GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

KITE to Migrate Token Contracts at 1:1 Ratio, Attacker Addresses Excluded

Odaily News: The KITE Foundation has provided an update on the handling of a token security incident. A new KITE ERC-20 contract has been deployed on the Ethereum mainnet, with the total token supply remaining unchanged. Old KITE tokens will be migrated to the new contract at a 1:1 ratio. Addresses confirmed to be controlled by the attacker will be excluded and will not receive new tokens.The migration snapshot is based on Ethereum mainnet block height 25,692,498. Regular self-custody wallet users will receive the new tokens directly without needing to redeem or authorize anything. Exchange users will have their migration coordinated between the exchange and the KITE team. Cross-chain channels will remain paused until migration and verification are complete.Previously, KITE detected abnormal transfers on August 6 and confirmed it had been attacked by hackers. The team stated that this incident did not result in any asset losses for users or the project, and the impact is currently under control.

Nearly 200,000 XRP Stolen, Coreum Cross-Chain Bridge Attacked

Odaily News: The cross-chain bridge connecting XRP Ledger and Coreum was attacked on August 9. The attacker exploited a validation logic vulnerability to steal approximately 199,900 XRP, reducing the bridge's asset balance from roughly 200,400 XRP to 493.5 XRP. The attack did not involve private key leaks and did not target the XRP Ledger protocol itself. The attacker forged deposit operations, causing the bridge system to recognize them as legitimate deposits and triggering the bridge wallet on the other end to send real XRP. On-chain data shows that the attacker completed the fund transfer through 94 multi-signature authorization transactions within 97 minutes. These transactions required signatures from 17 of the 28 relay node keys, allowing the attacker to bypass the bridge's validation mechanism. As of August 11, the Coreum cross-chain bridge remains suspended, and the Coreum Development Foundation has not yet released an official incident report. The XRP mainnet and user private keys remain unaffected and secure.

BTCPay Server Hit by Critical Vulnerability Exploit, Supporters Launch Up to 3 BTC Bounty to Recover Stolen Funds

According to The Block, open-source Bitcoin payment processor BTCPay Server disclosed a critical security vulnerability being actively exploited last Friday and urgently requested users to upgrade to version 2.4.2. The vulnerability affects all versions prior to 2.4.2; attackers can use it to steal administrator macaroon authentication credentials of LND nodes, thereby fully controlling the connected Lightning Network wallets. Users such as Foundation and Citadel21 have confirmed that their Lightning node funds were drained, but BTCPay has not publicly disclosed the total amount stolen or the number of affected nodes. Currently, the official release version 2.4.2 has fixed this vulnerability, and on-chain hot wallets are not affected. The BTCPay Server Foundation has donated 0.21 BTC each to security researcher Craig Raw and Bitcoin Red Team to commend their responsible private disclosure of the vulnerability. Meanwhile, BTCPay supporters have promised to provide a bounty incentive of "10% of recovered funds," capped at 3 BTC.

BTCPay Temporarily Restricts Lightning Network Remote Access Due to LND Vulnerability

According to Cointelegraph, BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes due to attackers exploiting a critical vulnerability in LND (Lightning Network Daemon) to steal node credentials and transfer funds. Version 2.4.2 has upgraded to LND 0.21.1 and automatically rotates macaroon credentials in standard installations. The project team reminds operators to check for abnormal payments, channel closures, and balance changes as soon as possible; if nodes are exposed via self-built reverse proxies, Tor services, or port forwarding, relevant credentials must also be manually replaced. Currently, Foundation and Citadel21 have reported node fund losses, but the specific scale of losses has not yet been disclosed.

BTCPay Server Temporarily Restricts Public Remote Connections to LND Nodes, Vulnerability Causes Credential Leakage and Fund Theft

Bitcoin payment processing service BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. Attackers exploited a severe vulnerability to obtain credentials and transfer funds. The number of affected operators and the total amount stolen have not yet been disclosed. This restriction affects external wallets such as Zeus that connect via BTCPay Server domains or Tor onion addresses in Docker deployments, but Lightning Network payments can still continue. BTCPay Server stated that remote access functionality will be restored once security is confirmed. BTCPay Server 2.4.2 will install LND 0.21.1 and automatically regenerate macaroon credentials during standard installation. Foundation and Citadel21 have respectively disclosed that funds from their Lightning Network nodes were swept. Foundation stated that hot wallets were not affected, and the specific amounts of losses have not been disclosed.

