GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

BNB Chain to Launch Pasteur Hard Fork on August 25

Odaily News: BNB Smart Chain (BSC) has announced that the Pasteur hard fork will officially go live on the mainnet at 10:30 AM Beijing time on August 25 (02:30 UTC on August 25). Node operators are required to upgrade their clients to v1.7.7 in advance.This upgrade includes three improvements—BEP-682, BEP-695, and BEP-675—focusing on enhancing cross-chain security, validator governance mechanisms, and network throughput. Among them, BEP-682 will strengthen the BNB Chain cross-chain bridge verification mechanism, preventing permission bypass risks caused by duplicate signature counting by validators, thereby improving the security of cross-chain asset transfers. BEP-695 optimizes the validator key rotation mechanism, ensuring that old keys no longer retain management privileges after exit, while also fixing potential vulnerabilities related to slashing and governance voting.In terms of performance, BEP-675 reduces the time consumption caused by validators repeatedly executing transactions by optimizing the block construction process. In BNB Chain's internal QANet test environment, this solution increased throughput from 1,237 TPS to 2,324 TPS. While maintaining the 450-millisecond block time and the 100 million Gas block limit unchanged, the average Gas usage per block rose from 46.35 million to 84.15 million.BNB Chain stated that this upgrade is primarily aimed at validators and block builders, designed to provide greater capacity during network peak periods and advance the throughput expansion goals outlined in BNB Chain's roadmap for the second half of 2026.

Data: Ethereum and BNB Chain Share 65,340 High-Risk Addresses, with Associated Losses Exceeding $574 Million

Odaily News - A study published at USENIX Security '26 reveals that researchers identified 65,340 high-risk cryptocurrency addresses involved in abuse on Ethereum and BNB Chain, with associated native token losses reaching 126,982.94 ETH and 17,726.7 BNB. The study estimates that total losses linked to these addresses exceed $574.8 million, of which two newly described active attack vectors directly caused approximately $15.7 million in losses (2.7% of the total). The first category involves contract account misuse and exploitation of deterministic contract addresses; the second leverages EIP-7702 to delegate accounts with exposed keys to malicious code that directly transfers deposits. The research team extracted over 16.3 million unique private keys by mining 63,004 GitHub repositories from January 2015 to May 2025, achieving an overall accuracy rate of 99.11% in detection results. (Cryptoslate)

Nearly 200,000 XRP Stolen, Coreum Cross-Chain Bridge Attacked

Odaily News: The cross-chain bridge connecting XRP Ledger and Coreum was attacked on August 9. The attacker exploited a validation logic vulnerability to steal approximately 199,900 XRP, reducing the bridge's asset balance from roughly 200,400 XRP to 493.5 XRP. The attack did not involve private key leaks and did not target the XRP Ledger protocol itself. The attacker forged deposit operations, causing the bridge system to recognize them as legitimate deposits and triggering the bridge wallet on the other end to send real XRP. On-chain data shows that the attacker completed the fund transfer through 94 multi-signature authorization transactions within 97 minutes. These transactions required signatures from 17 of the 28 relay node keys, allowing the attacker to bypass the bridge's validation mechanism. As of August 11, the Coreum cross-chain bridge remains suspended, and the Coreum Development Foundation has not yet released an official incident report. The XRP mainnet and user private keys remain unaffected and secure.

BNB Chain Announces "Build the Era" Hackathon

BNB Chain announces the "Build the Era" Hackathon, soliciting proposals to build the best AI Agent trading platform on BNB Chain. The hackathon offers over $40,000 in prizes jointly provided by BNB Chain, @TermiX_AI, @PancakeSwap, @alt_layer, @binance Pay, and @AltanaNetwork. Both individuals and teams can register to participate.

SlowMist: npm Supply Chain Under Massive Attack, Over 2000 Malicious Package Versions Published in Keyv Ecosystem

According to monitoring by blockchain security company SlowMist (@SlowMist_Team), its threat intelligence system MistEye detected a large-scale npm supply chain attack targeting the Keyv/Cacheable ecosystem. The attackers published over 2,000 malicious package versions in total, involving core components such as [email protected]. As a widely used key-value storage abstraction library, Keyv supports multiple backends including Redis, SQLite, PostgreSQL, and MongoDB, with weekly downloads reaching approximately 127 million, posing significant downstream supply chain exposure risks. This attack method is highly similar to the previous Shai-Hulud npm worm activity, characterized by high automation and scale. Potential risks include credential theft, environment variable leakage, CI/CD key leakage, remote payload delivery, and lateral penetration. SlowMist recommends security teams immediately investigate and remove affected package versions, upgrade to verified secure versions, review dependency lock files and build logs, monitor suspicious outbound connections, rotate exposed credentials, and rebuild relevant environments from trusted sources if intrusion is suspected.

