GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

BitMart Founder Refutes Withdrawal Blockage and Unpaid Salary Rumors, Exchange to End Trading on August 26

Odaily News: Sheldon Lee, founder of cryptocurrency exchange BitMart, stated that a post on X claiming users were unable to withdraw funds and that some employees had not received their July salaries is a "fabricated rumor," adding that the exchange's Chinese-language account had been hacked. Critics, including users and on-chain investigator ZachXBT, have demanded that BitMart resume withdrawals or undergo an independent third-party audit. BitMart is gradually winding down operations, with the final trading day set for August 26. Troubled investment firm Echo Base said it had proposed a funded restructuring plan to BitMart but received no response. The firm warned that resolving a large volume of customer claims may require proceedings through the courts. (CoinDesk)

Compound Finance Approves Record $52 Million Budget, Pivots to Institutional Clients

Odaily News: Decentralized lending protocol Compound Finance has completed a leadership overhaul and approved a record $52 million budget. The protocol's total value locked has fallen from a peak of $12 billion in 2021 to $1.2 billion, and it is now seeking to restore growth. Compound Finance is pivoting to serve institutional clients, developing real-world asset products, partner integration solutions, and credit infrastructure to meet the compliance and technical standards of traditional finance. Industry executives say Compound Finance's new leadership team and substantial budget align with the broader shift within the decentralized finance sector toward serving financial institutions. The sector's overall assets had previously declined due to market weakness and security breach incidents. (CoinDesk)

Israel's largest crypto brokerage, Bits of Gold, suffers data breach affecting approximately 200,000 customers

Odaily News: Bits of Gold, Israel's largest crypto brokerage, stated that hackers obtained the personal information of approximately 200,000 customers through a data breach at a third-party data analytics service provider. The compromised information includes names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details, and public wallet addresses, but does not include funds, passwords, private keys, or ID scans. The incident is part of a recent wave of data breaches in the crypto industry, following similar incidents at SafePal and Trezor, which were also compromised through breaches at external vendors. (CoinDesk)

Over 1,700 Unlicensed Crypto Platforms Ordered to Cease Operations, Scammers Lure Users to Migrate Assets After EU MiCA Takes Effect

Odaily News: Following the full implementation of the EU's MiCA regulation on July 1, over 1,700 unlicensed crypto platforms have been ordered to cease operations and guide users toward licensed platforms; currently, only 323 companies hold valid authorizations. Approximately 10 million users need to migrate their assets, and scammers are taking advantage of this by impersonating regulators and licensed exchanges, sending fake migration notices to lure users into transferring assets to fraudulent platforms. The French Financial Markets Authority (AMF) stated that scammers have been posing as its employees to defraud funds under the guise of collecting "management fees." The European Securities and Markets Authority (ESMA) confirmed that its identity and logos have been misused. The Dutch Authority for the Financial Markets (AFM) warned that migration from unlicensed exchanges has itself become an attack surface, advising users to verify service providers through ESMA's official register and to remain vigilant against unsolicited contact requesting fund transfers.

The S&P 500 added $2.1 trillion in market cap in a single month, approximately equal to the total market cap of the entire crypto market.

According to CoinDesk, the S&P 500 index has risen 3.12% this month, adding approximately $2.1 trillion in market value (equivalent to the total market cap of the entire crypto market), reaching a record high total market cap of $70.5 trillion, but Bitcoin has only risen about 2% this month, hovering near $64,600. Analysts point out that this round of stock market rise is mainly driven by AI and semiconductor individual stock narratives, rather than a broad-based recovery in risk appetite at the macro level, and Bitcoin lacks direct beneficial exposure to this. Meanwhile, the crypto market also faces multiple internal pressures: the Coldcard platform suffered a $120 million exploit, the prospects of the "Clarity Act" remain uncertain, MicroStrategy has reduced its BTC holdings for three consecutive months, and stablecoin supply continues to shrink—USDT's market cap dropped from $190 billion in April to $183 billion, and USDC's dropped from $79.5 billion to $72 billion.

Coldcard Hacker Wallet Becomes "Blockchain Message Wall," Holding Over $36 Million in Stolen BTC

According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.

Bitcoin Implied Volatility Drops to Two-Month Low, Coldcard Hack Fails to Trigger Market Panic

According to CoinDesk, the 30-day implied volatility index BVIV, which measures expected volatility in the Bitcoin options market, has continued to decline, now falling to 36%, the lowest level since May 31, significantly down from the high near 60% in early June. Recent influencing factors include the Coldcard wallet attack incident involving tens of millions of dollars, weak institutional demand, and uncertainty in the regulatory and macroeconomic environment, but there are no obvious signs of panic in the market. However, volatility has mean-reverting characteristics. When the indicator falls to historical lows, a rebound often follows. Currently, BVIV has approached levels that have previously formed support multiple times. If volatility rebounds quickly in the future, it may be accompanied by a significant directional move in Bitcoin; whether up or down, traders need to remain vigilant.

