GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Core Lightning warns unpatched nodes to upgrade as soon as possible

the Core Lightning team, which develops the Bitcoin Lightning Network node software, is warning node operators running version 26.06.7 or earlier to upgrade to the latest version as soon as possible. The team said it has received reports of attackers targeting unpatched nodes, but did not disclose the vulnerability exploited by the attackers or the potential impact.Core Lightning said on September 16 that it was investigating an issue that could affect experimental features and user funds, and on September 22 released version 26.06.8 to fix the vulnerability and update the software. This announcement did not state whether the previously reported attacks were related to the vulnerability fixed in this version. (Cointelegraph)

NEAR Intents Claims It Has Confirmed the Hacker's Identity, Demands Return of $3.8 Million in Stolen Funds Within 48 Hours

According to Cointelegraph, Alex Shevchenko, General Manager of NEAR Intents, stated that the team has identified the hackers behind the previous security incident and given them a 48-hour deadline to return the stolen funds through a "responsible disclosure." NEAR Intents previously suspended its services due to a vulnerability in the interaction between the Omni deposit and withdrawal infrastructure and its smart contracts. Initial investigations revealed that approximately $3.8 million in user funds were stolen in the incident, and the team has committed to fully compensating affected users. On-chain detective ZachXBT stated that the stolen funds were subsequently transferred to KuCoin and cross-chain converted into Bitcoin.

NEAR Intents Hit by $3.8 Million Exploit, Gives Hacker 48 Hours to Return Funds

Odaily News: NEAR Intents has stated that it has identified the attacker responsible for the loss of user funds and has demanded the return of $3.8 million within 48 hours through a "responsible disclosure" mechanism, after which the window will be closed.NEAR Intents suspended services on Thursday after discovering a vulnerability in the interaction between the Omni deposit and withdrawal infrastructure and its smart contracts. A preliminary investigation showed that the attack resulted in the theft of $3.8 million in user funds, and the platform has committed to fully compensating affected users.On-chain investigator ZachXBT disclosed that the related funds were transferred to the KuCoin exchange and subsequently bridged to Bitcoin. (Cointelegraph)

$388 Million in Crypto Assets Stolen, Bitget CEO Says Full Recovery Unlikely

Odaily News — Gracy Chen, CEO of cryptocurrency exchange Bitget, said the company is not optimistic about recovering the $388 million in crypto assets lost in last week's security incident. Citing the Bybit hack in 2025 as a reference, she noted that approximately one year after that incident, only about 3.5% of the stolen funds had been frozen, and that this does not equate to a completed recovery.Bitget has set up a bounty program offering 5% rewards for frozen funds and recovered funds respectively. The NEAR Intents team said it has intercepted over $50 million in assets related to the attack and frozen approximately $500,000. Tether and Circle have blacklisted the relevant wallets, freezing $318,000 worth of USDT and USDC.Gracy Chen stated that preliminary investigations indicate the attack may match VPN addresses used by North Korea-linked groups, but Bitget has not yet fully ruled out the possibility of an insider job. Bitget has resumed withdrawals in phases, starting with Bitcoin transactions on Monday and continuing with ETH transactions on Tuesday. (Cointelegraph)

SlowMist: It has not yet been confirmed that the iPhone Safari attack led to stolen crypto assets, and whether iOS 26.5 is affected remains to be verified.

According to Cointelegraph, SlowMist stated that it has not yet independently confirmed that the analyzed Safari attack sample has led to actual crypto asset theft. Existing technical evidence primarily covers iOS 18.4 through 18.6.2, while the previously circulated claim that "iOS 13 through iOS 26.5 are all affected" remains preliminary. Analysis by SlowMist reveals that the malicious Safari page exploits a chain of vulnerabilities previously patched by Apple to attempt access to the Apple Keychain, app files, and shared data, which may involve information stored in crypto wallets. However, the presence of exfiltration-capable code does not mean data has been successfully extracted from all targeted wallets. SlowMist continues to recommend that iPhone users promptly install the latest iOS security updates and avoid opening suspicious links.

