GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Serious Vulnerability Exposed on Aptos Blockchain, $70 Billion in Assets Once Faced Systemic Risk

According to CoinDesk, researchers at blockchain security company Hexens discovered an "expired cache" type confusion vulnerability in the Aptos blockchain Move virtual machine. Attackers require only about $3,000 in server costs to launch attacks in a simulated environment with a success rate of nearly 90%, without needing validator privileges or internal knowledge. Researchers ran approximately 20 attacks in simulated tests, succeeding 17-18 times, and verified the potential ability to control management permissions of cross-chain protocols such as LayerZero, Wormhole, and USDC CCTP. Hexens assessed that the vulnerability directly threatens protocols on the Aptos chain such as DeFi, stablecoins, and liquid staking, involving assets in the low single-digit billions of dollars; if spread through paths such as cross-chain bridges, stablecoin minting, and centralized exchanges, the systemic risk exposure could reach up to $70 billion. The Aptos team completed the fix and deployed it to the mainnet within hours after receiving the vulnerability report on February 25, and currently no user funds have been compromised.

David Bailey: "BIP-110 Failure" Strengthens Bitcoin Resilience, Consensus Mechanism Undergoes Stress Test

David Bailey, Chairman and CEO of Nasdaq-listed Bitcoin treasury company Nakamoto, stated that the failure of the so-called long-standing "BIP-110" controversy constitutes an "extremely bullish" outcome for Bitcoin, and believes this further validates the network's attack resistance and anti-splitting capabilities.

hinkal will fully compensate user funds, confirming approximately 797,000 USDC was extracted by an attacker and swapped for 454 ETH

decentralized privacy protocol hinkal has released an update on a security incident, confirming that an attacker extracted approximately 797,000 USDC from its Ethereum contract through a series of transactions and exchanged it for about 454 ETH. Of this, roughly 410 ETH was subsequently transferred to Tornado Cash, while the remaining approximately 44.67 ETH was bridged to the Bitcoin network via THORChain. hinkal is currently collaborating with an external security team to trace the flow of funds.hinkal stated that the impact of this security incident is limited to the relevant fund pools on the Ethereum chain, and contracts on other chains remain unaffected. However, all contracts have been temporarily suspended for fixes and security verification. All affected users will be fully compensated at a 1:1 ratio, with specific compensation procedures and timelines to be announced in a subsequent update.

UXLINK hacker swaps $10.54 million DAI for 6,001 ETH

According to Onchain Lens monitoring, the UXLINK hacker swapped $10.54 million in DAI for 6,001 ETH at an average price of $1,757, and subsequently transferred the funds to Tornado Cash.

The MCSA in the US no longer opposes the CLARITY Act, shifting its stance to neutral

the Major County Sheriffs of America (MCSA), in a letter to U.S. Senate Banking Committee Chairman Tim Scott and Senator Elizabeth Warren, stated that after some of its concerns regarding Section 604 of the bill were addressed, it has shifted its stance on the CLARITY Act to "neutral." Section 604, concerning the Blockchain Regulatory Certainty Act, aims to protect developers from liability for illegal activities conducted by users on their decentralized platforms. The MCSA had previously stated that Section 604 could provide loopholes for criminals to exploit, making it more difficult for law enforcement to investigate crypto-related crimes. The MCSA indicated that it still hopes the CLARITY Act will amend Section 309 to include state law enforcement agencies. This section requires the U.S. Treasury Department to study decentralized finance and illicit finance risks. (Cointelegraph).

OKX Star: Will Donate No Less Than 1 BTC to the First "One-Person Company" Achieving an Annual Income of $1 Million on OKX.AI

: OKX founder and CEO Star stated in a post on X that the first "one-person company" (OPC) to achieve an annual revenue of $1 million on OKX.AI will receive a personal donation of no less than 1 BTC. Star noted that every major technological revolution gives rise to a new generation of entrepreneurs and believes that the AI era will create millions of "one-person companies."It is reported that the OKX.AI Genesis Hackathon has been launched, allowing developers to build Agent Service Providers (ASP) on the OKX.AI platform. The event features a total prize pool of $100,000, aimed at encouraging AI Agent projects with real demand scenarios and practical use value, driving the implementation of the Agent economy.

