GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

MEXC Users Suffer Account Takeover, API Backdoor Leads to $340,000 in Stolen Assets

According to a post by user @shuangfei8, their MEXC account was compromised on September 25 when attackers used forged identification documents to complete a security reset and breach the account within 10 minutes. Although MEXC subsequently froze the account and assisted in its recovery, it failed to revoke the API key created by the attacker during the period of unauthorized control. At 04:12 on September 27, merely 27 minutes after the 24-hour withdrawal restriction was lifted, the attacker exploited this residual API to bypass Google verification and email verification, draining 322,110 USDT and 9,133,999 ONE (totaling approximately $340,000) from the account across six separate transactions. The user has submitted a formal compensation claim to MEXC and attempted to report the incident to the police, demanding that the platform preserve logs, provide a written response regarding the security vulnerability, and return the stolen assets. Furthermore, multiple MEXC users have recently reported receiving suspicious emails resembling a "request to reset security settings," prompting users to immediately navigate to 【API Management】 to check for any unknown API keys.

Harmony's preliminary ONE shortage narrows to 6.581 billion after cross-exchange reconciliation

: Harmony has released an update on the exchange reconciliation progress following the August 11 incident. It has verified on-chain deposits/withdrawals and cross-platform fund flows with Binance, Gate, KuCoin, MEXC, OKX, and Binance.US, prioritizing the coordination of restoring ONE deposits, withdrawals, and trading, with specific timelines to be announced separately by each exchange.Harmony stated that after matching 295 cross-exchange transfers totaling approximately 3.493 billion ONE and adjusting for circular transfers and returned funds, the preliminary shortage has been reduced from approximately 10.234 billion ONE to 6.581 billion ONE, a decrease of about 3.653 billion ONE. This change reflects an adjustment in reconciliation methodology and does not equate to newly recovered funds.Among these, Binance's data remains a preliminary upper-bound estimate, while some data from Gate and OKX are still pending final verification. Exchange teams have already frozen significant ONE balances and hacker proceeds. These efforts will be coordinated with the ONE migration and validator transition proposal, and validators may cease operations starting 22:00 Beijing time on September 10.

Harmony Release Incident Update: Team Has Fixed Vulnerability and Is Proceeding with Rollback Plan

Harmony released an incident update stating that on August 12, 2026, Beijing time, an unauthorized issuance event of the native token ONE occurred on the Harmony mainnet. Officials confirmed that the initial abnormal issuance volume was 4 billion ONE, completed through two empty block entries; additionally, on-chain reconstruction results show that the total forged cross-shard issuance volume could reach 3.0100001 trillion ONE, involving 6 forged cross-shard transactions and 4 attacker wallets, and the team is still further verifying the two sets of data.

Anomalous minting of over 3 trillion ONE tokens, Harmony says vulnerability fix is active and rollback plan is underway

Odaily News: According to Harmony's monitoring, Harmony stated that it is advancing a rollback plan and has reached an agreement with validators and exchanges on the specific approach. The minting vulnerability fix has been activated, and the full list of attacker wallets will be released soon. Previously, the number of ONE tokens anomalously minted on the Harmony network exceeded 3 trillion, involving 6 abnormal blocks.

Harmony:回滚目前是最受支持的处置方案,团队仍在制定具体处理计划

Harmony 官方 X 账号发文,Harmony 公链近期遭遇黑客攻击,攻击者通过漏洞恶意铸造代币并分散转移至 409 个钱包,涉及转账笔数达 10,288 笔。Harmony 团队已就数百笔可疑存款交易向交易所合作伙伴发出警报,相关交易所迅速冻结了黑客钱包。事件发生约 4 小时内,紧急补丁已发布,目前 53% 的验证节点已完成升级。团队表示,链回滚是目前最受认可的修复方案,将于数小时内公布进一步处置计划。

Harmony: Cross-chain bridge services suspended due to a security incident

According to official sources, Harmony announced that it has suspended cross-chain bridge services due to a security incident. Earlier reports indicated that Harmony was attacked, and the attacker exploited an empty block vulnerability to mint approximately 4 billion ONE without authorization, accounting for approximately 26% of the current supply.

ZachXBT: US Law Firms' "Free-Riding Claims" May Hinder Recovery and Compensation of Funds for Hacking Victims

Odaily Odaily PaperImperium, the head of MegaETH, disclosed on X platform that documents from the U.S. District Court for the Southern District of New York show that a U.S. court has issued an injunction against the Arbitrum DAO, prohibiting it from transferring approximately $71 million in ETH assets that were previously frozen during the KelpDAO hacking incident. In response, on-chain detective ZachXBT posted on X platform, stating that certain U.S. law firms are using his investigative work and on-chain forensics to help victims of some hacking incidents file legal claims. However, this practice may actually slow down or hinder victims from receiving compensation or recovering funds.ZachXBT added that in previous hacking incidents involving the Lazarus Group, such law firms often stepped in after on-chain fund tracking or freezing was completed, proposing subsequent legal actions that were weakly related to the crypto incidents themselves. Similar "free-riding claims" strategies were used in events like Harmony and Bybit. He called on the crypto community to establish a DAO to resist such practices.

SlowMist Issues Security Alert: Fake “Harmony Voice” Software Being Used in Social Engineering Attacks

According to threat intelligence released by the SlowMist security team (@SlowMist_Team), its threat intelligence system MistEye has received community reports identifying an active social engineering attack targeting cryptocurrency users. Attackers contact victims under the pretext of project collaboration and lure them into using a counterfeit “Harmony Voice” application (domain: harmony-voice[.]app) for so-called real-time translation—when in fact it is malicious software. SlowMist has already synchronized the relevant threat intelligence (IOCs) to its enterprise customers.