GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

A vault on the Base chain was hacked, with losses expanding to approximately $6 million.

According to Spot On Chain monitoring, a vault on the Base chain was attacked, with losses expanding to approximately $6 million, involving around 1,783 wstETH. The attacker added a new contract to the vault's whitelist, borrowed aBaswstETH, and transferred it to an attacker-controlled contract.

Losses Expand to Approximately $6 Million, Base Chain Vault Suffers Attack

According to Spot On Chain monitoring, the losses from the vault attack on Base chain have expanded to approximately $6 million, involving about 1,783 wstETH. The attacker added a new contract to the vault's whitelist, borrowed aBaswstETH from the vault, and transferred it to the attacker's contract. The attacker's address is a certain address. Spot On Chain stated that systemic risk is currently limited, but caution is needed regarding the potential short-term pressure on the peg of liquid staking tokens caused by the attacker selling off wstETH.

Approximately $2.02 Million in Assets Stolen, Vault on Base Chain Under Attack

According to Blockaid monitoring, a vault on the Base chain is currently under attack. The attacker added a brand-new contract to the vault's whitelist, then borrowed aBaswstETH and transferred it to the attacker's contract. The attack is still ongoing, and approximately 4 transactions have resulted in about $2.02 million in assets being stolen.

Zano Completes 30-Day Blockchain History Rollback and Releases Hotfix, Network Now Running Stably on Updated Chain

Odaily reports: The privacy-focused public chain Zano team has stated that in response to the inflation vulnerability discovered last Friday, a hotfix has been deployed, and the network is now running stably on the updated chain. The chain previously rolled back the block height to 3,833,000, erasing 30 days of previously confirmed transaction records.The Zano team stated that third-party wallets, exchanges, and payment service providers must first update their own nodes to the updated chain before they can safely resume transfers of ZANO and Zano-issued assets. Service providers will announce recovery progress through official channels, and recovery procedures for affected users are being prepared.The native asset ZANO has dropped 32% in price this week and 40.6% since the start of 2026. Zano's official X account stated that users can update their iOS, Android, and desktop wallets, and the team will soon release more details on the recovery process. (Bitcoin.com News)

Bitget Attackers Attempted to Transfer Stolen Funds via Cross-Chain Protocol Chainflip But Were Rejected

MistTrack monitoring indicates that a Bitget attacker recently attempted to transfer stolen funds through the cross-chain liquidity network Chainflip, but the deposit was rejected by the relevant broker (Broker). The platform did not freeze the funds, but instead executed a return to the originating address. MistTrack stated it will continue to track the subsequent flow of the stolen funds.

Chainlink Releases CCIP 2.0, Allowing Large Crypto Apps to Customize Cross-Chain Security Verification

Odaily News: Cross-chain protocol Chainlink has released CCIP 2.0, allowing enterprises to add their own security checks for cross-blockchain transfers on top of its default network of 16 operator validators.The upgrade comes after Kelp DAO suffered a $292 million hack in April, an incident attributed to a LayerZero cross-chain bridge setup using a single validator; Kelp DAO subsequently migrated its rsETH token to Chainlink.Chainlink's risk management network no longer operates as a standalone security safeguard, and users who do not add their own validators will rely on one validation network rather than two. (CoinDesk)

DYORSWAP Responds to Fake GIWA Incident: Approximately 766 ETH Transferred Out, Over 200 ETH Already Compensated

DYORSWAP has released an "Official Statement Regarding the Fake GIWA Mainnet 9134 Incident," stating that the incident was not a DYOR contract vulnerability, but rather was caused by a fraudulent network impersonating GIWA Chain 9134. This network had a bridge and batcher similar to OP Stack, deployed on September 27, 2026, at 02:10:59 (UTC+8). Approximately 8.5 hours before deployment, the address received about 0.045 ETH from a ChangeHero-related address. Data shows that a total of 1,335 addresses bridged approximately 767.65 ETH to it, of which about 766.25 ETH was ultimately transferred out from the cross-chain bridge.DYORSWAP stated that it has already used its own funds to compensate affected users with over 200 ETH. Additionally, the team is still tracking the cross-chain bridge deployer, the source of funds, early test wallets, and the subsequent flow of the transferred funds.

THORChain addresses questions regarding the Bitget security incident, emphasizing the permissionless nature of decentralized protocols.

MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.

"Money Laundering Dedicated Network" THORChain Official Cries Foul: As Decentralized and Permissionless as BTC, ETH, and BNB Chain, Not Responsible for Bitget Hack Money Laundering Process, Previously Suspended Services for 39 Days Due to Hacker Attack

Odaily News: Today, THORChain officially posted on X platform stating, "We have noticed the recent Bitget hack and are deeply saddened by it. We can imagine this is a difficult time for everyone in the industry. (However,) THORChain is as decentralized and permissionless as Bitcoin, Ethereum, and BNB Chain. When dealing with known stolen funds, what responsibility should Bitcoin, Ethereum, and BNB Chain bear?" Subsequently, it called out OKX CEO Star and Bitget CEO Gracy.However, crypto community members in the comments pointed out that when THORChain previously suffered an attack, it once suspended services for 39 days, and they are deeply ashamed of the differentiated treatment between the two situations.

OKX Star Responds to THORChain: TSS + Validator Model Is Not True Decentralization

Odaily News: OKX Star posted on X in response to THORChain, stating that he does not believe THORChain's TSS + validator model represents true decentralization. THORChain's validators collectively control the underlying assets in the TSS vault, and funds can be moved once the signature threshold is reached. Therefore, from a custody perspective, it cannot be compared to the underlying consensus mechanisms of Bitcoin and Ethereum, but instead acts as an intermediary between users and native chains. "TSS distributes control among multiple participants, but decentralizing an intermediary does not eliminate the intermediary itself."Previously, discussions arose after some stolen Bitget funds were transferred through THORChain. THORChain responded that it is decentralized and permissionless, just like Bitcoin, Ethereum, and BNB Chain, and stated that if stolen funds were known to flow through Bitcoin, Ethereum, or BNB Chain, what responsibility should those networks bear?

Zano to Roll Back ~24 Hours of On-Chain History Due to Inflation Bug

Odaily reports: Privacy blockchain network Zano has disclosed that an inflation vulnerability involving Gateway Addresses has forced it to plan a rollback of approximately 24 hours of blockchain history, and has urged users to immediately cease all economic activity related to ZANO and Confidential Assets.Zano has promised to compensate for losses caused by the rollback, but has not yet announced the target block height for the rollback, the patched version, the compensation process, the mechanics of the vulnerability, or the amount of unauthorized assets created. Gateway Addresses went live on August 26 with Hard Fork 6. (Bitcoin.com News)

On-Chain Analyst: Bitget User Protection Fund Consists of 5,500 BTC, Valued at $464 Million

on-chain analyst Yu Jin has monitored that the $464 million risk protection fund Bitget claims can cover stolen assets is a total of 5,500 BTC, distributed across 3 wallet addresses.

Blockaid: Meter is under ongoing attacks as the attacker has minted $2.3 million in wrapped MTRG and dumped it.

According to Blockaid, Meter is facing ongoing attacks on BNB Chain. Attackers are exploiting Meter Passport to mint a large amount of wrapped MTRG and sell portions on PancakeSwap. Approximately $2.3 million in unbacked wrapped MTRG has been minted through around two issuance transactions so far, and the attack remains ongoing.

Blockaid: Meter Under Sustained Attack on BNB Chain, Attacker Minted Approximately $2.3 Million in Wrapped MTRG

According to Blockaid monitoring, Meter is currently under a sustained attack on BNB Chain. The attacker exploited Meter Passport to mint a large amount of wrapped MTRG and sold some of the tokens on PancakeSwap. So far, approximately $2.3 million in unbacked wrapped MTRG has been minted through about 2 minting transactions, and the attack is still ongoing.

MemTensor AI Memory Tool Supply Chain Under Attack, Developer Credentials Face Leakage Risk

According to monitoring by blockchain security firm SlowMist (@SlowMist_Team), MemoryOS (PyPI), an AI memory toolkit under MemTensor, and its OpenClaw plugin (npm) were compromised in a supply chain attack. The affected versions ship with embedded cross-platform Go binaries that automatically execute malicious payloads when the package is loaded or imported. Affected versions include MemoryOS==2.0.34 on PyPI, along with plugin versions 0.1.21, 0.1.23, and 0.1.25 on npm. Through this compromise, attackers can exfiltrate sensitive data such as npm/PyPI tokens, GitHub/GitLab credentials, AWS keys, SSH keys, API tokens, and environment variables. Exfiltrated data is sent back to the attacker-controlled infrastructure at skyleen[.]fr, and the compromised npm plugin may also leak user prompt inputs. SlowMist advises users to immediately downgrade the affected packages to their secure versions (downgrade npm to 0.1.20 and PyPI to 2.0.33), terminate any sckit-related processes, block communication with the associated infrastructure, review network activity, and rotate all credentials across affected environments.

