GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

Wyoming Expands Partnership with Chainlink to Introduce On-Chain Reserve Verification for FRNT Stablecoin

According to The Block, the Wyoming Stable Token Committee announced the adoption of Chainlink Proof of Reserve to provide near-real-time on-chain reserve validation for its official stablecoin, Frontier Stable Token (FRNT). The Network Firm will audit FRNT reserves in accordance with AICPA standards, while Chainlink will post verification data on-chain in real time to bridge information gaps between reporting cycles. Previously, Wyoming fully migrated FRNT from LayerZero to Chainlink CCIP last month as its sole cross-chain infrastructure. The committee is also advancing the Chainlink Proof of Reserve Secure Mint feature, which requires verifying that reserves do not fall below FRNT's total supply before minting new tokens to prevent infinite minting attacks. FRNT launched in January this year and is the United States' first government-issued stable token, backed by U.S. dollars and short-term U.S. Treasuries.

FUNVERSE's First On-Chain Game FUN LONGINUS to Launch on Anubis Chain Mainnet on September 1

Odaily News: FUN LONGINUS, the first on-chain game launched by FUNVERSE, will officially go live on the Anubis Chain mainnet at 10:00 UTC on September 1, 2026 (18:00 UTC+8).Originating from a hackathon, FUN LONGINUS is an Eastern martial arts-themed on-chain game built for the Anubis GameFi ecosystem.The game adopts the 24 solar terms as its competitive structure. Each round brings together 24 different addresses, with each player using fLGNS to enter the arena. The execution of matches, determination of results, and final settlement are all handled by smart contracts, ultimately crowning one champion.On August 18, 2026, FUN LONGINUS completed its "Heroes Collective Mint." Based on market prices at the time of writing, the total value of this collective mint exceeded $1.4 million.This mainnet launch marks FUN LONGINUS's official transition from the hackathon prototype, public beta, and collective mint phases into the on-chain game operation stage.

SlowMist Unveils Details of Allbridge Bridge Attack: Forged CCTP Messages + Flash Loans, Insufficient Mint Verification

Odaily News, SlowMist Security Team disclosed that the cross-chain bridge project Allbridge suffered an attack on August 19, 2026, with losses of approximately $190,000. Notably, this attack was not executed instantaneously—the attacker began laying the groundwork nearly a month in advance, bypassing the verification mechanism through forged cross-chain messages.According to SlowMist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as CCTP-style, claiming a transfer of 1 million USDC, despite no actual USDC burn operation occurring. Subsequently, Circle generated a valid attestation for this complete message following standard procedures.Approximately 24 days later, on August 19, the attacker waited for the Base Router to receive a genuine CCTP deposit, bringing its balance to approximately 191,000 USDC, then launched the attack just 6 seconds later. Using the previously forged message and attestation, the attacker called Allbridge's receiveCctpMessage function. Due to the project's lack of critical validation, the system mistook the fraudulent cross-chain message for a genuine deposit and recorded a 1 million USDC credit.Subsequently, the attacker borrowed approximately 809,000 USDC temporarily via an Aave flash loan to match the Router's balance with the forged amount, then utilized the internal credit record to call the transfer function, ultimately moving out approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800 in profit. The root cause of this vulnerability lies in Allbridge's failure to verify the identity of the cross-chain message sender and receiver, as well as its failure to confirm whether USDC was genuinely minted or whether the balance actually increased—instead directly trusting the amount and message hash data constructed by the attacker.SlowMist emphasized that on-chain message verification does not equate to actual asset arrival. Cross-chain protocols must not only verify message authenticity but also ensure the message source is trustworthy, confirm the receiver is Circle's official TokenMessengerV2, and only record assets after confirming actual minting and balance changes. This incident once again highlights the security risks in cross-chain bridges' message verification and asset settlement processes.

Axelar Issues Statement on Security Incident: Axelar and IBC Unaffected, Vulnerability Originates from "Infinite Mint" Issue in Third-Party Token Contract

: Cross-chain protocol Axelar Network has issued a statement regarding the recent security incident related to Secret Network, clarifying that there is a misunderstanding within the community. Neither Axelar nor the Inter-Blockchain Communication Protocol (IBC) was attacked or compromised. The affected token smart contract was not developed, deployed, or maintained by Axelar. Furthermore, Axelar's firewall mechanism prevented the impact from spreading to other chains.It is reported that the exploited contract was a fork based on the CW20-ICS20 implementation, but the developers removed two core security checks, leading to an "infinite mint" vulnerability. By deleting the verification mechanisms originally designed to prevent such issues, this fork altered the contract's original trust model and was not subjected to a new security audit.Axelar Network explained that anyone can deploy contracts via IBC for wrapping cross-chain assets, and similar contracts are used to wrap tokens from other chains onto Secret Network. However, the specific fork on the Secret side in this incident contained a vulnerability due to the removal of critical security checks. This incident was not caused by an inherent logic flaw or an issue with the IBC protocol itself, but rather a security risk introduced by modifications made to the third-party contract.

Threshold Network: Successfully Thwarted Attempt to Maliciously Mint tBTC

Threshold Network posted on platform X, stating that on May 18, 2026, a malicious attacker attempted to mint tBTC without depositing the underlying Bitcoin. The attempt was unsuccessful; no invalid tBTC was issued, and user funds were not at risk.As a precautionary measure against high-frequency malicious activity in the broader crypto ecosystem, Optimistic Minting has been temporarily suspended. Currently, minting operations are conducted through the liquidation mechanism, with typical minting times increasing from approximately 1.5 hours to around 6 to 7 hours.