Ethereum Foundation Recruiting Protocol Security Researcher

The Ethereum Foundation (EF) is globally recruiting Protocol Security Researchers (Remote Full-time), a role within the Protocol Security team. The team is responsible for identifying and intercepting vulnerabilities before they reach mainnet, with work covering Execution Layer/Consensus Layer security reviews, AI-assisted vulnerability discovery, fuzzing, specification audits, and coordinating vulnerability disclosure. Candidates are required to have deep experience with the Ethereum protocol, be familiar with EL/CL specifications and client implementations, and be proficient in languages such as Go, Rust, Java, C#, Nim, or Python. There are no hard requirements on years of work experience, with technical depth being the core consideration.

Kite Foundation: KITE Token Attacked on Ethereum Mainnet, Incident Quickly Contained with No Token Loss

The Kite Foundation stated that it detected attacks targeting KITE tokens. After the security system discovered abnormal KITE token transfer activity on the Ethereum mainnet, the team immediately initiated the incident response mechanism and suspended KITE token transfers and cross-chain bridging on the Ethereum mainnet. The Foundation stated that the affected tokens have been frozen in place, cannot be transferred, and will not flow into the secondary market. Currently, the scope of the incident is limited to the Ethereum mainnet, and the relevant tokens have not moved since then.

One week after the NVIDIA-led AI Safety Alliance OSAA was established, it has already gathered over 120 companies.

According to TechCrunch, the Open Safety AI Alliance (OSAA), led by Nvidia, has exceeded 120 member companies just one week after its establishment, including tech and financial giants such as Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa. During the Black Hat Cybersecurity Conference held in Las Vegas this week, the alliance established a working group named "Shared AI Findings Exchange" (SAFE) and has submitted multiple proposals open for public comment, managed by the Linux Foundation. The proposals cover confidential reporting mechanisms for AI cybersecurity incidents, alert processes for affected parties, and no-fault attribution analysis frameworks. Meanwhile, member companies are also actively contributing open-source technologies: Nvidia open-sourced the LLM vulnerability scanning tool Garak, Amazon contributed the agent building tool Strands Agents and authorization language Cedar, and Okta and Red Hat are advancing agent identity authentication and governance technologies respectively. Notably, Anthropic, OpenAI, and Google have not yet joined the alliance, although OpenAI and Google previously co-signed the open letter that spurred the creation of the alliance.

Coldcard vulnerability-related losses may reach $130 million, hardware wallet manufacturers warn of increased phishing attacks

Odaily News: Hardware wallet manufacturers Trezor and Foundation have warned that following the disclosure of a Coldcard firmware vulnerability, phishing attempts targeting hardware wallet holders have increased, with attackers soliciting recovery phrases and luring victims into downloading malware. Security firm Proofpoint has detected phishing emails impersonating Coldcard, inviting users to complete a "hardware audit" with links to a cloned website. After clicking, users download a batch file hosted on GitHub that installs the remote access tool ScreenConnect. Proofpoint stated that the fraudulent website also features a customer service chat window, where real people guide victims through the installation process. This remote access tool can provide attackers with a pathway to steal data and funds, or further deploy malicious programs such as ransomware. Galaxy Research has confirmed three rounds of theft since July 30, with high-confidence losses of 1,596 BTC, exceeding $100 million; if a fourth round not yet confirmed with victims is included, total losses could reach $130 million.

Midnight Foundation: Wanchain Cardano<>BNB Bridge Attacked, Multiple Exchanges Jointly Freeze Related Assets

According to an official post from Midnight Foundation (@midnightfdn), the Wanchain Cardano<>BNB cross-chain bridge suffered a security attack. Currently, multiple major exchanges including KuCoin, Kraken, Binance, Bybit, OKX, and MEXC have responded rapidly, taking preventive measures to restrict the flow of stolen assets, including freezing relevant accounts and addresses, blacklisting the attacker's wallets, and suspending NIGHT token deposit and withdrawal services. The exchanges confirmed that this incident is an isolated third-party bridge vulnerability and is unrelated to the Midnight Network mainnet and the NIGHT asset itself.

Midnight:Multiple Exchanges Including Binance Freeze Funds Involved in Cross-Chain Bridge Attack

the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.

