GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

BTCPay Server Warns of Critical Vulnerability Being Actively Exploited, Potentially Leading to Loss of Funds

Odaily News: Bitcoin News stated on the X platform that BTCPay Server has reported a critical vulnerability being actively exploited, which could result in loss of funds. Users should immediately update to BTCPay Server v2.4.2; those who cannot update immediately should shut down their BTCPay Server until the update can be installed, to prevent unauthorized access.

Over 250 victim reports received, with the highest individual loss reaching 58.97 BTC

Odaily News – According to monitoring by Galaxy's Head of Research, the median dormancy period for stolen coins is 3.5 years, with 88% of stolen coins being over one year old. By address, the median loss is 0.014 BTC and the average loss is 0.212 BTC; over 250 victim reports have been received. Based on victim reports, the median loss is 1.022 BTC and the average loss is 4.04 BTC, with reported losses ranging from 624 satoshis to 58.97 BTC.

Trezor user claims life savings stolen after clicking Google-sponsored phishing result

Bitcoin News posted on X platform that a Trezor user claimed their life savings were stolen after clicking a Google-sponsored search result impersonating Trezor. The phishing page was hosted on Google Sites and allegedly tricked the victim into entering their wallet recovery seed. Trezor stated that it is upgrading its handling of the report, proceeding with the removal of the website, and reminding users to never enter wallet backups or mnemonic phrases on any website or online form. Google-sponsored phishing ads remain an ongoing attack vector for crypto users.

Russia Closes Down 9 Unregistered Crypto Exchanges in Moscow, FSB Alleges Money Laundering of Fraudulent Funds

Odaily News: Russia's Federal Security Service (FSB) conducted surprise raids on 9 unregistered cryptocurrency exchange service providers in Moscow, alleging they were involved in transferring funds obtained through fraud abroad via crypto assets. More than 20 employees were detained at the Moscow International Business Center.The FSB stated that these exchanges converted stolen funds from Russian phone scam victims into cryptocurrency and transferred them to accounts of what it claims are Ukrainian processors. The operation was carried out jointly by the FSB and the Russian Ministry of Internal Affairs.Russia's Ministry of Internal Affairs has launched a criminal investigation into large-scale fraud, which under Russian law carries a maximum sentence of 10 years in prison. The FSB said it is continuing to identify victims and assess potential compensation. (Cointelegraph)

Loss estimate rises to approximately $130 million; Coldcard manufacturer says it cannot independently verify

Odaily News: Coinkite, the manufacturer of the hardware wallet Coldcard, stated that it is currently focusing on assisting customers affected by the security incident and will release a post-mortem of the multi-day attack after the full investigation is completed. At this stage, it will not speculate on the scale of customer losses. Coinkite noted that due to the privacy-focused design of its products, the company cannot independently verify external estimates of the stolen amounts; recent external research has raised the relevant loss estimates to approximately $130 million.

Coldcard temporarily retains customer records to comply with legal procedures

Odaily News: Coldcard stated that due to legal record-keeping obligations related to the security incident disclosed on July 30, the company has temporarily suspended the automatic deletion of customer data. Under its original policy, customer records were typically automatically deleted after 120 days, retaining only information such as email addresses and countries of residence. Currently, such records will be retained until further notice. Coldcard noted that customers may contact official support to request continued processing under the original data retention policy, and the company will resume the automatic deletion mechanism once permitted by law.

QCP:当前市场呈现"韧性而非动能",利空已被消化

据 QCP Capital 8 月 7 日市场报告,BTC 本周从约 62,500 美元低点回升至 64,000 美元附近。尽管期间承压明显——Strategy 上周出售 1,638 枚 BTC(约 1.047 亿美元),Coldcard 安全事件波及约 5,000 个钱包、估计损失约 1,755 枚 BTC(约 1.1 亿美元)——市场并未出现持续性下跌。 期权市场同样未见恐慌情绪,7 日和 30 日平值隐含波动率分别为 28.8 和 32.6,处于近期区间低端;7 日 25-delta 风险逆转从 -7.39 快速收窄至 -2.10,显示短端下行偏斜明显缓解。 宏观层面,美国 7 月 ISM 制造业 PMI 升至 55.6(逾四年新高),但就业数据走软,ADP 私人就业仅新增 4.4 万人,市场等待当日晚些时候公布的非农数据(华尔街日报预期新增约 8.3 万人)。此外,霍尔木兹海峡局势仍未完全解除,布伦特原油重返 83 美元上方;日元干预及日本国债收益率走势持续牵动全球流动性预期。

