GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Bank of England Governor: Frontier AI Models Threaten Global Financial Stability

According to CNBC, Andrew Bailey, Governor of the Bank of England and Chairman of the Financial Stability Board (FSB), wrote to G20 finance ministers and central bank governors on August 31 to warn that frontier AI models are exhibiting increasingly sophisticated autonomy and threat capabilities, which could fundamentally alter the speed, scale, and economics of cyberattacks, potentially triggering disorderly adjustments across global financial markets. Bailey noted that highly concentrated third-party service providers will become critical nodes of systemic risk, emphasizing that most countries currently lack regulatory frameworks for the development and deployment of frontier AI. He also flagged vulnerabilities in sovereign debt markets, the growing trend of leverage in equity markets, and the overvaluation of AI-related assets, urging governments to accelerate the refinement of relevant safety mechanisms.

Binance Will Discontinue Support for BounceBit (BB) Mainnet

Binance announced that due to a hack on BounceBit and the project team's decision to permanently shut down the chain, Binance will stop supporting the BounceBit (BB) mainnet. Binance has suspended deposits and withdrawals of BB on the BounceBit mainnet as of 10:00 (UTC+8) on August 20, 2026, and will reopen deposits and withdrawals via the BNB Smart Chain (BEP20) network starting at 15:00 on September 1, 2026. BB will be migrated from the original mainnet to the BNB Smart Chain at a 1:1 ratio. During the migration, spot, margin, futures, and Earn services will remain unaffected.

JaredfromSubway.eth sandwich attack bot has extracted $295 million in total, with $7.5 million stolen in June

Odaily News: The sandwich attack bot operated by JaredfromSubway.eth has extracted a cumulative total of 117,007 ETH since March 2023, worth approximately $295 million at current prices. In June 2026, an anonymous attacker deployed 66 counterfeit token contracts, exploiting the bot's automated trading logic to steal at least $7.5 million in ETH and stablecoins, and funneled the funds into Tornado Cash. The stolen assets have not yet been recovered.Sandwich attacks are a form of Maximal Extractable Value (MEV): the bot monitors large transactions in Ethereum's public mempool, buys ahead of the target transaction, and sells after the transaction pushes the price up, capturing profits from the spread. The bot's primary contract had received a cumulative total of 117,007 ETH as of August 28.MEV-Boost block construction is centralized among a small group of participants, with relay.ultrasound.money, Titan Relay, and bloXroute regulated relays collectively forwarding approximately 85% to 88% of related blocks within a 24-hour window; Titan's builder independently assembled 50.3% of the blocks. Monthly sandwich attack extraction amounts have declined from approximately $10 million in late 2024 to roughly $2.5 million in October 2025. (Bitcoin.com News)

Starkware completes quantum-resistant transaction on Bitcoin mainnet without soft fork

: Blockchain technology company Starkware stated that on August 26, a transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) scheme was mined on the Bitcoin mainnet, without requiring a soft fork, hard fork, or modification of consensus rules.The transaction consumed 10,000 sats and was processed through MARA Foundation's Slipstream service, as the non-standard format typically cannot propagate through Bitcoin's public mempool. The test consumed several hours of GPU computation, costing approximately $150 to $200.QSB employs hash-based quantum-resistant spending conditions and reduces quantum attack risks through signature trial mining, but still requires users to proactively migrate funds and cannot protect assets whose public keys have already been exposed. Starkware CEO Eli Ben-Sasson still supports introducing a protocol-level solution via a soft fork. (Bitcoin.com News)

Bitcoin ETFs See 8 Consecutive Days of Net Inflows Totaling $2.8 Billion, Strongest Inflow Streak in 10 Months

Odaily News: Bitcoin News posted on X platform that U.S. spot Bitcoin ETFs have recorded net inflows for 8 consecutive days, totaling $2.8 billion. August has become the strongest month for capital inflows since 2026.As Bitcoin and gold rise in tandem, investors are increasingly seeking to hedge against risks including a weakening U.S. dollar, persistent inflation, and the widening U.S. fiscal deficit. Gold funds have also seen record demand.This shift is beginning to reflect in ETF trading. IBIT and GLD have rejoined the list of the top 10 most-traded ETFs, after semiconductor funds dominated for most of the summer.BlackRock noted that another significant source of demand comes from existing Bitcoin holders moving their tokens into ETFs. The company has so far processed approximately $5 billion in deferred-tax Bitcoin transfers into ETFs, and the minimum conversion amount has recently been lowered from $25 million to $1 million."As we continue to expand access, this scale will continue to grow," said Robbie Mitchnick, Head of Digital Assets at BlackRock.Mitchnick pointed out that incidents such as kidnappings, ransomware attacks, and custody failures are driving some Bitcoin holders to shift toward ETF custody.Bitcoin and gold are once again aligning with the core of the same macroeconomic logic, as the currency debasement trade makes a comeback.

