GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Drift Hack Victims Begin Redemptions, $3.11M Recovery Pool Pays Out Only About 1 Cent per Dollar

victims of the Drift hack, a perpetual contract exchange on Solana, began filing claims on October 1. The recovery pool's initial funding stands at approximately $3.11 million against nearly $295.4 million in verified losses. Victims can redeem USDT through DFX tokens, with each $1 of loss converting to roughly 1.04 cents at launch, meaning a $1,000 loss corresponds to about $10.40.The total supply of DFX is fixed at 299,500,810.998 tokens, with each token corresponding to $1 of verified loss from the April incident, and no additional tokens will be minted. Holders can choose to burn DFX to redeem USDT, sell on secondary markets such as Raydium, or continue holding their claims. Completed redemptions are irreversible, and unclaimed tokens will expire after the claims window closes on January 1, 2028.Future funding for the recovery pool includes a portion of daily net protocol revenue from Velocity, the rebranded exchange rebuilt by Drift, up to $127.5 million in USDT committed by Tether, $20 million in USDT committed by strategic partners, and recovered stolen assets. On the first Friday after claims opened, approximately 216,480 DFX tokens were redeemed for about 2,250 USDT, with Velocity's first revenue transfer amounting to 31 USDT; approximately 13,025.9 ETH is spread across 4 Ethereum wallets, another approximately 2,309.4 ETH passed through Tornado Cash, and about $9.2 million in assets have been frozen at other addresses. (Bitcoin.com News)

Over $6 Million in Assets Stolen from Base Anonymous Multisig Vault, 7 Signer Identities Unknown

A crypto asset vault on Base had approximately 1,783 wstETH transferred out on October 4, resulting in losses exceeding $6 million. On-chain records show that the vault is controlled by a 3-of-7 Safe, and the identities of the seven signers have not yet been made public.Security firms stated that the attacker borrowed aBaswstETH from the vault and swapped it for wstETH through Aave. Neither the Base chain itself nor Aave's core contracts have been identified as being exploited, and the specific authorization vulnerability remains unconfirmed. (Bitcoin.com News)

Zano Blockchain Rolled Back 30 Days Due to Over $200 Million in Illicit Tokens

Zano disclosed a validation flaw in the Gateway Addresses introduced by Hard Fork 6. An attacker minted approximately 18.4 million ZANO in a single transaction on August 29, then minted an equal amount again on September 25, and minted fUSD in the same manner.The project team stated that the value of the illicit tokens involved exceeds $200 million, with potentially affected activity involving 117,941 outputs and 65,301 transactions. Zano has restored the chain state from block 3,833,000 and disabled Gateway Addresses. All affected balances will be fully restored, and the ZANO supply and issuance schedule will remain unchanged. (Bitcoin.com News)

$900,000 Bitcoin Theft Case: US Seeks Forfeiture of 110,300 USDT

Odaily News: The U.S. Attorney's Office for the District of Massachusetts filed a civil forfeiture lawsuit on September 28, seeking the forfeiture of 110,300 USDT seized from a Binance account. The case involves phishing text messages impersonating Coinbase, which led to the theft of 33.7 bitcoins, worth approximately $900,000 at the time, from a beneficiary and their family trust held in the same Coinbase account.Investigators said that between June 5 and June 15, 2023, 11.2 of the stolen bitcoins were traced to the Binance account and were quickly converted into Monero. When the FBI requested the account be frozen, it held approximately 758.55 Monero; Binance transferred 110,300 USDT to a government-controlled wallet on August 3, 2026. (Bitcoin.com News)

Zano Completes 30-Day Blockchain History Rollback and Releases Hotfix, Network Now Running Stably on Updated Chain

Odaily reports: The privacy-focused public chain Zano team has stated that in response to the inflation vulnerability discovered last Friday, a hotfix has been deployed, and the network is now running stably on the updated chain. The chain previously rolled back the block height to 3,833,000, erasing 30 days of previously confirmed transaction records.The Zano team stated that third-party wallets, exchanges, and payment service providers must first update their own nodes to the updated chain before they can safely resume transfers of ZANO and Zano-issued assets. Service providers will announce recovery progress through official channels, and recovery procedures for affected users are being prepared.The native asset ZANO has dropped 32% in price this week and 40.6% since the start of 2026. Zano's official X account stated that users can update their iOS, Android, and desktop wallets, and the team will soon release more details on the recovery process. (Bitcoin.com News)

