GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

ZachXBT Goes Undercover in Lazarus Group-Linked Money Laundering Ring: Invested Nearly $3.5 Million in OTC Trades with Counterparty Using the Alias Jimmy Green

Odaily News: On-chain detective ZachXBT posted on X that he once posed as a client to infiltrate a criminal group suspected of laundering money for the North Korea-backed hacker organization Lazarus Group, and assisted in freezing funds related to the 2025 Bybit attack.ZachXBT stated that after Bybit suffered a $1.5 billion attack in February 2025, he discovered that more than 15 accounts in public Telegram and Discord groups were seeking help processing transactions related to the stolen funds. He subsequently contacted one of the Telegram users using the alias "Jimmy Green" and built trust through multiple transactions. According to his disclosure, on March 6, 2025, he transferred $3.497 million in USDC to an Ethereum address for a USDC-to-TRON-chain USDT exchange transaction with the counterparty. The source of gas funds for that address can be traced back to the Bybit attack funds and was publicly flagged as a Bybit attack blacklisted address.ZachXBT said that in subsequent communications, the counterparty revealed that their team had been involved in processing the stolen Bybit funds and disclosed in advance that the funds would be moved across chains including Solana. By matching transaction timing, amounts, and on-chain data, he identified a wallet cluster involving more than $12 million in Bybit attack funds, with fund paths spanning multiple networks including BTC→ETH→SOL→TRON. Approximately 442,000 USDT was frozen by Tether, and the group also attempted to launder money through Uniswap liquidity pools and low-liquidity tokens. Additionally, the counterparty disclosed having helped other clients process approximately $3 million in fraudulent proceeds, and ZachXBT traced the related funds to wallets associated with the sanctioned Huione Guarantee.ZachXBT revealed that in this investigation, he initially invested $3.497 million and bore a loss risk of approximately 5% per transaction. The intelligence ultimately obtained was provided to relevant investigative agencies and law enforcement authorities at the earliest opportunity. Since 2022, he has assisted in freezing over $75 million in funds related to North Korea-linked incidents.

Ostium Unveils Compensation Plan for July Exploit, Over 90% of Affected Wallets to Receive Full Reimbursement

Odaily — Ostium has released an update on the July 15 exploit and a recovery plan for OLP holders. Ostium stated that the attack resulted in approximately $23.75 million being withdrawn from the Ostium Liquidity Pool (OLP), and available evidence suggests the attack may have been carried out by a nation-state actor. As of now, 649,967 USDC has been recovered, and the remaining vault assets currently held by affected users are worth approximately 30% of their pre-incident OLP positions.Ostium launched its recovery portal today and took a snapshot of OLP balances at the time of the incident, identifying a total of 3,666 affected wallets. Of these, 3,321 wallets — or 90.59% — are eligible for full compensation of verified losses through the Phase 1 plan. Users with losses of 1,000 USDC or less can directly claim an equivalent amount in USDC; users with losses exceeding 1,000 USDC may choose to claim 1,000 USDC and forfeit the remaining recovery allocation, or participate in the Phase 2 proportional recovery plan.Phase 2 funding will primarily come from subsequent recovery of attacker funds and a share of Ostium protocol revenue, with the specific revenue share ratio and related arrangements to be announced by October 30.As previously reported, Ostium's off-chain infrastructure was hacked on July 15, resulting in approximately 23.75 million USDC being withdrawn from the OLP vault.

$388 Million in Crypto Assets Stolen, Bitget CEO Says Full Recovery Unlikely

Odaily News — Gracy Chen, CEO of cryptocurrency exchange Bitget, said the company is not optimistic about recovering the $388 million in crypto assets lost in last week's security incident. Citing the Bybit hack in 2025 as a reference, she noted that approximately one year after that incident, only about 3.5% of the stolen funds had been frozen, and that this does not equate to a completed recovery.Bitget has set up a bounty program offering 5% rewards for frozen funds and recovered funds respectively. The NEAR Intents team said it has intercepted over $50 million in assets related to the attack and frozen approximately $500,000. Tether and Circle have blacklisted the relevant wallets, freezing $318,000 worth of USDT and USDC.Gracy Chen stated that preliminary investigations indicate the attack may match VPN addresses used by North Korea-linked groups, but Bitget has not yet fully ruled out the possibility of an insider job. Bitget has resumed withdrawals in phases, starting with Bitcoin transactions on Monday and continuing with ETH transactions on Tuesday. (Cointelegraph)