"AI 教父"Hinton 警告:AI 模型越来越难以控制

According to IBTimes, Nobel laureate and "Godfather of AI" Geoffrey Hinton warned at the Ai4 conference in Las Vegas that as AI model capabilities rapidly improve, humans will find it increasingly difficult to exert effective control over them. He stated: "These systems are becoming smarter, and we will see them develop increasingly complex intentions, as well as increasingly strong abilities to escape control." Previously, OpenAI, Anthropic, and Meta successively disclosed that their experimental models accidentally gained internet access in test environments and infiltrated external systems. Hinton pointed out that the above incidents highlight the growing complexity of frontier AI models and warned that a large number of malicious cyber attacks will occur in the future. He estimates that the probability of advanced AI posing an existential threat to humanity is between 10% and 20%, and called on the industry to prioritize potential risks now, rather than waiting for problems to arise before responding.

US Regulatory Agencies Review Pathways for Chinese AI Companies to Rent Overseas Computing Power to Bypass Chip Bans

According to Bloomberg, sources familiar with the matter revealed that the US government department responsible for investigating chip export control violations is currently systematically reviewing the ways Chinese AI companies obtain advanced Nvidia chips through legal channels, with a particular focus on their practice of renting computing power in third countries. This move stems from recent consecutive technical breakthroughs by Chinese AI companies, indicating that they still possess the capability to acquire and use top-tier hardware under US chip export restrictions on China. Analysts believe that this review may drive the US to further tighten regulatory rules on computing power leasing in third countries to plug loopholes in the current export control system.

日本金融厅统一 17 领域网络安全报告样式,加密资产交换业者纳入规范

据 CoinPost 报道,日本金融厅于 8月 7 日公布"主要行等综合监督指针"部分修订案,将包括加密资产交换业者在内的 17 个监管领域的网络安全事件报告样式统一为共通格式。新增"其他网络攻击等事案共通样式",与现行的 DDoS 攻击及勒索软件专用样式共同构成三类报告区分体系。经过渡措施,2027年 3 月底前非特定社会基础设施事业者仍可沿用旧版报告书,意见征集截止日期为 2026年 9月 7 日。

July crypto asset thefts reached $247 million, marking the second-highest month of 2026

Odaily News: DefiLlama data shows that hackers stole $247 million in crypto assets in July, making it the second-highest month since 2026, trailing only April's $644 million; this figure represents a significant increase from June's $75 million and May's $60 million. Galaxy Digital stated that the Coldcard vulnerability was the largest attack event of the month, confirming three rounds of attacks involving 7,300 wallets, with at least $100 million in Bitcoin stolen; the firm also identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million. DefiLlama's hack tracker estimates losses related to this vulnerability at $115 million. Other attacks in July include a $9 million exploit on decentralized finance protocol Bonzo Lend, a $2.6 million theft from Cardano-based wallet SecondFi, a $24 million theft from Arbitrum-based perpetual trading platform AFX, and a $7.5 million theft from the Verus Ethereum Bridge.

Bitcoin Red Team: Nearly 5,000 Security Issues Found Across 391 Bitcoin Codebases, Only One Codebase with Zero Vulnerabilities

Odaily News: Bitcoin Red Team, a volunteer security audit team composed of Bitcoin developers and security researchers, has released its latest audit findings. In approximately 30 hours, the team reviewed 391 Bitcoin-related codebases and identified a total of 4,962 security issues, of which 720 were rated as high-risk or critical vulnerabilities. Only one codebase was found to have no issues at all. Currently, only 147 vulnerabilities have been submitted to project maintainers for resolution.Bitcoin Red Team is a volunteer security audit team made up of Bitcoin developers and security researchers, initiated following the Coldcard hardware wallet vulnerability incident. Key contributors include Calle, a developer of the Cashu protocol, among others. (Beincrypto)

stealing 2,055 BTC, the Coldcard hacker is active again, moving 30.185 BTC to a new wallet

Odaily News: According to Lookonchain monitoring, the hacker who stole 2,055 BTC (valued at $130 million) from Coldcard is active again. An hour ago, the hacker transferred 30.185 BTC (worth $1.94 million) to a new wallet.

