GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

ZachXBT: PolyArb is a Fake Prediction Market Product with a Wallet Drainer

"on-chain detective" ZachXBT posted on X platform, stating that PolyArb is a fake prediction market product with a wallet drainer on its website. Additionally, the product's account posted controversial replies under multiple tweets from well-known prediction markets to drive traffic and lure users into participating.

ZachXBT: PolyArb is a fake prediction market product equipped with a wallet stealer.

On-chain investigator ZachXBT replied that PolyArb is a fake prediction market product whose website contains a wallet-stealing script. Previously, PolyArb claimed on X that the Hyperliquid HIP-4 outcome market achieved $6.15 million in daily BTC trading volume within 48 hours. William LeGate, Head of User Growth, questioned its claims regarding Polymarket’s fee structure. ZachXBT warned that replying to the relevant account could generate further exposure and increase the number of potential victims.

ZachXBT: US Law Firms' "Free-Riding Claims" May Hinder Recovery and Compensation of Funds for Hacking Victims

Odaily Odaily PaperImperium, the head of MegaETH, disclosed on X platform that documents from the U.S. District Court for the Southern District of New York show that a U.S. court has issued an injunction against the Arbitrum DAO, prohibiting it from transferring approximately $71 million in ETH assets that were previously frozen during the KelpDAO hacking incident. In response, on-chain detective ZachXBT posted on X platform, stating that certain U.S. law firms are using his investigative work and on-chain forensics to help victims of some hacking incidents file legal claims. However, this practice may actually slow down or hinder victims from receiving compensation or recovering funds.ZachXBT added that in previous hacking incidents involving the Lazarus Group, such law firms often stepped in after on-chain fund tracking or freezing was completed, proposing subsequent legal actions that were weakly related to the crypto incidents themselves. Similar "free-riding claims" strategies were used in events like Harmony and Bybit. He called on the crypto community to establish a DAO to resist such practices.

New York court orders Arbitrum DAO to freeze $71 million in ETH, potentially for compensation to victims of North Korea-related cases

: MegaETH lead PaperImperium disclosed on X platform a court document from the U.S. District Court for the Southern District of New York, showing that a U.S. court has issued an injunction against the Arbitrum DAO, prohibiting it from transferring approximately $71 million worth of ETH assets that were previously frozen in the KelpDAO hacking incident. The plaintiffs are attempting to use these funds to enforce outstanding judgment compensation in cases related to North Korea's involvement in terrorism, kidnapping, and other matters spanning several years. They have also filed a motion to serve legal notice to the Arbitrum DAO via alternative means, treating it as an accountable "partnership." The court document further notes that the Arbitrum DAO has a Security Council governed by ARB holders, which has the authority to take action in emergencies. As a result, relevant members who refuse to comply may face legal consequences such as contempt of court. Market observers believe that this case could set an important precedent for the U.S. judicial system to directly constrain DAO governance structures, further highlighting the compliance pressure faced by DeFi protocols under real-world legal frameworks.

Wasabi Protocol: Users Can Now Safely Interact with Contracts and Withdraw Remaining Funds

Wasabi Protocol announced a security incident update on X, stating that users can now safely interact with the protocol’s contracts to withdraw remaining funds. The team said it is working behind the scenes to the best of its ability to address the issue; however, as the investigation remains ongoing, no further details can be disclosed at this time. The team will share the latest updates with the community as soon as conditions permit.

Arbitrum Council Decides to Unfreeze $71 Million Worth of ETH to Mitigate Kelp DAO Losses

According to Cointelegraph, the Arbitrum Committee voted to unfreeze $71 million worth of Ethereum to mitigate the $290 million loss caused by the Kelp DAO vulnerability.

A MEV bot exploited a Meteora pool vulnerability to turn $0.22 into $696,000

SolanaFloor posted on X platform, stating that a suspected MEV bot turned $0.22 USDC into $696,000 USDC in a single transaction by executing an MEV-style price manipulation attack on Meteora's ANB pool. The ANB token dropped 99%.

DeFi Experiences Its Most Severe Loss Month in History, with Over $606 Million Stolen in a Single Month

Within less than three weeks, 12 protocols were hacked for over $606 million. The Drift incident resulted in losses of $285 million, and the Kelp DAO incident caused $292 million in losses—these two attacks together accounted for approximately 95% of the total losses.