SlowMist: No Confirmed Link Yet Between iPhone Safari Attack and Crypto Asset Theft

Odaily reports: Blockchain security firm SlowMist has stated that the attack samples it analyzed targeting iPhone Safari have not been linked to any confirmed incidents of crypto asset theft. The available technical evidence primarily covers iOS 18.4 through 18.6.2, and whether iOS 26.5 is affected still lacks reproducible technical evidence.The attack reuses the previously disclosed DarkSword attack chain technique, loading code through malicious web pages disguised as free virtual private server services. The samples contain components that access Apple Keychain, extract and decrypt stored information, and can also access application files and shared data.SlowMist recommends that iPhone users install the latest iOS security updates available for their devices and avoid clicking suspicious links. Users who suspect their wallet private keys or seed phrases have been compromised should generate a new wallet on a clean device and transfer their assets. (Cointelegraph)

EU's Three Major Financial Regulators Warn Quantum Computing Could Threaten Blockchain Cryptography Security

Odaily News: The European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA) stated in a joint risk update that advances in quantum computing could weaken the cryptographic systems that secure blockchain transactions, communications, and database security.In March, Google Quantum AI researchers estimated that the number of physical qubits required to break the cryptographic techniques used by many cryptocurrencies may be about 20 times fewer than previously estimated. A computer capable of carrying out such an attack does not yet exist.In February, Bitcoin developer Jameson Lopp and others proposed phasing out current signature schemes and restricting how unmigrated funds can be used five years after the proposal's activation. The proposal has not yet been adopted. The Ethereum Foundation plans to make Ethereum's execution, consensus, and data layers quantum-resistant by December 2029. (Cointelegraph)

North Korean Hacker Group WaterPlum Poses as Recruiters, Infects 30,000 Devices and Steals $10.7 Million in Crypto Assets

Odaily reports: The North Korean hacker group WaterPlum has been posing as recruiters for cryptocurrency, AI, and NFT companies, targeting software developers and IT professionals with malware disguised as coding assignments or video conferencing fix files.The group has infected at least 30,000 devices across more than 100 countries, and between December 2025 and July 2026, extracted funds or account credentials from over 7,000 cryptocurrency wallets, stealing at least $10.7 million. (Cointelegraph)

Dragonfly Partner Calls for Zcash Development Fund to End When It Expires in 2028

Odaily reports: Haseeb Qureshi, managing partner at crypto-focused venture capital firm Dragonfly, has proposed that under current rules, the Zcash development fund should cease operations after its expiration in 2028.Qureshi wrote: "I think this should be the last development fund." He stated that the current fund size is already sufficient to support Zcash's remaining development work, and as the fund's value approaches $100 million, it may face "politicization" risks in the future. According to ZecStats data, as of press time, the Zcash development fund holds 63,962 ZEC, worth approximately $95 million.These remarks come amid ongoing industry discussions about the growing size of the development fund. The previous rise in ZEC's price drove a significant increase in the fund's value. Some also argue that Zcash should continue to maintain the development fund. Paradigm founder Matt Huang said on Wednesday that against the backdrop of improving AI network attack capabilities and the rapid development of quantum computing, the fund is particularly important.

Revolut Responds to Multiple Extortion Attempts: No Direct Contact Received, Italian Authorities Have Intervened

Odaily News: Following a customer data breach at Revolut, multiple hacker groups have publicly demanded ransom. A group calling itself "IAmNotAVillain" demanded that Revolut pay 6,000 Monero (XMR, approximately $3 million) within 24 hours, or it would sell customer data to other criminal organizations; another group, "Revolut Smilik," had earlier demanded 10,000 Bitcoin (approximately $780 million).In response, a Revolut spokesperson stated that the company has not received any direct contact or extortion demands from any of the aforementioned individuals or organizations. Meanwhile, Italy's Anti-Mafia and Anti-Terrorism Directorate has launched an investigation, with Italian prosecutors investigating unauthorized access to government computer systems, and Italy's privacy regulator has also asked banks to urgently review the security of their access systems. (Cointelegraph)

Italian authorities investigate government email security incident linked to Revolut customer data breach

Odaily reports: Italian cybercrime police are investigating a government email security incident linked to a Revolut customer data breach, involving suspected unauthorized access to computer systems and computer fraud.The accounts involved are said to belong to Italy's Certified Email System (PEC). Revolut did not confirm which government agency the compromised accounts belonged to, but said it has reported the incident to Italian authorities and that its systems, databases, and customer funds were not affected.Italy's CERT-AGID cybersecurity agency warned in June that PEC only certifies email delivery and does not guarantee the security of email contents. The agency said it has handled over 650 cases of abused or illegal PEC accounts since the beginning of 2026. (Cointelegraph)

The EU Cyber Resilience Act officially takes effect, requiring crypto wallet vendors to report vulnerabilities within 24 hours.