Cambridge Study: US Hosts ~31% of Ethereum Nodes; Over One-Third Nodes Offline Could Impact Finalization

Odaily Odaily A new study by the Cambridge Centre for Alternative Finance reveals that approximately 31% of Ethereum node activity is located in the United States, with another 39% distributed across EU countries excluding the UK, indicating that the geographic distribution of Ethereum nodes remains relatively concentrated in Western nations.Lead researcher Alexander Neumuller stated that while node distribution is not currently concentrated in any single country, it is heavily reliant on a few major cloud service providers, including Hetzner, Amazon AWS, and OVH. Notably, the Ethereum network does not require half of its validators to fail for problems to arise. If more than one-third of validators go offline simultaneously, the network may be unable to finalize block checkpoints (finalization). Neumuller pointed out that nodes and validators do not have a one-to-one correspondence; a single node may run multiple validators. Therefore, it is currently impossible to precisely assess the actual impact on the validator network from the failure of a specific node or service provider.Furthermore, the study reassessed the energy consumption of Ethereum following The Merge. Data shows that Ethereum's current annual energy consumption is approximately 7.9 GWh, equivalent to a continuous power draw of about 1 MW. This represents only about 0.02% of pre-merge levels, a reduction of approximately 99.98%. Currently, over 56% of the energy used by the Ethereum network comes from sustainable sources, exceeding the global average.The study also noted that client software diversity is another potential risk. If a dominant client software has a vulnerability, it could affect a large number of network participants. The report was published by the Cambridge Centre for Alternative Finance and supported by the Ethereum Foundation. (The)

Ethereum Foundation: AI Discovers Vulnerability That Could Cause Validator Nodes to Go Offline, But Manual Verification Still Required

According to CoinDesk, the Ethereum Foundation recently disclosed that its security team used AI agents to test the software running on Ethereum validator nodes and successfully discovered a vulnerability that could be triggered remotely, causing node crashes. However, researchers emphasized that amidst the large volume of security reports generated by AI, manual review remains a key step in distinguishing real vulnerabilities from false positives. Reportedly, the vulnerability discovered resides in the Ethereum network message propagation protocol gossipsub, where attackers can remotely trigger the node software into an abnormal computation state, causing the program to crash and shut down, taking the validator node offline until the operator manually restarts it. The vulnerability has been fixed and registered under the number "CVE-2026-34219". Nikos Baxevanis, a member of the Ethereum Foundation Protocol Security Team, stated that the truly surprising aspect of this incident was not the AI's ability to discover vulnerabilities, but the significant amount of time the team spent distinguishing which vulnerabilities were real and which were merely plausible "hallucinations".

Ethereum Foundation uses AI agents for red team testing of the ETH network and discovers real vulnerabilities

researchers from the Ethereum Foundation Protocol Security team said in a blog post on Thursday that they have deployed a series of AI agents to test the software relied upon by Ethereum, searching for vulnerabilities in encryption systems, protocol code, and smart contracts. The vulnerabilities discovered by the AI agents include a remotely triggerable panic issue in the libp2p gossipsub peer-to-peer layer used by Ethereum consensus clients. The issue has been fixed and disclosed on Github as CVE-2026-34219. Researchers stated that the AI agents are organized into specialized roles such as reconnaissance, search, patching, and verification, used to find potential attack paths, reproduce faults, and verify their applicability to production code. The Ethereum Foundation stated that AI has not replaced security researchers but has changed the way they work, enabling the team to cover far more scope than manual review. However, it requires researchers to exercise more careful judgment when evaluating a large number of seemingly credible conclusions. (Decrypt)

Opinion: Trump Signs Quantum Security Executive Order, Potentially Boosting Bitcoin Post-Quantum Security R&D

US President Trump signed two executive orders on Monday aimed at accelerating the nation's quantum computing capabilities and advancing the migration of government systems to post-quantum cryptography. While the orders do not directly mention Bitcoin, industry insiders believe this could benefit blockchain post-quantum security research and development.The two executive orders focus on defending against advanced cryptographic attacks and driving the frontier of quantum innovation. This includes a clear timeline: advancing quantum sensor construction by September 2028, and requiring federal high-value assets and high-impact systems to complete their post-quantum cryptography migration by the end of 2031.Alex Pruden, CEO of Project Eleven, stated that this means the US government will allocate funds and time to achieve post-quantum security goals. It may also extend these requirements to the entire federal contractor system, not just government agencies, thereby accelerating the practical application of post-quantum cryptographic technology.This policy comes amid growing attention within the blockchain industry to quantum threats. The Ethereum Foundation, Solana Foundation, and others have already begun advancing post-quantum security R&D, while the Bitcoin community is also discussing potential risks. Some Bitcoin held in publicly exposed addresses is considered vulnerable to private key derivation attacks once sufficiently powerful quantum computers emerge.Pruden noted that this executive order sets a clear deadline of 2031 for the adoption of post-quantum cryptography, which is more enforceable than the previous US government guidance which only proposed phasing out traditional cryptographic systems by 2035. For Bitcoin and the broader crypto industry, government-level investment in post-quantum security could accelerate the maturation of related tools, standards, and migration pathways.

