GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Ukraine Seizes $8.3 Million in Crypto Assets, Potentially Paving the Way for a Strategic Crypto Reserve

OdailyOdaily reports that the Prosecutor General's Office of Ukraine stated it has, for the first time, transferred approximately $8.3 million worth of USDT crypto assets into the national asset management system, marking the country's first official takeover of seized crypto assets. The funds originate from an investigation into an international hacking group, which is alleged to have laundered money through high-value real estate and other assets. The assets were received by the Asset Recovery and Management Agency (ARMA) of Ukraine, with the transfer completed pursuant to a court order.Officials stated that this operation marks a significant step for Ukraine in the regulation and management of crypto assets, and aligns with ongoing discussions regarding the establishment of a strategic crypto reserve. Previous data indicates that Ukraine ranked among the top in Europe in terms of crypto transaction volume between 2024 and 2025.However, the relevant assets are currently in a "custodial" state and have not been legally forfeited; subsequent judicial conviction procedures are still required. Analysts believe that the mechanism of this move is similar to the path of the United States using criminally forfeited crypto assets to build a potential strategic reserve. (CoinDesk)

Taiko: Mainnet to Resume Operations in Four Steps; Vulnerability Fixed and Security Review Completed

Taiko, an Ethereum Layer 2 project, announced that its fix has been reviewed by independent security experts. The mainnet will resume operations in four steps, including: deploying the fix and confirming the chain's final state is correct, ensuring there are no invalid checkpoints or attacker-submitted records that could be accepted; replenishing cross-chain bridge liquidity to ensure all L2 assets maintain a 1:1 reserve; restoring network operations and reopening L2 transfers, swaps, and trading functions; and having the security committee propose lifting the bridge suspension to fully restore asset deposit and withdrawal functionality.Taiko stated that during the initial reopening period, relatively conservative withdrawal limits will be set as an additional security measure, but this is not expected to affect users' normal asset operations.

curl fixes 18 security vulnerabilities, upgrade curl/libcurl as soon as possible and assess related risks

Odaily Planet Daily reported that 23pds, Chief Information Security Officer of SlowMist, posted on X, stating that Curl has fixed 18 security vulnerabilities involving authentication bypass, memory safety, and host verification issues. One of the libcurl vulnerabilities has existed for approximately 25 years. The risks affect a wide range of applications, SDKs, containers, firmware, gateways, and CI/CD environments that rely on libcurl. It is recommended to upgrade curl/libcurl as soon as possible and check for the use of outdated libcurl versions, with particular attention to mTLS, proxy authentication, and connection reuse scenarios.

Brother Machi Posts Multiple Tweets About Meme Coin Machi, Token Surges 235% Intraday

Brother Machi, Huang Licheng, has published multiple tweets about the Meme coin Machi. The token's price briefly broke through $0.0007 and is currently trading at $0.000668, representing an intraday increase of 235%.It remains unclear whether Brother Machi's X account has been compromised. Community users are advised to remain vigilant.Odaily reminds investors that Meme coin prices are highly volatile, primarily driven by market sentiment and concept speculation, and lack clear real-world utility. Investors should be aware of the associated risks.

Base Discloses Causes of Two Recent Outages, Identified as Sequencer Vulnerabilities

the Coinbase Layer 2 network Base experienced two block production outages last week, with the root cause identified as a vulnerability in the sequencer's block construction logic. This vulnerability allowed outdated log states to persist after transaction validation failed, preventing the sequencer and validator nodes from processing invalid blocks until sequencing was restored.The first incident lasted 116 minutes, while the second, caused by a race condition following a system reset that prevented the sequencer from keeping up, lasted 20 minutes. The team has since fixed the issue by applying a patch to the sequencer, with future plans to improve protocol fuzz testing and build a graceful recovery mechanism. (Cointelegraph)

Fidelity refutes claims that Bitcoin’s security declines post-halving, stating miners’ revenue increases as Bitcoin price rises.