According to Cointelegraph, the EU Cyber Resilience Act (CRA) officially entered into force, requiring cryptocurrency hardware and software wallet providers to submit an early warning within 24 hours of discovering a serious security vulnerability or an actively exploited vulnerability, a complete notification within 72 hours, and a final report within 14 days after remediation measures are implemented. The regulation applies to all "products with digital elements" sold in the EU market. Violating companies face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing false or misleading information will result in an additional fine of up to €5 million. Previously, Trezor and BitBox have both disclosed user data breach incidents and warned users to be vigilant against phishing emails disguised as security notifications.

EU's Cyber Resilience Act Takes Effect: Crypto Wallet Vulnerabilities Must Be Reported Within 24 Hours

The EU's Cyber Resilience Act has taken effect. Cryptocurrency hardware and software wallet providers must submit an initial early warning within 24 hours after discovering actively exploited vulnerabilities or severe security flaws in their products, and submit a full notification within 72 hours.Manufacturers must submit a final report within 14 days after corrective or mitigating measures become available; serious incidents must be reported within one month. Companies that violate the relevant regulations may face fines of up to €15 million or 2.5% of global annual turnover, whichever is higher; providing false, incomplete, or misleading information may result in fines of up to €5 million. (Cointelegraph)

Symbiosis Recovers 15 BTC From Bitcoin Bridge Exploit, Offers 20% Bounty for Leads

According to Cointelegraph, cross-chain liquidity protocol Symbiosis announced that it has recovered 15 BTC (approximately $1.1 million) from its Bitcoin bridge exploit and deposited them into a team-controlled multisignature wallet. The vulnerability occurred last Friday, as the attacker exploited the protocol flaw to mint 46.1 billion uncollateralized tokens, ultimately realizing profits of 4.3 WBTC (approximately $336,000). Symbiosis had previously offered the attacker a 20% white-hat bounty in exchange for returning the assets, but the deadline has passed without any response. The protocol is now offering a 20% bounty to anyone who provides leads to assist in recovering the assets, while committing to announce a compensation plan for affected liquidity providers. The impacted Bitcoin bridge feature remains paused.

North Korea uses third-country IT workers to pass interviews at US companies, then takes over the positions after hiring

North Korea is using remote IT workers from third countries such as Iran and Lebanon to infiltrate US companies in order to obtain funding to support its weapons programs. After the relevant individuals pass interviews, their positions are usually taken over by North Korean personnel.The US government and multiple foreign agencies issued warnings in July stating that North Korean IT workers seek contracts and send salaries back to their affiliated North Korean organizations, while also posing insider threats to companies, involving data leaks, cryptocurrency theft, and the theft of sensitive information.Some third-country IT workers are recruited through LinkedIn, and some of them work part-time as "interview facilitators," earning $500 in cryptocurrency per month.Data from cybersecurity company CrowdStrike shows that in 2025, cryptocurrency losses caused by North Korea state-linked hackers and threat actors exceeded $2 billion, an increase of 51% year over year. South Korea's central bank estimates that North Korea's GDP grew 3.5% in 2025. (Cointelegraph)

Brevo Login Breach Leads to Phishing Emails Sent to 347,000 Trezor Subscribers, BitBox and CoinTracking Accounts Also Affected