Aztec Labs: Attacked Product Discontinued Four Years Ago, No Control Over It

according to Aztec Labs monitoring, the team is investigating a potential vulnerability affecting an Aztec payments product that was discontinued in 2021. Approximately $2 million was transferred from an immutable smart contract. This discontinued product is an immutable Stage 2 Rollup version that was deactivated in 2022. Aztec Labs does not hold the admin keys or any control over the system, and thus cannot pause or upgrade it. This incident is separate from the attack on the Aztec Connect product on June 14. The Aztec Foundation stated that the product affected by this attack is not associated with any smart contracts of the current network or the AZTEC ERC20 token.

Zcash Founder Says Claude Mythos Audit Found No Critical Vulnerabilities

Odaily Zcash founder Zooko Wilcox posted on X stating that a security audit conducted by Anthropic's Claude Mythos AI model did not find any "more severe vulnerabilities" in the Zcash protocol. The audit was commissioned by Shielded Labs, a Swiss non-profit organization supporting Zcash development. On June 3, Zcash developers temporarily paused Orchard transactions after discovering a vulnerability in the shielded pool, restoring functionality through an emergency upgrade the same day. The issue stemmed from a four-year-old forging vulnerability in the Orchard shielded pool, identified by security researcher Taylor Hornby with the assistance of Anthropic's Claude Opus 4.8 model. The Zcash Foundation stated there is no evidence that the vulnerability was exploited, nor was any unauthorized value creation detected, and user privacy remained unaffected.Anthropic released the first public version of the Claude Mythos model, Fable 5, on Tuesday, and stated on Friday that it has suspended access to the Fable 5 and Mythos 5 AI models due to export control directives issued by the U.S. government citing national security concerns. (Cointelegraph)

Anthropic Mythos AI Audit of Zcash Finds No New Critical Vulnerabilities

According to Cointelegraph, Zcash founder Zooko Wilcox stated that a security audit of the Zcash protocol—commissioned by Shielded Labs and conducted using Anthropic’s Mythos AI model—did not uncover any new critical vulnerabilities. Previously, security researcher Taylor Hornby discovered, using Claude Opus 4.8, a four-year-old forgery vulnerability in the Orchard shielded pool, prompting developers to urgently suspend Orchard transactions on June 3 and complete the fix the same day. The Zcash Foundation confirmed there is no evidence the vulnerability was ever exploited, and user privacy remained unaffected.

Coinbase Advisory Board Warns of Bitcoin’s Quantum Risk: No Consensus Yet Within the Community—Quantum-Resistant Migration Preparations Should Begin Immediately

A cryptography expert advisory committee led by Coinbase released a report stating that Bitcoin should immediately begin preparing for potential quantum computing attacks. However, the committee did not take a clear stance on whether to freeze the millions of bitcoins potentially vulnerable to quantum-computing theft in the future. The committee includes several leading experts, such as Justin Drake, a researcher at the Ethereum Foundation. They argue that the current debate is not about *how* to introduce quantum-resistant signature schemes, but rather *how to handle* bitcoins held in long-dormant addresses that fail to migrate. One camp advocates setting a final deadline after which Bitcoin’s existing ECDSA and Schnorr signature schemes would no longer be supported, and unmigrated funds would be frozen—thereby preventing future quantum attackers from seizing large amounts of BTC and destabilizing markets. The other camp contends that freezing funds would effectively amount to asset confiscation, violating Bitcoin’s core principles of immutability and full user control over assets—and could set a precedent for future regulatory-driven freezes. The Coinbase advisory committee notes that these approaches are not mutually exclusive and could be combined. Yet it declines to state a position on whether “legacy BTC” should be frozen, asserting that the ultimate decision rests with Bitcoin’s community governance. It emphasizes two key points: first, technical development of quantum-resistant signature migration must begin immediately—not wait for governance debates to conclude; second, users must receive clear, timely risk communication to prevent prolonged uncertainty from harming the Bitcoin ecosystem.

Zcash Foundation Releases Zebra 4.5.3 and 5.0.0 to Address Critical Orchard Vulnerability via Emergency Soft Fork and NU 6.2

The Zcash Foundation released Zebra versions 4.5.3 and 5.0.0 to address a critical soundness vulnerability in the Orchard zero-knowledge proof circuit. Version 4.5.3 temporarily disables Orchard operations via an emergency soft fork, while version 5.0.0 activates NU 6.2, re-enables Orchard using the patched circuit, and permanently closes the vulnerability.