GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Non-upgraded nodes become attack targets, Core Lightning urges upgrade to 26.06.8

Odaily reports, according to Bitcoin News monitoring, Core Lightning stated that attackers are targeting nodes still running version 26.06.7 and earlier. The 26.06.8 patch released on September 22 fixes a channel closure issue that could jeopardize funds, as well as vulnerabilities that cause crashes and memory exhaustion. The project has not yet disclosed the name of the vulnerability used by attackers, nor has it reported any stolen funds. Node operators who have not yet upgraded are becoming attack targets.

Core Lightning warns unpatched nodes to upgrade as soon as possible

the Core Lightning team, which develops the Bitcoin Lightning Network node software, is warning node operators running version 26.06.7 or earlier to upgrade to the latest version as soon as possible. The team said it has received reports of attackers targeting unpatched nodes, but did not disclose the vulnerability exploited by the attackers or the potential impact.Core Lightning said on September 16 that it was investigating an issue that could affect experimental features and user funds, and on September 22 released version 26.06.8 to fix the vulnerability and update the software. This announcement did not state whether the previously reported attacks were related to the vulnerability fixed in this version. (Cointelegraph)

Experimental features could put channel funds at risk, and Core Lightning is urging node operators to disable them immediately

Odaily reports: Bitcoin News posted on X that Core Lightning is urging node operators to immediately disable experimental features, as developers are investigating a vulnerability that could put channel funds at risk. This is Core Lightning's second warning within a few weeks, following an August patch and the release of the 26.06.7 upgrade after a series of AI-generated CVE reports. Core Lightning has not yet disclosed how the experimental feature could be exploited.

Relying on AI to find vulnerabilities first is not a sustainable security strategy, warns Bitcoin Core developer Niklas Gögge

Odaily reports: Bitcoin News posted on X platform that Bitcoin Core developer Niklas Gögge warned that recent AI-driven vulnerability scanning is changing the Bitcoin security landscape. Large language models have significantly reduced the cost of vulnerability discovery, and attackers may be able to find catastrophic vulnerabilities with only a few hundred dollars in computing costs. For Bitcoin Core, Project Loupe, Bitcoin Red Team, and individual contributors have generated over 1,000 reports, but so far no high-risk or critical vulnerabilities have been found. Gögge stated that relying on stronger models to find vulnerabilities before attackers do is not a sustainable security strategy. Developers should build testing infrastructure through automated testing, fuzzing, and property-based testing that can prevent entire classes of vulnerabilities in advance. Key components of Bitcoin Core have cumulatively completed over 100 years of CPU fuzzing and decades of Bitcoin node network simulation.

Bitcoin Core 32.0 entered the final testing phase on September 14, with the official release date set for October 10.

According to CoinDesk, Bitcoin Core 32.0 entered its final testing phase on September 14, with its official release scheduled for October 10. This update adds a transaction fee estimator based on real-time mempool status, enabling fee estimates to be lowered more quickly once network congestion subsides. It also enables multi-threaded parallel reading of transaction data to speed up node blockchain synchronization, defaulting to 8 threads. Security-wise, it resolves a wallet naming vulnerability on non-Windows systems since version 24.0 that allowed attackers to execute arbitrary commands on the node host via a specially crafted wallet name. Additionally, it patches an out-of-memory vulnerability in the newly added built-in web server; testing indicates that 16 unauthenticated connections can spike node memory usage from 46MB to roughly 3GB in approximately one minute. This update does not include any changes to Bitcoin's consensus rules.

Bitcoin Core 32.0 enters final testing, official release scheduled for October 10

Odaily News: Bitcoin Core 32.0 entered its final testing phase on September 14, with the official version planned for release on October 10.This version will improve fee estimation, speed up block processing, and make PSBT version 2 the default option for multiple wallet commands, without changing Bitcoin's consensus rules.Developers also fixed a command execution vulnerability affecting certain wallet configurations, as well as a memory exhaustion vulnerability in the new web server. (CoinDesk)

ZKsync Announces EraVM Security Upgrade, Phasing Out Legacy Execution Environment Over the Next 6 Months

According to the official ZKsync X account (@zksync), ZKsync has announced a security upgrade for its EraVM chain. Core measures include introducing an instant upgrade framework, extending the proving delay from 3 hours to 24 hours, and deploying a second prover, EraBender, to defend against AI-driven vulnerability attacks. Over the next six months, all Boojum/EraVM chains will gradually phase out the legacy execution environment, with each chain formulating and publishing its own transition schedule. Users who hold funds directly in EOAs do not need to take any action at this time. Users who hold funds through smart contracts such as multisigs, smart accounts, DEXs, and lending protocols must take action as required once the transition plans for their respective chains are finalized. The ZKsync Atlas chain remains unaffected by this upgrade.