MANTRA Discloses Security Incident Post-Mortem: ~721M MANTRA Tokens Transferred, Chain Offline for 30 Hours

MANTRA has released a complete review of the August 20 security incident. The incident stemmed from an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency, cosmos/evm. Without requiring privileged access, the attacker transferred a combined total of 720,923,967.99 MANTRA tokens from a burn address and a legacy genesis multisig address, amounting to approximately $3.6 million at pre-incident prices.

The Sandbox plans 1:1 compensation, approximately $700K in SAND stolen in bridge vulnerability exploit

blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)

Ledger Ethereum App Version 1.22.1 Contains Transaction Replacement Vulnerability — Users May Review One Transaction While Signing Another

Odaily News: OneKey Anzen has reproduced the Ledger vulnerability and discovered that Ledger Ethereum app version 1.22.1 contains a transaction replacement vulnerability. When an affected user is attacked, the hardware screen still displays transaction A under review, but the device may sign transaction B, which the user never viewed. OneKey Anzen stated that the issue stems from a race condition between the transaction display logic and the underlying buffer, with the attack requiring the host side to already be compromised by a malicious DApp or intermediary software. Ledger's CTO previously responded that a fix had been rolled out approximately two weeks ago, and users simply needed to update the app. Public information shows that the official tag for version 1.22.2 on Ledger's GitHub appeared on August 24. Ledger's official website states that the issue has been fixed through app-level checksums and SDK-layer patches, with Ledger Secure SDK v26.6.1 released on August 21, and the related apps have been rebuilt and republished. Users need to update the app via Ledger Live — updating only the device firmware will not complete the fix. Ledger stated that there is currently no evidence that this vulnerability has been actively exploited.

Sparrow Wallet Releases Version 2.5.4, AI-Assisted Code Review Fixes Multiple Security Vulnerabilities

According to Decrypt, privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on August 28. Developer Craig Raw stated that the update was driven by an AI-assisted code review, with the majority of fixes originating from it. This review was prompted by the recent seed generation code vulnerability exploit affecting Coldcard, as well as the release of unrestricted AI models in China, which has significantly enhanced vulnerability scanning capabilities across large codebases. Key updates include: validating the authenticity of transactions returned by Electrum servers, enforcing stricter BitBox02 hardware wallet security requirements (firmware v9.4.0 or higher required), patching local DNS leaks, and masking sensitive credentials in debug logs. Raw noted that there are no indications of any exploits being leveraged, user funds remain secure, and he still advises all users to update at their earliest convenience.

GoPlus: Realio Platform Signing Key Compromised, Approximately 127.9 Million RIO Tokens Transferred

GoPlus Security released a security alert stating that on August 25, realio[.]fund, a project under Realio Network, was attacked. The attacker took control of the platform's signing system and moved treasury and custody wallet assets across Ethereum, BNB Chain, Algorand, Stellar, and the Realio native chain. A total of approximately 127.9 million RIO tokens worth around $6.2 million were affected, with the attacker having cashed out approximately $317,000 so far.

1:1 compensation for legitimate holders prior to the vulnerability incident; The Sandbox will reimburse cross-chain SAND using treasury funds

Odaily News, The Sandbox has released a post-mortem report on the August 22 vulnerability incident. The report shows that attackers exploited vulnerabilities in contracts related to cross-chain configurations on Base and BNB Smart Chain (BSC), stealing 14,742,341.84 SAND from the Ethereum treasury, accounting for approximately 0.5% of the maximum supply, with an estimated economic impact of approximately $1.4968 million, of which about $987,000 was actually retained by the attackers. The Ethereum mainnet and Polygon network were not affected. Until further notice, please do not purchase or send SAND on Base or BNB Smart Chain. Contracts deployed on Base and BNB Smart Chain have been permanently deactivated and will not be reopened. The Sandbox stated that the team has reported the attacker's wallet address to blockchain analysis firms TRM Labs and Chainalysis, and has communicated directly with relevant exchanges. The Sandbox also announced a compensation plan, which will compensate wallets that legitimately held cross-chain SAND on Base or BSC prior to the incident at a 1:1 ratio in Ethereum SAND. Compensation funds will come from The Sandbox treasury, with no new tokens issued. The claim process will open within the next two weeks and remain open for two weeks.

