GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Zano to Roll Back ~24 Hours of On-Chain History Due to Inflation Bug

Odaily reports: Privacy blockchain network Zano has disclosed that an inflation vulnerability involving Gateway Addresses has forced it to plan a rollback of approximately 24 hours of blockchain history, and has urged users to immediately cease all economic activity related to ZANO and Confidential Assets.Zano has promised to compensate for losses caused by the rollback, but has not yet announced the target block height for the rollback, the patched version, the compensation process, the mechanics of the vulnerability, or the amount of unauthorized assets created. Gateway Addresses went live on August 26 with Hard Fork 6. (Bitcoin.com News)

Security Vulnerability Exposed in Meta's AI Product Muse

Meta's AI product Muse has been reported to contain security vulnerabilities that could jeopardize user data and virtual environment security, with the company planning to strengthen risk warnings.

Bitget clarifies security breach losses rise to $388 million

Bitget updated its security incident report, adjusting the damaged asset amount from $352 million to approximately $388 million. The exchange stated that the situation is now under control and will continue to suspend withdrawals.

Xie Jiayin: Attack paths and methods have been precisely identified, and the stolen funds will be fully covered by the user protection fund.

Xie Jiayin, Head of Greater China at Bitget, announced the latest updates on the security incident, stating that the security team has accurately identified the hackers' attack vectors and methodologies, and obtained details on how the attackers bypassed security protocols. Tracing the attack back to its source is now highly imminent. Third-party security firms Mandiant and SlowMist are continuing their incident investigation and will release a detailed report subsequently. On-chain tracking confirms that approximately $387.5 million in assets were transferred to attacker addresses, an upward revision from the previously estimated $351.6 million. This adjustment simply incorporates ZEC and TRX into the total and does not indicate any new assets were stolen. No other unauthorized transfers have been detected. Bitget stated that all stolen funds at the platform level will be fully covered by the User Protection Fund, ensuring user assets remain unaffected. Bitget has also officially launched its Fund Recovery Bounty Program. Individuals or entities that voluntarily freeze or proactively retrieve attacker funds will be eligible for a 5% bounty, with prior assistance remaining eligible. The platform has published the attacker's addresses, a real-time fund tracking dashboard, and an information submission portal, and pledged to announce withdrawal times by 12:00 PM on September 26.

Bitget Raises Amount Involved in Security Incident to $387.5 Million and Launches Asset Recovery Bounty Program

Bitget is working to resume withdrawals and has stated it will announce the specific withdrawal restoration plan by 12:00 Beijing Time on September 26.

Bitget CEO: Stolen Funds Revised to $387.5 Million, Withdrawal Plan to Be Announced on September 26

Bitget CEO Gray Chen posted on X platform that following the security incident, on-chain tracking confirmed the attacker's address received a total of $387.5 million in assets, revised upward from the previously disclosed $351.6 million.Gray Chen stated that the revised amount incorporates Zcash and TRON assets that were not fully accounted for previously, and does not represent newly stolen funds. No unauthorized transfers have occurred since the incident, and the situation remains under control. Bitget has launched a Recovery Bounty Program, offering a 5% bounty to each party that voluntarily assists in freezing the attacker's funds or recovering the funds. The exchange has also launched a real-time tracking dashboard, an information submission portal, and an attacker address API, while supporting reports submitted through Bybit's Lazarus Bounty platform. Bitget is currently making full preparations to resume withdrawals, with a specific withdrawal plan to be announced before 4:00 AM (UTC) on September 26.

SlowMist: It has not yet been confirmed that the iPhone Safari attack led to stolen crypto assets, and whether iOS 26.5 is affected remains to be verified.

According to Cointelegraph, SlowMist stated that it has not yet independently confirmed that the analyzed Safari attack sample has led to actual crypto asset theft. Existing technical evidence primarily covers iOS 18.4 through 18.6.2, while the previously circulated claim that "iOS 13 through iOS 26.5 are all affected" remains preliminary. Analysis by SlowMist reveals that the malicious Safari page exploits a chain of vulnerabilities previously patched by Apple to attempt access to the Apple Keychain, app files, and shared data, which may involve information stored in crypto wallets. However, the presence of exfiltration-capable code does not mean data has been successfully extracted from all targeted wallets. SlowMist continues to recommend that iPhone users promptly install the latest iOS security updates and avoid opening suspicious links.