Cryptocurrency May Become Primary Target of Quantum Computing Attacks, Governance Speed Poses Greatest Risk

According to CoinDesk, Eddy Zervigon, CEO of quantum computing security infrastructure company Quantum Xchange, stated that cryptocurrencies, due to their decentralized nature, will become the "canary in the coal mine" for quantum computing attacks—that is, the area where vulnerabilities will be exposed first. Latest assessments by Google researchers show that the number of physical qubits required to break Bitcoin's elliptic curve encryption has decreased 20-fold compared to previous estimates, and multiple institutions have brought forward the expected date of "Q-Day" (the day quantum computers can break existing encryption systems) to 2029. Deutsche Digital Assets pointed out that the real risk lies not in the encryption technology itself, but in the speed of governance—Bitcoin upgrades require 90% miner consensus, which has historically triggered hard forks (such as the 2017 SegWit upgrade leading to the birth of Bitcoin Cash), whereas traditional financial institutions only need a board resolution to complete encryption infrastructure migration. Additionally, experts caution that the quantum threat is not a binary event that "arrives suddenly on a certain day"; even if quantum computers require months to crack data, as long as the cracking is completed while the data is still valuable, the threat is established.

Cardano wallet SecondFi announces shutdown after hack attack

According to CoinDesk, the Cardano wallet SecondFi was attacked due to a vulnerability in its transaction signing software. A total of 16.1 million ADA (approximately $2.4 million) across 374 wallets was stolen, and the platform has announced permanent closure. The vulnerability allowed attackers to derive private keys from transaction data visible on-chain. The Cardano network itself was not affected, nor were hardware wallet users. An investigation by Groom Lake, a blockchain intelligence company hired by EMURGO, revealed that the primary attackers were sophisticated and well-funded. Some indications point to North Korea's Lazarus Group, but this has not yet been officially confirmed. SecondFi plans to release a wallet export tool in early August and launch a zero-knowledge recovery portal later in the month. EMURGO has established an asset recovery wallet, with the specific distribution time to be determined.

Algorithmic Stablecoin Balance Coin Suffers Oracle Attack, Plummets 99%

According to CoinDesk reports, algorithmic stablecoin Balance Coin suffered an oracle price manipulation attack on July 22. The coin price plummeted from near the $1 peg to about $0.0014, a drop of over 99%, and the nominal market cap of about $3.5 million nearly went to zero. According to analysis by security firm SlowMist, the attacker fed abnormally low false Bitcoin prices into the protocol, bypassing price rationality checks and liquidation delay mechanisms. They forcibly liquidated multiple ineligible collateral vaults in a single transaction, subsequently exchanged the acquired collateral for arbitrage, and ultimately profited about $912,000 from the protocol governance entity 42DAO.

Ethereum Foundation: AI Discovers Vulnerability That Could Cause Validator Nodes to Go Offline, But Manual Verification Still Required

According to CoinDesk, the Ethereum Foundation recently disclosed that its security team used AI agents to test the software running on Ethereum validator nodes and successfully discovered a vulnerability that could be triggered remotely, causing node crashes. However, researchers emphasized that amidst the large volume of security reports generated by AI, manual review remains a key step in distinguishing real vulnerabilities from false positives. Reportedly, the vulnerability discovered resides in the Ethereum network message propagation protocol gossipsub, where attackers can remotely trigger the node software into an abnormal computation state, causing the program to crash and shut down, taking the validator node offline until the operator manually restarts it. The vulnerability has been fixed and registered under the number "CVE-2026-34219". Nikos Baxevanis, a member of the Ethereum Foundation Protocol Security Team, stated that the truly surprising aspect of this incident was not the AI's ability to discover vulnerabilities, but the significant amount of time the team spent distinguishing which vulnerabilities were real and which were merely plausible "hallucinations".

Serious Vulnerability Exposed on Aptos Blockchain, $70 Billion in Assets Once Faced Systemic Risk

According to CoinDesk, researchers at blockchain security company Hexens discovered an "expired cache" type confusion vulnerability in the Aptos blockchain Move virtual machine. Attackers require only about $3,000 in server costs to launch attacks in a simulated environment with a success rate of nearly 90%, without needing validator privileges or internal knowledge. Researchers ran approximately 20 attacks in simulated tests, succeeding 17-18 times, and verified the potential ability to control management permissions of cross-chain protocols such as LayerZero, Wormhole, and USDC CCTP. Hexens assessed that the vulnerability directly threatens protocols on the Aptos chain such as DeFi, stablecoins, and liquid staking, involving assets in the low single-digit billions of dollars; if spread through paths such as cross-chain bridges, stablecoin minting, and centralized exchanges, the systemic risk exposure could reach up to $70 billion. The Aptos team completed the fix and deployed it to the mainnet within hours after receiving the vulnerability report on February 25, and currently no user funds have been compromised.

