News linked to both this project and an event.
CZ posted a warning urging Ledger hardware wallet users to be more vigilant, especially those who recently purchased devices. He stated that based on currently available information, the incident appears to be related to a supply chain attack involving a certain vendor, and a small number of users may have purchased counterfeit or tampered Ledger devices.CZ said that Ledger is one of the most established and secure hardware wallets in the industry, having long withstood market tests, but similar incidents can still occur. He expressed hope and belief that BNB ecosystem participants and the entire crypto industry will assist in tracking and recovering the related funds.
Odaily News: Dragonfly Managing Partner Haseeb Qureshi stated that the "bunker mode" proposed by Ethereum researcher Justin Drake to address the risk of AI cracking cryptographic signatures amounts to "cryptographic doomerism," and argued that migrating tokens to new addresses is not a real solution.Qureshi said that "bunker mode" can only protect assets that users have not yet transferred out of new addresses. If tokens in other addresses are attacked and heavily sold off, those assets could still lose value. He suggested that blockchain networks adopt a "Cryptographic Recovery Mode," using hash-based backup signature schemes that allow users to bind recovery mechanisms in advance, so that validators can assist in recovering assets after cryptographic signatures are cracked.Previously, Ethereum researcher Justin Drake warned that with the rapid improvement of AI mathematical capabilities, the ECDSA signature algorithm protecting crypto wallets could face the risk of being cracked within "months rather than years," and advised users to gradually migrate funds to new wallets that have not exposed public keys. Glassnode data shows that approximately 6.26 million BTC are currently held in addresses with potential risk. (Cointelegraph)
Odaily News: U.S. Commodity Futures Trading Commission (CFTC) Chair Mike Selig stated that the CFTC's proposed crypto asset regulatory framework will establish a federal-level oversight system to protect exchange customers from fraud, market manipulation, and theft of customer funds, preventing a repeat of the FTX collapse. Mike Selig noted that the CFTC is working to introduce market-based regulatory mechanisms for crypto exchanges; he stated that critics who oppose these measures and support maintaining the status quo may objectively be benefiting fraudsters, manipulators, and those who misappropriate customer funds, and warned that the absence of such regulation could leave the door open for the next Sam Bankman-Fried figure.
According to CoinDesk, the privacy cryptocurrency Zcash (ZEC) development team plans to introduce a post-quantum signature opcode on the network in January to support hash-based signatures, thereby defending against potential quantum computing attacks. This proposal primarily targets the transparent (public) payment pool, where approximately 70% of ZEC is currently held. Although developers have set January as the target deadline, the specific timing for network activation has not yet been finalized.
Odaily reports: Second, a project built on Ark Protocol, disclosed that its server was exploited in an attack on Monday, resulting in the loss of 0.75 BTC of its own funds, worth approximately $62,300. The team stated that user funds were not affected and that the issue was fixed within hours.The attacker subsequently continued attempting to withdraw more funds from the project and launched a denial-of-service attack. On Tuesday, Second said the attack may have degraded the ability of Bark-based wallets to receive Lightning Network transfers.Second stated that the vulnerability was in the Ark server's boarding process, where an attacker could register and exit the relevant boards using only their own signature, while simultaneously spending the same batch of VTXOs in the node via the Lightning Network. The attacker also attempted to use bitcoin linked to the Blink Wallet security breach on September 19, but was unsuccessful. (Bitcoin.com News)
Odaily News: Lido is developing a decentralized lending market called Lido Lend, which is built on a modified fork of Morpho Blue, adopts an isolated lending market design, is proposed to be governed by Lido DAO, and is pending a governance vote for approval. Lido Lend is limited to blue-chip assets, encourages price-correlated trading pairs such as stETH/ETH, and provides a deposit screening mechanism to guard against bad collateral. Lido stated that Lido Lend is not a general-purpose pool-based lending solution but is aimed at professional borrowers and risk-averse lenders; currently, stETH staking scale exceeds $25 billion, with no major security incidents since launch.
Odaily News: Galaxy Research on-chain tracking shows that the US government transferred approximately 9,261 BTC, worth about $770 million, to Coinbase Prime over two days. Since the deposit address was first activated in December 2025, it has cumulatively received 11,567 BTC, of which 6,406 came from wallets already labeled as belonging to the US government, and 5,160 came from previously unlabeled wallets.Of the 9,261 BTC transferred this time, nearly half can be traced back to Bitfinex hacker funds recovered by the US government, with some coming from previously known Binance-related seized assets; among them, 2,456 BTC previously had no clear government attribution label, but because they entered this address through the same path as government funds, they are currently regarded as US government seized assets. The US government currently holds approximately 319,100 BTC, of which about 71% comes from LuBian-related BTC and Bitfinex recovered funds.In January 2025, a US federal court approved the return in kind of seized Bitfinex hacker funds to Bitfinex, and the main address holding approximately 94,600 BTC has still not moved. In October 2025, the US Department of Justice filed a civil forfeiture lawsuit against Chen Zhi and related assets, involving approximately 127,300 BTC; this batch of LuBian BTC entered addresses attributed to the US government between June and July 2024. Since 2013, US government-related addresses have received a total of approximately 555,300 BTC, worth about $16.1 billion at prices at the time; during the same period, approximately 236,200 BTC flowed out, worth about $3.8 billion at prices at the time. After excluding internal transfers between the government's own addresses, this transfer, based on labeled government addresses, ranks 9th among the largest single-day BTC outflows in US government history, and is also the largest since December 2, 2024. BTC being transferred to Coinbase Prime does not mean the US government has already sold it, and on-chain transfers alone cannot confirm the specific purpose of the funds.