BitGo Switches Its $7.3B WBTC Cross-Chain Service Provider to Chainlink CCIP

: Crypto infrastructure company BitGo will switch its exclusive cross-chain service provider for $7.3 billion worth of WBTC from LayerZero to Chainlink CCIP. Following the $292 million cross-chain bridge exploit at Kelp, multiple projects have announced migrations from LayerZero to Chainlink, with disclosed migration volumes totaling $14.5 billion. BitGo will use CCIP for future assets while retaining control over token contracts, rate limits, and transfer settings.

LULA Token on BSC Chain Suspected of Attack, Losses Approximately $578,100

According to TenArmorAlert monitoring, its system detected a suspicious attack involving the LULA token on the BSC chain, resulting in losses of approximately $578,100.

Garden Finance Hacked, Loss of Approximately $450,000 USDT

According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.

Robinhood CEO's X Account Hacked, Fake Meme Coin Information Deleted

According to The Block, Robinhood CEO Vlad Tenev's X account was hacked at approximately 17:24 UTC on July 23. Hackers posted claiming to launch "Vladhood ($VLAD)" as the "official mascot of Robinhood Chain," and attached a contract address. The Robinhood Chain blockchain explorer has labeled the token as a "potential scam," and the token has generated approximately 1,868 transactions since deployment. Robinhood officially confirmed later that the account was compromised, the relevant posts have been deleted, and the company is working with the X platform to restore account access.

Taiko: Attack Resulted from Off-Chain Signature Key Leak and Verification Process Gap

Odaily News: Ethereum Layer 2 network Taiko released a post-mortem of the June 21 security incident, stating that the attack resulted from an off-chain signature key leak and a verification process gap. The attacker exploited these to forge proofs and bypass the Prover whitelist, rather than breaking ZK cryptography or smart contracts. The attacker stole approximately $1.75 million from cross-chain bridges and Vaults, but over $11 million in assets were protected, and no user funds were lost. Taiko has fixed the vulnerability, restored the pre-attack state, and resumed operation on July 2; an OpenZeppelin audit confirmed the fixes with no high, medium, or low-risk vulnerabilities identified. The official statement also indicated that the Unzen upgrade, scheduled for August 6, will require ZK proofs for every block to further enhance network security.

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

B² Network suspected of being exploited, attacker transfers 8.591 million B2

: According to on-chain detective Specter’s monitoring, B² Network may have suffered a vulnerability exploit on BNB Chain. The attacker transferred 8.591 million B2, worth $3.86 million, and exchanged them for 5,409 WBNB, worth $3.11 million. The funds were then bridged to Ethereum, and are currently being transferred to Zcash via NEAR Intents. The addresses used for the theft are 0xEc443f7D79835B464FBEAC798d3f92B62d6Ff433 and 0xf977427Ec8e583C55D413061FC205BCD57e8Bf6D.

B² Network Suffers Hacker Attack, Losses Approximately $3.86 Million

According to on-chain analyst Specter, B² Network on BNB Chain suffered a hack, resulting in a loss of approximately 8.591 million B2 tokens (approximately $3.86 million). The attacker swapped them for 5409 WBNB (approximately $3.11 million) and bridged to Ethereum, and is currently transferring the funds to Zcash via NEAR Intents.