According to Cointelegraph, Fidelity Digital Assets has rebutted concerns in a new research report that Bitcoin’s long-term security will deteriorate as mining rewards decline, asserting that the network’s economic incentives remain sufficient to secure the blockchain over the long term. Authored by Fidelity research analyst Daniel Gray, the report reiterates that Bitcoin’s security depends not only on block rewards but also on transaction fees and market-driven economic incentives, which will continue to motivate miners to protect the network—and render sustained attacks prohibitively costly. The report challenges a longstanding critique that Bitcoin’s security is weakened every four years by the halving event, which reduces new coin issuance. It notes that since April 20, 2024, Bitcoin miners have received a subsidy of 3.125 BTC per block—down from 6.25 BTC in the previous halving cycle—but this reduction in issuance has not translated into diminished miner incentives, as Bitcoin’s price appreciation has more than offset the decline in block rewards. Gray points out that average daily miner revenue has surged from approximately $26,300 during Bitcoin’s first halving cycle to over $40.2 million today. The report also notes that although Fidelity views the long-term incentive structure as sound, many publicly listed mining companies are currently facing financial pressure, with some diversifying into artificial intelligence and high-performance computing. VanEck recently

Base Releases Block Production Outage Analysis Report: Sequencer Bug Causes Brief On-Chain Downtime, Protocol Stress Testing to Be Strengthened

Base has officially released an analysis report on the block production outage, disclosing that the Base mainnet experienced two block production interruptions on June 25 and 26, lasting 116 minutes and 20 minutes respectively. On-chain asset security was unaffected, and funds remained safe at all times. The root cause was a vulnerability in the sequencer's block construction logic: after a transaction execution failure, the old journal state was not properly cleared, causing subsequent legitimate transactions to encounter gas calculation errors during execution, thereby generating invalid state transition blocks and halting block production on the entire L2 chain.Base stated that the issue has been resolved through a patch, and will strengthen the protocol's fuzz testing and stress testing framework to identify potential malicious transaction paths, while optimizing monitoring and operational processes. Additionally, plans are in place to introduce a recovery mechanism to enhance rapid recovery capabilities in future similar events.

Anthropic's Restricted Spillover Effect Emerges: Asian AI Companies Simultaneously Launch Rival Frontier Models

as Anthropic faces export restrictions limiting the global availability of its advanced models, multiple Asian AI companies are accelerating efforts to fill the market gap. Chinese cybersecurity firm 360 Security Technology has reportedly launched an AI tool called "Tulongfeng," claiming it can directly compete with Anthropic's high-end model "Mythos." Meanwhile, its more restricted version, "Fable 5," also falls within the scope of relevant export controls.In the same week, Japanese AI startup Sakana AI released a new model named "Fugu," taken from the Japanese word for pufferfish. It is positioned as a frontier model designed for agents. The company stated that the model's capabilities are comparable to Fable 5 and Mythos Preview, and it supports coordinating multi-model calls via API to enable agent orchestration.Sakana AI emphasized that the timing of this release and the U.S. export restrictions are "purely coincidental," but the product's official website still clearly promotes "providing frontier capabilities without the risk of export controls." Company co-founder David Ha stated that future AI development will shift from competition among single large models to "model orchestration systems," adding that "access can disappear at any time, and distributed intelligence is a realistic hedge against the risks of centralization."On the other hand, Chinese 360 founder Zhou Hongyi views AI vulnerability detection capabilities as a "national strategic asset" and warns of the so-called "one-way transparency" risk, where certain entities may monopolize advanced security capabilities.According to reports, the U.S. export restrictions on Anthropic's advanced models have been in place for about two weeks. Against this backdrop, Asian manufacturers are accelerating the launch of local alternatives. Although some companies still emphasize the importance of American models in the Asian market, the trend of differentiation within the regional AI ecosystem has begun to emerge. (TechCrunch)

ZachXBT: Funds stolen from Humanity Protocol and Kelp DAO have been mixed; attackers may overlap.

On-chain investigator ZachXBT stated that the stolen funds from the Humanity Protocol and Kelp DAO security incidents have been mixed and transferred, suggesting potential overlap among the attackers and further undermining the possibility of an insider attack on Humanity Protocol.

Thailand Issues Arrest Warrant for Chinese Businessman Allegedly Involved in "Pig Butchering" Scam and Illegal Crypto Mining Money Laundering Worth Billions of Dollars

The Thai government has officially issued an arrest warrant for Chinese businessman Wang Yicheng, accusing him of colluding with transnational criminal syndicates to launder billions of dollars through illegal cryptocurrency "mining" activities on behalf of cross-border internet fraud and online gambling syndicates. Reuters, citing an investigation by blockchain analytics firm TRM Labs, reported that Wang Yicheng's cryptocurrency wallet received at least $9.1 million (approximately HKD 71.35 million) between 2021 and 2022, with funds linked to "pig butchering" scams.Thailand's Special Investigation Department stated in a statement that U.S. law enforcement agencies have confirmed Wang Yicheng's involvement in a digital asset fraud case. The U.S. side had previously traced the flow of stolen funds from a victim in Massachusetts to an account registered under Wang Yicheng's name and seized approximately $500,000 worth of cryptocurrency. (Lianhe Zaobao)

