GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Wyoming Expands Partnership with Chainlink to Introduce On-Chain Reserve Verification for FRNT Stablecoin

According to The Block, the Wyoming Stable Token Committee announced the adoption of Chainlink Proof of Reserve to provide near-real-time on-chain reserve validation for its official stablecoin, Frontier Stable Token (FRNT). The Network Firm will audit FRNT reserves in accordance with AICPA standards, while Chainlink will post verification data on-chain in real time to bridge information gaps between reporting cycles. Previously, Wyoming fully migrated FRNT from LayerZero to Chainlink CCIP last month as its sole cross-chain infrastructure. The committee is also advancing the Chainlink Proof of Reserve Secure Mint feature, which requires verifying that reserves do not fall below FRNT's total supply before minting new tokens to prevent infinite minting attacks. FRNT launched in January this year and is the United States' first government-issued stable token, backed by U.S. dollars and short-term U.S. Treasuries.

FUNVERSE's First On-Chain Game FUN LONGINUS to Launch on Anubis Chain Mainnet on September 1

Odaily News: FUN LONGINUS, the first on-chain game launched by FUNVERSE, will officially go live on the Anubis Chain mainnet at 10:00 UTC on September 1, 2026 (18:00 UTC+8).Originating from a hackathon, FUN LONGINUS is an Eastern martial arts-themed on-chain game built for the Anubis GameFi ecosystem.The game adopts the 24 solar terms as its competitive structure. Each round brings together 24 different addresses, with each player using fLGNS to enter the arena. The execution of matches, determination of results, and final settlement are all handled by smart contracts, ultimately crowning one champion.On August 18, 2026, FUN LONGINUS completed its "Heroes Collective Mint." Based on market prices at the time of writing, the total value of this collective mint exceeded $1.4 million.This mainnet launch marks FUN LONGINUS's official transition from the hackathon prototype, public beta, and collective mint phases into the on-chain game operation stage.

Binance Will Discontinue Support for BounceBit (BB) Mainnet

Binance announced that due to a hack on BounceBit and the project team's decision to permanently shut down the chain, Binance will stop supporting the BounceBit (BB) mainnet. Binance has suspended deposits and withdrawals of BB on the BounceBit mainnet as of 10:00 (UTC+8) on August 20, 2026, and will reopen deposits and withdrawals via the BNB Smart Chain (BEP20) network starting at 15:00 on September 1, 2026. BB will be migrated from the original mainnet to the BNB Smart Chain at a 1:1 ratio. During the migration, spot, margin, futures, and Earn services will remain unaffected.

Yi Lihua: A New Crypto Bull Market Is About to Begin, On-Chain Stocks Unlock New Potential for the Industry

Yi Lihua, founder of LD Capital, stated that over the past decade-plus, the crypto industry has gradually formed a "small world." However, in recent years, industry attention has increasingly been captured by negative content such as smear articles, traffic competition, personal attacks, and fabricated narratives, which has inevitably impacted the sector's reputation. He believes the industry should refocus its attention on innovation and opportunities themselves, stating that "a new bull market is approaching." On-chain finance, particularly on-chain stocks, is unlocking new avenues for imagination, with substantial meaningful developments and wealth-creation opportunities still ahead. Furthermore, compared to the crypto industry, the significantly larger AI sector is equally worth exploring.

Oracle Protocol Switchboard Suspected of Attack, Suspends Multiple On-Chain Services Including Aptos and Sui

Oracle protocol Switchboard issued a statement disclosing a report of a potential overnight attack. The Switchboard team has partnered with relevant projects and security agencies to take measures, suspending its network services on the Aptos, Sui, IOTA, and Movement chains. Currently, there are no similar reports indicating a comparable intrusion attack on the Solana chain. However, for security reasons, official channels recommend that users migrate to alternative oracle solutions as soon as possible, at least temporarily, during the investigation period. The team continues to investigate the incident and will release further details subsequently.