Odaily News: A vulnerability in email platform Brevo's login system allowed attackers to access 138 customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. Accounts belonging to BitBox and cryptocurrency portfolio and tax reporting platform CoinTracking were also used to send similar scam emails.Trezor stated that the phishing email was titled "Critical Security Alert: STM32 Entropy Vulnerability," with links pointing to an app that asked users to submit their wallet backups. Trezor disabled the relevant domain via DNS within 20 minutes, but approximately 2,500 people had visited the link, and the company has alerted all 347,000 subscribers to the risk.Brevo stated that attackers exploited a failure in single sign-on configuration permission boundaries to access all organizations reachable by invited users. Six accounts were used to send phishing emails, and contact data from 43 accounts was exported. BitBox and CoinTracking said they have found no evidence of leaked company credentials, funds, or recovery phrases, but are treating the affected email addresses as potentially compromised. (Cointelegraph)

Four people killed in Mexico, suspects accused of stealing a cold wallet holding millions of dollars in Bitcoin

Odaily News: The State Attorney General's Office of Mexico (FGJEM) stated that two suspects are accused of killing four people in search of a cold wallet believed to contain millions of dollars in Bitcoin. The two are scheduled to appear in court on Wednesday, where a judge will determine whether there is sufficient evidence to continue criminal proceedings.The surnames of suspects Diego Sebastián and Gerardo have not been disclosed. Prosecutors allege that the pair killed Jonathan Meléndez, keyboardist for the rock band Camilo Séptimo, his pregnant wife, their daughter, and an employee at a residence in the city of Atizapán de Zaragoza. The family's golden retriever was also killed.Mexico's Secretary of Security, Omar García Harfuch, stated that one of the suspects was a business partner of the victim and allegedly used that relationship to gain entry into the residence. If convicted, the two could face sentences ranging from 25 to 70 years in prison for each victim.Blockchain security firm CertiK reported that 52 violent coercion attacks against cryptocurrency holders were recorded globally in the first half of 2026, a 33.3% increase from 39 during the same period in 2025. Blockchain analysis company Chainalysis estimates that the value of stolen cryptocurrency from related attacks exceeded $30 million. (Cointelegraph)

Core DAO Plans Emergency Hard Fork as Validators Receive Excess CORE Rewards

Odaily News: Blockchain project Core DAO has announced a coordinated emergency hard fork, caused by validators receiving CORE rewards exceeding the blockchain's originally scheduled issuance. Core DAO stated that the incident is under control, malicious validators can no longer continue to obtain excess rewards, and the upgrade will not roll back the network or revoke confirmed transactions.Core DAO previously stated that a small number of validators had accumulated rewards significantly higher than the protocol's set issuance, and that the incident only involved reward distribution, with user assets remaining secure. Coinbase, Bithumb, Coinone, Bitget, and LBank had restricted CORE deposits, withdrawals, or transfers.Core DAO has not yet disclosed the amount of excess CORE issued, the duration of the related activity, whether the extra tokens entered circulation, or the cause of the vulnerability, and stated that it will publish a technical post-mortem report. (Cointelegraph)

Fake Claude Desktop App Distributes RevStealer Malware, Capable of Stealing Over 50 Types of Cryptocurrency Wallet Data

According to Cointelegraph, cybersecurity firm Morphisec has revealed that a counterfeit desktop application masquerading as Anthropic’s "Claude Opus 5 Free Desktop" is being leveraged to distribute the Windows malware RevStealer. The malicious program can exfiltrate data from over 50 cryptocurrency wallets, while simultaneously harvesting sensitive information including browser passwords, cookies, VPN configurations, message logs, and screenshots. RevStealer incorporates anti-detection measures, performing system environment checks on the target device prior to execution. If traces of debugging or virtualized environments are detected, it aborts its operation. Additionally, Russian cybersecurity company Kaspersky has disclosed OkoBot, a novel malware framework targeting crypto investors capable of harvesting wallet files, injecting malicious extensions, and capturing wallet application windows to siphon assets.

Polygon Discloses Multiple PoS Network Security Vulnerabilities, Resolved via Two Hard Forks

According to Cointelegraph, Polygon disclosed several previously undisclosed security vulnerabilities affecting its Bor and Heimdall clients, which could lead to denial of service (DoS), validator resource exhaustion, and anomalies in checkpoint and milestone processing. The relevant vulnerabilities have currently been patched through two hard forks: Austin and Kyoto.