GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

ZetaChain: Users targeted in the prior vulnerability attack did not suffer fund losses; the mainnet patch has been deployed.

According to an official disclosure by ZetaChain, on April 27, ZetaChain suffered a targeted vulnerability exploit. The attacker first acquired funds via Tornado Cash and performed wallet address spoofing, then exploited a vulnerability in GatewayEVM’s arbitrary call functionality, resulting in approximately $334,000 in losses across four connected chains. ZetaChain stated that this attack did not affect cross-chain $ZETA transfers; all affected wallets were under ZetaChain’s internal control, and user funds remained unaffected. A patch for the mainnet has now been deployed, and cross-chain transactions will resume after ongoing monitoring.

Prediction market platform Polymarket疑似遭遇数据泄露,逾30万条记录及漏洞利用工具包外泄

According to Dark Web Informer, the decentralized prediction market platform Polymarket is suspected of having been hacked. The threat actor “xorcat” posted over 300,000 data records and a corresponding exploit toolkit on a well-known cybercrime forum. The data extraction occurred on April 27, 2026. Reportedly, the attacker extracted data via an undisclosed API endpoint, pagination bypasses, and misconfigured CORS settings in Polymarket Gamma and the CLOB API. The leaked data includes: - Full personal information for 10,000 users (including names, proxy wallets, and base addresses); - 4,111 comments; - 1,000 moderation reports (including 58 ETH addresses and administrator authentication address identifiers); - Metadata for 48,536 Gamma markets; - Constant-product market maker addresses for over 250,000 active CLOB markets; and - Social graph data for 9,000 followers. The toolkit contains proof-of-concept code for multiple vulnerabilities, including CVE-2025-62718 (Axios NO_PROXY bypass, CVSS 9.9, enabling server-side request forgery), CVE-2024-51479 (Next.js middleware authentication bypass, CVSS 7.5), and the aforementioned CORS misconfigurations. Additionally, the toolkit includes automated continuous data-extraction scripts and a comprehensive red-team report (including M

Bitcoin lending protocol Tropykus announces shutdown of its current version; deposit and lending functions are permanently discontinued.

According to an official announcement by Tropykus, the decentralized lending protocol Tropykus has initiated a phased shutdown of its current protocol version. Deposit and lending functionalities will be permanently discontinued. Users may withdraw funds and repay loans via tropykus.com until the deadline of July 27, 2026; thereafter, such operations will only be supported through direct interaction with smart contracts. The team stated that this shutdown decision stems from long-term strategic evolution—not from the security report previously received by Money on Chain, a partner of Tropykus. That report had prompted the protocol to proactively suspend deposits and new lending activities. However, the team emphasized that internal discussions regarding the shutdown predated the security incident, and the incident merely accelerated the decision. Technically, the team noted that the original architecture was designed for an earlier technological environment and is no longer capable of meeting long-term development needs in the face of emerging security challenges posed by technologies such as artificial intelligence. The team advises all users to complete withdrawals and settle their lending positions via tropykus.com before July 27, 2026. After this date, users will need technical proficiency to interact directly with smart contracts to perform these operations.

Alchemix yvVault Users Attacked Due to Unauthorized Approvals, Suffering ~$1M in Losses

According to on-chain analyst PeckShield (@PeckShieldAlert), a user’s Alchemix Yearn yvVault position (token $yvWETH) was attacked, resulting in an estimated loss of approximately $1 million. The root cause of the attack lies in the user’s prior approval grant to an unverified contract (contract address: 0x143a), deployed 10 days ago. Reverse-engineering analysis revealed that this contract contains a vulnerability enabling arbitrary call execution. Exploiting this vulnerability, the attacker successfully transferred the victim’s yvVault position. PeckShield has now publicly disclosed the specific logic of this vulnerability. Users are advised to review and revoke token approvals granted to unknown or unverified contracts to mitigate asset risks.

Trading Protocol’s treasury attacked, suffering losses of approximately $398,000

According to on-chain analyst PeckShield (@PeckShieldAlert), the YieldCore-3rd-deal treasury under Trading Protocol was attacked, resulting in losses of approximately $398,000. The attack exploited a vulnerability in the contract—specifically, a missing caller permission check—which allowed the attacker to bypass the authorization mechanism and withdraw all funds from the treasury. Relevant on-chain transaction records have now been disclosed.