Slow Mist's Cosine Talks About THORChain: Decentralization Is Not Just a Slogan, and "Decentralized, No Right to Interfere" Should Not Be Used to Respond to Industry Security Incidents

Slow Mist's Cosine posted on X platform, stating that the Bitget hack incident has spread widely, involves a huge amount of funds, and the related funds were quickly linked to North Korean hackers. Institutions such as Circle and Tether promptly assisted in freezing the related funds, with Circle freezing the USDC held by the hackers.Regarding THORChain, Cosine pointed out that when THORChain itself previously suffered a hack, it also quickly intervened in its so-called "decentralized" platform; but this time, when facing a major industry security incident, it responded on the grounds of being "decentralized and having no right to interfere," likened itself to Bitcoin and Ethereum, and continued to earn fees from the hackers' large cross-chain transactions.He stated that decentralization should not just be a slogan. After major security incidents occur, the key is to distinguish which issues need to be solved jointly by the industry. He also believes that platforms such as THORChain should not be easily mentioned in the same breath as Bitcoin and Ethereum, as there are clear differences in the degree of decentralization and mechanisms among different systems.

Bitget Asset Recovery Bounty Program Launched: 5% Reward Each for Freezing and Recovering Attacker Funds

Bitget CEO Gracy Chen thanked Circle and Tether for their swift action. The Bitget Asset Recovery Bounty Program has now been launched, offering a 5% reward respectively to participants who assist in freezing the attacker's funds and recovering the assets, and calls on exchanges, security researchers, and on-chain investigators to participate.

Bitget Stolen Funds Tracking: Circle Has Frozen Nearly 100,000 USDC on Linked Addresses; 218,000 USDT Remains Transferable

According to on-chain detective SomaXBT, Circle has frozen 99,989.91 USDC in an address associated with the Bitget hacker, while approximately 218,000 USDT at the same address remains unfrozen. According to prior on-chain tracking, this address shares a multi-hop fund connection with Bitget's initial stolen funds address. The transferred USDC and USDT remained inactive for over 2.5 hours. The community had previously publicly called on Circle and Tether to freeze the relevant assets. Circle has now taken the lead in executing the action, and SomaXBT subsequently urged Tether to follow suit.

Bitget Security Incident Response Contest: Circle Quickly Freezes 100,000 USDC in Address Linked to a Hacker, Tether Yet to Take Corresponding Action

on-chain analyst tanuki42 disclosed that address 0xe07 holds 100,000 USDC and 218,000 USDT originating from the initial address of the stolen Bitget funds. These funds had been dormant for over 2.5 hours before the analyst publicly called on Circle and Tether to freeze the assets. At around 5 PM, crypto researcher SomaXBT posted that Circle had frozen the USDC assets and called on Tether to follow suit. As of press time, Tether has yet to respond.

Bitget Security Incident 12-Hour Progress Report: Cold Wallets Secure, No Commitment to Withdrawal Recovery Timelines That Cannot Be Fulfilled

Bitget CEO Gracy Chen posted a 12-hour progress report on the security incident on X, including:1. Affected assets include ETH, XRP (largest single-chain loss), BNB, AVAX, USDT, USDC, and other tokens. Affected chains include: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. All on-chain cold wallets have been confirmed secure and unaffected.2. All foundations of the affected chains have been contacted, and some foundations have confirmed the freezing of the hacker's wallet addresses.3. Based on IP behavioral characteristics and on-chain analysis, the attack methodology is highly consistent with known patterns of North Korean hacker groups. Relevant authorities have been notified, and full cooperation is being provided for a global investigation.4. Bitget Wallet (decentralized wallet) operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it. Bitget Wallet assets are completely safe.5. Transparent disclosure regarding the platform's financial status: In addition to over $464 million in protection funds (all held in publicly verifiable wallet addresses), Bitget's own assets exceed $1 billion. User funds are covered at a 1:1 ratio, and all data can be verified on-chain.6. Regarding withdrawal recovery timing: The goal is to achieve full recovery as soon as possible. Once a specific time window is confirmed, an announcement will be made immediately. No commitment will be made to timelines that cannot be fulfilled.