Ethereum co-founder Vitalik Buterin warned in a post that AI-accelerated mathematical research could pose a severe threat to existing cryptographic systems within the next two years, particularly lattice-based cryptography (Lattices), ML-DSA, and FHE schemes, with ECDSA also facing a heightened risk of being compromised sooner than anticipated. Vitalik noted that AI could replicate breakthroughs akin to the transition from naive factorization to the Number Field Sieve, substantially undermining the security of lattice-based cryptography. In such a scenario, hash-based schemes would comprehensively outperform lattice-based ones in efficiency. The Ethereum Lean Roadmap is already progressing toward a "pure-hash" approach, employing signature schemes like WOTS or SPHINCS+ without incorporating any lattice-based components. From a personal standpoint, Vitalik offers the following recommendations: • Prioritize hash-based schemes, replacing lattice cryptography in feasible scenarios • Conservatively estimate lattice parameter sizes, with a recommendation to increase key sizes by a factor of 10 • Ensure privacy protocols avoid posting encrypted data on-chain, opting instead for off-chain transmission through third parties • Utilize offline confirmation for multi-signature wallets to prevent signatures from being publicly exposed • It is acceptable to retain funds in "fresh addresses" that have never initiated a transaction; however, address migration must be handled with extreme care, as losses resulting from operational errors may far exceed those caused by hacker breaches.
Odaily News: Iranian President Pezeshkian stated that Iran "no longer trusts negotiations with Washington," because after every round of talks, the US repeatedly launched attacks and imposed sanctions. Qatar and Pakistan are currently mediating between Iran and the US, relaying Tehran's messages to Washington.Pezeshkian also said that the negotiations were based on a previously signed memorandum of understanding between the two countries, and added that the Americans must clarify their position on this memorandum. In addition, he blamed the US for the closure of the Strait of Hormuz, saying that "it was the US that blocked our path." When Iran's path is blocked, closing the Strait of Hormuz is a natural response. The Strait of Hormuz crisis can be resolved through negotiations rather than the use of force." If negotiations lead to a resolution of the dispute, the waterway "will remain open for trade." (Sina Finance)
the North Korea-linked threat group TraderTraitor, also known as UNC4899 and Jade Sleet, recently breached an IT services company based in India that is unrelated to the crypto industry. The attackers posted fake job listings on GitHub, using technical interview assignments as bait to carry out phishing attacks targeting DevOps and crypto engineers.After victims download the project, a malicious .terraform.lock.hcl file points to a Terraform Provider domain controlled by the attackers. Upon running terraform init, the malicious Provider module is downloaded and executed, ultimately deploying the Rust/ARM64 backdoors FLATROOF and ROOFDECK on macOS devices. The associated malware can steal credentials and sensitive data, execute shell commands, collect and exfiltrate files, and gain access to cloud services and code repositories.
According to CoinDesk, London-based crypto institutional technology services provider Haruko was targeted by a cyberattack earlier this week, affecting a total of 15 clients. Attackers exploited vulnerabilities in Haruko’s infrastructure to extract user access tokens, gaining access to clients’ read-only exchange API information and trading data. A small amount of client funds were stolen, and smaller hedge funds with weaker security controls face a higher risk of loss. Haruko co-founder and CTO Adam Carlile confirmed that the attack specifically targeted Haruko itself. The vulnerability has been patched, and the company plans to release a complete technical post-incident report. Haruko serves over 80 institutional clients globally and connects to more than 100 centralized exchanges and 30 blockchains.
Odaily reports: Bitcoin News posted on X platform that Bitcoin Core developer Niklas Gögge warned that recent AI-driven vulnerability scanning is changing the Bitcoin security landscape. Large language models have significantly reduced the cost of vulnerability discovery, and attackers may be able to find catastrophic vulnerabilities with only a few hundred dollars in computing costs. For Bitcoin Core, Project Loupe, Bitcoin Red Team, and individual contributors have generated over 1,000 reports, but so far no high-risk or critical vulnerabilities have been found. Gögge stated that relying on stronger models to find vulnerabilities before attackers do is not a sustainable security strategy. Developers should build testing infrastructure through automated testing, fuzzing, and property-based testing that can prevent entire classes of vulnerabilities in advance. Key components of Bitcoin Core have cumulatively completed over 100 years of CPU fuzzing and decades of Bitcoin node network simulation.