Dormant Bitcoin Wallet Moves $3.2 Million in BTC After 15 Years

Odaily News – A long-dormant Bitcoin wallet moved nearly 50 BTC, worth approximately $3.2 million, on Thursday. The wallet received 49.97 BTC back in 2011, when Bitcoin was trading at around $10 per coin. The BTC was sent to a SegWit address that has previously transferred Bitcoin to institutional broker FalconX and received funds from wallets linked to Nexo and Prime Trust. The newly transferred BTC has not left this address. The transfer comes amid long-term holders rechecking their old storage setups following a major vulnerability exploit in Coldcard hardware wallets. There is currently no evidence linking the 2011 wallet to this vulnerability.

Jaredfromsubway 事件攻击者低卖高买 ETH,累计损失 264 枚 ETH

据链上分析平台 Lookonchain 监测,Jaredfromsubway 事件攻击者在资金操作中出现明显损失。该地址一个月前窃取约 770 万美元 资金后将其兑换为 以太坊,随后以约 1695 美元 的价格卖出 2327 枚以太坊,总价值约 394 万美元;又于约 10 小时前 以约 1912 美元 的价格回购 2063 枚以太坊,同样耗资约 394 万美元。按此计算,其此次操作累计亏损 264 枚以太坊,约合 50.5 万美元。

曾攻击 Jaredfromsubway.eth 的黑客再度转移资金,花费 244 万枚 DAI 买入 1277 枚以太坊

According to monitoring by on-chain analyst Ai Yi (@ai_9684xtpa), the hacker address that previously attacked the MEV bot Jaredfromsubway.eth and caused over $7.5 million in losses has shown unusual fund activity again after one month. Approximately 10 hours ago, the address used the remaining 2.44 million DAI to buy 1,277 ETH. Analysis suggests that the relevant funds may next be mixed via Tornado Cash, and this asset may also be the hacker's last pending on-chain funds.

A hacker who previously caused Jaredfromsubway.eth losses exceeding $7.5 million has spent 2.44 million DAI to purchase 1,277 ETH

Odaily News According to on-chain analyst Ai Yi's monitoring, the hacker who attacked the MEV bot Jaredfromsubway.eth and caused it to lose over $7.5 million spent the final 2.44 million DAI to purchase 1,277 ETH 10 hours ago. This amount represented the hacker's last pending funds on-chain, and the next step may involve mixing the funds through Tornado Cash.

Bitcoin ETF Gains New Attention Due to Coldcard Hacking Incident

Bloomberg analyst Eric Balchunas says the Coldcard security vulnerability enhances the appeal of spot Bitcoin ETFs, with the incident involving approximately $88.6 million in losses.

Ethereum Foundation Recruiting Protocol Security Researcher

The Ethereum Foundation (EF) is globally recruiting Protocol Security Researchers (Remote Full-time), a role within the Protocol Security team. The team is responsible for identifying and intercepting vulnerabilities before they reach mainnet, with work covering Execution Layer/Consensus Layer security reviews, AI-assisted vulnerability discovery, fuzzing, specification audits, and coordinating vulnerability disclosure. Candidates are required to have deep experience with the Ethereum protocol, be familiar with EL/CL specifications and client implementations, and be proficient in languages such as Go, Rust, Java, C#, Nim, or Python. There are no hard requirements on years of work experience, with technical depth being the core consideration.

OpenAI Countersues Apple Over Trade Secret Lawsuit: Using Lawsuits to Hinder AI Hardware Competition, Vulnerabilities in Its Own Information Management

According to TechCrunch, OpenAI is countering Apple's lawsuit over alleged trade secret leaks, claiming that Apple's own information security management and employee offboarding processes have vulnerabilities, and that it cannot prove the relevant information constitutes protected trade secrets. Apple previously accused OpenAI of obtaining hardware-related secrets through former employees who joined OpenAI from Apple, and requested the court to expedite the evidence discovery process. In its latest legal filings, OpenAI stated that Apple allows employees to use personal iCloud accounts to process work materials and did not revoke access rights in a timely manner after employees departed. OpenAI states that Apple did not clearly specify the concrete trade secrets alleged to be stolen, but merely referred generally to information such as product development processes, supply chains, and testing. OpenAI argues that Apple's current lawsuit is primarily intended to restrict its development in the AI hardware sector, and denies that the company needs or uses Apple trade secrets. The dispute between the two parties centers on employee mobility, intellectual property protection, and competition in the AI hardware sector.