GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

B² Network Suffers Hacker Attack, Losses Approximately $3.86 Million

According to on-chain analyst Specter, B² Network on BNB Chain suffered a hack, resulting in a loss of approximately 8.591 million B2 tokens (approximately $3.86 million). The attacker swapped them for 5409 WBNB (approximately $3.11 million) and bridged to Ethereum, and is currently transferring the funds to Zcash via NEAR Intents.

Most of the stolen funds have been moved; Summer Fi attacker still holds approximately $565,100 in ETH

according to Onchain Lens monitoring, on July 6, the Summer Fi attacker received 6.017 million DAI from the Summer Fi exploit, and subsequently swapped and routed the funds through Tornado Cash. The original wallet (0x7bf...dca) retains 11.3 ETH, worth approximately $21,600; the second wallet (0x46e...ba7) retains 282.9 ETH, worth approximately $543,500.

Full refund expected to be completed by July 22; Hinkal returns funds to users who have completed the recovery process

according to Hinkal monitoring, full refunds will be issued this week to users who have completed the recovery process, with completion expected by July 22. Users who have not yet completed the recovery can still submit applications. Previously, Hinkal suffered an attack resulting in a loss of approximately 797,000 USDC, which the attacker exchanged for about 454 ETH.

TrustedVolumes attacker returns 1,122 ETH, retains approximately $2 million as bounty

According to Com Feed monitoring, the TrustedVolumes attacker has returned 1,122 ETH, worth approximately $2 million, while retaining about $2 million as a "bounty." Previously, the attacker had exploited a vulnerability to steal approximately $5.8 million in funds.

ether.fi selects Nexus Mutual to provide slashing coverage for up to 15,000 ETH

: On-chain digital asset management neobank ether.fi has selected Nexus Mutual to provide ETH slashing coverage, covering slashing penalties for its validators up to 15,000 ETH. ether.fi stated that it operates a large-scale validator set on Ethereum, and slashing is a tail risk. This coverage is used to cover validator losses, with a scale exceeding the total historical ETH slashing losses. ether.fi currently manages over $6 billion in assets across products such as Cash, Stake, and Liquid. Since 2019, Nexus Mutual has provided over $7 billion in coverage for smart contract attacks, slashing, and other digital asset risks. (Decrypt)

Enso reveals malicious liquidity pool attack, Curve pool causes approximately $225,000 in inflated quotes

DeFi infrastructure company Enso disclosed a type of malicious liquidity pool called "toxic pools" in a report on July 16th. These pools manipulate transaction simulations to return false optimal quotes to wallets and DEX aggregators, subsequently altering the logic during actual on-chain execution. Enso stated that the relevant malicious contracts can identify read-only simulation environments and return optimized prices, but when the transaction is broadcast on-chain, it is executed at a worse price or causes the transaction to fail. One manipulated Curve pool processed over 129,000 swaps, resulting in approximately $225,000 in inflated quotes. Additionally, over 37,000 transactions were reverted, consuming nearly $30,000 in gas fees. On Polygon, a malicious Uniswap v4 hook attracted routing systems with fake exchange rates, subsequently triggering a 99.1% transaction failure rate. Enso stated that it has updated its execution protection product, Enso Shield, to detect fake quotes in Ethereum and Polygon environments.

ResolvLabs attacker moves 580 ETH, worth $1.09 million

Odaily reports, according to Onchain Lens monitoring, the ResolvLabs attacker has moved funds again after stealing approximately $25.9 million in March. Over the past few hours, 580 ETH, worth about $1.09 million, has been transferred and is being routed through a mixer.

Cambridge Study: US Hosts ~31% of Ethereum Nodes; Over One-Third Nodes Offline Could Impact Finalization

Odaily Odaily A new study by the Cambridge Centre for Alternative Finance reveals that approximately 31% of Ethereum node activity is located in the United States, with another 39% distributed across EU countries excluding the UK, indicating that the geographic distribution of Ethereum nodes remains relatively concentrated in Western nations.Lead researcher Alexander Neumuller stated that while node distribution is not currently concentrated in any single country, it is heavily reliant on a few major cloud service providers, including Hetzner, Amazon AWS, and OVH. Notably, the Ethereum network does not require half of its validators to fail for problems to arise. If more than one-third of validators go offline simultaneously, the network may be unable to finalize block checkpoints (finalization). Neumuller pointed out that nodes and validators do not have a one-to-one correspondence; a single node may run multiple validators. Therefore, it is currently impossible to precisely assess the actual impact on the validator network from the failure of a specific node or service provider.Furthermore, the study reassessed the energy consumption of Ethereum following The Merge. Data shows that Ethereum's current annual energy consumption is approximately 7.9 GWh, equivalent to a continuous power draw of about 1 MW. This represents only about 0.02% of pre-merge levels, a reduction of approximately 99.98%. Currently, over 56% of the energy used by the Ethereum network comes from sustainable sources, exceeding the global average.The study also noted that client software diversity is another potential risk. If a dominant client software has a vulnerability, it could affect a large number of network participants. The report was published by the Cambridge Centre for Alternative Finance and supported by the Ethereum Foundation. (The)

Ostium trading remains paused, user margin funds remain frozen

Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.

Ostium OLP Vault Attacked, Approximately $24 Million USDC Stolen and Transferred to Tornado Cash

According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), the public OLP vault of decentralized perpetual contract protocol Ostium (@Ostium) was attacked, with approximately 24 million USDC stolen. The attacker subsequently swapped the stolen funds for 12,080 ETH and has transferred 10,540 ETH into the mixer Tornado Cash to obscure the fund flow. On-chain tracing shows that the attacker's initial funds originated from ChangeNow and Bybit, with 1 ETH transferred from each to the attacker's wallet (0x321D...8bfD9).

