News linked to both this project and an event.
Odaily News: Bitget posted on X platform that the vulnerability involved in the September 24 security incident has been identified and fixed. The team is conducting additional verification and security checks on the withdrawal infrastructure, with Mandiant and SlowMist continuing to assist with the investigation. The temporary suspension of withdrawals is a security measure and is unrelated to the availability of user assets; user account balances have not been affected, and the Bitget Protection Fund will cover the financial impact of this platform-wide incident.Bitget plans to resume withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on the Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on the Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate, and users do not need to take any action in advance.
Odaily reports: Privacy blockchain network Zano has disclosed that an inflation vulnerability involving Gateway Addresses has forced it to plan a rollback of approximately 24 hours of blockchain history, and has urged users to immediately cease all economic activity related to ZANO and Confidential Assets.Zano has promised to compensate for losses caused by the rollback, but has not yet announced the target block height for the rollback, the patched version, the compensation process, the mechanics of the vulnerability, or the amount of unauthorized assets created. Gateway Addresses went live on August 26 with Hard Fork 6. (Bitcoin.com News)
Bitget stated that the losses resulting from this hot wallet security incident will be covered by the protection fund following an assessment, and the fund will be replenished after use. The specific scope of compensation and terms will be announced separately.
on-chain analyst Yu Jin has monitored that the $464 million risk protection fund Bitget claims can cover stolen assets is a total of 5,500 BTC, distributed across 3 wallet addresses.
according to Bitcoin News monitoring, this batch of Bitcoin is worth over $4 million, accounting for approximately 2.8% of the total Bitcoin related to the Coldcard vulnerability. Crypto Recovery Trust will verify the ownership of the funds and attempt to return them; Galaxy Digital research director Alex Thorn stated that another 3.0134 BTC was transferred to this address in the same transaction, but its source has not yet been confirmed.
According to Bitcoin News monitoring, $176 million worth of ETH and USDT0 was transferred from multiple Bitget wallets to a single address, in what appears to be unauthorized activity. This suspected hack did not involve Bitcoin. Bitget has not yet commented.
Bitcoin News posted on X platform stating that Blink said all account balances that suffered financial losses in the September 19 security incident have been restored to pre-incident levels.The software vulnerability had allowed attackers to transfer funds from dozens of accounts and obtain account information of approximately 3,400 other users. Blink stated that no funds were stolen from these 3,400 accounts, and the attackers did not obtain users' names, identification documents, or addresses; the company has contacted affected users and will publish a full incident review.
Odaily News: Canadian Bitcoin exchange and wallet company Bull Bitcoin stated that due to the Liquid Network attack on September 6, users are temporarily unable to redeem L-BTC back to Bitcoin through the platform, and redemption operations are still pending resumption.Bull Bitcoin expects the related redemption service to potentially resume within 30 days, but stated that this expectation is not guaranteed. Due to its reliance on the L-BTC redemption mechanism to balance inventory, the platform has temporarily closed inbound Lightning Network payments.In this attack, the attacker transferred out nearly 4,000 Bitcoin from the protocol, later returning approximately 3,400; currently still holding 598.50 Bitcoin, valued at over $51 million. Liquid Network stated on September 17 that block production, network transactions, and L-BTC transfers have returned to normal. (Bitcoin.com News)
Odaily News: The European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA) stated in a joint risk update that advances in quantum computing could weaken the cryptographic systems that secure blockchain transactions, communications, and database security.In March, Google Quantum AI researchers estimated that the number of physical qubits required to break the cryptographic techniques used by many cryptocurrencies may be about 20 times fewer than previously estimated. A computer capable of carrying out such an attack does not yet exist.In February, Bitcoin developer Jameson Lopp and others proposed phasing out current signature schemes and restricting how unmigrated funds can be used five years after the proposal's activation. The proposal has not yet been adopted. The Ethereum Foundation plans to make Ethereum's execution, consensus, and data layers quantum-resistant by December 2029. (Cointelegraph)
Odaily News: On September 21, a white hat actor transferred 40.71 BTC linked to the Coldcard vulnerability in a single transaction valued at approximately $3.31 million. The transaction consolidated funds from 11 addresses and included an OP_RETURN message pointing to the Crypto Recovery Trust.Alex Thorn, head of Galaxy Research, disclosed that the broader consolidation involved a total of 52.37 BTC across multiple clusters of attacker addresses, accounting for approximately 2.8% of the funds tied to the vulnerability. A firmware flaw in Coldcard devices dating back to March 2021 resulted in insufficient mnemonic seed randomness, with the total funds involved peaking at approximately $130 million. (Decrypt)
Odaily reports: SlowMist Chief Information Security Officer 23pds has stated that attackers are exploiting the Darksword vulnerability to bypass iOS security mechanisms through Safari, take control of devices, and extract private keys and other data from self-custodial crypto wallets. The vulnerability was previously used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.Google Threat Intelligence Group previously disclosed that Darksword initially only affected iOS versions 18.4 through 18.7. According to 23pds, attackers have now adapted it to iOS 26.5, though this assessment has not yet been officially verified.Attacks typically begin with social engineering. After users click on malicious links sent via social media or messaging apps, their devices may be rooted and wallet data extracted. Users should promptly update their phone's operating system and avoid visiting website links sent by strangers. Separately, three investors who lost nearly $1.8 million in Bitcoin after downloading fake wallet apps from Apple's official App Store have filed a lawsuit against Apple. (Bitcoin.com News)
Odaily News: According to monitoring by Galaxy's head of research, Coldcard white hat funds consolidated 52.37 BTC from Wave 2, Footprints AA, AU, and AX into a new address, which inscribed the OP_RETURN message "claim:cryptorecoverytrust dot com" in block 967,948. These white hat funds account for 2.8% of the Coldcard exploit attack funds.