Zcash Foundation: Zebra 4.4.0 Released—Multiple Consensus-Level Security Vulnerabilities Fixed; Nodes Urged to Upgrade Immediately

The Zcash Foundation officially announced the release of Zebra 4.4.0, which addresses multiple critical consensus-level security vulnerabilities. All node operators are strongly advised to upgrade immediately. The vulnerabilities include a denial-of-service (DoS) flaw that could permanently halt the discovery of new blocks; a signature operation (sigop) counting error in block validation that may cause consensus divergence; abnormal handling of transparent transaction signature hashes; and a memory allocation amplification attack risk. The Zcash Foundation stated that some of these vulnerabilities could cause Zebra nodes to accept blocks rejected by zcashd, potentially triggering a chain fork. Without timely upgrades, nodes risk interruption of block discovery, consensus forks, and amplified resource consumption. No alternative mitigations are currently available.

US Media: Iran Eases Conditions for Resuming Talks with the US

: Iran has submitted a new proposal to Washington aimed at ending the war, which shows signs of compromise and is intended to restart negotiations to resolve the deadlock that is exacting a heavy toll on its economy. According to sources, Iran's new proposal moves a step closer to the US: it suggests discussing Tehran's conditions for reopening the Strait of Hormuz simultaneously with the US commitment to cease attacks and lift the blockade on Iranian ports. Previously, Iran had demanded that the US lift the blockade as a prerequisite for starting negotiations and required the US to agree on terms for ending the war before discussing the future management of the strait and nuclear program. The sources also noted that the new proposal then suggests discussing issues related to Iran's nuclear program in exchange for the US implementing sanctions relief. Iran has informed mediators that if Washington is open to this new proposal, Iran is prepared to travel to Pakistan for talks early next week. (The Wall Street Journal)

Paradigm researcher proposes timestamp escape mechanism to protect early Bitcoin from quantum computing threats

Paradigm researcher Dan Robinson proposed a new scheme called PACT (Prove Address Control with Timestamp), aimed at protecting long-dormant Bitcoin, including Satoshi Nakamoto's early addresses, from future quantum computing attacks.The mechanism allows users to prove control over an address via a timestamp without transferring assets or exposing on-chain activity. Should a future quantum attack occur, assets can be recovered based on this proof within a quantum-resistant version of the Bitcoin network.Compared to mandatory migration schemes such as BIP-361, PACT avoids the privacy exposure issues caused by proactively transferring assets, offering long-term holders a more flexible proactive protection path.

Purrlend: Security incident caused by compromise of admin multisig, resulting in ~$1.52M loss

Purrlend announced that it suffered a security incident on April 25 on HyperEVM and MegaETH, resulting in losses of approximately $1.52 million. The attacker compromised the team’s 2-of-3 multisig wallet and granted the malicious EOA permissions—including BRIDGE_ROLE—enabling the minting of unbacked pUSDm and pUSDC via the `mintUnbacked` function, which were then used as collateral to borrow assets from the lending pool. Purrlend stated it has suspended the protocol, revoked the compromised permissions, and is collaborating with security teams, law enforcement agencies, and cross-chain bridge partners to trace and attempt recovery of the stolen funds.

Hundreds of ETH Mainnet Wallets Suspectedly Attacked by Same Address, Some Inactive for Over 7 Years, Possibly Linked to LastPass Secure Notes

According to the anonymous on-chain detective Wazz, hundreds of wallets on the ETH mainnet have been drained by the same address, with several of these wallets remaining inactive for over 7 years. The incident is suspected to be a novel real-time exploit attack. Crypto user Capitulation commented, suggesting that the most likely vulnerability stems from storing seed phrases in LastPass secure notes during 2020/21.

