GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Due to sanctions, NoOnes will gradually wind down its operations

Odaily News: Peer-to-peer cryptocurrency trading platform NoOnes announced that it will begin gradually winding down operations after running for over three years. The company stated that it had been continuously seeking to resolve and lift the sanctions imposed on NoOnes, but ultimately failed. The sanctions caused the platform to lose key partners, and blockchain monitoring firms also flagged transactions associated with NoOnes as high-risk, making it increasingly difficult for the platform to continue normal operations. According to the plan, the business contraction began on August 17, and the P2P marketplace will close at 23:59 UTC on August 21. Services such as Swap, NoOnes Visa, fiat withdrawals, the gift card store, and the Bitcoin Lightning Network will also be discontinued progressively. After that, the platform will only support withdrawals, and users will still be able to log in, view balances, and withdraw remaining assets. The company advises users to complete asset withdrawals as soon as possible, no later than August 23. Previously, on January 26, 2025, NoOnes revealed that the platform had suffered a major security breach earlier that month, resulting in losses of approximately $8 million in crypto assets. CEO Ray Youssef confirmed the news after on-chain detective ZachXBT disclosed the hacking incident on his Telegram channel.

BTCPay Server Hit by Critical Vulnerability Exploit, Supporters Launch Up to 3 BTC Bounty to Recover Stolen Funds

According to The Block, open-source Bitcoin payment processor BTCPay Server disclosed a critical security vulnerability being actively exploited last Friday and urgently requested users to upgrade to version 2.4.2. The vulnerability affects all versions prior to 2.4.2; attackers can use it to steal administrator macaroon authentication credentials of LND nodes, thereby fully controlling the connected Lightning Network wallets. Users such as Foundation and Citadel21 have confirmed that their Lightning node funds were drained, but BTCPay has not publicly disclosed the total amount stolen or the number of affected nodes. Currently, the official release version 2.4.2 has fixed this vulnerability, and on-chain hot wallets are not affected. The BTCPay Server Foundation has donated 0.21 BTC each to security researcher Craig Raw and Bitcoin Red Team to commend their responsible private disclosure of the vulnerability. Meanwhile, BTCPay supporters have promised to provide a bounty incentive of "10% of recovered funds," capped at 3 BTC.

BTCPay Temporarily Restricts Lightning Network Remote Access Due to LND Vulnerability

According to Cointelegraph, BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes due to attackers exploiting a critical vulnerability in LND (Lightning Network Daemon) to steal node credentials and transfer funds. Version 2.4.2 has upgraded to LND 0.21.1 and automatically rotates macaroon credentials in standard installations. The project team reminds operators to check for abnormal payments, channel closures, and balance changes as soon as possible; if nodes are exposed via self-built reverse proxies, Tor services, or port forwarding, relevant credentials must also be manually replaced. Currently, Foundation and Citadel21 have reported node fund losses, but the specific scale of losses has not yet been disclosed.

BTCPay Server Temporarily Restricts Public Remote Connections to LND Nodes, Vulnerability Causes Credential Leakage and Fund Theft

Bitcoin payment processing service BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. Attackers exploited a severe vulnerability to obtain credentials and transfer funds. The number of affected operators and the total amount stolen have not yet been disclosed. This restriction affects external wallets such as Zeus that connect via BTCPay Server domains or Tor onion addresses in Docker deployments, but Lightning Network payments can still continue. BTCPay Server stated that remote access functionality will be restored once security is confirmed. BTCPay Server 2.4.2 will install LND 0.21.1 and automatically regenerate macaroon credentials during standard installation. Foundation and Citadel21 have respectively disclosed that funds from their Lightning Network nodes were swept. Foundation stated that hot wallets were not affected, and the specific amounts of losses have not been disclosed.

Zeus Wallet Urgently Taken Offline After Cyber Attack, States Customer Funds Safe

According to Cointelegraph, Bitcoin Lightning Network self-custodial wallet Zeus Wallet voluntarily took its infrastructure offline following a cybersecurity attack on Wednesday and is currently conducting a comprehensive audit of the system, with services to be restored upon completion. Zeus founder Evan Kaloudis stated that the attack was contained within hours, no customer fund losses were found, and there was no evidence that the Lightning node software was affected; the scope of the incident was limited to Zeus's own infrastructure. For users forced to close LSP channels during this incident, Zeus promised to provide replacement channels after services are restored. The company has not yet disclosed the specific nature of the attack or a timeline for resuming operations. Zeus stated that this incident will further drive its security development on Trusted Execution Environment (TEE) and Validating Lightning Signer (VLS) projects.

Boltz indefinitely suspends Bitcoin swap service due to accelerated AI-assisted attacks

Odaily News: Non-custodial Bitcoin swap service Boltz has indefinitely suspended its Bitcoin swap service, stating that the service will remain offline until further notice, with no timeline for restoration provided. Boltz allows users to transfer Bitcoin between the Lightning Network and the Bitcoin base layer, without the company ever holding custody of user funds. Boltz stated that over the past few months, its infrastructure has faced a continuous increase in automated, AI-assisted probing, and the team has already handled multiple exploit incidents. The company said each incident was contained, but the speed at which attackers iterate has outpaced the team's ability to discover and patch vulnerabilities. Boltz disclosed that the pace of attacks has accelerated over the past few days, and after reviewing recent security scan results, the company concluded that it cannot responsibly re-enable the swap service. Its API remains available for processing collaborative refunds, unilateral refunds remain operational as they do not rely on Boltz infrastructure, and customer support remains accessible.

Boltz indefinitely suspends swap service due to AI-assisted attacks

Odaily News: Bitcoin News posted on X platform, stating that Boltzhq has indefinitely suspended its swap service after reporting an increase in AI-assisted attacks and multiple contained exploits. Due to its non-custodial design, user funds were never at risk, but wallets relying on Boltz for Lightning Network swaps, including AquaBitcoin and BULLBITCOIN, experienced service disruptions while alternative infrastructure is being deployed.

StarkWare Researcher Proposes Bitcoin Post-Quantum Transaction Scheme Without Soft Fork

According to The Block, Avihu Levy, a researcher at StarkWare, published a paper proposing the Quantum Safe Bitcoin (QSB) scheme, claiming it enables quantum-resistant transactions under Bitcoin’s existing script rules—without requiring a soft fork. This scheme replaces elliptic-curve cryptography with the RIPEMD-160 hash function via a “hash-to-signature” puzzle, thereby enhancing resilience against quantum attacks. The paper notes that QSB’s current per-transaction cost ranges from $75 to $150—significantly higher than today’s average transaction fee—and involves complex user experience; thus, it is recommended only as a “last resort.” The scheme remains constrained by script opcodes and size limits, and does not yet support all use cases—such as the Lightning Network. Compared to BIP-360—which requires protocol-level changes—QSB needs no modifications to the Bitcoin protocol, but remains experimental.