Zano rolls back to before the 6th hard fork, deleting about a month of on-chain transaction records

privacy blockchain project Zano has rolled back its blockchain to block height 3,833,000, before the 6th hard fork, deleting approximately one month of on-chain transaction records in order to address an inflation vulnerability involving Gateway Addresses.The vulnerability allowed unauthorized minting of the native token ZANO and the USD-pegged stablecoin fUSD. Zano stated that the core consensus protocol, wallet spending keys, and ordinary transaction privacy were not affected, and that nodes, miners, stakers, and service providers need to adopt the update.Freedom Dollar stated that millions of dollars in assets held by the project had been swapped into counterfeit fUSD, and that the related losses will be borne by the project. Freedom Dollar has asked fUSD holders to suspend economic activity involving the token until the stabilized Zano chain is confirmed after repairs. (Bitcoin.com News)

Bitget Hacked, Loses $351 Million and Suspends Withdrawals

Cryptocurrency exchange Bitget has been hacked, losing approximately $351 million. Bitget CEO Gracy Chen stated that the platform's protection fund will cover the losses, and the exchange has temporarily suspended withdrawals. (Bitcoin.com News)

Zano to Roll Back ~24 Hours of On-Chain History Due to Inflation Bug

Odaily reports: Privacy blockchain network Zano has disclosed that an inflation vulnerability involving Gateway Addresses has forced it to plan a rollback of approximately 24 hours of blockchain history, and has urged users to immediately cease all economic activity related to ZANO and Confidential Assets.Zano has promised to compensate for losses caused by the rollback, but has not yet announced the target block height for the rollback, the patched version, the compensation process, the mechanics of the vulnerability, or the amount of unauthorized assets created. Gateway Addresses went live on August 26 with Hard Fork 6. (Bitcoin.com News)

Liquid Attack Leaves L-BTC Redemptions Paused, Attacker Holds Over $51 Million in Bitcoin

Odaily News: Canadian Bitcoin exchange and wallet company Bull Bitcoin stated that due to the Liquid Network attack on September 6, users are temporarily unable to redeem L-BTC back to Bitcoin through the platform, and redemption operations are still pending resumption.Bull Bitcoin expects the related redemption service to potentially resume within 30 days, but stated that this expectation is not guaranteed. Due to its reliance on the L-BTC redemption mechanism to balance inventory, the platform has temporarily closed inbound Lightning Network payments.In this attack, the attacker transferred out nearly 4,000 Bitcoin from the protocol, later returning approximately 3,400; currently still holding 598.50 Bitcoin, valued at over $51 million. Liquid Network stated on September 17 that block production, network transactions, and L-BTC transfers have returned to normal. (Bitcoin.com News)

SlowMist Warns Darksword Exploit Reportedly Now Capable of Attacking iOS 26.5 and Stealing Wallet Private Keys

Odaily reports: SlowMist Chief Information Security Officer 23pds has stated that attackers are exploiting the Darksword vulnerability to bypass iOS security mechanisms through Safari, take control of devices, and extract private keys and other data from self-custodial crypto wallets. The vulnerability was previously used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.Google Threat Intelligence Group previously disclosed that Darksword initially only affected iOS versions 18.4 through 18.7. According to 23pds, attackers have now adapted it to iOS 26.5, though this assessment has not yet been officially verified.Attacks typically begin with social engineering. After users click on malicious links sent via social media or messaging apps, their devices may be rooted and wallet data extracted. Users should promptly update their phone's operating system and avoid visiting website links sent by strangers. Separately, three investors who lost nearly $1.8 million in Bitcoin after downloading fake wallet apps from Apple's official App Store have filed a lawsuit against Apple. (Bitcoin.com News)

Bitcoin BLAKE2b Proposes Requiring Miners to Wait 45 Days Before Accessing Newly Mined BTCB2, Token Down 84% From Peak

Odaily News: Bitcoin fork project Bitcoin BLAKE2b developers plan to restrict miners from unlocking newly mined tokens, with a waiting period set at 45 days. The related change is proposed to be executed at block height 973440. The chain forked from Bitcoin on August 8.Its native token BTCB2 is also labeled by some trading platforms as Bitcoin BLAKE2b, Bitcoin BIP-110, or XBT. BTCB2 has fallen 84% from its September high of $1,799, trading at approximately $270 to $315 in recent hours.Developer Luke Dashjr stated that some BLAKE2b mining pools are "attacking" the network. After forking, the chain inherited Bitcoin's difficulty, mining only about 8 blocks in the first 22 days, before resuming operation by enabling BLAKE2b hashing and adjusting difficulty.Currently, the chain is not listed by most trading platforms or CoinGecko and CoinMarketCap. Trading platform Neoxa has stated it supports the upcoming soft fork. (Bitcoin.com News)