SlowMist: No Confirmed Link Yet Between iPhone Safari Attack and Crypto Asset Theft

Odaily reports: Blockchain security firm SlowMist has stated that the attack samples it analyzed targeting iPhone Safari have not been linked to any confirmed incidents of crypto asset theft. The available technical evidence primarily covers iOS 18.4 through 18.6.2, and whether iOS 26.5 is affected still lacks reproducible technical evidence.The attack reuses the previously disclosed DarkSword attack chain technique, loading code through malicious web pages disguised as free virtual private server services. The samples contain components that access Apple Keychain, extract and decrypt stored information, and can also access application files and shared data.SlowMist recommends that iPhone users install the latest iOS security updates available for their devices and avoid clicking suspicious links. Users who suspect their wallet private keys or seed phrases have been compromised should generate a new wallet on a clean device and transfer their assets. (Cointelegraph)

Magic Eden co-founder: Platform was not attacked, vulnerability involves Limit Break transaction protocol

Odaily News: Magic Eden co-founder Jack posted on X platform that Magic Eden was not attacked today. This incident involves Limit Break's transaction protocol and smart contracts, which Magic Eden stopped using two years ago. The team is currently discussing further measures with Limit Break, including pushing for a pause on asset transfers at the protocol level; until then, users should follow official guidance to revoke relevant authorizations on Magic Eden. Jack also thanked white-hat hacker 0xQuit for participating in the rescue and said more updates will be announced later.

Bitget Stolen Funds Tracking: Circle Has Frozen Nearly 100,000 USDC on Linked Addresses; 218,000 USDT Remains Transferable

According to on-chain detective SomaXBT, Circle has frozen 99,989.91 USDC in an address associated with the Bitget hacker, while approximately 218,000 USDT at the same address remains unfrozen. According to prior on-chain tracking, this address shares a multi-hop fund connection with Bitget's initial stolen funds address. The transferred USDC and USDT remained inactive for over 2.5 hours. The community had previously publicly called on Circle and Tether to freeze the relevant assets. Circle has now taken the lead in executing the action, and SomaXBT subsequently urged Tether to follow suit.

Bitget Security Incident Response Contest: Circle Quickly Freezes 100,000 USDC in Address Linked to a Hacker, Tether Yet to Take Corresponding Action

on-chain analyst tanuki42 disclosed that address 0xe07 holds 100,000 USDC and 218,000 USDT originating from the initial address of the stolen Bitget funds. These funds had been dormant for over 2.5 hours before the analyst publicly called on Circle and Tether to freeze the assets. At around 5 PM, crypto researcher SomaXBT posted that Circle had frozen the USDC assets and called on Tether to follow suit. As of press time, Tether has yet to respond.

Magic Eden responds to vulnerability issue: Discontinued Payment Processor V2 in October 2024; No impact on existing listings.

Magic Eden clarified on the X platform that Payment Processor V2, an NFT trading protocol under Limit Break, was recently exploited. Magic Eden stopped using this protocol in October 2024 and will completely shut down its EVM marketplace in Q1 2026, so this exploit did not affect existing Magic Eden listings. However, NFTs listed on the Magic Eden EVM marketplace from February to October 2024 may have been impacted, and users should revoke the "Approve for All" authorization for the contract on Ethereum, Polygon, and Base. Additionally, Magic Eden stated it is collaborating with Limit Break to investigate and seek further mitigation measures.