Odaily reports: Bitcoin News posted on X that China launched a next-generation commercial cryptography algorithm initiative in 2025, aimed at developing and evaluating cryptographic standards capable of withstanding future quantum computers. Independent researcher @mjos_crypto, while analyzing the candidate algorithms, has discovered critical vulnerabilities in multiple proposed algorithms, including publicly reproducible private keys, easily constructible hash collisions, and signature implementations that accept invalid signatures. Bitcoin currently relies on well-validated elliptic curve cryptography, which quantum computers may pose a threat to its security model in the future; however, prematurely adopting insufficiently tested post-quantum cryptography schemes could also introduce vulnerabilities before quantum threats emerge.
Odaily reports, according to monitoring by Bitcoin News, security researchers have discovered that versions 1.1 and 1.2 of FomoPeek, distributed through the Apple App Store, contain an iOS exploit framework capable of escaping the app sandbox, enabling the extraction of keychain data, wallet files, and mnemonic phrases. SlowMist has linked the app to multiple theft incidents and traced nearly $580,000 in stolen USDT flowing into a primary address. Users who have installed either of the aforementioned versions should treat any keys accessible on that iPhone as compromised, generate new mnemonic phrases on a clean device, and immediately transfer their funds.
Odaily reports: Bitcoin News posted on X that Core Lightning is urging node operators to immediately disable experimental features, as developers are investigating a vulnerability that could put channel funds at risk. This is Core Lightning's second warning within a few weeks, following an August patch and the release of the 26.06.7 upgrade after a series of AI-generated CVE reports. Core Lightning has not yet disclosed how the experimental feature could be exploited.
Odaily News: Bitcoin fork project Bitcoin BLAKE2b developers plan to restrict miners from unlocking newly mined tokens, with a waiting period set at 45 days. The related change is proposed to be executed at block height 973440. The chain forked from Bitcoin on August 8.Its native token BTCB2 is also labeled by some trading platforms as Bitcoin BLAKE2b, Bitcoin BIP-110, or XBT. BTCB2 has fallen 84% from its September high of $1,799, trading at approximately $270 to $315 in recent hours.Developer Luke Dashjr stated that some BLAKE2b mining pools are "attacking" the network. After forking, the chain inherited Bitcoin's difficulty, mining only about 8 blocks in the first 22 days, before resuming operation by enabling BLAKE2b hashing and adjusting difficulty.Currently, the chain is not listed by most trading platforms or CoinGecko and CoinMarketCap. Trading platform Neoxa has stated it supports the upcoming soft fork. (Bitcoin.com News)
Odaily reports: Owen Simonin, founder and CEO of French crypto platform Meria, stated that following several recent data breach incidents in France, there has been an increase in scam calls impersonating customer service representatives from legitimate platforms such as Binance and Meria.Scammers falsely claim that users' accounts or funds are at risk, inducing them to urgently transfer their crypto assets to designated addresses. Simonin emphasized that platforms will not ask users to initiate transactions or provide personal information when users have not proactively contacted them.In August, the French General Directorate of Public Finances (DGFiP) disclosed that a data breach incident allowed hackers to obtain the data of 678,000 taxpayers. (Bitcoin.com News)
Odaily News: A 2021 firmware vulnerability in the hardware wallet Coldcard resulted in insufficient randomness in some recovered seeds. Since July 30, attackers have transferred approximately 1,600 to 1,800 BTC from affected wallets, involving thousands of addresses, with an estimated value exceeding $100 million.Coldcard manufacturer Coinkite stated that it must be assumed that someone used AI to review its public firmware. The vulnerability has existed for about five years, and whether AI was involved in the related attacks has not yet been confirmed.Shielded Labs researcher Taylor Hornby used a Claude Opus 4.8 audit agent and discovered a vulnerability in the Zcash Orchard shielded pool circuit dating back to 2022, which in testing could generate unlimited counterfeit ZEC without a trace. Developers completed the fix within days, and no theft of coins has been confirmed.Statistics from blockchain analytics firm Chainalysis show that on-chain writes carrying malware instructions and command-and-control information rose from about 2.06 per day to 11.1 per day, an increase of 440%. (Bitcoin.com News)
Bitcoin News posted on X that attackers accessed a small number of Blink custodial accounts and withdrew funds. Blink stated that the vast majority of funds remain safe, and non-custodial wallets were not affected; the Bitcoin payment protocol Spark, which it uses, supports multiple Lightning Network wallets, but it has not yet been confirmed that Spark was the source of this security incident.
Odaily reports: Bitcoin News posted on X platform that Bitcoin Core developer Niklas Gögge warned that recent AI-driven vulnerability scanning is changing the Bitcoin security landscape. Large language models have significantly reduced the cost of vulnerability discovery, and attackers may be able to find catastrophic vulnerabilities with only a few hundred dollars in computing costs. For Bitcoin Core, Project Loupe, Bitcoin Red Team, and individual contributors have generated over 1,000 reports, but so far no high-risk or critical vulnerabilities have been found. Gögge stated that relying on stronger models to find vulnerabilities before attackers do is not a sustainable security strategy. Developers should build testing infrastructure through automated testing, fuzzing, and property-based testing that can prevent entire classes of vulnerabilities in advance. Key components of Bitcoin Core have cumulatively completed over 100 years of CPU fuzzing and decades of Bitcoin node network simulation.