North Korean hackers spent months meeting Drift Protocol employees in person before stealing $285 million

North Korean spies spent months conducting multiple in-person meetings with Drift Protocol employees before executing one of the largest social engineering attacks against a crypto protocol, stealing $285 million. According to TRM Labs data, losses attributed to North Korean hackers accounted for 76% of total crypto hack losses in 2026. (CoinDesk)

Carrot Announces Shutdown; Users Must Withdraw Remaining Funds Before May 14

DeFi project Carrot announced it will cease operations due to the significant operational impact caused by the Drift vulnerability exploit. Carrot has set May 14 as the deadline for users to withdraw remaining funds from Boost, Turbo, and CRT. Following this, the platform will begin deleveraging its system—reducing all leverage to zero—to free up liquidity for CRT redemptions. Carrot stated that user-deposited funds remain the property of users; should Drift pursue any subsequent recovery measures, related funds will still be distributed per prior announcements.

Wasabi Protocol: Solana Contract Security—Vulnerability Impact Limited to EVM Deployments

Wasabi Protocol stated that the Wasabi smart contracts on Solana are secure and unaffected by this vulnerability. The vulnerability is limited to Wasabi’s EVM deployments. The team is collaborating with leading security firms and has contacted law enforcement and the FBI. Further updates will be shared as they become available.

Arbitrum DAO Launches Vote to Release 30,766 ETH for Kelp Attack Aftermath

: Arbitrum DAO has initiated a governance vote to release the previously frozen 30,766 ETH to support DeFi United, a recovery plan following the Kelp DAO attack.These assets, worth approximately $71.1 million, were frozen by the Arbitrum Security Council on April 20. They were originally funds transferred to the Arbitrum network by the attacker. If the proposal passes, it will become the largest single source of funding for the DeFi United plan.In the early stage of voting, 16.9 million ARB have already been cast in support. Currently, there are no opposing votes. The voting is set to continue until May 7.

Syndicate Labs Suffers Private Key Leak Attack, Cross-Chain Bridge Maliciously Upgraded Resulting in Approximately 18.5 Million SYND Transferred

Syndicate Labs disclosed a security incident: an attacker compromised the system through a private key leak and maliciously upgraded the cross-chain bridge contracts on two chains, leading to the transfer of approximately 18.5 million SYND and about $50,000 in user assets. The attack originated from a compromised development endpoint. The attacker exploited production environment permissions to upgrade the bridge contracts to a malicious version, but other chains were unaffected. The losses include:Commons Bridge: Approximately 18.5 million SYND were transferred and sold, worth roughly $330,000.Another Appchain: Approximately $50,000 in user assets were transferred.Syndicate Labs stated that affected SYND holders will receive full compensation, along with additional excess compensation, leaving their overall holdings higher than before the incident. Affected users on the Appchain will also be fully reimbursed for their losses.

Trump family-backed drone company Powerus signs weapons procurement agreement with the U.S.

the U.S. Air Force has agreed to purchase an undisclosed number of interceptor drones from a company backed by the son of President Trump. As the war between the U.S. and Iran enters its third month, this move deepens the ties between the U.S. military and defense contractors associated with the Trump family. Powerus co-founder Veljkovic stated that the company will sell these drones to the Pentagon following a demonstration in Arizona. This is Powerus' first contract to sell such weapons to the U.S. military. The company declined to disclose the terms or scale of the deal, but such transactions are common when the military evaluates new weapon systems. This move aligns with the U.S. strategy of using low-cost interceptor drones, rather than expensive missiles, to counter Iranian attack drones. Reports indicate that the U.S. military has already deployed 10,000 AI-equipped Merops interceptor drones, developed in Ukraine, to the Middle East.

Ethereum Application Guild (EAG) Launched to Advance the Application-Layer Ecosystem and Build a Global Developer Network

The Ethereum Applications Guild (EAG) has officially launched as a global, nonprofit collaborative organization dedicated to supporting the growth of the Ethereum application ecosystem—driving its evolution from infrastructure to the application layer. EAG will operate across four key pillars: accelerating real-world application adoption, connecting cross-domain ecosystem networks, establishing unified evaluation and development frameworks, and building sustainable funding mechanisms. EAG will implement a membership contribution model based on institutional scale (e.g., valuation, market cap, or assets under management), and introduce a staking-rewards donation mechanism—allocating a portion of ETH staking rewards into an Ecosystem Growth Fund. Additionally, EAG has unveiled its 2026 Global Applications & Developers Program, which includes developer education initiatives, hackathons, and research projects, alongside regional roadshows and ecosystem showcases to strengthen local developer communities.