NFTs Worth Over $5.7 Million Protected in White Hat Rescue, Payment Processor Vulnerability Leads to Theft of NFTs Across Multiple Projects

Odaily reports: According to monitoring by Quit, at 9 AM EST today, an attacker exploited a vulnerability in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives. More than 12 hours after the incident, no one had reported it, and an investigation subsequently revealed that a large number of NFTs were facing the same risk. Quit stated that after contacting the LimitBreak team, they quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain was also temporarily in a state where it could not be paused, so the team carried out a white hat operation, transferring and protecting a total of 23,155 NFTs worth over $5.7 million. The team later discovered that the vulnerability could also be used in reverse to steal WETH, with approximately 660 WETH at risk, but these could not be recovered in time. Currently, all rescued NFTs have been transferred to secure addresses, and holders will be able to claim their assets in the future after revoking approvals for the vulnerable contracts.

Binance CEO Richard Teng: The security team is assisting Bitget in tracking funds and supporting asset recovery.

Binance CEO Richard Teng stated that following Bitget's recent security incident, the Binance security team has been closely collaborating with the Bitget team since the breach was identified. The teams are currently sharing threat intelligence, tracking relevant funds, and assisting in asset recovery. Richard Teng emphasized that the industry will collectively tackle attackers in response to such security incidents, with ongoing operations continuing to advance.

Blockaid: Limit Break Faces Sustained Attacks, Approximately $1.7 Million in NFTs Stolen

Blockaid warns that users who previously authorized Payment Processor V2 as an NFT Operator should immediately revoke the relevant authorization. Simply canceling listings or Master Nonce cannot remove this permission.

Yuga Labs Blockchain Vice President Quit Reminds Users to Revoke Payment Processor V2 and V3 Approvals as Soon as Possible

Odaily News: According to monitoring by Quit, users should revoke their contract approvals for Ethereum Payment Processor V2 and ApeChain Payment Processor V3 as soon as possible, using revoke.cash or other similar tools. Quit stated that if a user's assets were transferred without authorization and are currently held at an address starting with 0x71cf, the relevant assets are in a safe state, but affected users still need to revoke the aforementioned contract approvals.Previously, NFT marketplace Magic Eden was suspected of having an NFT security vulnerability, with a white hat hacker transferring 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million. Quit stated that this transfer was a white hat operation, and the relevant NFTs are currently held at an address starting with 0x71cF and will all be returned once the risk is resolved.

Magic Eden Suspected of NFT Security Vulnerability as White-Hat Hacker Transfers 3,832 NFTs from Hundreds of Wallets

On-chain data shows that a single address received a total of 3,832 NFTs from hundreds of different wallets within a short period, sparking concerns among community members about a large-scale NFT theft incident.

Bitget 引入 Mandiant 与慢雾调查安全事件,提币仍处于暂停状态

Bitget CEO Gracy Chen 发布安全事件最新进展称,平台正与独立第三方安全团队 Mandiant 和慢雾合作,对此次事件展开全面调查。 Gracy Chen 表示,目前用户账户余额保持完整,此次平台层面安全事件造成的影响将由 Bitget 用户保护基金覆盖;Bitget Wallet 采用自托管模式,其基础设施与 Bitget Exchange 相互独立,因此未受到此次事件影响。 目前 Bitget Exchange 的充值、交易及奖励等功能继续运行,但提币仍暂时暂停,平台正在进行额外安全核查,确认安全后将恢复。Bitget 官方公告也显示,提币服务目前仍处于暂停状态,充值和交易正常运行。 Bitget 表示,后续调查进展及安全事件相关信息将通过官方渠道持续公布。

Magic Eden appears to have an NFT security vulnerability, white hat hacker moves 3,832 NFTs from hundreds of wallets

according to monitoring, Magic Eden appears to have an NFT security vulnerability, with a white hat hacker moving 3,832 NFTs from hundreds of wallets.

KelpDAO Sues LayerZero and Its CEO Over the $292 Million rsETH Theft

Evercrest Technologies, an entity associated with KelpDAO, has filed a civil lawsuit in British Columbia, Canada against LayerZero Labs and its co-founder and CEO Bryan Pellegrino, formally initiating legal proceedings over the rsETH cross-chain bridge attack in April that caused approximately $292 million in losses.