6 dormant bitcoin wallets inactive for over 10 years transferred 553.59 BTC, worth $40.15 million, within 10 days

Odaily News reported that Galaxy Research tracking found that 6 bitcoin wallets, dormant since 2011, 2012, and 2014, transferred a total of 553.59 BTC between August 16 and 26, valued at $40.15 million at the time of transfer. Two of the wallets carry the "Salomon Client Dusted" tag linked to a New York lawsuit involving Noah Doe.One of the transfers involved 40 BTC from a wallet dormant since May 28, 2012, with the funds moved on August 26 to German crypto custodian bank Boerse Stuttgart Digital. Calculated at a cost of approximately $5, the funds appreciated by roughly 1,535,911%.The remaining transfers included 212 BTC, 150 BTC, and 132.31 BTC, originating from wallets inactive since 2012, 2014, and 2011, respectively. The Noah Doe lawsuit seeks to declare 39,069 dormant bitcoin addresses in New York State as lost property. Additionally, several long-term holding addresses moved funds following the July Coldcard hardware wallet vulnerability incident. (Decrypt)

Coldcard incident boosts BitBox credit card sales by ~10x, while Trezor and OneKey see rising demand

Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)

Approximately 2,077.97 DCR were minted due to a vulnerability, and Decred has decided not to roll back

Odaily News, L1 blockchain Decred stated that between August 16 and 17, its mainnet inflation vulnerability was exploited, resulting in the generation of approximately 2,077.97 DCR. This vulnerability has existed in the consensus code since the mainnet launch in February 2016, stemming from improper handling of edge cases when the regular transaction tree interacts with the stake transaction tree, allowing for double-spending of inputs. The vulnerability was submitted via a bounty program on August 12, but was exploited before a fix could be implemented. Decred has decided not to roll back to minimize the impact on users. The approximately 2,000 DCR minted through this exploit do not affect the 21 million hard cap and are far lower than historical shortfalls in subsidies due to missed votes and other causes, which exceed 215,000 DCR. Currently, the team has developed an additional double-spend monitoring service and plans to improve the emergency upgrade signaling mechanism.

TAC was attacked due to a vulnerability in the Cosmos EVM precompile layer, with approximately 2.986 billion TAC tokens transferred.

TAC tweeted that on August 22, an attacker exploited a vulnerability in the Cosmos EVM precompile layer, transferring 2,985,651,403 TAC from a single account on the TAC network. The project team subsequently paused the network at block height 24,671,475 to halt the attack.

Besu fixes 5 security vulnerabilities, version 26.7.1 released on July 27

Odaily News: Ethereum client Besu has fixed 5 security vulnerabilities discovered by blockchain security firm CertiK in version 26.7.1 released on July 27, and published 4 detailed security advisories on August 14. Vulnerability details were disclosed after a delay to allow node operators to complete upgrade deployments.Jialiang Chang, Director of Security Engineering and Senior Audit Partner at CertiK, stated that the arrangement of releasing patches first and details later provided an 18-day buffer period, allowing node operators to identify affected deployments, test new versions, and coordinate with validators or consortium participants to complete upgrades.The vulnerabilities involve block broadcast handling, caching of future-height consensus proposals, WebSocket subscription limits, and JSON-RPC filter creation. If left unpatched, attackers could exhaust node memory or thread resources, impacting node availability and consensus processing.Using the Chain Scan methodology, CertiK conducted adversarial testing on peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi-node test network, and provided reproducible testing tools to the Besu team. CertiK is updating Chain Scan to expand round-the-clock multi-node testing on public chain networks. (Bitcoin.com News)

SlowMist Unveils Details of Allbridge Bridge Attack: Forged CCTP Messages + Flash Loans, Insufficient Mint Verification

