GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

DeBot Reports Security Incident Update: Confirms APT Attack, Fund Isolation Ongoing

DeBot team member Cat has released a security incident update, confirming that the previous wallet security incident was an APT (Advanced Persistent Threat) attack. No related fund losses have been identified so far. According to the announcement, analyses by multiple security teams and cloud service providers revealed traces of intrusion in the system, and the relevant private keys remain at security risk. Therefore, the platform will continue to implement automatic fund isolation. Currently, DeBot is operating in a fully isolated environment. Users can still trade and withdraw normally, but other operations involving private keys have been suspended and will be gradually restored after the security audit is completed.A new security solution is being upgraded and is being audited by the SlowMist team and cloud service providers. DeBot stated that this incident exposed security issues in the project, and the team will further upgrade security measures.

North Korean hacking group “HexagonalRodent” leverages AI to industrialize attacks against Web3 developers, stealing over $12 million in crypto assets in three months

According to a research report released by cybersecurity firm Expel, the company is tracking an advanced persistent threat (APT) group dubbed “HexagonalRodent,” which is highly assessed to be a North Korean (DPRK) state-sponsored actor. This group primarily targets Web3 developers and specializes in stealing high-value digital assets—including cryptocurrencies and NFTs. In the first quarter of 2026 alone, the group compromised 2,726 developer devices and stole access credentials for 26,584 cryptocurrency wallets, with the total value of stolen assets reaching as high as $12 million. The group primarily carries out its attacks via fake job postings—publishing lucrative positions on LinkedIn and Web3 recruitment platforms to lure job seekers into completing “skills assessments” embedded with malicious code. These assessments exploit VSCode’s tasks.json functionality to automatically execute malware when victims open the project folder. The malware used includes BeaverTail, OtterCookie, and InvisibleFerret, all of which possess capabilities such as password theft, remote control, and reverse shell execution. Notably, the group extensively leverages generative AI tools—including ChatGPT and Cursor—to develop malware, build counterfeit corporate websites, and generate AI-forged executive teams. It even registered a shell company in Mexico to enhance the credibility of its operations. Additionally, the group recently carried out its first-ever supply-chain attack, successfully infiltrating a VSCode extension.