Core DAO Plans Emergency Hard Fork as Validators Receive Excess CORE Rewards

Odaily News: Blockchain project Core DAO has announced a coordinated emergency hard fork, caused by validators receiving CORE rewards exceeding the blockchain's originally scheduled issuance. Core DAO stated that the incident is under control, malicious validators can no longer continue to obtain excess rewards, and the upgrade will not roll back the network or revoke confirmed transactions.Core DAO previously stated that a small number of validators had accumulated rewards significantly higher than the protocol's set issuance, and that the incident only involved reward distribution, with user assets remaining secure. Coinbase, Bithumb, Coinone, Bitget, and LBank had restricted CORE deposits, withdrawals, or transfers.Core DAO has not yet disclosed the amount of excess CORE issued, the duration of the related activity, whether the extra tokens entered circulation, or the cause of the vulnerability, and stated that it will publish a technical post-mortem report. (Cointelegraph)

Core Lightning releases emergency security update, all node operators advised to upgrade immediately

Odaily News: Bitcoin News posted on X platform that Core Lightning version 26.06.7 has been released, fixing multiple vulnerabilities that were responsibly disclosed over the past three weeks. Recently, there has been an increase in AI-generated security reports targeting open-source Bitcoin projects. Specific vulnerability details will be kept confidential for two weeks to allow node operators to complete upgrades before technical details and source code are published. Developers warned that immediately disclosing the fixes could allow attackers to reverse-engineer the vulnerabilities and attack nodes that have not yet been updated. All Core Lightning node operators should upgrade immediately. Docker images are not yet available, and developers have explicitly warned users not to wait for the Docker image.

Core Lightning recommends unupgraded nodes run offline; a fix version has not yet been released.

According to The Defiant, the Core Lightning (CLN) maintainers for the Bitcoin Lightning Network have notified node operators that if they are unable to upgrade to the upcoming patched version, they should run their nodes offline using the --offline parameter. The team stated it will release binaries containing fixes for multiple disclosed vulnerabilities, but specific vulnerability details will remain confidential for two more weeks; as of press time, the relevant binaries and security advisory have not been published. CLN had previously noted that it received several AI-generated CVE reports over the past ten days, and the team is working with open-source contributors to verify, classify, and patch them. The latest public release is v26.06.6, issued on July 22, and the v26.09 release, originally slated for late September, continues to proceed as planned.

Core Lightning Warns Users to Upgrade, Unupgraded Nodes Should Be Taken Offline

: Bitcoin News posted on X that Core Lightning developers have received a large number of AI-generated CVE reports over the past 10 days, and have verified the existence of vulnerabilities that need to be fixed. The team has now escalated its response, will release signed binaries, and will keep vulnerability details confidential for a two-week period. Core Lightning strongly urges all users to upgrade during this period; users who have not upgraded should take their nodes offline. Previous versions, including 26.04, will no longer be supported.

BIP-110 Supporters Propose Restarting Minority Chain with BLAKE2b, Replay Attack Concerns Raised

Odaily News: BIP-110 supporters are discussing a hard fork to change the stalled minority chain's mining algorithm from SHA-256d to BLAKE2b. Transaction history before the fork remains shared by both chains. If transaction and signature rules remain consistent, the same transaction could be replayed on the other chain, creating a replay attack.BIP-110's peak miner support was approximately 2.53%. After the consensus rules took effect on August 8, the minority chain produced only two consecutive blocks before stalling, while the Bitcoin main chain continued operating and widening the block height gap. The BIP-110 proposal was subsequently marked as closed, and supporters shifted focus to discussing the BLAKE2b proof-of-work scheme.Bitcoin Knots plans to add a new signature hash option, but RDTS will still maintain compatibility with Bitcoin Core's existing signature hash types. Regular transactions may continue to be valid on both chains. Users will need to use the new option and rely on wallets or hardware signing firmware that support it to achieve asset separation.Luke Dashjr stated on August 18 that Bitcoin should bear the responsibility for replay protection, calling it "Spamcoin." If the BLAKE2b fork proceeds around September 1, exchanges, wallets, and holders will need to distinguish between cross-chain transactions and chain-specific transactions. (Bitcoin.com News)

Crypto Companies Send Joint Letter to AI Labs, Urging Access to Frontier Models for Bitcoin Developers

据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。

Loss of approximately $130 million: Coldcard firmware vulnerability leads to the theft of around 2,000 BTC

Odaily News: Part of hardware wallet manufacturer Coldcard's firmware had a random number generation vulnerability in 2021, causing some mnemonic phrases generated by the devices to carry predictable risks. The vulnerability was only discovered years later, and by then approximately 5,200 addresses and around 2,000 BTC had been stolen, with losses totaling about $130 million. Following the incident, some investors turned to Wall Street custody products. U.S. spot Bitcoin ETFs saw net inflows of approximately $626 million within days of the event. ETF analyst Eric Balchunas noted that security incidents like this could further drive capital flows into ETFs. The Bitcoin core community continues to uphold the principle of self-custody. Casa co-founder Jameson Lopp said recent events should not weaken user confidence in self-custody, as third-party custody carries risks as well. Early Bitcoin Core developer Peter Todd stated that self-custody has a better long-term security track record than centralized institutions. Michael Tanguma, co-founder of Bitcoin custody platform Onramp, said both approaches have flaws: concentrating large amounts of assets in a single institution creates a "honey pot," while hardware wallets face risks related to supply chains, firmware, and random number generation. Michael Tanguma proposed a "multi-institution custody" approach, in which multiple regulated institutions each hold keys through a multi-signature mechanism, and any transaction requires joint signing by multiple institutions to reduce the risk of single points of failure. Critics argue that while multi-institution custody improves security, it also introduces permissioned management, which conflicts with the decentralized ideals Bitcoin originally pursued. As Bitcoin enters pension funds, trusts, and institutional asset allocation, the industry is seeking custody solutions suitable for long-term wealth management. How to strike a balance among security, decentralization, and usability remains a challenge facing the Bitcoin ecosystem.

