News linked to both this project and an event.
Odaily reports: A wallet linked to the $387.5 million Bitget exploit transferred 2,746 ZEC into Zcash's Ironwood privacy pool on Wednesday across three transactions, worth approximately $3.9 million.The funds account for roughly 15% of the ZEC stolen on September 24. The Ironwood privacy pool can conceal the sender, recipient, and transfer amount, but investigators may still be able to trace the path of funds returning to public addresses through transaction timing and amounts. (CoinDesk)
Odaily News: Cross-chain protocol Chainlink has released CCIP 2.0, allowing enterprises to add their own security checks for cross-blockchain transfers on top of its default network of 16 operator validators.The upgrade comes after Kelp DAO suffered a $292 million hack in April, an incident attributed to a LayerZero cross-chain bridge setup using a single validator; Kelp DAO subsequently migrated its rsETH token to Chainlink.Chainlink's risk management network no longer operates as a standalone security safeguard, and users who do not add their own validators will rely on one validation network rather than two. (CoinDesk)
Odaily News: Crypto technology service provider Haruko suffered a targeted cyberattack, with 15 clients affected. Read-only API information and trading data from some exchanges were leaked.Haruko stated that smaller hedge fund clients with weaker security controls may have lost a small amount of funds. The company has patched the vulnerability and updated its server-side keys. (CoinDesk)
According to CoinDesk, London-based crypto institutional technology services provider Haruko was targeted by a cyberattack earlier this week, affecting a total of 15 clients. Attackers exploited vulnerabilities in Haruko’s infrastructure to extract user access tokens, gaining access to clients’ read-only exchange API information and trading data. A small amount of client funds were stolen, and smaller hedge funds with weaker security controls face a higher risk of loss. Haruko co-founder and CTO Adam Carlile confirmed that the attack specifically targeted Haruko itself. The vulnerability has been patched, and the company plans to release a complete technical post-incident report. Haruko serves over 80 institutional clients globally and connects to more than 100 centralized exchanges and 30 blockchains.
According to CoinDesk, Ethereum plans to launch Glamsterdam upgrade testing on the Sepolia testnet on October 6. Developers have warned that attackers could exploit free testnet ETH and numerous temporary block builder identities to win block auctions at high prices and then refuse to submit transaction payloads, thereby disrupting the testing process. This risk will not affect mainnet funds, but could hinder upgrade verification. Glamsterdam aims to increase the block gas limit to approximately 200 million, with the mainnet launch date remaining undetermined.
Odaily reports: Ethereum developers have warned that attackers could exploit free testnet ETH and one-time builder identities to win Sepolia block auctions and withhold transaction payloads during the Glamsterdam testing period.This attack does not threaten mainnet funds, but it could disrupt infrastructure testing. The Sepolia public test is scheduled to launch on October 6, while the Hoodi test is tentatively set for October 27. The mainnet activation date remains undetermined. (CoinDesk)
According to CoinDesk, Bitcoin Core 32.0 entered its final testing phase on September 14, with its official release scheduled for October 10. This update adds a transaction fee estimator based on real-time mempool status, enabling fee estimates to be lowered more quickly once network congestion subsides. It also enables multi-threaded parallel reading of transaction data to speed up node blockchain synchronization, defaulting to 8 threads. Security-wise, it resolves a wallet naming vulnerability on non-Windows systems since version 24.0 that allowed attackers to execute arbitrary commands on the node host via a specially crafted wallet name. Additionally, it patches an out-of-memory vulnerability in the newly added built-in web server; testing indicates that 16 unauthenticated connections can spike node memory usage from 46MB to roughly 3GB in approximately one minute. This update does not include any changes to Bitcoin's consensus rules.
Odaily News: Bitcoin Core 32.0 entered its final testing phase on September 14, with the official version planned for release on October 10.This version will improve fee estimation, speed up block processing, and make PSBT version 2 the default option for multiple wallet commands, without changing Bitcoin's consensus rules.Developers also fixed a command execution vulnerability affecting certain wallet configurations, as well as a memory exhaustion vulnerability in the new web server. (CoinDesk)
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
According to CoinDesk, OpenAI said it will provide subsidized access to the $1 billion Daybreak cybersecurity model over the next six months, along with training and technical support, to help organizations defend against AI-driven cyberattacks, including potential zero-day exploits. Daybreak is divided into two tiers, Blue and Red, tailored for routine defense and more sensitive cybersecurity tasks, respectively, with about 2,000 organizations already using it.
According to CoinDesk, US cybersecurity firm CrowdStrike has partnered with federal law enforcement agencies to successfully dismantle the Russian botnet Sality, which has been operating for over two decades. Over the past eight years, the network has continuously stolen cryptocurrency through clipboard hijacking; its core payload, "EggJagger," resides on infected machines, monitoring the user's clipboard. Once a Bitcoin or Ethereum wallet address is detected, it is replaced with the attacker's address, causing victims to unknowingly complete transfers. Sality employs a decentralized P2P architecture with no central server, checking node online status every 40 minutes, and self-propagates via network-shared drives and USB devices. By exploiting an authentication vulnerability, CrowdStrike replaced legitimate node addresses with those of its own servers, successfully severing the network connections of over 15,000 infected machines. The operation was demonstrated live at the Day Zero summit in Las Vegas. Estimates indicate that the attackers stole at least 12.1 million rubles (approximately $150,000) over the eight-year period. Undisturbed crypto assets appreciated alongside the broader market, reaching a value of roughly $1.35 million by early 2025. Security experts advise users to always verify the first and last characters after pasting a wallet address to defend against such attacks.