Latest Data: Top 3 Stolen Assets from Bitget Are XRP, ETH, and USDT, with XRP Losses Exceeding $157 Million

Odaily News: According to LookonChain monitoring, the breakdown of assets stolen from Bitget is as follows:102.93 million XRP (approximately $157.48 million);31,890 ETH (valued at $85.75 million);34.75 million USDT (approximately $34.75 million);21.05 million USDC ($21.05 million);19.67 million USD₮0 ($19.67 million);3,000 XAUt (equivalent to $12.82 million);12,719 BNB (valued at $9.88 million);821,012 AVAX (valued at $8.38 million);20.59 million $TRX (approximately $7.07 million).

Stolen assets at Bitget involve 9 types of tokens, with XRP valued at up to $157 million.

According to Lookonchain data, the assets stolen in the Bitget incident comprise 9 different token categories, totaling approximately $356.9 million in value. Of these, approximately 102.93 million XRP (worth around $157.48 million) represents the highest-valued category, alongside 31,890 ETH (approximately $85.75 million). The remaining stolen assets include approximately 34.75 million USDT ($34.75 million), 21.06 million USDC ($21.06 million), 19.67 million USD₮0 ($19.67 million), 3,000 XAUt ($12.82 million), 12,719 BNB ($9.88 million), 821,000 AVAX ($8.38 million), and 20.59 million TRX ($7.07 million).

Payy confirms Ethereum bridge contract was hacked, with losses of approximately $1.8 million.

Privacy stablecoin payment network Payy Network has confirmed that its cross-chain contract on Ethereum was hacked, resulting in the theft of its entire balance. The investigation is ongoing, and all Payy Network transactions have been suspended, including deposits, withdrawals, transfers, and card transactions. Payy has notified law enforcement authorities and is collaborating with multiple incident response organizations. Previously reported, according to monitoring by Specter Investigation, Payy Network was suspected to have been hacked, with approximately 1.8 million USDC transferred out.

Duelbits Hot Wallet Suspected Private Key Leak, Approximately $4.2 Million in Assets Stolen and Transferred

According to Scam Sniffer (@realScamSniffer), Duelbits' hot wallets on Ethereum, BSC, and Tron are suspected of having leaked private keys, with approximately $4.2 million in assets flowing to newly created addresses. The transferred assets include 836 ETH, 1.62 million USDT, 97,000 USDC, 209 BNB, and 192,000 TRX, with most of them already converted to ETH. The hacker's EVM address is 0xa77e24fe29d16e051e487ef4ea7b056cb05aef76.

Approximately 1.8 million USDC was transferred away, privacy stablecoin payment network Payy Network suspected of being attacked

according to monitoring, the attacker initially obtained seed funding through the privacy protocol Railgun, then swapped the stolen USDC for ETH and distributed the funds across 3 addresses.

Cosmos Hub Resumes Block Production, Neutron Attacker Wallet Transfers 1.23 Million ATOM

According to The Defiant, Cosmos Hub resumed operations after ceasing block production for 24 hours and 48 minutes. The Neutron attacker purchased voting power for 20,199 USDC and completed staking just 12 minutes before an expedited proposal expired; the relevant wallet subsequently transferred 1.23 million ATOM.

Loss of approximately $3.5 million, Nostra hit by oracle attack

Odaily News: Nostra suffered an oracle attack. The manipulated NSTR oracle price allowed a single account to borrow approximately $3.5 million worth of ETH, STRK, USDC, USDT, WBTC, and DAI on Nostra's Starknet money market using NSTR as collateral. The attacker subsequently bridged approximately $1.92 million of the stolen funds—234.57 ETH and 1.3 million DAI—to Ethereum.

Ampleforth Faces Malicious Governance Proposal Attack, $2.5 Million USDC Treasury Funds at Risk

The GoPlus Chinese community released a security alert stating that on September 12, a newly activated external account address submitted a malicious governance proposal to Ampleforth. Under the guise of applying for funding for completed work on the SPOT ecosystem analytics tool, the proposal attempted to transfer 2.5 million USDC from the treasury to the proposer themselves, an amount that nearly comprised all of the treasury's liquid funds.

