News linked to both this project and an event.
Odaily News: Iranian President Pezeshkian stated that Iran "no longer trusts negotiations with Washington," because after every round of talks, the US repeatedly launched attacks and imposed sanctions. Qatar and Pakistan are currently mediating between Iran and the US, relaying Tehran's messages to Washington.Pezeshkian also said that the negotiations were based on a previously signed memorandum of understanding between the two countries, and added that the Americans must clarify their position on this memorandum. In addition, he blamed the US for the closure of the Strait of Hormuz, saying that "it was the US that blocked our path." When Iran's path is blocked, closing the Strait of Hormuz is a natural response. The Strait of Hormuz crisis can be resolved through negotiations rather than the use of force." If negotiations lead to a resolution of the dispute, the waterway "will remain open for trade." (Sina Finance)
the North Korea-linked threat group TraderTraitor, also known as UNC4899 and Jade Sleet, recently breached an IT services company based in India that is unrelated to the crypto industry. The attackers posted fake job listings on GitHub, using technical interview assignments as bait to carry out phishing attacks targeting DevOps and crypto engineers.After victims download the project, a malicious .terraform.lock.hcl file points to a Terraform Provider domain controlled by the attackers. Upon running terraform init, the malicious Provider module is downloaded and executed, ultimately deploying the Rust/ARM64 backdoors FLATROOF and ROOFDECK on macOS devices. The associated malware can steal credentials and sensitive data, execute shell commands, collect and exfiltrate files, and gain access to cloud services and code repositories.
According to CoinDesk, London-based crypto institutional technology services provider Haruko was targeted by a cyberattack earlier this week, affecting a total of 15 clients. Attackers exploited vulnerabilities in Haruko’s infrastructure to extract user access tokens, gaining access to clients’ read-only exchange API information and trading data. A small amount of client funds were stolen, and smaller hedge funds with weaker security controls face a higher risk of loss. Haruko co-founder and CTO Adam Carlile confirmed that the attack specifically targeted Haruko itself. The vulnerability has been patched, and the company plans to release a complete technical post-incident report. Haruko serves over 80 institutional clients globally and connects to more than 100 centralized exchanges and 30 blockchains.
Odaily reports: Bitcoin News posted on X platform that Bitcoin Core developer Niklas Gögge warned that recent AI-driven vulnerability scanning is changing the Bitcoin security landscape. Large language models have significantly reduced the cost of vulnerability discovery, and attackers may be able to find catastrophic vulnerabilities with only a few hundred dollars in computing costs. For Bitcoin Core, Project Loupe, Bitcoin Red Team, and individual contributors have generated over 1,000 reports, but so far no high-risk or critical vulnerabilities have been found. Gögge stated that relying on stronger models to find vulnerabilities before attackers do is not a sustainable security strategy. Developers should build testing infrastructure through automated testing, fuzzing, and property-based testing that can prevent entire classes of vulnerabilities in advance. Key components of Bitcoin Core have cumulatively completed over 100 years of CPU fuzzing and decades of Bitcoin node network simulation.
Odaily reports: Blockchain analytics firm Chainalysis has released a report stating that hackers are increasingly leveraging open-source artificial intelligence (AI) to implant malware control instructions into on-chain transactions and smart contracts, with such cases surging approximately 440% in less than a year. Data shows that these incidents have risen from roughly 2 per day to approximately 11 per day. Attackers write malicious instructions on-chain to manipulate infected devices into stealing passwords and funds, and redirect assets to designated wallets; since on-chain records cannot be deleted, defense and interception are becoming increasingly difficult.The report notes that state-sponsored hackers from countries such as North Korea and Iran have become the primary drivers of such activity. Open-source models support local independent operation and modification, allowing them to directly bypass cloud-based defenses. However, the public and transparent nature of blockchain also leaves critical evidence for tracing attack infrastructure. (Bloomberg)
According to CoinDesk, Bitcoin Core 32.0 entered its final testing phase on September 14, with its official release scheduled for October 10. This update adds a transaction fee estimator based on real-time mempool status, enabling fee estimates to be lowered more quickly once network congestion subsides. It also enables multi-threaded parallel reading of transaction data to speed up node blockchain synchronization, defaulting to 8 threads. Security-wise, it resolves a wallet naming vulnerability on non-Windows systems since version 24.0 that allowed attackers to execute arbitrary commands on the node host via a specially crafted wallet name. Additionally, it patches an out-of-memory vulnerability in the newly added built-in web server; testing indicates that 16 unauthenticated connections can spike node memory usage from 46MB to roughly 3GB in approximately one minute. This update does not include any changes to Bitcoin's consensus rules.