Cryptocurrency hackers have stolen a total of $17.1 billion in assets over the past decade

According to Odaily, over the past decade (2016–2026), cumulative losses have reached $17.1 billion, spanning 518 incidents. In the last five years (2021–2026), losses have amounted to approximately $15.2 billion across more than 450 incidents. Over the past year (April 2025 – April 2026), losses were roughly $2.5 billion, involving over 140 incidents. Recent losses indicate that crypto attacks have shifted from smart contract vulnerabilities to private key leaks and access control breaches. (Solid Intel)

Robinhood Phishing Attack Exploits Gmail’s “Dot Alias” Feature to Forge Official Emails and Lure Users into Logging In

According to Cointelegraph, Robinhood users have recently fallen victim to a phishing attack. Attackers exploited Gmail’s feature of ignoring periods (“.”) in email usernames, along with a vulnerability in Robinhood’s account creation process, to register accounts with email addresses highly similar to those of their targets. This enabled them to trick Robinhood’s official email server into delivering spoofed alert emails containing phishing links directly to victims’ inboxes. Cybersecurity researcher Alex Eckelberry noted that these emails pass SPF, DKIM, and DMARC authentication checks and thus appear to originate from Robinhood’s official domain. Robinhood stated that this incident does not involve any breach of its systems or customer accounts, and user funds and personal information remain unaffected. However, the company urges users to delete such emails and avoid clicking any suspicious links.

ZetaChain Exploited, Vulnerability May Originate from Flaw in GatewayZEVM Call Function

SlowMist stated ZetaChain has been exploited. Preliminary analysis indicates the root cause of the vulnerability lies in the lack of access control and input validation in the call function of the GatewayZEVM contract. This allowed attackers to initiate malicious cross-chain calls and, via the relayer mechanism, execute arbitrary operations on the target chain to transfer funds.SlowMist noted that the attacker forged cross-chain events to trigger the relayer into executing malicious calls, thereby stealing funds. The relevant attack transactions have been disclosed.

ZetaChain: GatewayEVM Contract Attacked; Cross-Chain Transactions Suspended

According to an official announcement, ZetaChain stated that its GatewayEVM contract was attacked today, with the impact limited solely to internal wallets controlled by the ZetaChain team. The official statement confirmed that the attack vector has been blocked and no further funds are currently at risk. As a precautionary measure, ZetaChain has suspended cross-chain transactions. Meanwhile, the investigation remains ongoing; according to the official statement, no user funds have been affected by this incident, and a detailed post-mortem report will be released upon completion of the investigation.

DeFi United Raises Over $300 Million in Funding

Circle Ventures, Consensys, and Joseph Lubin have announced their support for the DeFi United initiative, aimed at mitigating losses caused by the Kelp DAO vulnerability. Circle Ventures is supporting the ecosystem by purchasing AAVE tokens. Consensys and Ethereum co-founder Joseph Lubin have confirmed the provision of 30,000 ETH to DeFi United. To date, DeFi United has raised over 132,000 ETH, with a total value exceeding $300 million. These funds will be used to cover bad debts resulting from an attacker minting unbacked rsETH via the LayerZero bridge and borrowing assets on Aave. Previously, Aave proposed a donation of 25,000 ETH, while Lido DAO, Ether.fi, and Kelp have respectively proposed or pledged donations of 2,500 ETH, 5,000 ETH, and 2,000 ETH.

Galaxy Digital OTC-linked address deposits 15,000 ETH to exchange, valued at $34.74 million

Odaily报道 According to Ai Yi monitoring, a Galaxy Digital OTC-related address (0x16F...1Fde) has deposited 15,000 ETH, worth $34.74 million, to an exchange. These funds originated from 38,000 ETH withdrawn from Aave a week ago, which was the day when Kelp DAO was attacked, causing Aave to potentially face bad debt.

France charges 88 suspects in crypto "wrench attack" cases, including over a dozen minors

the French National Organized Crime Prosecutor's Office (PNACO) issued a statement on Friday stating that France has launched judicial investigations into 12 cryptocurrency kidnapping cases orchestrated by organized crime groups, and has indicted 88 suspects, including more than 10 minors.According to statistics, since 2023, France has recorded 135 cryptocurrency-related attacks, including 18 in 2024, 67 in 2025, and 47 so far in 2026. The accused individuals face charges including kidnapping, illegal detention, extortion, and money laundering. Recently, police arrested six suspects in two operations targeting kidnapping cases, and all individuals are currently in preventive detention. CertiK blockchain intelligence analyst Jonathan Riss stated that the masterminds behind such criminal gangs are typically located outside the European Union.

Developer proposes to fork Bitcoin eCash, reallocate Satoshi Nakamoto's BTC holdings

Paul Sztorc, a developer who has long focused on Bitcoin scaling solutions, proposed a Bitcoin hard fork named eCash, set to occur at block height 964,000 in August 2026. Users holding BTC at the time of the fork will receive eCash on a 1:1 basis, and the new chain will introduce the Drivechains sidechain architecture. The controversy mainly centers on the plan to pre-allocate a portion of the eCash corresponding to the Satoshi Nakamoto address on the new chain to early investors, a move that has drawn criticism from the community, with some accusing it of "stealing" tokens. Paul Sztorc stated that this initiative aims to provide incentives for development and collaboration before the project's launch.

