GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Payy confirms Ethereum bridge contract was hacked, with losses of approximately $1.8 million.

Privacy stablecoin payment network Payy Network has confirmed that its cross-chain contract on Ethereum was hacked, resulting in the theft of its entire balance. The investigation is ongoing, and all Payy Network transactions have been suspended, including deposits, withdrawals, transfers, and card transactions. Payy has notified law enforcement authorities and is collaborating with multiple incident response organizations. Previously reported, according to monitoring by Specter Investigation, Payy Network was suspected to have been hacked, with approximately 1.8 million USDC transferred out.

Blockaid: Meter is under ongoing attacks as the attacker has minted $2.3 million in wrapped MTRG and dumped it.

According to Blockaid, Meter is facing ongoing attacks on BNB Chain. Attackers are exploiting Meter Passport to mint a large amount of wrapped MTRG and sell portions on PancakeSwap. Approximately $2.3 million in unbacked wrapped MTRG has been minted through around two issuance transactions so far, and the attack remains ongoing.

Blockaid: Meter Under Sustained Attack on BNB Chain, Attacker Minted Approximately $2.3 Million in Wrapped MTRG

According to Blockaid monitoring, Meter is currently under a sustained attack on BNB Chain. The attacker exploited Meter Passport to mint a large amount of wrapped MTRG and sold some of the tokens on PancakeSwap. So far, approximately $2.3 million in unbacked wrapped MTRG has been minted through about 2 minting transactions, and the attack is still ongoing.

Specter: A MetaMask Swap Router Contract Address Has Been Blacklisted by Tether Since 2021

blockchain security researcher Specter has stated that while investigating the Payy Network attack incident, he discovered that an address associated with a MetaMask Swap router contract was blacklisted by Tether in 2021 and has remained blacklisted ever since. Specter said he had not previously noticed this situation.

MemTensor AI Memory Tool Supply Chain Under Attack, Developer Credentials Face Leakage Risk

According to monitoring by blockchain security firm SlowMist (@SlowMist_Team), MemoryOS (PyPI), an AI memory toolkit under MemTensor, and its OpenClaw plugin (npm) were compromised in a supply chain attack. The affected versions ship with embedded cross-platform Go binaries that automatically execute malicious payloads when the package is loaded or imported. Affected versions include MemoryOS==2.0.34 on PyPI, along with plugin versions 0.1.21, 0.1.23, and 0.1.25 on npm. Through this compromise, attackers can exfiltrate sensitive data such as npm/PyPI tokens, GitHub/GitLab credentials, AWS keys, SSH keys, API tokens, and environment variables. Exfiltrated data is sent back to the attacker-controlled infrastructure at skyleen[.]fr, and the compromised npm plugin may also leak user prompt inputs. SlowMist advises users to immediately downgrade the affected packages to their secure versions (downgrade npm to 0.1.20 and PyPI to 2.0.33), terminate any sckit-related processes, block communication with the associated infrastructure, review network activity, and rotate all credentials across affected environments.

Duelbits Hot Wallet Suspected Private Key Leak, Approximately $4.2 Million in Assets Stolen and Transferred

According to Scam Sniffer (@realScamSniffer), Duelbits' hot wallets on Ethereum, BSC, and Tron are suspected of having leaked private keys, with approximately $4.2 million in assets flowing to newly created addresses. The transferred assets include 836 ETH, 1.62 million USDT, 97,000 USDC, 209 BNB, and 192,000 TRX, with most of them already converted to ETH. The hacker's EVM address is 0xa77e24fe29d16e051e487ef4ea7b056cb05aef76.

布鲁克林男子因加密货币诈骗近 1600 万美元被判最高 12 年监禁

据布鲁克林地区检察官 Eric Gonzalez 宣布,布鲁克林男子 Ronald Spektor(23 岁)因实施大规模 Coinbase 网络钓鱼诈骗,于 2026年 9月 23 日被布鲁克林最高法院判处 4至 12 年有期徒刑。 Spektor 冒充 Coinbase 客服代表,以"账户遭黑客攻击"为由,诱骗全美约 100 名用户将加密资产转入其控制的钱包,累计盗窃金额约 1594.4 万美元。被盗资产随后经多个加密交易所反复兑换洗钱,最终流向赌博平台、礼品卡及数字资产购买渠道。 Spektor 在 Telegram 频道"Blockchain enemies"中以 @lolimfeelingevil 为昵称公开炫耀犯罪所得,并招募他人协助实施社会工程攻击。调查人员通过区块链分析、数字取证及多项搜查令,将其家庭 IP 地址与多个被盗钱包关联,最终锁定其身份。 Spektor 已就全部 31 项指控认罪,包括一级洗钱罪、一级重大盗窃罪等,并被命令没收逾 50 万美元资产,同时赔偿受害者近 1600 万美元。

Approximately 1.8 million USDC was transferred away, privacy stablecoin payment network Payy Network suspected of being attacked

according to monitoring, the attacker initially obtained seed funding through the privacy protocol Railgun, then swapped the stolen USDC for ETH and distributed the funds across 3 addresses.