MANTRA Discloses Security Incident Post-Mortem: ~721M MANTRA Tokens Transferred, Chain Offline for 30 Hours

MANTRA has released a complete review of the August 20 security incident. The incident stemmed from an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency, cosmos/evm. Without requiring privileged access, the attacker transferred a combined total of 720,923,967.99 MANTRA tokens from a burn address and a legacy genesis multisig address, amounting to approximately $3.6 million at pre-incident prices.

The Sandbox plans 1:1 compensation, approximately $700K in SAND stolen in bridge vulnerability exploit

blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)

GoPlus: Realio Platform Signing Key Compromised, Approximately 127.9 Million RIO Tokens Transferred

GoPlus Security released a security alert stating that on August 25, realio[.]fund, a project under Realio Network, was attacked. The attacker took control of the platform's signing system and moved treasury and custody wallet assets across Ethereum, BNB Chain, Algorand, Stellar, and the Realio native chain. A total of approximately 127.9 million RIO tokens worth around $6.2 million were affected, with the attacker having cashed out approximately $317,000 so far.

1:1 compensation for legitimate holders prior to the vulnerability incident; The Sandbox will reimburse cross-chain SAND using treasury funds

Odaily News, The Sandbox has released a post-mortem report on the August 22 vulnerability incident. The report shows that attackers exploited vulnerabilities in contracts related to cross-chain configurations on Base and BNB Smart Chain (BSC), stealing 14,742,341.84 SAND from the Ethereum treasury, accounting for approximately 0.5% of the maximum supply, with an estimated economic impact of approximately $1.4968 million, of which about $987,000 was actually retained by the attackers. The Ethereum mainnet and Polygon network were not affected. Until further notice, please do not purchase or send SAND on Base or BNB Smart Chain. Contracts deployed on Base and BNB Smart Chain have been permanently deactivated and will not be reopened. The Sandbox stated that the team has reported the attacker's wallet address to blockchain analysis firms TRM Labs and Chainalysis, and has communicated directly with relevant exchanges. The Sandbox also announced a compensation plan, which will compensate wallets that legitimately held cross-chain SAND on Base or BSC prior to the incident at a 1:1 ratio in Ethereum SAND. Compensation funds will come from The Sandbox treasury, with no new tokens issued. The claim process will open within the next two weeks and remain open for two weeks.

NES holdings inflated to $50 million, Cosmos EVM exploit attacker actually profited about $60,000

According to Odaily, an investigation into the security vulnerability exploit of the Cosmos EVM module reveals that the primary attacker (0x9AE7) purchased $250,000 worth of NES and bridged it to Nesa Chain, exploiting a balance vulnerability to inflate holdings to 200 times their original size, then bridged approximately $50 million worth of NES back to Ethereum. The attacker's initial funding for the wallet originated from Monero. Through multiple wallets, the attacker exchanged NES for ETH on DEXs and deposited the proceeds into centralized exchanges. Due to rapid liquidity withdrawal, most exchanges suffered extreme slippage, and the attacker ultimately sold for only $315,000, netting a profit of approximately $60,000 after deducting costs.

Besu fixes 5 security vulnerabilities, version 26.7.1 released on July 27

Odaily News: Ethereum client Besu has fixed 5 security vulnerabilities discovered by blockchain security firm CertiK in version 26.7.1 released on July 27, and published 4 detailed security advisories on August 14. Vulnerability details were disclosed after a delay to allow node operators to complete upgrade deployments.Jialiang Chang, Director of Security Engineering and Senior Audit Partner at CertiK, stated that the arrangement of releasing patches first and details later provided an 18-day buffer period, allowing node operators to identify affected deployments, test new versions, and coordinate with validators or consortium participants to complete upgrades.The vulnerabilities involve block broadcast handling, caching of future-height consensus proposals, WebSocket subscription limits, and JSON-RPC filter creation. If left unpatched, attackers could exhaust node memory or thread resources, impacting node availability and consensus processing.Using the Chain Scan methodology, CertiK conducted adversarial testing on peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi-node test network, and provided reproducible testing tools to the Besu team. CertiK is updating Chain Scan to expand round-the-clock multi-node testing on public chain networks. (Bitcoin.com News)