QCP: BTC Monthly Gain Exceeds 14%; Geopolitical and Security Incidents Disrupt Market Sentiment

QCP Group’s analysis states that U.S.-Iran negotiations have once again collapsed, while the Middle East ceasefire continues, leaving the overall geopolitical landscape relatively static. A shooting incident occurred at the White House Correspondents’ Dinner, with Trump suspected as the target. Following Asia’s market open, BTC briefly surged past $79,000 and ETH above $2,400—but gains quickly reversed amid concerns triggered by news of Iran’s Foreign Minister traveling to Russia for talks with Putin. Since early April, BTC has rallied over 14% cumulatively, marking four consecutive weeks of positive closes. Spot ETFs recorded nine straight days of net inflows totaling approximately $2.11 billion. Strategy funds added over $3.8 billion worth of BTC in the past month. The current key resistance level for BTC lies near the CME gap around $82,000. BTC perpetual contract funding rates remain persistently negative; a breakout above this level could trigger short-covering. Implied volatility continues declining, and risk-reversal skew has narrowed somewhat, signaling gradually rising market interest in upside exposure. Key events this week: - April 29: Earnings reports from Microsoft, Amazon, Meta, and Google, plus the FOMC interest-rate decision. - April 30: Apple earnings report, U.S. Q1 GDP data, and March PCE inflation data.

Senator Tillis Ends Months-Long Obstruction, Clearing the Way for Waller’s Fed Chairmanship

According to The Wall Street Journal, North Carolina Republican Senator Thom Tillis said Sunday local time that he would support the confirmation of Kevin Warsh as Federal Reserve Chair, thereby clearing the final major hurdle for Trump’s chosen successor to Powell. Tillis had refused for months to vote in favor of Warsh, stating he would not advance any Fed nominee’s confirmation while the Justice Department’s criminal investigation into Powell remained ongoing—calling the probe an attack on the central bank’s independence. However, that investigation appears to have concluded last Friday. (Jin10)

Scallop: Suffers $150,000 SUI loss due to sSUI reward pool vulnerability; will bear full loss

Scallop, a lending protocol in the Sui ecosystem, announced on X that a vulnerability was discovered in a subsidiary contract related to Scallop’s sSUI reward pool, resulting in the loss of approximately 150,000 SUI. The affected contract has been frozen. Scallop stated that its core contracts remain secure and only the sSUI reward pool is impacted; all other reward pools are unaffected and secure. Scallop will fully cover 100% of the losses and will release further updates as soon as possible.

Sources: Suspect in the dinner incident confirmed to be a 30-year-old man from California

According to CNN, citing sources, the suspect in the “security incident” at the White House Correspondents’ Dinner has been confirmed as a 30-year-old man from California. (CCTV International News)

US Department of Justice Sentences Member of $263 Million Crypto Fraud Scheme to 70 Months in Prison, Involving Social Engineering Fraud and Lavish Money Laundering

: The U.S. Department of Justice (DOJ) announced that a 22-year-old California man, Evan Tangeman, has been sentenced to 70 months (approximately 5 years and 10 months) in prison, followed by 3 years of supervised release, for his involvement in a criminal organization that stole approximately $263 million in crypto assets through social engineering fraud and home invasions.According to court documents, Tangeman pleaded guilty in December 2025, admitting to helping the criminal network launder at least $3.5 million in illicit funds.The criminal group allegedly used the stolen funds for lavish spending, including multi-million dollar nightclub bills, Lamborghini sports cars, and high-end assets like Rolex watches.U.S. District Attorney for the District of Columbia, Jeanine Pirro, stated in a release that the organization "built a criminal system based on nearly absurd greed," emphasizing that Tangeman not only participated in money laundering but also destroyed evidence after his accomplices were arrested, demonstrating clear criminal intent.This sentencing comes as data shows that the crypto industry suffered $482 million in losses from scams and hacks in the first quarter of 2026, with social engineering fraud and physical violent robberies on the rise. (Cointelegraph)

Donald Trump is "safe and sound," White House Correspondents' Dinner will proceed as planned

: After a "security incident" at the White House Correspondents' Dinner, U.S. President Donald Trump is "safe and sound" and the dinner will continue as scheduled. (Xinhua News Agency)

Balancer attacker has exchanged 21,000 ETH for 617.43 BTC over the past three days

according to Onchain Lens monitoring, a Balancer attacker has exchanged 21,000 ETH for 617.43 BTC over the past three days, worth $48.72 million. The attacker currently still holds 1,000 ETH, worth $2.32 million, and may conduct further sell-offs.