According to CoinDesk, several prominent figures in the cryptocurrency industry and CoinDesk employees received numerous unsolicited password reset emails via the X platform on Tuesday, with some users receiving up to 10 within a few hours. Crypto investor Nic Carter urged users to enable X's "password reset protection" feature as soon as possible. Currently, there is no evidence that the X system has been breached or that accounts were hijacked en masse, and X has not issued an official statement regarding the incident.
According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.
Odaily News - The U.S. Internal Revenue Service (IRS) has issued a warning about an advanced email phishing campaign targeting cryptocurrency holders in the United States. Attackers are using forged official tax letters to trick users into scanning malicious QR codes, aiming to steal crypto wallet credentials and private keys.According to reports, the attackers are impersonating the IRS by sending physical letters that create a sense of urgency under the guise of "tax compliance" or "account verification," and include QR codes within the correspondence. Once users scan these codes, they may be redirected to counterfeit websites, potentially exposing wallet login information, recovery phrases, or private keys, ultimately leading to the theft of digital assets.The IRS reminds taxpayers that official agencies will never request users to provide crypto wallet private keys, recovery phrases, or perform similar "wallet verification" procedures through unofficial channels. Cryptocurrency holders should remain vigilant against any suspicious emails or letters that ask them to scan QR codes, connect wallets, or submit sensitive information.As the number of crypto asset holders continues to grow, social engineering attacks targeting digital wallets are on the rise. Regulatory and security agencies are stepping up efforts to raise awareness and prevent such fraudulent activities. (CoinDesk)
Odaily News: Sheldon Lee, founder of cryptocurrency exchange BitMart, stated that a post on X claiming users were unable to withdraw funds and that some employees had not received their July salaries is a "fabricated rumor," adding that the exchange's Chinese-language account had been hacked. Critics, including users and on-chain investigator ZachXBT, have demanded that BitMart resume withdrawals or undergo an independent third-party audit. BitMart is gradually winding down operations, with the final trading day set for August 26. Troubled investment firm Echo Base said it had proposed a funded restructuring plan to BitMart but received no response. The firm warned that resolving a large volume of customer claims may require proceedings through the courts. (CoinDesk)
Odaily News: Decentralized lending protocol Compound Finance has completed a leadership overhaul and approved a record $52 million budget. The protocol's total value locked has fallen from a peak of $12 billion in 2021 to $1.2 billion, and it is now seeking to restore growth. Compound Finance is pivoting to serve institutional clients, developing real-world asset products, partner integration solutions, and credit infrastructure to meet the compliance and technical standards of traditional finance. Industry executives say Compound Finance's new leadership team and substantial budget align with the broader shift within the decentralized finance sector toward serving financial institutions. The sector's overall assets had previously declined due to market weakness and security breach incidents. (CoinDesk)
Odaily News: Bits of Gold, Israel's largest crypto brokerage, stated that hackers obtained the personal information of approximately 200,000 customers through a data breach at a third-party data analytics service provider. The compromised information includes names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details, and public wallet addresses, but does not include funds, passwords, private keys, or ID scans. The incident is part of a recent wave of data breaches in the crypto industry, following similar incidents at SafePal and Trezor, which were also compromised through breaches at external vendors. (CoinDesk)
Odaily News: Following the full implementation of the EU's MiCA regulation on July 1, over 1,700 unlicensed crypto platforms have been ordered to cease operations and guide users toward licensed platforms; currently, only 323 companies hold valid authorizations. Approximately 10 million users need to migrate their assets, and scammers are taking advantage of this by impersonating regulators and licensed exchanges, sending fake migration notices to lure users into transferring assets to fraudulent platforms. The French Financial Markets Authority (AMF) stated that scammers have been posing as its employees to defraud funds under the guise of collecting "management fees." The European Securities and Markets Authority (ESMA) confirmed that its identity and logos have been misused. The Dutch Authority for the Financial Markets (AFM) warned that migration from unlicensed exchanges has itself become an attack surface, advising users to verify service providers through ESMA's official register and to remain vigilant against unsolicited contact requesting fund transfers.
According to CoinDesk, the S&P 500 index has risen 3.12% this month, adding approximately $2.1 trillion in market value (equivalent to the total market cap of the entire crypto market), reaching a record high total market cap of $70.5 trillion, but Bitcoin has only risen about 2% this month, hovering near $64,600. Analysts point out that this round of stock market rise is mainly driven by AI and semiconductor individual stock narratives, rather than a broad-based recovery in risk appetite at the macro level, and Bitcoin lacks direct beneficial exposure to this. Meanwhile, the crypto market also faces multiple internal pressures: the Coldcard platform suffered a $120 million exploit, the prospects of the "Clarity Act" remain uncertain, MicroStrategy has reduced its BTC holdings for three consecutive months, and stablecoin supply continues to shrink—USDT's market cap dropped from $190 billion in April to $183 billion, and USDC's dropped from $79.5 billion to $72 billion.
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.