GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Cybersecurity company Rapid7 discloses encrypted phishing campaign targeting 885,000 phone numbers.

According to Cointelegraph, cybersecurity company Rapid7 has disclosed a cryptocurrency phishing campaign named "Operation Asterix" targeting approximately 885,000 phone numbers, aimed at luring users into visiting fraudulent Ledger, Trezor, and Exodus wallet apps or websites to steal mnemonic phrases and crypto assets.

Rapid7 discloses crypto phishing campaign targeting 885,000 phone numbers and involving 5,576 Binance accounts

Odaily News Rapid7, a cybersecurity firm, has disclosed a crypto phishing campaign named Operation Asterix that targets approximately 885,000 phone numbers across multiple countries, redirecting victims to fraudulent wallet service websites. A total of 5,576 phone numbers have been matched with Binance user accounts and placed on the attack queue.The attackers steal seed phrases through fake apps impersonating Ledger, Trezor, and Exodus, while also contacting victims via fraudulent customer support emails and phone calls. Rapid7 also found that among over 316,000 phone numbers in Germany, 43,066 were matched with crypto trading accounts, representing a hit rate of approximately 13.6%.The related attacks also include a bulk phone number verification tool targeting Kraken accounts, and the investigation revealed that AI tools are being widely used in phishing operations. According to data from blockchain security firm Hacken, phishing attacks and social engineering scams caused $306 million in losses in the first quarter of this year, accounting for the majority of the $482 million total losses in the crypto industry. (Cointelegraph)

DefiLlama delays mobile app launch due to phishing impersonators on Apple's App Store

Odaily News, DefiLlama founder 0xngmi, of the crypto data analytics platform, stated that the team spent months asking Apple to remove phishing apps impersonating DefiLlama from the App Store, which delayed the mobile app's launch until all such counterfeit apps had been removed. 0xngmi noted that after the team downloaded one of the malicious apps and documented a small crypto wallet being stolen, Apple removed it within days. In 2024, the App Store also saw counterfeit apps impersonating Rabby Wallet and Curve Finance; in November 2023, a fake Ledger Live app on the Microsoft Store siphoned off $588,000 across 38 transactions. (Cointelegraph)

Approximately 233,000 Bitcoin moved as a precaution, with around $15 billion involved following the Coldcard exploit

Odaily News: After a firmware vulnerability in Coldcard hardware wallets was exploited, approximately 2,100 Bitcoin were stolen, with losses nearing $130 million. On-chain data shows that in the days surrounding the incident, wallets held by long-term holders transferred out approximately 233,000 Bitcoin, valued at around $15 billion. Casa CEO Nick Neuman stated that some of the transferred funds came from Coldcard users migrating to multi-signature wallets, with Ledger and Trezor users also taking similar measures after the event. During the same period, approximately 22,000 Bitcoin were transferred into exchanges. Coinkite has advised users who generated seed phrases using firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and immediately migrate to new seed phrases. These versions cover the period from March 2021 to July 2026. (Decrypt)

Crypto Companies Send Joint Letter to AI Labs, Urging Access to Frontier Models for Bitcoin Developers

据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。

Nearly 200,000 XRP Stolen, Coreum Cross-Chain Bridge Attacked

Odaily News: The cross-chain bridge connecting XRP Ledger and Coreum was attacked on August 9. The attacker exploited a validation logic vulnerability to steal approximately 199,900 XRP, reducing the bridge's asset balance from roughly 200,400 XRP to 493.5 XRP. The attack did not involve private key leaks and did not target the XRP Ledger protocol itself. The attacker forged deposit operations, causing the bridge system to recognize them as legitimate deposits and triggering the bridge wallet on the other end to send real XRP. On-chain data shows that the attacker completed the fund transfer through 94 multi-signature authorization transactions within 97 minutes. These transactions required signatures from 17 of the 28 relay node keys, allowing the attacker to bypass the bridge's validation mechanism. As of August 11, the Coreum cross-chain bridge remains suspended, and the Coreum Development Foundation has not yet released an official incident report. The XRP mainnet and user private keys remain unaffected and secure.

Over $3 million has been stolen as the same attacker runs phishing campaigns targeting Ledger

Odaily News: According to on-chain investigator Specter, the same attacker is running similar phishing campaigns targeting Ledger. The relevant screenshots were taken two days ago, and the sponsored ads have now been removed. To date, these campaigns have stolen over $3 million.