After the French data leak, scam calls impersonating crypto platform customer service are on the rise

Odaily reports: Owen Simonin, founder and CEO of French crypto platform Meria, stated that following several recent data breach incidents in France, there has been an increase in scam calls impersonating customer service representatives from legitimate platforms such as Binance and Meria.Scammers falsely claim that users' accounts or funds are at risk, inducing them to urgently transfer their crypto assets to designated addresses. Simonin emphasized that platforms will not ask users to initiate transactions or provide personal information when users have not proactively contacted them.In August, the French General Directorate of Public Finances (DGFiP) disclosed that a data breach incident allowed hackers to obtain the data of 678,000 taxpayers. (Bitcoin.com News)

Coldcard 2021 Firmware Vulnerability Led to Over $100 Million in Bitcoin Theft

Odaily News: A 2021 firmware vulnerability in the hardware wallet Coldcard resulted in insufficient randomness in some recovered seeds. Since July 30, attackers have transferred approximately 1,600 to 1,800 BTC from affected wallets, involving thousands of addresses, with an estimated value exceeding $100 million.Coldcard manufacturer Coinkite stated that it must be assumed that someone used AI to review its public firmware. The vulnerability has existed for about five years, and whether AI was involved in the related attacks has not yet been confirmed.Shielded Labs researcher Taylor Hornby used a Claude Opus 4.8 audit agent and discovered a vulnerability in the Zcash Orchard shielded pool circuit dating back to 2022, which in testing could generate unlimited counterfeit ZEC without a trace. Developers completed the fix within days, and no theft of coins has been confirmed.Statistics from blockchain analytics firm Chainalysis show that on-chain writes carrying malware instructions and command-and-control information rose from about 2.06 per day to 11.1 per day, an increase of 440%. (Bitcoin.com News)

Liquid Network hacker still holds 598.5 bitcoins, L-BTC-to-bitcoin redemption channel paused for 11 days

Odaily News: The Liquid Network attacker has returned 3,400 bitcoins after the September 6 exploit, accounting for approximately 85% of the transferred assets; they currently still hold 598.50 bitcoins, worth over $45 million.Blockstream, the digital asset infrastructure company responsible for maintaining the Liquid Network, has refused to pay a ransom for the remaining assets and is demanding the return of the relevant bitcoins. The network shows 4,234.76 L-BTC in circulation, while the bitcoin reserves stand at only 3,632.23.The L-BTC-to-bitcoin redemption function has still not been restored, with Sideswap stating that redemptions are currently unavailable; Blockstream founder Adam Back said that L-BTC will be backed 1:1 by bitcoin reserves and reminded holders not to sell L-BTC off-market at a discount.As of now, Blockstream has not yet issued an announcement that "redemptions are live." The attacker's wallet continues to receive on-chain messages and has been subjected to address poisoning attacks and scam messages, with the related attacks inducing transfers by generating visually similar addresses. (Bitcoin.com News)

Trader loshmi bought STONK at a $1 million market cap, earning $327,400 in 30 days

Odaily News: Trader loshmi stated that he closed all positions on September 13, realizing $327,400 in profits from 30 days of public trading. He said he began buying when STONK had a market cap of approximately $1 million over a month ago and continued to add to his position as the price declined.Stonkfun is a Solana token launch platform that went live on August 3, allowing creators to pair new tokens with tokenized stocks. STONK is the platform's native token.loshmi disclosed that his portfolio once rose from $5,000 to over $25,000 before falling back to $4,000; during this period, he also lost over $6,000 due to a hack. He cited fatigue from intensifying competition in recent market trading as the reason for closing his positions. (Bitcoin.com News)

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

US Department of Justice Has Frozen Approximately $938 Million in Fraud-Related Crypto, With About $52 Million Added in a Single Day