Odaily News, SlowMist Security Team disclosed that the cross-chain bridge project Allbridge suffered an attack on August 19, 2026, with losses of approximately $190,000. Notably, this attack was not executed instantaneously—the attacker began laying the groundwork nearly a month in advance, bypassing the verification mechanism through forged cross-chain messages.According to SlowMist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as CCTP-style, claiming a transfer of 1 million USDC, despite no actual USDC burn operation occurring. Subsequently, Circle generated a valid attestation for this complete message following standard procedures.Approximately 24 days later, on August 19, the attacker waited for the Base Router to receive a genuine CCTP deposit, bringing its balance to approximately 191,000 USDC, then launched the attack just 6 seconds later. Using the previously forged message and attestation, the attacker called Allbridge's receiveCctpMessage function. Due to the project's lack of critical validation, the system mistook the fraudulent cross-chain message for a genuine deposit and recorded a 1 million USDC credit.Subsequently, the attacker borrowed approximately 809,000 USDC temporarily via an Aave flash loan to match the Router's balance with the forged amount, then utilized the internal credit record to call the transfer function, ultimately moving out approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800 in profit. The root cause of this vulnerability lies in Allbridge's failure to verify the identity of the cross-chain message sender and receiver, as well as its failure to confirm whether USDC was genuinely minted or whether the balance actually increased—instead directly trusting the amount and message hash data constructed by the attacker.SlowMist emphasized that on-chain message verification does not equate to actual asset arrival. Cross-chain protocols must not only verify message authenticity but also ensure the message source is trustworthy, confirm the receiver is Circle's official TokenMessengerV2, and only record assets after confirming actual minting and balance changes. This incident once again highlights the security risks in cross-chain bridges' message verification and asset settlement processes.

The Sandbox cross-chain bridge exploited to mint 14.9 billion unbacked SAND, Coinbase to delist SAND futures

Odaily News: Metaverse gaming platform The Sandbox has confirmed a vulnerability in its cross-chain bridge, allowing attackers to mint unbacked SAND on Base and BNB Smart Chain. Blockchain security firm PeckShield detected on August 21 that two addresses had collectively minted approximately 14.9 billion SAND. The Sandbox subsequently shut down bridging functionality on both networks.The Sandbox stated that the affected assets are bridged assets on Base and BNB Smart Chain, while SAND on Ethereum and Polygon, user wallet assets, and the Ethereum-locked assets backing the token remain unaffected. The proportion of genuinely collateralized assets involved in this incident is less than 0.01% of the total SAND supply.The Sandbox is developing a compensation plan for affected liquidity providers and advises users not to trade SAND on Base or BNB Smart Chain until bridging is restored. Coinbase plans to delist 10 perpetual futures contracts, including SAND, on August 26, with open positions to be automatically settled at that time. (Bitcoin.com News)

Grok has an "Encrypted Context Injection" vulnerability, putting user chat data at risk of leakage.

According to Cryptopolitan, cybersecurity firm Adversa AI has disclosed that xAI's AI assistant Grok contains a security vulnerability known as "Encrypted Context Injection." Attackers can embed encrypted commands within standard web pages. When a user requests Grok to summarize such a page, Grok automatically decrypts and executes the hidden command, forwarding the user's name, geographic location, subscription tier, and complete chat history to the attacker's server. The vulnerability was reported to xAI through the HackerOne platform on June 3, 2026. Researcher Rony Utevsky followed up on August 4 and August 10, respectively. However, as of August 19, the vulnerability remains unpatched on Grok.com, and xAI has not provided a timeline for a fix.

Researchers disclose Solana PoH clock attack vulnerability; transition risks prior to the Alpenglow upgrade remain unresolved.

According to CryptoSlate, researchers from USENIX Security publicly disclosed a clock attack vulnerability against Solana’s Proof of History (PoH) mechanism on August 12. The vulnerability had been privately reported to the Solana development team as early as December 2025. Research indicates that a malicious scheduler leader could manipulate the PoH logical clock through "re-anchoring," slowing the progression of logical time. This would yield a longer transaction selection window within physical time, allowing the attacker to isolate honest leaders' blocks via the TowerBFT fork-choice mechanism, with the required stake for the attack falling below 33%. The Alpenglow security contest hosted by Anza, which offered a 50,000 SOL prize pool, concluded on August 19. However, the vulnerability was excluded from the evaluation scope because the contest rules explicitly excluded "behaviors that can only be triggered when Alpenglow is inactive." The Solana development team confirmed awareness of the issue, stating that the probability of the worst-case scenario occurring under current conditions is low. They expect the Alpenglow upgrade to fundamentally eliminate the attack's prerequisites. The Alpenglow code is already integrated into the Agave 4.2 client but remains inactive on the mainnet, with full deployment expected alongside Agave 4.3. Until then, the transitional risks associated with this vulnerability have yet to receive public implementation-level analysis or official responses.