COLDCARD vulnerability may have originated from compiler bypass handling

Odaily News: Bitcoin News posted on X platform that a new technical analysis by Core-Lightning developer ddustin shows that the 2021 COLDCARD vulnerability may have originated when developers attempted to connect the wallet using Python code, MicroPython's C code, and the STM32 hardware random number generator. The custom code appears to have conflicted with MicroPython's existing implementation, potentially triggering a compiler error. Evidence suggests that developers subsequently set MICROPY_HW_ENABLE_RNG to 0, allowing the firmware to compile successfully. This change led to unintended consequences: when users created new wallets, the firmware no longer used the hardware random number generator, instead falling back to MicroPython's weaker Yasmarang software random number generator. The commit message left by the developers was only "runs." The analysis states that this serves as a reminder to developers not to release security-critical code they do not fully understand, especially when it protects billions of dollars in Bitcoin.

Bitcoin Core Developer Claims to Have Reproduced COLDCARD MK3 Vulnerability, MK2/MK3 Devices May Be Affected

: Bitcoin News posted on X platform, stating that Bitcoin Core developer instagibbs claimed to have successfully reproduced the reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device, using only the number of button presses during the setup process, and said, "Sorry, now is the time to panic." He believes the issue affects MK2/MK3 devices, but stated that it is currently unable to confirm whether the MK4 has the vulnerability. Developer Antoine Poinsot stated that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller's True Random Number Generator (TRNG), while the MK3 does not. The proof of concept and mnemonic phrase verification are still under review.

CertiK Report: Wrench Attacks Surge Nearly 12x in Losses, “Operational Security” Becomes New Core of Prevention

Odaily Odaily News, July 22nd - Web3 security firm CertiK released its "H1 2026 Wrench Attack Report." The report indicates that a total of 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report notes that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world social networks. Home invasion incidents increased from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents in the period. Europe has become a high-incidence area for attacks, with 33 cases occurring in France alone, representing 63.5% of the global total.CertiK stated that as real-world risks become a significant challenge for digital asset security, enterprises and high-net-worth individuals need to establish more comprehensive protection systems. CertiK has launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes. Simultaneously, through the CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities. Furthermore, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol, providing technical support for cross-border attack investigations and security policy research.

Cross-chain protocol Allbridge confirms $1.65 million loss from liquidity pool and plans to deprecate old architecture

the cross-chain protocol Allbridge has issued an official statement confirming that an attacker has withdrawn approximately $1.65 million in assets from the Allbridge Core liquidity pool. A detailed analysis of the incident is currently being compiled, and the full investigation results will be published subsequently. The team emphasizes that there is no further risk to current user liquidity and that the Allbridge Next service is operating normally.In response to this incident, Allbridge plans to relaunch the Core version but will remove the liquidity pool design. Future cross-chain transfers will be facilitated via Circle CCTP and the LayerZero router to eliminate the risk of liquidity pool imbalance and the model vulnerabilities exploited in this attack. This incident has accelerated the previously initiated migration plan to fully transition to the more secure new infrastructure, Allbridge Next. According to the plan, Allbridge Core and Allbridge Classic will cease operations in their current form within the next three months, and users are advised to withdraw their relevant liquidity in advance.It is understood that this attack has exposed the risks inherent in the traditional cross-chain liquidity pool model and has further driven the protocol's transition towards a cross-chain architecture based on message passing and native asset transfer.

Approximately $1.1 million extracted, Allbridge Core exploited on Solana

Odaily reports, according to monitoring by Onchain Lens, Allbridge Core has been exploited on Solana. The attacker borrowed $1.12 million USDC via a Kamino flash loan, then rapidly executed a USDC/USDT swap, distorting the stablecoin pool ratio of Allbridge. They withdrew liquidity at the manipulated exchange rate and repaid the flash loan within the same transaction, extracting approximately $1.1 million in funds. The funds were subsequently mixed through a privacy protocol. The maximum single withdrawal from Allbridge was $2.24 million USDC. Further analysis of the vulnerability exploit and the affected pools is ongoing.

LayerZero_Core Executor wallet allegedly hacked, multi-chain losses of $2.1 million

according to on-chain detective Specter's monitoring, the LayerZero_Core Executor wallet may have been compromised, resulting in a total multi-chain loss of $2.1 million. The attacker bridged the stolen funds to Ethereum via Stargate and Relay, and is currently holding 955 ETH (worth $1.78 million) and 322,000 USDC. CyversAlerts first identified this suspicious activity.