OKX Officially Launches OKX.AI Genesis Hackathon

: According to official sources, OKX has announced the official launch of the OKX.AI Genesis Hackathon, recruiting the first batch of Agent Service Providers (ASP) from global AI developers. The total prize pool for this hackathon is $100,000, with the highest single prize being 10,000 USDT. From now until 8:00 on July 18 (UTC+8), participants can submit their projects through the OKX.AI official website and post introduction threads on the X platform.It is reported that OKX.AI is an economic system specifically designed for Agents, where users and Agents can discover and utilize professional services provided by ASPs.

CertiK: Hinkal Protocol Exploited, Approximately $800K USDC Stolen

according to CertiK's monitoring, suspicious transactions occurred in the Hinkal Protocol. An address (0xbB3...fc20) executed multiple "Transact" transactions after initiating a "Proofless Deposit," siphoning approximately $800,000 USDC from the Hinkal contract.

Humanity Protocol Shifts to Enterprise AI Business After $36 Million Attack

Odaily Planet Daily reported that Humanity Protocol founder Terence Kwok stated that after suffering a hacker attack of approximately $36 million, which caused the H token to plummet, the project is realigning its strategic direction, gradually shifting from a "decentralized identity + blockchain project" to enterprise-grade AI products and services. It is reported that Humanity Protocol will place less emphasis on the blockchain identity narrative in the future, instead focusing on developing enterprise AI-related products and services. (The Block)

US Department of Justice Extradites Scattered Spider Hacker Group Members Involved in Over $100 Million Cryptocurrency Ransomware Attack

According to Financefeeds, the U.S. Department of Justice announced criminal charges against 19-year-old U.S.-Irish dual citizen Peter Stokes, who is alleged to be a member of the cybercrime organization "Scattered Spider" and has been extradited from Finland to the United States.

Citadel Securities Sues Former Employee for Over $7.9 Million Over Crypto Startup

Citadel Securities has filed a lawsuit in London, seeking over £6 million (approximately $7.9 million) from Leonard Lancia, its former European Head of Derivatives Systematic Market Making and co-founder of high-frequency crypto trading firm Portofino Technologies.Citadel Securities alleges that Leonard Lancia and his colleagues began planning their startup while still employed, and has won damages and legal cost support in related labor arbitration. Additionally, Citadel Securities filed a lawsuit against Portofino Technologies in the US in 2023, accusing it of stealing trade secrets. Leonard Lancia and Portofino Technologies have denied all allegations. The High Court in London rejected Leonard Lancia's request to lift the asset freezing order last Friday. (Bloomberg)

Taiko: The network has fully recovered, and all user funds have been replenished

Ethereum Layer 2 project Taiko has reopened its cross-chain bridge. Taiko stated that the network is now fully recovered, all user funds have been replenished, and it will soon release a full post-mortem report on the vulnerability incident. (The Block)

France records 77 crypto-related kidnappings and extortion cases in first half of year, a sharp increase from 45 cases in all of 2025

Odaily French Interior Minister Laurent Nuñez confirmed that France recorded 77 crypto-related kidnapping and extortion cases in the first half of 2026, a significant rise from 45 cases throughout the entire year of 2025. Authorities have launched a rapid alert system, with 724 people registered, and emergency measures have led to 200 arrests. Nuñez pledged to introduce a three-part plan to strengthen security measures in the crypto industry, including enhanced intelligence sharing, deeper cooperation with ADAN, and improved coordination among security agencies.CertiK stated that France has become a center for attacks, citing reasons including the presence of multiple leading crypto companies and their executives based locally, a “culture of炫耀 and voluntary disclosure of identity” within the community, and multiple sensitive data breaches. (cointelegraph)

SecondFi Launches Asset Recovery Wallet Check Tool; Users Can Preliminary Check if Wallets Are Affected

Odaily, Cardano wallet service provider SecondFi has launched an asset recovery wallet check tool, allowing users to preliminarily check whether their relevant wallets have been affected by the previous security incident.SecondFi stated that the addresses currently displayed in the tool are based on the team's preliminary review data of the security incident and are not final. The list may not be complete and does not represent the final scope of recovery.