Odaily reports: Blockchain analytics firm Chainalysis has released a report stating that hackers are increasingly leveraging open-source artificial intelligence (AI) to implant malware control instructions into on-chain transactions and smart contracts, with such cases surging approximately 440% in less than a year. Data shows that these incidents have risen from roughly 2 per day to approximately 11 per day. Attackers write malicious instructions on-chain to manipulate infected devices into stealing passwords and funds, and redirect assets to designated wallets; since on-chain records cannot be deleted, defense and interception are becoming increasingly difficult.The report notes that state-sponsored hackers from countries such as North Korea and Iran have become the primary drivers of such activity. Open-source models support local independent operation and modification, allowing them to directly bypass cloud-based defenses. However, the public and transparent nature of blockchain also leaves critical evidence for tracing attack infrastructure. (Bloomberg)
According to CoinDesk, Bitcoin Core 32.0 entered its final testing phase on September 14, with its official release scheduled for October 10. This update adds a transaction fee estimator based on real-time mempool status, enabling fee estimates to be lowered more quickly once network congestion subsides. It also enables multi-threaded parallel reading of transaction data to speed up node blockchain synchronization, defaulting to 8 threads. Security-wise, it resolves a wallet naming vulnerability on non-Windows systems since version 24.0 that allowed attackers to execute arbitrary commands on the node host via a specially crafted wallet name. Additionally, it patches an out-of-memory vulnerability in the newly added built-in web server; testing indicates that 16 unauthenticated connections can spike node memory usage from 46MB to roughly 3GB in approximately one minute. This update does not include any changes to Bitcoin's consensus rules.
According to EU-Startups, Lyon-based AI-driven Vulnerability Operations Center (VOC) Hackuity has announced the completion of a €16 million funding round (approximately $19 million), led by Forgepoint Capital International alongside Bright Pixel, Bpifrance, and Seventure Partners, bringing its cumulative funding to €32 million. The funds will be allocated toward product innovation, AI capability enhancements, and expansion into European and Asian markets. Hackuity’s platform integrates data from over 130 security tools, automating vulnerability prioritization and remediation through a proprietary risk scoring engine. It currently serves more than 6,000 users, protects over 2 million assets, and manages 1 billion security findings, with enterprise clients including ENGIE, BPCE, and Orange Cyberdefense.
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
Odaily News: Binance stated that in the first half of 2026, the Binance Wallet Security Center helped users avoid approximately $540 million in potential losses, filtering about 206 million spam transfers, identifying 4.93 million high-risk transactions, and approximately 996,000 malicious authorizations during the period. Binance noted that AI is being used by attackers to mass-generate malicious code, phishing websites, and fake identities, shifting attacks from broad-based approaches to more targeted fraud.
Odaily News: The decentralized lending protocol Secured Finance's lending market was attacked on September 5, resulting in a loss of approximately $104,000. The root cause was that collateral was priced based on the average execution price of the order book for the current block, allowing attackers to influence the price through self-trading, causing fraudulent lending positions to be counted as valid collateral. The attacker initially deployed the contract but did not execute immediately, then used flash loans and self-trading to inflate the price and withdraw USDC. The original attacking wallet was rolled back due to insufficient gas fees; approximately 48 seconds later, the general-purpose sandwich bot coffeebabe took about 0.9 WBTC, worth approximately $72,000, and transferred about 28.8 ETH of it to the ultra sound money builder, keeping only about $29 for itself. Subsequently, another bot took part of the USDC.
: The G7 cybersecurity working group stated in its latest report that quantum computing poses both a security threat and an economic threat to public and private institutions, and related organizations should immediately begin migrating to post-quantum cryptography (PQC).The working group noted that the migration process could take several years, as attackers can already collect and store encrypted data today and decrypt it once sufficiently powerful quantum computers emerge. Quantum computing could also break digital signatures, leading to identity theft and exposing companies and their supply chains.The report did not mention cryptocurrencies, but similar public-key cryptography is used for blockchain wallets and transaction authorization. Current quantum computers are not yet capable of breaking Bitcoin's cryptography, but developers are considering post-quantum solutions such as BIP-360.Ethereum researchers plan to replace multiple cryptographic components used by accounts, validators, and applications. The Solana Foundation has tested post-quantum signatures on its testnet and launched an optional hash-based vault. The G7 working group also urged governments to support related research, public-private cooperation, and national PQC strategies. (Decrypt)
Odaily News – According to Bitcoin News monitoring, hackers linked to the third wave of Coldcard wallet thefts have begun moving stolen funds for the first time, converting Bitcoin into ETH via THORChain. Galaxy Research's Alex Thorn stated that approximately 10% of the stolen BTC has been moved, while the remaining 90% remains untouched. The attacker reportedly encountered difficulties during the fund conversion, with multiple THORChain transactions being returned and retried. Researchers have traced the related swap activity to a new Ethereum address, which Alex Thorn noted has been shared with relevant authorities and cryptocurrency companies. Galaxy Research indicated that the broader Coldcard exploit has resulted in losses of at least 1,789 BTC across 8,865 addresses, valued at approximately $115 million based on prices at the time of the theft.