ETH loan from Mantle, and 5,000 ETH from LayerZero.

Consensus Miami: Institutional Investors Remain Cautious Toward Perpetual DEXs; Security Risks and KYC Compliance Are Core Barriers

According to CoinDesk, at the “Perp DEX Explosion: Bullish Volumes and Bear Market Resilience” panel at Consensus Miami, several industry insiders stated that institutional investors are still largely avoiding decentralized exchanges offering perpetual futures (Perp DEXs). Veteran trader Wizard of SoHo pointed out that Drift’s recent multi-million-dollar hack highlights security vulnerabilities in the DeFi ecosystem, making secure onboarding of institutional capital a core competitive focus for major Perp DEXs. Anderson of Canary Labs expressed concern about DeFi’s current security posture, noting that large institutions face significantly greater challenges adopting decentralized exchanges compared to centralized platforms. Additionally, the structural tension between DeFi’s permissionless, open design and institutions’ stringent KYC compliance requirements is seen as a key barrier to scaling adoption. Michaël van de Poppe, founder of MN Fund, shared his views on AI-powered trading tools, stating that AI agents represent an evolutionary extension of algorithmic trading—and that trading will increasingly become fully automated.

SlowMist Chief Security Officer: Linux System Exposed to High-Risk Vulnerability "Dirty Frag," Users Urged to Upgrade Immediately

: SlowMist Chief Information Security Officer 23pds posted on Platform X stating that a privilege escalation vulnerability named "Dirty Frag" has been exposed in the Linux system, with full details and exploit code now publicly available.This vulnerability allows any local low-privileged user to directly gain root privileges on virtually all mainstream Linux distributions. It is a deterministic logic vulnerability; the attack does not rely on complex race conditions, has an extremely high success rate, and does not cause kernel crashes, making it highly dangerous. It is recommended that Linux users update their systems promptly.

Vitalik Buterin’s ~$4 token swap transaction was sandwiched by an MEV bot

According to CoinDesk, Ethereum co-founder Vitalik Buterin was sandwiched by the well-known MEV bot jaredfromsubway.eth on April 30 during a small token swap. On-chain data shows that Buterin exchanged 26,544 XDB tokens—valued at approximately $3.86—for 0.00197 ETH (worth about $4.56) in block 24993038. The bot then deployed roughly $1.14 million worth of WETH to manipulate prices across SushiSwap and Uniswap V2 to execute the sandwich attack. After deducting $5.14 in gas fees, the bot incurred an actual loss on this operation.

OpenAI Launches GPT-5.5-Cyber and Deploys Trusted Access Framework for Cybersecurity

OpenAI has officially launched the GPT-5.5-Cyber model and the "Trusted Access for Cyber" (TAC) framework designed for cybersecurity defenders. Simultaneously, GPT-5.5-Cyber has been opened for a limited preview to defenders responsible for critical infrastructure, supporting specialized cybersecurity workflows.TAC is an identity and trust-based framework aimed at ensuring that enhanced AI capabilities are wielded by verified defenders. Defenders verified through this framework will encounter fewer instances of model refusal when performing tasks such as vulnerability identification, triage, malware analysis, binary reverse engineering, and patch verification. Starting from June 1, 2026, individual members accessing this capability will be required to enable advanced account security protection.OpenAI is currently collaborating with security vendors including Cisco, CrowdStrike, and Palo Alto Networks to accelerate the defense cycle of the security ecosystem through GPT-5.5, enhancing the efficiency of vulnerability research, patching, monitoring, and supply chain security.

Solv Abandons LayerZero, Migrates $700M in Tokenized Bitcoin Assets to Chainlink CCIP

Solv Protocol has announced the migration of over $700 million in tokenized Bitcoin assets to Chainlink's cross-chain protocol CCIP, and will gradually phase out LayerZero's bridging support across multiple chains. The migration involves core assets such as SolvBTC and xSolvBTC. Solv stated that the decision is based on the latest security reviews and recent cross-chain security incidents, and CCIP will become its standard cross-chain infrastructure. This move follows Kelp DAO's migration of approximately $290 million in assets to Chainlink, further strengthening the trend of "cross-chain infrastructure shifting toward security-first migration." (CoinDesk)