The Sandbox cross-chain bridge exploited to mint 14.9 billion unbacked SAND, Coinbase to delist SAND futures

Odaily News: Metaverse gaming platform The Sandbox has confirmed a vulnerability in its cross-chain bridge, allowing attackers to mint unbacked SAND on Base and BNB Smart Chain. Blockchain security firm PeckShield detected on August 21 that two addresses had collectively minted approximately 14.9 billion SAND. The Sandbox subsequently shut down bridging functionality on both networks.The Sandbox stated that the affected assets are bridged assets on Base and BNB Smart Chain, while SAND on Ethereum and Polygon, user wallet assets, and the Ethereum-locked assets backing the token remain unaffected. The proportion of genuinely collateralized assets involved in this incident is less than 0.01% of the total SAND supply.The Sandbox is developing a compensation plan for affected liquidity providers and advises users not to trade SAND on Base or BNB Smart Chain until bridging is restored. Coinbase plans to delist 10 perpetual futures contracts, including SAND, on August 26, with open positions to be automatically settled at that time. (Bitcoin.com News)

The Sandbox confirms SAND cross-chain bridge vulnerability, cross-chain functionality on Base and BSC networks suspended

The Sandbox has officially confirmed and fully secured the recent SAND cross-chain bridge vulnerability affecting the Base and BNB Smart Chain (BSC) networks. Attackers exploited the flaw to mint uncollateralized SAND tokens across both networks, but the impact remains limited, accounting for less than 0.01% of the total SAND supply. SAND on Ethereum and Polygon, along with user wallets, remain unaffected. The Sandbox has since disabled cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable and non-redeemable. The official team advises users to avoid buying, selling, or trading SAND on the aforementioned networks.

MANTRA Chain has resumed block production; user funds remain unaffected.

RWA Layer 1 blockchain MANTRA Chain announced that the vulnerability in the Cosmos-EVM module has been patched, the network has resumed operations and block production, and the incident did not affect user funds. The team will release a complete post-incident analysis report in the coming days.

BounceBit:将永久停止 BounceBit Chain,按攻击前快照在 BNB Chain 重新发行 BB

BounceBit Chain 已于 8 月 20 日 02:36:37(UTC)在区块高度 20,702,857 停止出块。团队决定永久停止 BounceBit Chain,不再进行网络升级,并将在 BNB Chain 上以 BEP-20 代币形式重新发行 BB。新 BB 余额将依据 8 月 19 日 21:02:35(UTC)区块高度 20,697,260 的快照确定,攻击期间被转移的 286,543,148 枚 BB 不会计入重新发行代币。

SlowMist Warns Rust Supply Chain Attack Spans Multiple Legitimate Crates

SlowMist warned that legitimate crates in the Rust ecosystem—[email protected], [email protected], and [email protected]—were targeted in a supply chain attack. A malicious dependency, proc-macro1, was injected into these packages, enabling the download and execution of cross-platform malware during the Cargo build process. The attack poses risks including remote code execution at build time, host information collection, persistence, and browser data gathering.

Nearly $3 Million in Unusual GALA Transfers Detected on GalaChain; Cross-Chain Bridge Suspended

According to reporter Kate Irwin (@kateirwin), GalaChain experienced an anomalous on-chain capital outflow this Tuesday. Approximately 1.99 billion GALA tokens (worth roughly $2.9 million), along with other tokens, were transferred from five major addresses to a newly created wallet, subsequently bridged out and swapped for ETH within approximately one hour. Of these, approximately 1.639 billion GALA (representing roughly 82%) originated from a wallet linked to Gala Games CEO and co-founder Eric Schiermeyer, which simultaneously transferred out other tokens valued at over $500,000. Within hours of the incident, the Gala development team urgently merged a fix commit on GitHub, classifying the event as resulting from a GalaChain EIP-712 unsigned field injection vulnerability. The Gala Ethereum cross-chain bridge has since been halted, with the Solana bridge concurrently deactivated. While officially cited as routine maintenance, users have been unable to access the cross-chain bridge services normally for several consecutive days.