Cosmos Hub Resumes Block Production, Neutron Attacker Wallet Transfers 1.23 Million ATOM

According to The Defiant, Cosmos Hub resumed operations after ceasing block production for 24 hours and 48 minutes. The Neutron attacker purchased voting power for 20,199 USDC and completed staking just 12 minutes before an expedited proposal expired; the relevant wallet subsequently transferred 1.23 million ATOM.

Nano Labs founder's X account compromised and used to post false project information

Nano Labs, a US-listed BNB treasury company, issued a risk warning stating that its founder Jack Kong’s personal X account has been compromised. Recent posts on the account regarding tokens and AI trading models were not authorized by him or the company. The company emphasized that it has not issued or endorsed any related token projects, and advised users not to click suspicious links, transfer assets to related contracts, or trust direct messages, urging them to remain vigilant against scams.

OpenAI Models Breached Australian Government Websites, Reported Only Three Months Later

According to a Bloomberg report, Australian Prime Minister Anthony Albanese stated that an OpenAI model gained unauthorized access to files on an Australian government medical statistics reporting website earlier this year, becoming one of the earliest known cyberattacks on a government database carried out by artificial intelligence. OpenAI notified the Australian government only three months after the incident occurred. Albanese said he has spoken with OpenAI CEO Sam Altman and expressed "grave concern" regarding the incident and the delayed notification.

Liquid Attack Leaves L-BTC Redemptions Paused, Attacker Holds Over $51 Million in Bitcoin

Odaily News: Canadian Bitcoin exchange and wallet company Bull Bitcoin stated that due to the Liquid Network attack on September 6, users are temporarily unable to redeem L-BTC back to Bitcoin through the platform, and redemption operations are still pending resumption.Bull Bitcoin expects the related redemption service to potentially resume within 30 days, but stated that this expectation is not guaranteed. Due to its reliance on the L-BTC redemption mechanism to balance inventory, the platform has temporarily closed inbound Lightning Network payments.In this attack, the attacker transferred out nearly 4,000 Bitcoin from the protocol, later returning approximately 3,400; currently still holding 598.50 Bitcoin, valued at over $51 million. Liquid Network stated on September 17 that block production, network transactions, and L-BTC transfers have returned to normal. (Bitcoin.com News)

EU's Three Major Financial Regulators Warn Quantum Computing Could Threaten Blockchain Cryptography Security

Odaily News: The European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA) stated in a joint risk update that advances in quantum computing could weaken the cryptographic systems that secure blockchain transactions, communications, and database security.In March, Google Quantum AI researchers estimated that the number of physical qubits required to break the cryptographic techniques used by many cryptocurrencies may be about 20 times fewer than previously estimated. A computer capable of carrying out such an attack does not yet exist.In February, Bitcoin developer Jameson Lopp and others proposed phasing out current signature schemes and restricting how unmigrated funds can be used five years after the proposal's activation. The proposal has not yet been adopted. The Ethereum Foundation plans to make Ethereum's execution, consensus, and data layers quantum-resistant by December 2029. (Cointelegraph)

North Korean hacker group WaterPlum poses as recruiters to steal over 7,000 crypto wallets worth $10.71 million

Odaily News: North Korean hacker group WaterPlum obtained funds or credentials from over 7,000 crypto wallets through fake recruitment processes and transferred approximately $10.71 million to North Korea. Between December 2025 and July 2026, the group infected at least 30,000 devices across more than 100 countries.WaterPlum impersonates AI, crypto, or NFT companies and approaches developers through social media, job platforms, and freelance platforms, luring them into downloading malware-laden files under the guise of technical interviews or coding assignments. Targets include web designers, engineers, and professionals in the crypto, blockchain, and Web3 sectors.Japanese law enforcement dismantled a "laptop farm" within the country for the first time, discovering that hundreds of millions of yen in crypto assets had already been transferred overseas. Investigations suggest that WaterPlum and some North Korean remote IT workers both belong to the 313th General Bureau of North Korea's Ministry of Munitions Industry and share IP addresses used to access the laptop farm and job-seeking services. (Decrypt)