GoPlus and Salus Officially Join TermiX Agent.family, Launching On-Chain Security Audit Provider Agent Services

: BNB Chain Agent commercial clearing layer TermiX announced that Web3 security infrastructure GoPlus and smart contract security auditing firm Salus have officially become Provider Agents on the Agent.family platform. They have launched two production-grade security audit services, promoting the autonomous invocation and settlement of "security capability as a service" for AI Agents in on-chain commercial scenarios.GoPlus has packaged its verified token contract deep scanning capability as a standard Provider Agent service. DeepScan conducts comprehensive security checks on token contracts, identifying risk patterns such as Rug Pulls, honeypot scams, contract permission abuse, and trading restrictions, and generates structured audit reports.Salus has launched smart contract auditing and penetration testing services, encompassing formal verification, fuzz testing, machine learning-based vulnerability detection, and manual expert auditing. It covers high-risk vulnerability categories such as reentrancy attacks, access control issues, integer overflows, and DoS attacks. Salus, a seed-stage investment from Binance Labs, is a core security partner within the BNB Chain ecosystem.

Balance Coin Plunges Over 99%, 42DAO Allegedly Hit by $915,000 Attack

Odaily Planet Daily reported that the algorithmic stablecoin Balance Coin dropped from $0.9954 to $0.001358, a decline of over 99%. The stablecoin is the native algorithmic stablecoin of the Balance Protocol, designed to maintain a peg to the US dollar. Blockchain security firm PeckShield stated that the depegging occurred following an exploit of the decentralized autonomous organization 42DAO, which governs the Balance Protocol and its BLC token, resulting in a $915,000 loss. TenArmor reported detecting suspicious attacks involving GemJoin and 42DAO on the BNB Chain.

Midnight:Multiple Exchanges Including Binance Freeze Funds Involved in Cross-Chain Bridge Attack

the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.

Pons responds to front-end authorization vulnerability: Launchpad trading page lacks Multicall3 functionality, only $0.66 worth of NOXA affected

Robinhood Chain launchpad Pons has officially responded to earlier reports about a token authorization vulnerability in its front end, stating that the Pons launchpad trading page does not have any Multicall3 functionality. The Multicall3 feature mentioned in the tweet originated from the previous Debank Chain old version bridge and was released before the Pons launchpad, thus it does not affect launchpad users. It is currently confirmed that only 0.60 NOXA tokens, valued at approximately $0.66, are affected.As a security precaution, Pons recommends that users who previously used the old version bridge revoke token authorizations via revoke.cash. The team is currently working with audit firms to investigate potential risks and has stated that Pons' front-end services will be restored after confirming the absence of any actual vulnerabilities.

Token Pocket Chief Business Officer: Robinhood Founder's Seed Phrase Leaked During Live Stream, Address Now Frozen

Michael, Chief Business Officer of Token Pocket, stated on platform X that Robinhood founder's seed phrase was leaked during a live stream. After gaining control of the address, the hacker used it and associated addresses to heavily purchase the Meme token $1, prompting thousands of investors to follow suit. In a short time, the token's market cap quickly surged from approximately $500,000 to $14 million.Subsequently, the price of the $1 token dropped sharply, with two-hour trading volume reaching around $20 million. After the address was frozen, the hacker quickly moved to the BNB Chain, using the address and its associated addresses to issue a new token. They created trading activity through tactics like wash trading, ultimately dumping the tokens for profit.Currently, Robinhood's RPC has frozen the address, and the node does not allow transactions originating from this address to be packaged, making transfers, purchases, or sales impossible.

TAC Responds to Sharp Price Drop: No Attack, No Internal Sell-Off, Decline Triggered by Chain Reaction of Contract Liquidations

According to official sources, TAC issued a statement regarding the significant price drop in the past 24 hours, stating that the protocol was not attacked, on-chain assets are secure, and the system is operating normally; the team and early investors did not participate in the sell-off, relevant tokens remain in the lock-up and vesting period, and there is no possibility of unlocking at this stage.

BNB Chain Launches New Layer 1 for Agent Trading, Targeting 2027 Mainnet Launch

According to The Block, BNB Chain is building a new Layer 1 blockchain designed specifically for agent trading, targeting transaction pre-confirmation in under 50 milliseconds, and suppressing MEV behaviors such as sandwich attacks by eliminating the public mempool (adopting the TxStream mechanism). The new chain will also reserve block space for oracles, liquidations, and cross-chain bridges via PriorityLane, with a designed throughput target exceeding 100,000 TPS, and supporting sub-second block finality. This chain will become the fourth chain in the BNB Chain ecosystem, connected to BNB Smart Chain via a native bridge, with BSC serving as the settlement hub. The testnet is planned to launch at the end of 2026, and the mainnet is expected to deploy in early 2027.