GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Zano Blockchain Rolled Back 30 Days Due to Over $200 Million in Illicit Tokens

Zano disclosed a validation flaw in the Gateway Addresses introduced by Hard Fork 6. An attacker minted approximately 18.4 million ZANO in a single transaction on August 29, then minted an equal amount again on September 25, and minted fUSD in the same manner.The project team stated that the value of the illicit tokens involved exceeds $200 million, with potentially affected activity involving 117,941 outputs and 65,301 transactions. Zano has restored the chain state from block 3,833,000 and disabled Gateway Addresses. All affected balances will be fully restored, and the ZANO supply and issuance schedule will remain unchanged. (Bitcoin.com News)

NEAR Intents attacker address interacted with Lazarus Group flagged address.

According to PeckShield monitoring, the NEAR Intents attacker has transferred the stolen funds to KuCoin and bridged them to BTC; the associated address had previously interacted with addresses flagged as Lazarus Group.

SlowMist: Bitget hack involved a zero-day vulnerability in a third-party security product, attacker used custom withdrawal tool

Odaily News — SlowMist security team has disclosed preliminary investigation findings on the September 25 theft of assets from Bitget's hot wallet. The investigation found that the attack involved certain third-party security products and wallet application hosts, with a zero-day vulnerability present in one of the third-party products. The attacker also gained unauthorized access to a third-party product management platform by impersonating an internal employee.SlowMist stated that the team has obtained the custom withdrawal tool used by the attacker to interact with the wallet system's withdrawal logic. On-chain attack activity began at 2:31 on September 25, lasted approximately 2 hours and 52 minutes, and involved multiple blockchains. The attacker subsequently attempted to tamper with withdrawal records and trigger additional BTC withdrawals. The team is still investigating how the attacker moved laterally between the affected systems.

North Korean hackers swap stolen Bitget funds cross-chain into BTC, involving CoW Protocol and Chainflip

Odaily News — According to monitoring by SlowMist's Yu Xian, MistTrack_io's TrackAgent discovered that North Korean hackers used automated scripts to create orders on CoW Protocol and set the receiving address to pre-prepared Chainflip Deposit-related contract addresses. After the orders were filled, the relevant assets could complete cross-chain operations on Chainflip and be swapped into BTC. The operation involves stolen Bitget funds.

$900,000 Bitcoin Theft Case: US Seeks Forfeiture of 110,300 USDT

Odaily News: The U.S. Attorney's Office for the District of Massachusetts filed a civil forfeiture lawsuit on September 28, seeking the forfeiture of 110,300 USDT seized from a Binance account. The case involves phishing text messages impersonating Coinbase, which led to the theft of 33.7 bitcoins, worth approximately $900,000 at the time, from a beneficiary and their family trust held in the same Coinbase account.Investigators said that between June 5 and June 15, 2023, 11.2 of the stolen bitcoins were traced to the Binance account and were quickly converted into Monero. When the FBI requested the account be frozen, it held approximately 758.55 Monero; Binance transferred 110,300 USDT to a government-controlled wallet on August 3, 2026. (Bitcoin.com News)

Zano Completes 30-Day Blockchain History Rollback and Releases Hotfix, Network Now Running Stably on Updated Chain

Odaily reports: The privacy-focused public chain Zano team has stated that in response to the inflation vulnerability discovered last Friday, a hotfix has been deployed, and the network is now running stably on the updated chain. The chain previously rolled back the block height to 3,833,000, erasing 30 days of previously confirmed transaction records.The Zano team stated that third-party wallets, exchanges, and payment service providers must first update their own nodes to the updated chain before they can safely resume transfers of ZANO and Zano-issued assets. Service providers will announce recovery progress through official channels, and recovery procedures for affected users are being prepared.The native asset ZANO has dropped 32% in price this week and 40.6% since the start of 2026. Zano's official X account stated that users can update their iOS, Android, and desktop wallets, and the team will soon release more details on the recovery process. (Bitcoin.com News)