According to EU-Startups, Lyon-based AI-driven Vulnerability Operations Center (VOC) Hackuity has announced the completion of a €16 million funding round (approximately $19 million), led by Forgepoint Capital International alongside Bright Pixel, Bpifrance, and Seventure Partners, bringing its cumulative funding to €32 million. The funds will be allocated toward product innovation, AI capability enhancements, and expansion into European and Asian markets. Hackuity’s platform integrates data from over 130 security tools, automating vulnerability prioritization and remediation through a proprietary risk scoring engine. It currently serves more than 6,000 users, protects over 2 million assets, and manages 1 billion security findings, with enterprise clients including ENGIE, BPCE, and Orange Cyberdefense.
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
Odaily News: Binance stated that in the first half of 2026, the Binance Wallet Security Center helped users avoid approximately $540 million in potential losses, filtering about 206 million spam transfers, identifying 4.93 million high-risk transactions, and approximately 996,000 malicious authorizations during the period. Binance noted that AI is being used by attackers to mass-generate malicious code, phishing websites, and fake identities, shifting attacks from broad-based approaches to more targeted fraud.
Odaily News: The decentralized lending protocol Secured Finance's lending market was attacked on September 5, resulting in a loss of approximately $104,000. The root cause was that collateral was priced based on the average execution price of the order book for the current block, allowing attackers to influence the price through self-trading, causing fraudulent lending positions to be counted as valid collateral. The attacker initially deployed the contract but did not execute immediately, then used flash loans and self-trading to inflate the price and withdraw USDC. The original attacking wallet was rolled back due to insufficient gas fees; approximately 48 seconds later, the general-purpose sandwich bot coffeebabe took about 0.9 WBTC, worth approximately $72,000, and transferred about 28.8 ETH of it to the ultra sound money builder, keeping only about $29 for itself. Subsequently, another bot took part of the USDC.
: The G7 cybersecurity working group stated in its latest report that quantum computing poses both a security threat and an economic threat to public and private institutions, and related organizations should immediately begin migrating to post-quantum cryptography (PQC).The working group noted that the migration process could take several years, as attackers can already collect and store encrypted data today and decrypt it once sufficiently powerful quantum computers emerge. Quantum computing could also break digital signatures, leading to identity theft and exposing companies and their supply chains.The report did not mention cryptocurrencies, but similar public-key cryptography is used for blockchain wallets and transaction authorization. Current quantum computers are not yet capable of breaking Bitcoin's cryptography, but developers are considering post-quantum solutions such as BIP-360.Ethereum researchers plan to replace multiple cryptographic components used by accounts, validators, and applications. The Solana Foundation has tested post-quantum signatures on its testnet and launched an optional hash-based vault. The G7 working group also urged governments to support related research, public-private cooperation, and national PQC strategies. (Decrypt)
Odaily News – According to Bitcoin News monitoring, hackers linked to the third wave of Coldcard wallet thefts have begun moving stolen funds for the first time, converting Bitcoin into ETH via THORChain. Galaxy Research's Alex Thorn stated that approximately 10% of the stolen BTC has been moved, while the remaining 90% remains untouched. The attacker reportedly encountered difficulties during the fund conversion, with multiple THORChain transactions being returned and retried. Researchers have traced the related swap activity to a new Ethereum address, which Alex Thorn noted has been shared with relevant authorities and cryptocurrency companies. Galaxy Research indicated that the broader Coldcard exploit has resulted in losses of at least 1,789 BTC across 8,865 addresses, valued at approximately $115 million based on prices at the time of the theft.
Odaily News, September 3 — WEEX Exchange announced that the WEEX Hackathon Season 2, themed "AI Wars II: The Algorithm Era," is now officially live. Global AI developers, quantitative traders, Web3 builders, teams, and individuals are invited to join Team AI or Team Human to compete in five rounds of live market trading battles, vying for rankings and rewards based on PnL% performance. The total prize pool stands at 600,000 USDT, with multi-tiered incentives designed to accommodate different participation methods.The early registration phase runs from September 3 to 6, during which the first 2,000 registrants can share in the 100,000 USDT Early Bird prize pool. Additionally, users who register early can complete event tasks ahead of time to accumulate activity points for the upcoming competition.