Trump’s Financial Disclosures Fuel Crypto Ethics Controversy; Democrats Demand Inclusion of Restrictive Clauses

U.S. President Trump’s newly released 927-page financial disclosure document reveals income including hundreds of millions of dollars in crypto-related earnings. Among these are millions of dollars in revenue linked to World Liberty Financial, the DeFi project launched by the Trump family in 2024. This disclosure has heightened the urgency of congressional negotiations over ethics provisions within the Clarity Act, the crypto market structure bill.Currently, bipartisan lawmakers are negotiating the Clarity Act, which aims to establish the first comprehensive federal crypto regulatory framework in the United States. A key focus of the negotiations is whether to include ethics restrictions preventing the President, Vice President, members of Congress, and other federal officials from profiting from digital assets while in office.Following the document's release, Democratic lawmakers reiterated that the bill must contain strict ethics clauses. Senator Angela Alsobrooks stated that such restrictions should apply to the President, Vice President, and all members of Congress. She noted that ordinary Americans should benefit from digital assets in a fair and honest manner, rather than allowing political figures to profit through corruption and institutional loopholes.Senator Kirsten Gillibrand also indicated that both parties are still advancing stringent ethics reforms, proposing to prohibit the President, Vice President, and lawmakers from using crypto assets for personal gain. Meanwhile, Elizabeth Warren argued that if the Clarity Act fails to prevent the President, members of Congress, and their families from profiting from the crypto industry, the bill would further fuel controversies surrounding Trump-related crypto corruption.Republicans, for their part, stated that ethics clauses remain part of the bipartisan negotiations. With the July window for advancing the Clarity Act approaching, the disclosure of Trump family crypto income could become a key variable influencing the final text of the bill and the level of Democratic support.

CertiK: Edel Finance Lending Market Attacked, Losses Approximately $204,000

According to monitoring by security firm CertiK Alert (@CertiKAlert), the Edel Finance lending market suffered a vulnerability exploit, with the attacker manipulating the collateral price of the wGOOGLx token (which relies on its GOOGLx balance) to extract approximately $204,000 in funds through the lending function.

PeckShield: A total of 40 major hacking incidents occurred in the crypto sector in June, with total losses of approximately $75.87 million.

According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), a total of 40 major hacking incidents occurred in the cryptocurrency sector in June 2026, with total losses of approximately $75.87 million, down 7.13% month-over-month from May ($81.7 million). The top three incidents with the largest losses this month were: $31 million stolen from Humanity Protocol, $10 million lost from Syscoin Bridge, and $7.5 million stolen from the JaredFromSubway.eth MEV bot.

StarkWare Releases Starknet Quantum Resistance Roadmap

zero-knowledge scaling company StarkWare has released a Starknet quantum resistance roadmap, stating that the roadmap is divided into three phases to address the risk of future quantum computing attacks. StarkWare CEO Eli Ben-Sasson stated that Starknet can leverage its architectural advantages to achieve quantum resistance, as its underlying cryptography is based on zero-knowledge STARK proofs. According to reports, the first phase of the roadmap includes replacing part of the existing secure mathematical mechanism, Pedersen hash, with a quantum-resistant version, and adding quantum-resistant signatures; the second phase focuses on migration tools, upgrading existing smart contracts without requiring developers to manually rebuild applications; the third phase involves dependencies that Starknet cannot solve alone, primarily relying on Ethereum's quantum upgrade roadmap. Circle, Ethereum, Solana, Tezos, and Algorand have all proposed quantum resistance roadmaps. (Cointelegraph)

SecondFi: On-Chain Recovery Plan More Complex Than Expected, Recovery May Exceed Two Weeks

: Cardano wallet service provider SecondFi has released an update on the security incident recovery progress, stating that EMURGO has established an asset recovery fund to return assets to users affected by the attack.SecondFi stated that emergency measures have been taken to protect and restore access to some assets. The team is currently discussing appropriate custody mechanisms with Intersect to ensure the safe return of assets to users.Furthermore, SecondFi is collaborating with a Cardano community-led working group to advance the on-chain recovery plan. Due to the recovery plan being more complex than initially expected, the overall recovery time may exceed the previously estimated two weeks.

The U.S. partially eases export restrictions on Anthropic, marking a new phase of tiered AI regulation liberalization

the U.S. Department of Commerce has made differentiated adjustments to export restrictions on frontier models from AI company Anthropic, signaling that global AI regulation has entered a new phase of "tiered liberalization." The policy shows that the official ban on exporting Claude Mythos 5 has been lifted, allowing specific compliant and controlled users to resume using this cybersecurity model. Meanwhile, another high-end model, Fable 5, remains under export restrictions, with related policy consultations still ongoing.Industry analysts indicate that this layered control model—loosening restrictions in some areas while tightening in others—reflects the U.S. balancing act between national security, data sovereignty, and international AI competition. As the global AI race continues to accelerate, specialized models capable of vulnerability exploitation are facing increasingly stringent scrutiny from various countries. Multiple nations have initiated discussions on establishing a unified cross-border regulatory framework for frontier AI capabilities. (Forbes)