$388 Million in Crypto Assets Stolen, Bitget CEO Says Full Recovery Unlikely

Odaily News — Gracy Chen, CEO of cryptocurrency exchange Bitget, said the company is not optimistic about recovering the $388 million in crypto assets lost in last week's security incident. Citing the Bybit hack in 2025 as a reference, she noted that approximately one year after that incident, only about 3.5% of the stolen funds had been frozen, and that this does not equate to a completed recovery.Bitget has set up a bounty program offering 5% rewards for frozen funds and recovered funds respectively. The NEAR Intents team said it has intercepted over $50 million in assets related to the attack and frozen approximately $500,000. Tether and Circle have blacklisted the relevant wallets, freezing $318,000 worth of USDT and USDC.Gracy Chen stated that preliminary investigations indicate the attack may match VPN addresses used by North Korea-linked groups, but Bitget has not yet fully ruled out the possibility of an insider job. Bitget has resumed withdrawals in phases, starting with Bitcoin transactions on Monday and continuing with ETH transactions on Tuesday. (Cointelegraph)

Bitcoin Pioneer Adam Back's Multiple Ventures Hit Setbacks: BSTR Ordered to Pay $15 Million Breakup Fee

Odaily News — Multiple Bitcoin ventures associated with Bitcoin pioneer and Blockstream co-founder Adam Back have recently suffered a series of setbacks: the merger between BSTR Holdings, the Bitcoin treasury project he championed, and a SPAC under Cantor Fitzgerald has been terminated, with BSTR ordered to pay a $15 million breakup fee; Blockstream Mining, the Bitcoin mining operation he co-founded and in which he holds a minority stake, along with its partner Exacore, has faced multiple lawsuits following its spin-off from Blockstream, accused of owing equipment payments, electricity bills, and customer deposits, with related financing totaling approximately $2 billion; meanwhile, Liquid Network, the Bitcoin sidechain initiated by Blockstream, suffered a hack in which approximately 4,000 BTC were stolen, of which 3,400 have been returned, with the hacker still retaining approximately $47 million worth of Bitcoin. (Bloomberg)

About 50 BTC Unable to Be Redeemed, User Claims Their Address Remains Restricted After Solv Protocol Restored Functionality

according to monitoring by neil lee (@neillee99), they claim to have withdrawn approximately 50 BTC from Binance on July 8, converted it into SolvBTC and BTC+ to earn approximately 3% annualized yield, after which BTC+ minting and redemption functionality was suspended. On July 22, Solv Protocol publicly disclosed the related security incident and stated that assets were not affected; on July 31, the project team said functionality had been restored, but their address remained restricted, and approximately 50 BTC still cannot be redeemed to this day. They claim to have submitted proof of fund sources and wallet control, and called on Binance and investors to pay attention.

SlowMist's Cos: Chainflip bridge blocks North Korean hacker money laundering, but AML/KYT speed lags behind

Odaily report: According to monitoring by SlowMist's Cos, the Chainflip bridge is attempting to block North Korean hacker money laundering, but the response speed of AML/KYT lags behind the speed of money laundering. Money laundering groups use automation to split funds into large numbers of small amounts, transferring them across chains through various bridges; if funds are intercepted or returned by risk controls, they immediately try the next money laundering path, ultimately converting to BTC and continuing to obfuscate the source of funds through CoinJoin. This money laundering operation is still continuously evolving.

Stealing $351.6 Million: Bitget Hacker Swaps ETH for BTC via THORChain

Odaily reports, according to Lookonchain monitoring, the Bitget hacker (0xf7bC...96C3) swapped ETH for BTC via THORChain, having stolen $351.6 million.

Zano rolls back to before the 6th hard fork, deleting about a month of on-chain transaction records

privacy blockchain project Zano has rolled back its blockchain to block height 3,833,000, before the 6th hard fork, deleting approximately one month of on-chain transaction records in order to address an inflation vulnerability involving Gateway Addresses.The vulnerability allowed unauthorized minting of the native token ZANO and the USD-pegged stablecoin fUSD. Zano stated that the core consensus protocol, wallet spending keys, and ordinary transaction privacy were not affected, and that nodes, miners, stakers, and service providers need to adopt the update.Freedom Dollar stated that millions of dollars in assets held by the project had been swapped into counterfeit fUSD, and that the related losses will be borne by the project. Freedom Dollar has asked fUSD holders to suspend economic activity involving the token until the stabilized Zano chain is confirmed after repairs. (Bitcoin.com News)

Bitget Hacked, Loses $351 Million and Suspends Withdrawals

Cryptocurrency exchange Bitget has been hacked, losing approximately $351 million. Bitget CEO Gracy Chen stated that the platform's protection fund will cover the losses, and the exchange has temporarily suspended withdrawals. (Bitcoin.com News)

1830 BTC Stolen: COLDCARD Seed Entropy Theft Affects 256 Victims

according to Galaxy's head of research, the COLDCARD Seed Entropy theft incident has resulted in 1,830 BTC being stolen, involving 3 rounds of attacks and more than 30 smaller related indicators. A total of 256 victims have reported their situations to GLXY Research, with a median loss of 1.1 BTC, and efforts to track the attackers are still ongoing.