Ukraine Seizes $8.3 Million in Crypto Assets, Potentially Paving the Way for a Strategic Crypto Reserve

OdailyOdaily reports that the Prosecutor General's Office of Ukraine stated it has, for the first time, transferred approximately $8.3 million worth of USDT crypto assets into the national asset management system, marking the country's first official takeover of seized crypto assets. The funds originate from an investigation into an international hacking group, which is alleged to have laundered money through high-value real estate and other assets. The assets were received by the Asset Recovery and Management Agency (ARMA) of Ukraine, with the transfer completed pursuant to a court order.Officials stated that this operation marks a significant step for Ukraine in the regulation and management of crypto assets, and aligns with ongoing discussions regarding the establishment of a strategic crypto reserve. Previous data indicates that Ukraine ranked among the top in Europe in terms of crypto transaction volume between 2024 and 2025.However, the relevant assets are currently in a "custodial" state and have not been legally forfeited; subsequent judicial conviction procedures are still required. Analysts believe that the mechanism of this move is similar to the path of the United States using criminally forfeited crypto assets to build a potential strategic reserve. (CoinDesk)

Aave Founder Responds to Payward Acquisition Rumors: Will Not Sell AAVE at a 70% Discount

Aave founder Stani Kulechov has responded to reports suggesting Kraken's parent company Payward is interested in acquiring a 15% stake in the Aave protocol, stating that AAVE is "not going to be sold at a 70% discount."Prior reports from CoinDesk indicated that Payward was in talks to acquire a 15% stake in Aave at a valuation of $385 million. If calculated at this valuation, it would represent only approximately 30% of AAVE's fully diluted valuation, significantly below the market valuation.In a post on X, Kulechov stated that the relevant reports were not entirely accurate. He did not completely deny the possibility of Aave Labs selling a portion of its held AAVE tokens, but noted that Aave Labs does have a certain allocation of AAVE, and that multiple market participants have discussed purchasing either directly or indirectly, or engaging in deeper collaboration centered around long-term partnerships.Aave is the largest decentralized lending protocol on the Ethereum ecosystem. Kulechov stated that Aave currently generates an annualized revenue of approximately $134 million, with the relevant revenue flowing to the Aave DAO. He has also previously proposed a governance plan to redirect revenue from Aave Labs, the protocol, and its products to the Aave DAO and token holders.These rumors emerge at a time when Aave is experiencing certain pressures. Following the Kelp DAO incident in April, Aave's TVL saw a significant decline. Although Aave itself was not directly attacked, the KelpDAO cross-chain bridge attacker utilized Aave to convert the stolen rsETH into other assets.

Standard Chartered Bank: Aave is expected to rise to $3,500 by 2030, an increase of approximately 50x from its current price.

According to CoinDesk, Geoff Kendrick, Head of Digital Asset Research at Standard Chartered Bank, released a report initiating coverage of the decentralized lending protocol Aave, with a target price of $3,500 by end-2030—approximately 50 times its current price of around $70—and expects Aave to outperform both Bitcoin and Ethereum. Kendrick stated that Aave has recovered from the April 2026 KelpDAO rsETH bridge vulnerability incident, during which attackers used approximately $290 million worth of stolen tokens as collateral to borrow real assets on Aave, exposing the protocol to up to $230 million in potential losses. Assets have now begun flowing back onto the platform, and Aave’s dominant position in on-chain lending remains solid. Looking ahead, Standard Chartered forecasts that the value of tokenized assets actively used in DeFi applications will grow 37-fold by 2030. Aave—whose revenue model is directly tied to lending activity—is poised to benefit directly. Additionally, Aave’s Horizon initiative (enabling tokenized real-world asset lending in permissioned environments) and the potential relaunch of its token buyback program are viewed as key catalysts.

Aave Founder Calls Protocol "Resilient" Despite $8.45 Billion Deposit Run Exposing Risks

in April this year, KelpDAO's LayerZero bridge was exploited in a $292 million vulnerability attack, triggering an $8.45 billion deposit run on Aave within 48 hours, marking the largest capital outflow event in decentralized finance (DeFi) history. Aave founder Stani Kulechov stated that the design of Aave V3 withstood the market test, demonstrating the network's "resilience." However, independent data indicates that Aave's survival primarily relied on $300 million in emergency rescue, including a 25,000 ETH guarantee from the Aave DAO and a personal injection of 5,000 ETH (approximately $8.4 million) by Kulechov.Kulechov attributed the vulnerability to third-party infrastructure rather than core smart contracts. However, analysts pointed out that this incident exposed deficiencies in Aave's risk architecture and insurance mechanisms, leading the platform to incur significant bad debt (approximately $123.7 million in wETH). To prevent future bridge failures from triggering systemic bank runs, Aave V4 will adopt a modular "hub-and-spoke" architecture, enabling local risk auto-adjustment and collateral freezing. (CoinDesk)