Aave plans comprehensive upgrade of collateral and listing standards following KelpDAO security incident

Linda Jeng, Chief Legal and Policy Officer at Aave Labs, stated during Consensus Miami 2026 that Aave's previous risk framework overly focused on financial risks and price volatility. Looking ahead, the protocol will incorporate assessments of cross-chain interoperability, cybersecurity vulnerabilities, and underlying asset architecture.This reform directly stems from the rsETH incident that occurred in April. At that time, an attacker exploited a vulnerability in the KelpDAO cross-chain bridge to mint approximately 116,500 unbacked rsETH (valued at around $293 million), deposited it as collateral into Aave, and borrowed real WETH, leading to significant bad debt risks for the protocol.Jeng revealed that Aave will also release a formal "listing standards handbook" for asset issuers in the future, and will begin evaluating the correlation between DeFi protocols from a systemic risk perspective, rather than analyzing individual pools in isolation.Additionally, a "DeFi United" bailout plan involving Lido Finance, EtherFi, Ethena, and others has been launched to cover collateral shortfalls and prevent further proliferation of bad debt. (CoinDesk)

Lido Updates Kelp Security Incident Progress: EarnETH Vault to Reopen After Protocol Recovery

Lido has provided the latest update on the Kelp security incident, stating that the Snapshot vote regarding the EarnETH first-loss protection mechanism falling below the 1% threshold has reached quorum and been approved. User losses from EarnETH will be fully covered by Lido Earn’s first-loss mechanism. The rsETH held by the attacker has been liquidated, and the related stETH has been transferred to the DeFi United rescue plan.Additionally, the EarnETH vault is expected to reopen shortly after the Kelp protocol resumes operation, at which point users will be able to deposit and withdraw funds normally. Lido emphasized that during the freeze period, both the EarnETH and EarnUSD vaults continued to generate yield. Currently, EarnETH users only need to wait for a brief unfreezing process to complete. Once funds are restored, compensation will be provided in accordance with the first-loss protection mechanism.

TrustedVolumes: Stolen Amount Approximately $6.7 Million, Willing to Engage in Constructive Communication with the Attacker

1inch market maker TrustedVolumes confirmed on the X platform that it had been attacked, disclosing that the stolen funds are currently held in three addresses, with a total amount of approximately $6.7 million. Two of the addresses each hold about $3 million in assets, while another address holds approximately $700,000 in assets. Meanwhile, TrustedVolumes expressed its willingness to engage in constructive communication with the attacker regarding a bug bounty and mutually acceptable solutions.

California Man Sentenced to 78 Months in Prison for Role in $250 Million Crypto Theft

According to Cointelegraph, Marlon Ferro, a 20-year-old man from California known online as “GothFerrari,” was sentenced to 78 months in federal prison, three years of supervised release, and ordered to pay $2.5 million in restitution for his involvement in a cryptocurrency theft ring responsible for over $250 million in losses. Prosecutors stated that when co-conspirators were unable to remotely breach victims’ systems or trick them into surrendering their crypto assets, Ferro carried out physical break-ins to steal hardware wallets containing the funds. The group operated from late 2023 through early 2025 and its members were also involved in database intrusions, target identification, scam phone calls, and money laundering. The investigation was led by the FBI and the IRS Criminal Investigation Division.

1inch: Unrelated to the TrustedVolumes Security Incident; Protocol and User Funds Remain Unaffected

1inch announced on X that it has taken note of the reports concerning TrustedVolumes and confirmed that neither 1inch nor any of its protocols are involved in this incident. The 1inch system, infrastructure, and user funds remain unaffected. TrustedVolumes operates independently as a liquidity provider and is utilized by multiple protocols across the industry—not exclusively by 1inch.

1inch: Unrelated to TrustedVolumes Security Incident; Protocol and User Funds Unaffected

1inch posted on X platform, stating it has taken note of reports concerning TrustedVolumes and confirmed that neither 1inch nor any of its protocols are involved in the incident. The 1inch system, infrastructure, and user funds remain unaffected. TrustedVolumes operates independently as a liquidity provider and is utilized by multiple protocols within the industry, not exclusively by 1inch. 1inch will continue to monitor the situation and actively assist relevant security parties as appropriate.