738,600 USDC Transferred Out, Hyperliquid User Account Compromised with Over 10,000 HYPE Unstaked

Odaily News – A Hyperliquid user's account was compromised through unauthorized access, with approximately 738,600 USDC transferred out and an additional 10,287 HYPE unstaked. The affected account is identified by a specific address, with some of the stolen funds flowing to an address suspected to be associated with Bitget. As of the time of verification, the 10,287 HYPE remained in the staking balance and had not yet entered the withdrawal queue. If the attacker proceeds to initiate cWithdraw, the affected assets would be further transferred after a 7-day waiting period. In two similar recent cases, staked assets were stolen a second time due to the lack of a user-triggerable emergency pause mechanism, resulting in losses exceeding $1.1 million. Relevant recommendations include introducing a Guardian or Recovery mechanism that users can pre-enable, which would only temporarily pause withdrawals, transfers, and authorization changes. The pause would expire automatically, and restoration would require a time lock and evidence review, with all actions recorded on-chain.

Tectonic hit by oracle manipulation attack, $120.4 million in assets stolen

According to the post-incident report released by Tectonic, the Cronos blockchain lending protocol Tectonic suffered an oracle manipulation attack at 12:49 UTC on August 30, 2026. By repeatedly borrowing and re-collateralizing TONIC tokens 98 times within a single transaction, the attacker drove up the TONIC collateral price by approximately 195 times. Leveraging this artificially inflated value, they subsequently extracted assets with a nominal value of $120.4 million from nine lending markets, spanning USDC, USDT, WBTC, WETH, and other assets. The attacker then bridged the stablecoins to Ethereum and converted them to ETH, while selling the remaining assets for CRO on the Cronos chain before withdrawing them. Approximately $9.19 million in total successfully escaped before the network halt. At 14:32 UTC, Cronos validators emergency-paused the network, rolling back the on-chain state to pre-attack conditions and restoring assets still held on Cronos. Currently, Tectonic's supply and borrowing functions remain suspended, while withdrawal and repayment capabilities continue normally. Tracing efforts for the stolen funds are being coordinated by blockchain forensics firms, law enforcement agencies, and stablecoin issuers, with freeze requests already filed with the relevant issuers.

Loss of approximately $104,000: Secured Finance lending market suffers attack

Odaily News: The decentralized lending protocol Secured Finance's lending market was attacked on September 5, resulting in a loss of approximately $104,000. The root cause was that collateral was priced based on the average execution price of the order book for the current block, allowing attackers to influence the price through self-trading, causing fraudulent lending positions to be counted as valid collateral. The attacker initially deployed the contract but did not execute immediately, then used flash loans and self-trading to inflate the price and withdraw USDC. The original attacking wallet was rolled back due to insufficient gas fees; approximately 48 seconds later, the general-purpose sandwich bot coffeebabe took about 0.9 WBTC, worth approximately $72,000, and transferred about 28.8 ETH of it to the ultra sound money builder, keeping only about $29 for itself. Subsequently, another bot took part of the USDC.

Bitcoin fork asset BTCB2 once hit $1,799, with a fully diluted valuation of $20.9 billion calculated at a price of $1,000

Odaily News: Bitcoin fork asset BTCB2 hit an all-time high of $1,799 on September 5. Over the past 4 hours, its price has fluctuated between 750 and 1,000 USDC; the Neoxa USDC market recorded a 24-hour trading volume of approximately $1 million.BTCB2 originated from a chain split that occurred on August 8, 2026, at block height 961,632. The network subsequently changed its proof-of-work algorithm to Blake2 and reduced block size, and it can now be mined using Blake2-compatible ASIC miners.Neoxa Exchange and Nonkyc.io have listed BTCB2, with the former offering BTC, USDC, and USDT trading pairs, and the latter offering a USDT trading pair. Both platforms have limited liquidity, and CoinMarketCap and CoinGecko have not yet listed the asset.Based on a BTCB2 price of $1,000, its fully diluted valuation stands at approximately $20.9 billion. Since UTXOs need to be split from Bitcoin first, transactions may otherwise be vulnerable to replay attacks; the network's hash rate has risen by 30.41% over the past 7 days, reaching approximately 5.1 PH/s. (Bitcoin.com News)