Analysis: AI Will Accelerate Quantum Computing Threats, Crypto Industry May Enter an Era of Persistent Security Arms Race

multiple blockchain and post-quantum cryptography researchers have warned that artificial intelligence (AI) is accelerating the development of quantum computing and could potentially impact the security systems of mainstream blockchains, including Bitcoin and Ethereum, earlier than anticipated.Alex Pruden, CEO of Project Eleven, a firm focused on quantum-resistant infrastructure, stated that the combination of AI and quantum computing is fundamentally reshaping the future security landscape. "People will no longer be able to rely on existing security assumptions as they have in the past," he said.Researchers point out that AI is already being used to optimize quantum error correction, which is one of the key technical bottlenecks in the development of quantum computing. Illia Polosukhin also noted that AI has been accelerating scientific breakthroughs for years, and in the future, there may even be a circular acceleration effect where "AI helps build the next generation of quantum computers."One of the industry's biggest current concerns is the "Harvest Now, Decrypt Later" strategy, where governments or advanced attackers begin mass-collecting encrypted data now, waiting to decrypt it all at once once quantum computing matures. Polosukhin warned that if quantum computers become viable within a few years, "most of today's important data on the internet could be decrypted in the future."Given that most blockchain networks and internet infrastructure currently rely on elliptic curve cryptography (ECC), a sufficiently powerful quantum computer could theoretically derive a private key from a public key, directly breaking wallets and on-chain systems. Simultaneously, AI itself is strengthening hacking capabilities. Pruden stated that AI models are becoming increasingly adept at discovering software vulnerabilities and cryptography implementation flaws, and may even be able to crack some encryption algorithms directly in the future.However, AI is also being used by developers for code auditing, formal verification, and testing post-quantum security systems, creating a "long-term security arms race" with simultaneous upgrades on both the offensive and defensive sides. Researchers believe the most significant change brought by AI and quantum computing together is that the core assumption of "long-term cryptographic reliability" in the digital age is being challenged. Future security systems may shift from "static upgrades" to continuous dynamic evolution. (CoinDesk)

Data: ETH lending protocol TVL has dropped from its year-to-date high of $32 billion to $23 billion.

According to CoinDesk, the total value locked (TVL) in ETH lending protocols has declined from a year-to-date high of $32 billion to $23 billion—a drop of approximately 28%. The oracle vulnerability incident involving KelpDAO triggered a market confidence crisis, and combined with overall bearish market sentiment, led to roughly $9 billion in outflows from the DeFi lending sector.

Elliptic CEO: Cryptographic security is evolving into an AI arms race, and compliance teams struggle to keep up with transaction volumes at machine speed

According to CoinDesk, Simone Maini, CEO of blockchain analytics firm Elliptic, stated that the biggest emerging risk to crypto security is not larger-scale hacking attacks, but rather AI-driven financial activity operating at a speed and scale that human compliance teams cannot keep up with. As AI lowers the barriers to hacking, scams, and fraud, security firms like Elliptic are responding by deploying AI agents to analyze on-chain data in real time—sparking an automated arms race between adversaries and defenders. Maini noted that current compliance systems remain heavily reliant on manual review, and the global pool of compliance analysts specializing in digital assets is simply insufficient to meet future demand. Elliptic has raised $120 million in funding—including from Nasdaq and Deutsche Bank—to build an “agent-based compliance system” that leverages AI to automate transaction monitoring and investigation workflows, thereby reducing the cost per alert and per investigation.

Lombard Gradually Phasing Out LayerZero, Plans to Migrate Over $1 Billion in BTC Collateral Assets to Chainlink

following the $292 million exploit of Kelp DAO's LayerZero bridge, the security of cross-chain infrastructure has once again come under scrutiny. DeFi protocols Kelp DAO, Solv Protocol, Re, and crypto exchange Kraken have all taken similar migration measures, with the total value of this outflow reaching approximately $4 billion.Decentralized finance protocol Lombard has become the latest project to join the migration wave, announcing a gradual phase-out of LayerZero and the migration of over $1 billion in Bitcoin collateral assets to Chainlink's Cross-Chain Interoperability Protocol (CCIP). Bitcoin-related tokens issued by Lombard include LBTC and BTC.b. It is reported that Lombard's initial migration assets cover the Solana, Etherlink, Berachain, Corn, and TAC chains, while the use of LayerZero on Morph and Swell will also be terminated. As of now, LayerZero has not responded to requests for comment. (CoinDesk)