Coinbase assists Brooklyn District Attorney in combating impersonation scam, involving approximately $16 million

Coinbase officially stated it is cooperating with the Brooklyn District Attorney's Office in New York to assist in investigating a long-term impersonation scam targeting platform users and supporting victims in recovering funds.According to the Brooklyn District Attorney's Office, a Brooklyn man has been charged with long-term impersonation of Coinbase customer service. Using social engineering tactics, he tricked users into believing their accounts had been compromised and instructed them to transfer funds to a "secure wallet," subsequently moving and stealing the funds. The case involves approximately 100 victims, with the total amount involved nearing $16 million. Over $600,000 has been recovered so far.Coinbase stated that this type of scam does not stem from platform security vulnerabilities but is a social engineering attack exploiting user trust and a sense of urgency. Common methods include identity forgery, impersonating customer service, and creating panic over account risks. The company stated it has cooperated with law enforcement agencies to complete various investigative tasks, including identifying suspects, assisting with victim notifications, providing data support for legal requests, and conducting on-chain fund tracing. It emphasized that blockchain traceability helps law enforcement track the flow of funds.Coinbase also reminded users that the platform will never ask them to transfer funds to a "secure wallet" or request 2FA codes, seed phrases, or password reset links. It recommends that users only contact customer service through official in-app channels. The company will continue to strengthen its anti-fraud mechanisms, user education, and cooperation with law enforcement agencies to address increasingly sophisticated crypto asset fraud activities.

SecondFi: User Asset Repayment Expected to Begin in Approximately Two Weeks

Odaily, Cardano wallet service provider SecondFi has released an update on the security incident, stating that the team has completed the final balance snapshot of affected user assets. Several rounds of snapshots were continuously recorded during the incident response period to serve as the basis for subsequent asset recovery and reconciliation. SecondFi stated that the engineering and security teams are advancing the asset recovery plan. It is estimated that asset repayment can begin in approximately two weeks — one week allocated for finalizing a viable technical solution and another week for testing and review. The specific timeline may be subject to minor adjustments as progress unfolds. The platform will resume operations only after passing a comprehensive security review. Currently, users only need to submit a support request via the official website's ticketing system, with no additional action required.

Analyst: Base Network Outage Due to Invalid Block Highlights Centralization Risk of Single Sequencer Model

Odaily Odaily News Blockchain analyst Vadim noted that Base experienced a network outage today due to a consensus bug triggered by a single invalid block. All block generation after height 47806542 ceased, halting the network for nearly two hours. Since Base utilizes a single sequencer architecture, when that node encountered an error, the entire network stopped running, with no backup block producer or other validator nodes available to bypass the fault and maintain on-chain activity. During the outage, users were unable to conduct transactions, perform liquidations, or process withdrawals.Furthermore, the network recovery process was not automated; node operators within the ecosystem had to manually restart for block synchronization to gradually resume. This is not the first such incident for Base. In August of last year, the network also experienced a freeze lasting approximately 33 minutes due to a sequencer switching failure. The single sequencer model exposes the centralization risks in some current L2 networks: while offering higher speed, the entire chain can come to a halt due to a single point of failure when the core component malfunctions.

Bitget Collaborates with SlowMist to Release the “2026 Anti-Fraud Report”: Cross-Asset Users Account for Over 10%; AI-Integrated Fraud Accelerates Evolution

According to the “2026 Anti-Fraud Report” jointly released by Bitget and SlowMist, as digital finance continues expanding into equities, tokenized assets, and AI tools, cross-asset trading is gradually emerging as a key trend for user participation in markets. The proportion of users engaging in cross-asset portfolio allocation has risen from less than 1% in mid-2025 to over 10% by May 2026. The report notes that fraud techniques are evolving from single-point attacks toward sophisticated attack chains—integrating AI-generated content, deepfakes, voice cloning, and multi-channel social engineering. Between July 2025 and June 2026, Bitget’s security system intercepted over 150 million malicious requests, identified more than 13,000 high-risk malicious IPs, and assisted users in recovering approximately $32.3 million in funds linked to security incidents and fraudulent activities. Gracy Chen, CEO of Bitget, stated: “This year marks the third annual Anti-Fraud Month initiative. Bitget will continue rolling out security education content, risk identification guides, and industry collaboration programs to help users enhance their ability to detect and defend against AI-powered fraud, phishing attacks, and scams occurring across multi-asset scenarios.”