Slow Mist's Cosine Talks About THORChain: Decentralization Is Not Just a Slogan, and "Decentralized, No Right to Interfere" Should Not Be Used to Respond to Industry Security Incidents

Slow Mist's Cosine posted on X platform, stating that the Bitget hack incident has spread widely, involves a huge amount of funds, and the related funds were quickly linked to North Korean hackers. Institutions such as Circle and Tether promptly assisted in freezing the related funds, with Circle freezing the USDC held by the hackers.Regarding THORChain, Cosine pointed out that when THORChain itself previously suffered a hack, it also quickly intervened in its so-called "decentralized" platform; but this time, when facing a major industry security incident, it responded on the grounds of being "decentralized and having no right to interfere," likened itself to Bitcoin and Ethereum, and continued to earn fees from the hackers' large cross-chain transactions.He stated that decentralization should not just be a slogan. After major security incidents occur, the key is to distinguish which issues need to be solved jointly by the industry. He also believes that platforms such as THORChain should not be easily mentioned in the same breath as Bitcoin and Ethereum, as there are clear differences in the degree of decentralization and mechanisms among different systems.

THORChain addresses questions regarding the Bitget security incident, emphasizing the permissionless nature of decentralized protocols.

MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.

"Money Laundering Dedicated Network" THORChain Official Cries Foul: As Decentralized and Permissionless as BTC, ETH, and BNB Chain, Not Responsible for Bitget Hack Money Laundering Process, Previously Suspended Services for 39 Days Due to Hacker Attack

Odaily News: Today, THORChain officially posted on X platform stating, "We have noticed the recent Bitget hack and are deeply saddened by it. We can imagine this is a difficult time for everyone in the industry. (However,) THORChain is as decentralized and permissionless as Bitcoin, Ethereum, and BNB Chain. When dealing with known stolen funds, what responsibility should Bitcoin, Ethereum, and BNB Chain bear?" Subsequently, it called out OKX CEO Star and Bitget CEO Gracy.However, crypto community members in the comments pointed out that when THORChain previously suffered an attack, it once suspended services for 39 days, and they are deeply ashamed of the differentiated treatment between the two situations.

OKX Star Responds to THORChain: TSS + Validator Model Is Not True Decentralization

Odaily News: OKX Star posted on X in response to THORChain, stating that he does not believe THORChain's TSS + validator model represents true decentralization. THORChain's validators collectively control the underlying assets in the TSS vault, and funds can be moved once the signature threshold is reached. Therefore, from a custody perspective, it cannot be compared to the underlying consensus mechanisms of Bitcoin and Ethereum, but instead acts as an intermediary between users and native chains. "TSS distributes control among multiple participants, but decentralizing an intermediary does not eliminate the intermediary itself."Previously, discussions arose after some stolen Bitget funds were transferred through THORChain. THORChain responded that it is decentralized and permissionless, just like Bitcoin, Ethereum, and BNB Chain, and stated that if stolen funds were known to flow through Bitcoin, Ethereum, or BNB Chain, what responsibility should those networks bear?

AMLBot: Some of Bitget's Stolen Funds Reportedly Begin Mixing Through Wasabi CoinJoin

According to AMLBot monitoring, some of the stolen funds from the Bitget hack have reportedly begun being mixed through Wasabi CoinJoin. The related funds originally came from a TRON wallet on Bitget. The attacker swapped TRX for USDT, then bridged via USDT0 to Ethereum and exchanged it for approximately 145 ETH, which was subsequently swapped through THORChain into approximately 4.59 BTC. These BTC were then split and pre-processed before entering CoinJoin.

Xie Jiaxin: The method of theft in this security incident differs from last year's Bybit incident, so different withdrawal recovery arrangements are being adopted

Odaily reports: Xie Jiaxin posted on X stating that this Bitget security incident involved multiple non-EVM chains and 10 tokens, and due to the different method of asset theft, different approaches to handling and restoring withdrawals were taken compared to last year's Bybit security incident in order to thoroughly eliminate potential risks.Additionally, Xie Jiaxin stated that he and Bitget CEO Gracy Chen will host a community livestream 30 minutes before withdrawals resume on Monday to discuss this security incident and answer community questions.Bitget announced on X that it will restore withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate normally, and users do not need to take any action in advance.