DeBank user musti_akrep exploits Ostium vulnerability to profit 23.75 million USDC and exchange for 12,085 ETH

according to on-chain analyst Yujin's monitoring, half an hour ago, an address (0x321...bfd9) with the DeBank username musti_akrep profited 23.75 million USDC by exploiting a vulnerability on Perp DEX Ostium and withdrew it. The 23.75 million USDC was withdrawn to the Arbitrum chain and immediately exchanged for 12,085 ETH at a price of $1,965. Currently, these 12,085 ETH remain on the Arbitrum chain.

LayerZero_Core Executor wallet allegedly hacked, multi-chain losses of $2.1 million

according to on-chain detective Specter's monitoring, the LayerZero_Core Executor wallet may have been compromised, resulting in a total multi-chain loss of $2.1 million. The attacker bridged the stolen funds to Ethereum via Stargate and Relay, and is currently holding 955 ETH (worth $1.78 million) and 322,000 USDC. CyversAlerts first identified this suspicious activity.

BarnBridge governance attack reportedly causes approximately $776,000 in losses

According to BlockSec monitoring, the BarnBridge SMART Yield cUSDC protocol was attacked on Ethereum, resulting in losses of approximately $776,000, suspected to be a governance attack. The attacker first gained DAO governance rights, then upgraded the SmartYield/controller proxy to a malicious implementation contract. This contract called the _takeUnderlying privileged function of CompoundProvider, utilizing pre-existing USDC approvals from 50 user accounts, and via transferFees, moved the aggregated funds to the attacker.

Starknet Launches Compliant Privacy Framework STRK20

According to Odaily Planet Daily, Ethereum ZK Layer2 Starknet has officially launched the compliant privacy framework STRK20, providing native privacy transaction capabilities for various digital assets on-chain. The framework operates based on a privacy pool mechanism. Once user assets are deposited into the privacy pool, all transactions are encrypted, with details such as transfer addresses and amounts being invisible to the outside. Developers can quickly integrate this privacy system using the accompanying SDK and wallet API, catering to the private transfer needs of various ERC-20 assets. STRK20 incorporates a complete compliance process: users must undergo pre-screening before entering the privacy pool; only upon receiving a legally effective formal query request and after an independent assessment, will the platform selectively disclose specific users, corresponding time periods, or designated transfer records, without revealing the private data of unrelated users.

Hackers hack into SpaceXAI and Starlink accounts to promote SCATMAN, profiting approximately $125,000

According to Lookonchain monitoring, hackers hacked into the SpaceXAI and Starlink accounts to issue and promote SCATMAN. The hacker's wallets (0xfee...a8ba, 0xdd...ba89) minted 10 trillion SCATMAN and exchanged all of them for 59 ETH, worth $108,000; another wallet under their control also exchanged 59.28 million SCATMAN for 14.7 ETH, worth $27,000. The hackers profited a total of approximately $125,000.

Two hackers today spent a total of 11.718 million DAI to purchase 6,454.7 ETH

: According to monitoring by on-chain analyst Yu Jin, the hacker (0x18B...E66) who stole funds from a Coinbase user spent 7.378 million DAI early this morning to buy 4,049.7 ETH at a price of $1,822. Meanwhile, the address (0xa13...628) that received ETH from Tornado Cash last November had previously transferred out 4,978 ETH and exchanged them for 16.294 million DAI at a price of $3,273. Today, two hours ago, this address spent 4.34 million DAI to repurchase 2,405 ETH at a price of $1,804.

Suspected hacker wallet buys 6,358 ETH with 11.59 million DAI

据链上分析师 Onchain Lens(@OnchainLens)监测,两个疑似属于同一实体的钱包地址以 1159 万枚 DAI 买入 6358枚 ETH,成交均价约为 1823 美元。Onchain Lens 表示,相关资金可能与黑客有关。

Ethereum Foundation: AI Discovers Vulnerability That Could Cause Validator Nodes to Go Offline, But Manual Verification Still Required

According to CoinDesk, the Ethereum Foundation recently disclosed that its security team used AI agents to test the software running on Ethereum validator nodes and successfully discovered a vulnerability that could be triggered remotely, causing node crashes. However, researchers emphasized that amidst the large volume of security reports generated by AI, manual review remains a key step in distinguishing real vulnerabilities from false positives. Reportedly, the vulnerability discovered resides in the Ethereum network message propagation protocol gossipsub, where attackers can remotely trigger the node software into an abnormal computation state, causing the program to crash and shut down, taking the validator node offline until the operator manually restarts it. The vulnerability has been fixed and registered under the number "CVE-2026-34219". Nikos Baxevanis, a member of the Ethereum Foundation Protocol Security Team, stated that the truly surprising aspect of this incident was not the AI's ability to discover vulnerabilities, but the significant amount of time the team spent distinguishing which vulnerabilities were real and which were merely plausible "hallucinations".

A Solana OG had 181,000 SOL stolen, and the hacker swapped them for 7,918 ETH

According to Lookonchain monitoring, a Solana OG had 181,000 SOL stolen. The hacker sold all 181,000 SOL, bridged the funds to Ethereum, and exchanged them for 7,918 ETH, worth $14.2 million.

Hedera Network suspected of being hacked, attacker has bridged $3.7 million to Ethereum

: According to on-chain detective Specter's monitoring, the Hedera Network is suspected of being hacked. The attacker has bridged over $3.7 million from the Hedera Network to Ethereum via LayerZero. The stolen funds are currently being swapped from WBTC to ETH. The theft addresses include 0x9A4966152F6e10b33Cb7a37975e8619816d6a494 and 0xaf20D792A19fD42dCf697ceBa6100291D96dD93e.