Binance will support Zilliqa (ZIL) network migration

According to a Binance announcement, due to a security incident involving Zilliqa, the project team has announced the migration of ZIL from the Zilliqa mainnet to the ZILEVM network. Binance will discontinue support for the Zilliqa mainnet and will support ZIL deposits and withdrawals via the ZILEVM network. ZIL will be migrated from the Zilliqa mainnet to the ZILEVM network at a 1:1 ratio. Binance paused ZIL deposits and withdrawals on the Zilliqa mainnet at 9:00 on August 5, and will reopen deposits and withdrawals on the ZILEVM network upon completion of the migration without further notice. During the migration period, spot trading, leverage trading, contract trading, and Binance wealth management services remain unaffected.

Coldcard Vulnerability-Linked Funds Peak at $130 Million, White Hat Moves 52.37 Bitcoin to Crypto Recovery Trust

Odaily News: On September 21, a white hat actor transferred 40.71 BTC linked to the Coldcard vulnerability in a single transaction valued at approximately $3.31 million. The transaction consolidated funds from 11 addresses and included an OP_RETURN message pointing to the Crypto Recovery Trust.Alex Thorn, head of Galaxy Research, disclosed that the broader consolidation involved a total of 52.37 BTC across multiple clusters of attacker addresses, accounting for approximately 2.8% of the funds tied to the vulnerability. A firmware flaw in Coldcard devices dating back to March 2021 resulted in insufficient mnemonic seed randomness, with the total funds involved peaking at approximately $130 million. (Decrypt)

Astroport:Neutron 上发生的攻击事件可能已经导致 Astroport 合约的管理员权限被盗

Cosmos 生态 DEX Astroport 发文表示,Neutron 上发生的攻击事件可能已经导致 Astroport 合约的管理员权限被盗,Neutron 已暂停链运行进行调查。Astroport 建议用户从所有 Astroport 资金池中撤回流动性。

Kazakhstan's Regulated Crypto Market Surpasses $10 Billion, Web3 Ecosystem Ranks Among Global Top 10

As reported by Astana Times, Kazakhstan's regulated cryptocurrency market recorded a trading volume of $10.58 billion in 2025, marking a significant surge from $320 million in 2023, while the number of users increased from 53,000 to 215,000. At the same time, Kazakhstan ranked within the global top 10 for submission numbers to the International Solana Hackathon, with over 8,000 individuals completing training through the Solana ecosystem and more than 2,000 earning certificates. Additionally, 57 Web3 startups in the country have already received a combined total of approximately $262,000 in funding, and plan to complete the tokenization of real estate and logistics projects valued at up to $60 million by the end of 2026, exploring the feasibility of digital assets as a new channel for economic financing.

North Korea-linked hackers TraderTraitor expand attack targets beyond the crypto industry, using malicious Terraform projects to launch phishing attacks

the North Korea-linked threat group TraderTraitor, also known as UNC4899 and Jade Sleet, recently breached an IT services company based in India that is unrelated to the crypto industry. The attackers posted fake job listings on GitHub, using technical interview assignments as bait to carry out phishing attacks targeting DevOps and crypto engineers.After victims download the project, a malicious .terraform.lock.hcl file points to a Terraform Provider domain controlled by the attackers. Upon running terraform init, the malicious Provider module is downloaded and executed, ultimately deploying the Rust/ARM64 backdoors FLATROOF and ROOFDECK on macOS devices. The associated malware can steal credentials and sensitive data, execute shell commands, collect and exfiltrate files, and gain access to cloud services and code repositories.

SlowMist Warns Darksword Exploit Reportedly Now Capable of Attacking iOS 26.5 and Stealing Wallet Private Keys

Odaily reports: SlowMist Chief Information Security Officer 23pds has stated that attackers are exploiting the Darksword vulnerability to bypass iOS security mechanisms through Safari, take control of devices, and extract private keys and other data from self-custodial crypto wallets. The vulnerability was previously used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.Google Threat Intelligence Group previously disclosed that Darksword initially only affected iOS versions 18.4 through 18.7. According to 23pds, attackers have now adapted it to iOS 26.5, though this assessment has not yet been officially verified.Attacks typically begin with social engineering. After users click on malicious links sent via social media or messaging apps, their devices may be rooted and wallet data extracted. Users should promptly update their phone's operating system and avoid visiting website links sent by strangers. Separately, three investors who lost nearly $1.8 million in Bitcoin after downloading fake wallet apps from Apple's official App Store have filed a lawsuit against Apple. (Bitcoin.com News)