Odaily News: In an operation targeting the Telegram crypto escrow trading platform Xinbi Guarantee, the U.S. Department of Justice's Scam Center Strike Force restricted the handling of approximately $52 million in fraud-related cryptocurrency in a single day, bringing the cumulative total to approximately $938 million. Previously, the cumulative amount frozen, seized, or recovered had already exceeded $580 million.The U.S. Department of the Treasury stated that since its founding around 2022, Xinbi Guarantee has processed over $24 billion in transactions, involving digital assets and fiat currency, primarily serving Southeast Asian transactions. North Korean hackers and sanctioned entities are alleged to have used the platform, including entities under Jin Bei Group and Prince Group.A U.S. federal court approved the seizure on September 7 of the Telegram channel operated by Xinbi Guarantee. Law enforcement authorities also seized two payment wallets totaling approximately $12 million and applied to freeze another 47 cryptocurrency wallets suspected of being used for money laundering or associated with fraud-related service providers.The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) added Xinbi Guarantee and its two supporting companies, Safew Technology and Anwen Technology, to its sanctions list on September 9. The U.S. Department of Justice also dispatched investigators to Madagascar to assist local law enforcement in cracking down on 13 scam compounds operated by Chinese nationals and to process over 3,200 electronic devices. (Bitcoin.com News)

Bitcoin fork asset BTCB2 once hit $1,799, with a fully diluted valuation of $20.9 billion calculated at a price of $1,000

Odaily News: Bitcoin fork asset BTCB2 hit an all-time high of $1,799 on September 5. Over the past 4 hours, its price has fluctuated between 750 and 1,000 USDC; the Neoxa USDC market recorded a 24-hour trading volume of approximately $1 million.BTCB2 originated from a chain split that occurred on August 8, 2026, at block height 961,632. The network subsequently changed its proof-of-work algorithm to Blake2 and reduced block size, and it can now be mined using Blake2-compatible ASIC miners.Neoxa Exchange and Nonkyc.io have listed BTCB2, with the former offering BTC, USDC, and USDT trading pairs, and the latter offering a USDT trading pair. Both platforms have limited liquidity, and CoinMarketCap and CoinGecko have not yet listed the asset.Based on a BTCB2 price of $1,000, its fully diluted valuation stands at approximately $20.9 billion. Since UTXOs need to be split from Bitcoin first, transactions may otherwise be vulnerable to replay attacks; the network's hash rate has risen by 30.41% over the past 7 days, reaching approximately 5.1 PH/s. (Bitcoin.com News)

2026 has seen 32 price manipulation attacks, impacting a nearly $50 billion crypto lending market

Odaily News: Blockchain intelligence firm TRM Labs reports that 32 price manipulation attacks have been recorded in 2026, surpassing the total of any previous full year; 2025 saw 12 incidents throughout the year. Such attacks account for roughly one-eighth of hacker incidents, up from one-seventeenth in 2022.Attackers typically first inflate the price of low-liquidity tokens, then use them as collateral to borrow other assets from lending protocols. Subsequently, they cause the collateral price to plummet and abandon the collateral, potentially leading to bad debt in the lending pools.According to DeFiLlama data, the total value locked in crypto-collateralized lending protocols has grown by approximately 56% over the past two years, approaching $50 billion, with active loan volume nearing $29 billion. The sector currently hosts over 570 lending protocols.Recently, Tectonic suffered losses exceeding $70 million after the TONIC price was artificially inflated, with the attacker ultimately extracting approximately $6 million in assets after the Cronos chain was rolled back; Moonwell also previously incurred losses of around $8.7 million due to manipulation of the MAMO oracle price. (Bitcoin.com News)

JaredfromSubway.eth sandwich attack bot has extracted $295 million in total, with $7.5 million stolen in June

Odaily News: The sandwich attack bot operated by JaredfromSubway.eth has extracted a cumulative total of 117,007 ETH since March 2023, worth approximately $295 million at current prices. In June 2026, an anonymous attacker deployed 66 counterfeit token contracts, exploiting the bot's automated trading logic to steal at least $7.5 million in ETH and stablecoins, and funneled the funds into Tornado Cash. The stolen assets have not yet been recovered.Sandwich attacks are a form of Maximal Extractable Value (MEV): the bot monitors large transactions in Ethereum's public mempool, buys ahead of the target transaction, and sells after the transaction pushes the price up, capturing profits from the spread. The bot's primary contract had received a cumulative total of 117,007 ETH as of August 28.MEV-Boost block construction is centralized among a small group of participants, with relay.ultrasound.money, Titan Relay, and bloXroute regulated relays collectively forwarding approximately 85% to 88% of related blocks within a 24-hour window; Titan's builder independently assembled 50.3% of the blocks. Monthly sandwich attack extraction amounts have declined from approximately $10 million in late 2024 to roughly $2.5 million in October 2025. (Bitcoin.com News)