: Blockchain technology company Starkware stated that on August 26, a transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) scheme was mined on the Bitcoin mainnet, without requiring a soft fork, hard fork, or modification of consensus rules.The transaction consumed 10,000 sats and was processed through MARA Foundation's Slipstream service, as the non-standard format typically cannot propagate through Bitcoin's public mempool. The test consumed several hours of GPU computation, costing approximately $150 to $200.QSB employs hash-based quantum-resistant spending conditions and reduces quantum attack risks through signature trial mining, but still requires users to proactively migrate funds and cannot protect assets whose public keys have already been exposed. Starkware CEO Eli Ben-Sasson still supports introducing a protocol-level solution via a soft fork. (Bitcoin.com News)
blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)
According to Cointelegraph, the latest statistics from Galaxy Research show that the Coldcard hack involved 8,865 addresses, resulting in the theft of 1,789.28 Bitcoin valued at approximately $114.7 million based on the price at the time of the incident. Of this amount, 1,561 Bitcoin, representing roughly 87.3% of the stolen funds, have not yet been transferred and remain in aggregation or holding addresses controlled by the attackers.
According to BeInCrypto, Kylie Jenner’s X account appears to have been compromised, with an attacker posting the ticker and Pump.fun page link for the Solana-based memecoin kylie before the post was subsequently deleted. The token’s market cap briefly spiked to approximately $1.19 million before retreating by around 68%; at press time, it stood at roughly $378,500.
Odaily News According to Galaxy's head of research, the Coldcard vulnerability incident involved 8,865 addresses, resulting in total losses of 1,789.28 BTC, valued at $114.7 million at the time of theft and currently valued at $138.8 million.By address, the median loss per address was 0.00152 BTC, with an average of 0.20184 BTC; the median dormancy period for affected addresses was 3.2 years, with an average of 3.6 years.Among 221 victim reports, the median loss was 1.04272 BTC, with an average of 3.57792 BTC; the median dormancy period was 3.25 years, with an average of 2.99 years. The losses reported by victims amount to 790.72 BTC, accounting for 44.2% of total losses. If medium-confidence losses are included and related losses remain unconfirmed, total losses would reach 1,824 BTC, valued at $140 million based on prices at the time of the incident.
Odaily News: Ethereum co-founder Vitalik Buterin has published his latest article "Obfuscation (Part 3): Local Mixing," providing an in-depth introduction to an emerging cryptographic obfuscation approach — "Local Mixing" — and describing it as a potential new fundamental cryptographic tool following elliptic curves, RSA, and lattice-based cryptography.Vitalik noted that current mainstream obfuscation techniques primarily rely on complex mathematical assumptions but often incur extremely high computational costs. Local mixing, by contrast, takes a completely different approach. Rather than depending on elliptic curves, large integer factorization, or lattice cryptography, it draws on design principles from symmetric cryptography and hash functions, continuously shuffling, restructuring, and hiding circuit architecture to eliminate information leakage while preserving functionality.He explained that the local mixing technique mainly involves steps such as reversibility, hardening, mixing, splitting, crossing walk, and "gadgetization." By introducing random structures into circuits, rearranging logic gates, and employing nonlinear hiding mechanisms, it makes it difficult for attackers to recover the original computational logic.Vitalik pointed out that the technique remains in its early stages, with security not yet subject to long-term validation, and it still faces challenges such as random attacks and linear analysis. Nevertheless, he believes local mixing represents an entirely new path of cryptographic exploration aimed at building more efficient indistinguishability obfuscation (iO) schemes.He stated that if local mixing achieves a breakthrough, it could lead to new quantum-resistant public-key encryption schemes and advance the development of general-purpose obfuscation techniques. While the field still requires years of cryptanalysis and optimization validation, AI-assisted research could significantly accelerate this maturation process.Vitalik described obfuscation as the "final frontier" of cryptography, as theoretically all other cryptographic primitives can be constructed from obfuscation and one-way functions. Local mixing not only has the potential to reduce the cost of traditional obfuscation schemes but could also become an important direction for future cryptographic infrastructure.
Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following the emergency fix on July 31, addressing security risks brought by the previous mnemonic generation attack. Each newly generated mnemonic must now include at least one source of user entropy, including at least 65 irregular keystrokes, 50 physical dice throws, or 128 physical coin flips, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2. The new firmware also adds instant staged PSBT verification before signing, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks. The official reminder notes that updating the firmware cannot fix existing mnemonics generated by previously affected firmware. If users' mnemonics fall within the scope of this security advisory, they should first update the device, then generate and verify a completely new mnemonic, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signature of the downloaded firmware.