BIP-110 Supporters Propose Restarting Minority Chain with BLAKE2b, Replay Attack Concerns Raised

Odaily News: BIP-110 supporters are discussing a hard fork to change the stalled minority chain's mining algorithm from SHA-256d to BLAKE2b. Transaction history before the fork remains shared by both chains. If transaction and signature rules remain consistent, the same transaction could be replayed on the other chain, creating a replay attack.BIP-110's peak miner support was approximately 2.53%. After the consensus rules took effect on August 8, the minority chain produced only two consecutive blocks before stalling, while the Bitcoin main chain continued operating and widening the block height gap. The BIP-110 proposal was subsequently marked as closed, and supporters shifted focus to discussing the BLAKE2b proof-of-work scheme.Bitcoin Knots plans to add a new signature hash option, but RDTS will still maintain compatibility with Bitcoin Core's existing signature hash types. Regular transactions may continue to be valid on both chains. Users will need to use the new option and rely on wallets or hardware signing firmware that support it to achieve asset separation.Luke Dashjr stated on August 18 that Bitcoin should bear the responsibility for replay protection, calling it "Spamcoin." If the BLAKE2b fork proceeds around September 1, exchanges, wallets, and holders will need to distinguish between cross-chain transactions and chain-specific transactions. (Bitcoin.com News)

Bybit Releases H1 2026 Security Report: Intercepts Over $700M in Potential Losses, Achieves 100% On-Chain Monitoring

Odaily News  Bybit today released its H1 2026 Risk and Security Report. Following the security incident in February 2025, Bybit has comprehensively upgraded its security architecture, transitioning toward a new defense model characterized by earlier detection, faster response, and continuous adaptation. Key highlights from the report are as follows:User Fund Protection: In H1, over 30,000 suspicious withdrawals were intercepted, protecting nearly 20,000 users from potential losses exceeding $700 million. The average initial review time was just 4.7 minutes (with 95% completed within 10 minutes).100% On-Chain Monitoring: Monitoring covers all business-related on-chain activities (including listed tokens, ecosystem contracts, and hot/cold wallets). In H1, 10 security incidents involving listed token projects were handled with zero platform losses; of these, responses to 8 incidents were faster than other major exchanges, and 2 attacks were detected before the project teams themselves. Additionally, approximately $212 million in potentially fraudulent on-chain funds was identified, and over 10,000 malicious addresses were blacklisted.AI-Driven Security Operations: More than 100,000 security alerts were processed. AI-assisted audits identified critical vulnerabilities at an efficiency 3-5 times that of manual efforts; the automated red team platform reduced the time from asset discovery to initial testing to within 24 hours (compared to weeks with traditional manual methods), and the cycle from security assessment to testing was shortened from two weeks to two hours.Accountability and Asset Recovery: In collaboration with law enforcement agencies and blockchain intelligence firms, stolen assets are being traced, and legal action has been taken against North Korea and the Lazarus Group to hold them accountable and recover funds.David Zong, Head of Risk Control and Security at Bybit Group, stated: "The cybersecurity arms race has entered the era of 'minute-level' response. Leveraging AI to strengthen risk control capabilities and ensuring the security of AI systems themselves is our top priority, but critical security decisions remain centered on human judgment."

Maya Protocol Suffers Attack, Losing Approximately $1.7 Million

Maya Protocol founder AaluxxMyth disclosed that the protocol was attacked, with approximately 20 BTC (around $1.4 million) and other assets (around $300,000) stolen. The team has suspended global operations to contain losses and is fixing vulnerabilities to restore trading. Most of the losses resulted from arbitrage and pool fees caused by extreme slippage. The team is communicating with relevant parties and plans to recoup the funds through methods such as investments in Aztec Chain. If the 20 BTC are returned to the pool, the CACAO token price will recover to $0.115. The team also hopes the attacker will accept the bug bounty and return the funds.