Ledger: Coldcard Vulnerability Losses Reach Approximately $130 Million, Hardware Wallet Security Needs to Adapt to AI

Odaily News: Hardware wallet manufacturer Ledger has stated that the recent Coldcard vulnerability indicates the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, as their recovery phrases are generated by a hardware random number generator built into a certified secure element. Coldcard manufacturer Coinkite disclosed last week that its air-gapped Coldcard Bitcoin hardware wallet contains a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, allowing certain private keys to be guessed, with related losses reaching approximately $130 million. Coinkite released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited — the flaw had existed in public code for over five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed. Charles Guillemet also said that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process has received independent certification.

Bloomberg ETF Analyst Questions Coldcard Team Size: Approximately 5-Person Team Undertaking Critical Wallet Security Responsibilities Poses Risk

Bloomberg Senior ETF Analyst Eric Balchunas commented on the Coldcard wallet security incident, questioning whether a company with only about 5 employees is suitable to undertake such critical Bitcoin storage responsibilities. He stated that the number of employees behind Coldcard "seems unbelievably low," asking whether people would be willing to store their life savings in a bank with only 5 employees headquartered in Canada. In the crypto industry, this might be viewed as a feature, but from a traditional finance perspective, it becomes a clear risk signal. Balchunas further stated that, in comparison, institutions with larger teams such as Coinbase and Ledger may hold advantages in security investment and operational capabilities, even if users need to bear higher transaction costs. Bitcoin ETFs offer another option: investors can obtain the security guarantees provided by large, professional, regulated financial institutions while also enjoying lower management fees.

Next week's release: XRP Ledger's new version, xrpld 3.3.0, will feature five new capabilities

Odaily News: Jazzi Cooper, RippleX Product Lead, announced on X that the next version of XRP Ledger, xrpld 3.3.0, is set to launch next week. Upon release, it will introduce five new features to validators: confidential MPT, batch transactions, delegated permissions, fee sponsorship and reserves, and dynamic MPT. Among these, the amendments for batch transactions and delegated permissions were previously urgently withdrawn after security researchers discovered severe vulnerabilities. She noted that XRP Ledger already has the capacity to support tokenized assets at scale, and this upgrade will further drive the adoption of these assets in global transfers, trading, collateralization, and settlement scenarios.

Native transactions have been suspended; a legacy vulnerability from 2019 exists in the Zilliqa Ledger application

Zilliqa has stated there is a critical vulnerability in its Ledger application that has existed since 2019, causing private keys used for native ZIL transactions to be susceptible to recovery attacks. At present, native transactions have been suspended, and relevant parties are working on a coordinated fix. EVM transactions are not affected.

Ledger Researchers Disclose Tangem Hardware Wallet Card Vulnerability

According to The Block, Ledger's security research team Donjon disclosed a security vulnerability in Tangem hardware wallet cards. After obtaining the physical card, attackers can use laser fault injection equipment to bypass recovery state verification in the firmware and reset the password, thereby controlling the wallet and initiating transactions. The research states that this vulnerability affects all Tangem cards currently in circulation, and since the product does not support firmware updates, it cannot be fixed via patches.

Trezor Safe 7’s Chip Has a Hardware Vulnerability, Team Says User Funds Are Safe

Ledger's Donjon security research team successfully bypassed the firmware verification system of the TROPIC01 chip inside the Trezor Safe 7 using laser attacks in a laboratory setting. Chip manufacturer Tropic Square subsequently discovered another attack path affecting the chip's MAC-and-Destroy security mechanism. This vulnerability currently impacts all TROPIC01 chips in production within the field. Trezor stated that the TROPIC01 chip is one of three independent security layers within the Trezor Safe 7, and user funds, wallet backups, and private keys are not stored on it.The chip's hardware encryption storage mechanism completely withstood Ledger's extraction attempts during initial testing. Tropic Square has delayed the release of technical details regarding the vulnerability until the launch of a reinforced silicon version of the TROPIC01 chip later in 2026, with full details expected to be disclosed in the spring of 2027.A firmware mitigation is currently available by disabling the chip's MAINTENANCE mode. Trezor CEO Matej Zak stated that PINs, wallet backups, and user fund keys have never been stored on a single chip. (The Block)