Santiment: BTC Social Sentiment Bullish Ratio Hits Four-Month High

According to on-chain data platform Santiment (@SantimentData), as Bitcoin’s price reclaimed the $80,000 level, the ratio of bullish-to-bearish comments on social media rose to 1.37:1.00—the highest in nearly four months—signaling a notable surge in market optimism. However, Santiment cautions that historically, sharp increases in bullish sentiment often serve as warning signs rather than buy signals. When retail FOMO dominates social media discussions, traders tend to enter positions late in the trend, raising the likelihood of local tops, profit-taking, and sudden price volatility. Santiment notes that peak market euphoria frequently coincides with the onset of waning momentum. By comparison, following the Kelp DAO vulnerability incident in mid-April, social sentiment plunged into deeply bearish territory; the exit of “weak-handed investors” instead laid a healthier foundation for the current rally. With sentiment now having reversed dramatically, Santiment advises traders to remain vigilant against potential risks stemming from excessive leverage and overly concentrated positions.

California Man Sentenced to 78 Months in Prison for Involvement in $250 Million Cryptocurrency Theft

According to The Block, a U.S. federal court sentenced Marlon Ferro of California—known online as “GothFerrari”—to 78 months in prison, three years of supervised release, and $2.5 million in restitution. Ferro participated in a nationwide social engineering fraud scheme spanning from late 2023 to early 2025, involving over $250 million worth of cryptocurrency assets. The criminal group employed a range of tactics—including database breaches, fraudulent phone calls, money laundering, and residential burglaries—specifically targeting victims holding large amounts of cryptocurrency assets. Ferro carried out two residential burglaries to steal hardware wallets and assisted in laundering illicit funds. U.S. prosecutors stated that this sentence sends a clear message: cryptocurrency fraud is a serious criminal offense and will result in federal imprisonment.

PeckShield: Trusted Volumes Attacked, Suffering ~$5.9M in Losses

According to PeckShieldAlert’s monitoring, TrustedVolumes was attacked, resulting in losses of approximately $5.9 million, including $3.02 million in ETH, $1.37 million in WBTC, and $1.47 million in stablecoins; the attacker has exchanged the stolen funds for 2,513 ETH.

CertiK: An attacker exploited a smart contract vulnerability to steal approximately $5.87 million in pre-authorized funds.

According to CertiK Alert, an attacker stole approximately $5.87 million. The attacker exploited a public function to register as an AllowedOrderSigner and then executed orders to transfer pre-approved funds from victims’ addresses. CertiK urges users to immediately revoke approvals for the vulnerable contract and remain vigilant.

Aave has completed the liquidation of the rsETH attacker’s positions, and the related assets have been transferred to the Recovery Guardian address.

Aave stated that, per the previously disclosed technical recovery plan, the attacker’s rsETH positions on Ethereum and Arbitrum have been liquidated on Aave, and the associated collateral assets have now been transferred to the Recovery Guardian address designated by the AIP. Aave noted that this action did not impact other users, nor did it affect the Umbrella mechanism, and emphasized that this step is a critical milestone in the overall recovery roadmap, with further recovery efforts continuing as planned.

Aave has liquidated the remaining rsETH position of the KelpDAO attacker, with the relevant assets to be transferred to a recovery treasury.

Aave has announced the completion of the liquidation of the remaining rsETH position belonging to the Kelp DAO attacker. The related collateral assets will be transferred to the Recovery Guardian multi-signature wallet managed by DeFi United, to be used for restoring rsETH reserves and compensating affected users.This liquidation is part of the recovery plan following the previous $292 million attack incident. Aave had previously passed a governance vote to temporarily adjust the rsETH oracle price in order to create bad debt in the attacker's position and trigger liquidation. The relevant parameters will be restored upon completion of the liquidation. Previously, the attacker exploited the Kelp DAO cross-chain bridge based on LayerZero to forge 116,500 unbacked rsETH and borrowed ETH from protocols such as Aave and Compound. Currently, the recovery funds managed by DeFi United have exceeded $320 million.