Tornado Cash suspicious DAO proposal emerges, potentially threatening $23 million in DAO funds

L2BEAT researcher @sergeyshemyakov posted on X platform, stating that a suspicious DAO proposal appeared on Tornado Cash on June 25, and the target contract of the proposal has not been verified.The address of the proposal creator obtained funds through Railgun 4 days ago. If the proposal passes and is executed, the governance contract will make a delegatecall to this target contract. The Tornado Cash fund pool itself is secure, but this proposal may directly target the Tornado Cash DAO for an attack. The DAO currently holds TORN tokens worth approximately $23 million.

Polymarket 遭攻击 300 万美元用户资金被盗

预测市场平台 Polymarket 因第三方供应商被黑,约 300 万美元用户资金被盗,平台称将全额退款。

Aave Founder Responds to Payward Acquisition Rumors: Will Not Sell AAVE at a 70% Discount

Aave founder Stani Kulechov has responded to reports suggesting Kraken's parent company Payward is interested in acquiring a 15% stake in the Aave protocol, stating that AAVE is "not going to be sold at a 70% discount."Prior reports from CoinDesk indicated that Payward was in talks to acquire a 15% stake in Aave at a valuation of $385 million. If calculated at this valuation, it would represent only approximately 30% of AAVE's fully diluted valuation, significantly below the market valuation.In a post on X, Kulechov stated that the relevant reports were not entirely accurate. He did not completely deny the possibility of Aave Labs selling a portion of its held AAVE tokens, but noted that Aave Labs does have a certain allocation of AAVE, and that multiple market participants have discussed purchasing either directly or indirectly, or engaging in deeper collaboration centered around long-term partnerships.Aave is the largest decentralized lending protocol on the Ethereum ecosystem. Kulechov stated that Aave currently generates an annualized revenue of approximately $134 million, with the relevant revenue flowing to the Aave DAO. He has also previously proposed a governance plan to redirect revenue from Aave Labs, the protocol, and its products to the Aave DAO and token holders.These rumors emerge at a time when Aave is experiencing certain pressures. Following the Kelp DAO incident in April, Aave's TVL saw a significant decline. Although Aave itself was not directly attacked, the KelpDAO cross-chain bridge attacker utilized Aave to convert the stolen rsETH into other assets.

Specter: Multiple Polymarket Users Suspected Victims of Phishing Attack, Losses Approximately $2.94 Million

on-chain security analyst Specter has stated that a suspected phishing attack targeting Polymarket users is underway, with cumulative losses currently estimated at approximately $2.94 million. According to their monitoring, the attacker has transferred funds from over 11 victim wallets holding PUSD, swapping the stolen assets for ETH. Specter also reminds users to be vigilant against phishing risks and notes that the incident is still being actively tracked.

Taiko Releases Security Incident Update: Launches Fix Testing, Full Collateral for Bridged Assets to Be Restored Before Reopening

Ethereum Layer 2 project Taiko has released the latest update on a security incident, stating that this incident will not result in any user fund losses. Currently, bridged assets are under-collateralized, and the team will complete supplementary collateral for all assets before reopening the bridge, ensuring that each user's balance is supported on a 1:1 basis, identical to the state before the incident. Since the security incident occurred, cautious measures have been taken, including controlling the scope of impact, determining the root cause, and collaborating with the board to develop a plan to protect user assets.Furthermore, the CEO of Taiko has submitted a formal report to relevant authorities in Singapore, and the team will fully cooperate in tracing the responsible parties. Users are currently not required to take any action. The completed fix is now being tested, and Taiko will reopen the chain and bridge services as soon as it is deemed safe. Meanwhile, users are reminded to be vigilant against scams. The Taiko team will not proactively message users, and there are no claim or refund websites. Any links offering such services are fraudulent.

ZachXBT: Polish Social Engineering Hacker “Merry” Suspected of Being Raided and Investigated by Police

Odaily Odaily News According to “on-chain detective” ZachXBT, who posted in his personal channel, Polish social engineering attacker Wojtek Kulisz (online alias “Merry”) was recently suspected of being raided and investigated by Polish law enforcement, and three other individuals were also taken away. Although the official press release did not disclose his name or photo, multiple designer clothes and jewelry displayed on his public Instagram account “wojtekk” are highly consistent with the items seized during the police operation. The case is led by the Polish Central Cybercrime Combat Division (CBZC), with assistance from agencies such as the FBI and HSI.