CertiK: Crypto “wrench attacks” surge in 2026, with Europe the hardest-hit region—France especially prominent

According to The Block, blockchain security firm CertiK released a report on May 8 stating that 34 confirmed “wrench attacks” (i.e., offline physical assaults and extortion targeting cryptocurrency holders) occurred globally in the first four months of 2026—an increase of 41% compared to the same period in 2025. Victims’ total losses amounted to approximately $101 million. If this trend continues, the annual number of incidents is projected to reach around 130, with losses potentially totaling hundreds of millions of dollars. Geographically, 28 of the 34 incidents (82%) occurred in Europe, with France standing out particularly: 24 cases were recorded there in the first four months of 2026 alone—exceeding the full-year total of 20 incidents in 2025. CertiK attributes this surge to France’s hosting of flagship crypto firms such as Ledger and Binance, frequent data breaches, and a community culture of conspicuous wealth display and proactive doxxing. In contrast, reported incidents in the U.S. dropped from nine in Q1 2025 to three in Q1 2026, while Asia saw a decline from 25 to two. Regarding attack patterns, CertiK notes that criminal groups have shifted toward a “data-driven targeting” model—purchasing victims’ names, addresses, and asset information from data brokers, thereby reducing the need for physical reconnaissance. Over half of this year’s incidents involved threats against or direct harm to victims’ family members (spouses, children, elderly parents) as a coercive tactic. Operationally, small gangs of three to five individuals typically carry out these attacks via

Ledger CTO Analyzes Post-Quantum Cryptography Migration, Blockchain Favors Hash-Based Signature Schemes

Ledger Chief Technology Officer Charles Guillemet pointed out that the development of post-quantum cryptography has entered a critical stage. Although the timeline for a practical quantum computer remains unclear, a full-scale migration of the encryption systems across the industry is an inevitable trend. Led by NIST, the traditional sector plans to phase out high-risk algorithms by 2030 and completely ban them by 2035, with government and enterprise institutions expected to complete their migration layouts by 2029. Encryption and key exchange will adopt ML-KEM to defend against quantum decryption attacks on harvested data, with digital signatures becoming the core of blockchain transformation. The traditional industry prefers ML-DSA hybrid schemes, while the blockchain sector favors the more secure and robust SLH-DSA hash-based signature. Both schemes have their respective advantages and disadvantages. The compatibility challenges of post-quantum algorithms with MPC and threshold signatures remain a key risk that the industry urgently needs to address.

France Has Recorded 41 Kidnapping Cases Targeting Cryptocurrency Holders This Year

Odaily News France has become a hotspot for wrench attacks, with at least 41 cryptocurrency-related kidnappings and home invasions reported this year, averaging one incident every 2.5 days. Jean-Didier Berger, the Deputy Minister of the Interior, stated that a series of new measures are being prepared with Interior Minister Laurent Nuñez to address this issue.A wrench attack refers to the use of physical violence to force victims to transfer crypto assets. Data from Certik and Jameson Lopp shows that globally, there were 72 verified cases of physical coercion in 2025, a 75% year-on-year increase, with cases involving physical assaults rising by 250%. Ledger co-founder David Balland was kidnapped in France in January 2025. Security researchers point out that attackers are shifting from targeting wallets to hunting individuals, using social media and leaked data to identify targets. Due to the irreversible nature of crypto transactions, attackers often convert illicit proceeds into stablecoins and transfer them across chains to evade tracking. Experts recommend using tools such as multi-signature wallets, withdrawal delays, and spending limits to reduce the risk of attack.

US Musician Loses 5.9 BTC Due to Fake Ledger Wallet

According to The Block, U.S. musician Garrett Dutton (stage name G. Love) lost 5.9 BTC—worth approximately $420,000—after downloading and using a counterfeit Ledger wallet app from the App Store and entering his recovery phrase. On-chain analyst ZachXBT discovered that the attacker laundered the stolen Bitcoin via the KuCoin platform. This incident once again exposes the security risks posed by fake wallet apps, reminding users to exercise heightened caution when downloading and using cryptocurrency-related applications, and to avoid entering sensitive information through unofficial channels.