Binance Alpha 2.0 will support Nesa (NES) contract replacement, with trading resuming at 16:00 today.

Binance Wallet announced that following a security incident involving the Nesa (NES) token contract, Binance Alpha 2.0 will support NES contract swaps on BNB Smart Chain (BEP20) and provide compensation arrangements for eligible users: first, balances held by users as of 14:51 UTC on August 24, 2026, and maintained through to 04:00 UTC on September 5, 2026, will be swapped to the new contract at a 1:1 ratio; subsequent purchases will not be eligible for the swap and will be refunded separately. Second, users with net purchases of NES between 14:51 UTC on August 24, 2026, and 04:00 UTC on September 5, 2026, will receive an email detailing the specific refund plan within seven working days. Trading of NES on Binance Alpha 2.0 is expected to resume on September 10, 2026, at 08:00 UTC.

The Sandbox Launches SAND Compensation Claims

The Sandbox stated that it will provide full compensation to affected users for the SAND vulnerability incident on Base and BNB Smart Chain that occurred on August 22. Any wallet that legitimately held cross-chain SAND at the time of the snapshot prior to the incident will receive SAND compensation on the Ethereum network at a 1:1 ratio.

SlowMist: Approximately 62.28 BNB Lost in Attack on a Router on BNB Chain

According to Odaily, as monitored by SlowMist, per the SlowMist TI security alert, a Router contract has been exploited due to security flaws in its Swap entry point and uniswapV3SwapCallback, resulting in losses of approximately 62.28 BNB. The Router fails to verify whether the caller is a legitimate V3 Pool, nor does it bind the payer in the callback to the original transaction context. The attacker forged a V3 Pool/adapter and injected a victim's address as the payer, exploiting users' existing ERC-20 approvals granted to the Router to execute transferFrom() and transfer assets. Users who have previously granted sufficient token approvals to this Router may see their approved assets transferred out, even without further interaction on their part.

White-Hat Hacker Withdraws Approximately 4,000 BTC from Liquid Network; Side Chain Suspends Operations

According to an announcement from the official Liquid Network X account (@Liquid_BTC), a suspected whitehat hacker withdrew approximately 4,000 BTC worth around $320 million from a Liquid Federation wallet using a SideSwap PAK (Peg-out Authorization Key). The official statement indicated that the key itself was not leaked, and the Blockstream team is attempting to contact the party through on-chain signed messages. Following the incident, exchanges have paused or are about to pause LBTC deposit and withdrawal services. Bridge nodes have been temporarily shut down, and the Liquid sidechain is currently suspended, unable to submit new transactions. Officials emphasized that other Liquid assets such as USDT, DePix, and RWA remain unaffected by this incident, while Federation members are actively working to resolve the issue to restore normal network operations as soon as possible.

SlowMist: iOS Safari DarkSword Attack Can Steal Wallet Inputs, Zero-Click Trigger with Six-Vulnerability Chain

Odaily News, According to a disclosure by the SlowMist security team, they have detected an attack campaign disguised as a free VPS service, specifically targeting iPhone Safari browsers running iOS versions 18.4 to 18.6.2. The attackers exploited a chain of six vulnerabilities codenamed DarkSword to form a complete attack sequence, covering WebKit remote code execution, sandbox escape, and kernel read/write operations. This allows them to access app container files and keychain data without user awareness, and record keyboard inputs while wallets such as imToken, TokenPocket, or TronLink are in the foreground.The SlowMist team stated that all six aforementioned vulnerabilities have been patched by Apple, and the current attack constitutes reuse of an n-day vulnerability chain. Merely visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen, and device forensics is still required for confirmation. iOS/iPadOS users are advised to upgrade their systems to version 18.7.3 or 26.3 and above as soon as possible.