GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

US Congress Considering Making AI Kill Switch a Legal Requirement

According to Forbes, the US Congress continues to debate a federal bill establishing an "AI kill switch," but AI scientist Lance Eliot warns of potential "backfire effects." From a technical standpoint, distributed AI systems are difficult to effectively shut down with a single switch; legally, disputes remain over activation authority and definitional boundaries; internationally, this initiative could deter other countries from adopting US AI technology and trigger reciprocal retaliation; domestically, mandatory shutdowns of AI within critical infrastructure could cause widespread social chaos while providing hackers with new attack vectors. Moreover, advanced AI systems may even bypass the kill switch itself, casting doubt on the legislation's practical impact.

Ampleforth Faces Malicious Governance Proposal Attack, $2.5 Million USDC Treasury Funds at Risk

The GoPlus Chinese community released a security alert stating that on September 12, a newly activated external account address submitted a malicious governance proposal to Ampleforth. Under the guise of applying for funding for completed work on the SPOT ecosystem analytics tool, the proposal attempted to transfer 2.5 million USDC from the treasury to the proposer themselves, an amount that nearly comprised all of the treasury's liquid funds.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

Chainflip Hit by Attack, 736,442 USDT Stolen, Recovery Expected Around Monday

Odaily reports: Cross-chain protocol Chainflip has disclosed that an attack targeting Tron USDT occurred yesterday. It has been confirmed that 736,442.17 USDT was stolen through 6 unauthorized payments, while another 115,654.41 USDT in user swaps remained in the vault due to failed payments. All other funds were unaffected.Chainflip stated that the attacker exploited a vulnerability in the Tron transaction memo mechanism by attaching custom memos to transactions already signed by validators, causing the system to identify the same deposit as separate swaps and issue refunds again, ultimately resulting in duplicate payments. The attacker carried out 8 operations over approximately 90 minutes, gradually increasing the amounts. Chainflip said it has completed a fix and has flagged the stolen funds to relevant authorities in an attempt to recover them. The protocol is expected to resume operations as early as Monday and will be responsible for compensating affected users for their losses.

US Department of Justice Has Frozen Approximately $938 Million in Fraud-Related Crypto, With About $52 Million Added in a Single Day

Odaily News: In an operation targeting the Telegram crypto escrow trading platform Xinbi Guarantee, the U.S. Department of Justice's Scam Center Strike Force restricted the handling of approximately $52 million in fraud-related cryptocurrency in a single day, bringing the cumulative total to approximately $938 million. Previously, the cumulative amount frozen, seized, or recovered had already exceeded $580 million.The U.S. Department of the Treasury stated that since its founding around 2022, Xinbi Guarantee has processed over $24 billion in transactions, involving digital assets and fiat currency, primarily serving Southeast Asian transactions. North Korean hackers and sanctioned entities are alleged to have used the platform, including entities under Jin Bei Group and Prince Group.A U.S. federal court approved the seizure on September 7 of the Telegram channel operated by Xinbi Guarantee. Law enforcement authorities also seized two payment wallets totaling approximately $12 million and applied to freeze another 47 cryptocurrency wallets suspected of being used for money laundering or associated with fraud-related service providers.The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) added Xinbi Guarantee and its two supporting companies, Safew Technology and Anwen Technology, to its sanctions list on September 9. The U.S. Department of Justice also dispatched investigators to Madagascar to assist local law enforcement in cracking down on 13 scam compounds operated by Chinese nationals and to process over 3,200 electronic devices. (Bitcoin.com News)

Solana Mobile Third-Party Email Service Provider Brevo Hacked, Accounts Experience Unauthorized Access

Solana Mobile stated that its third-party marketing email service provider Brevo experienced a security incident, resulting in unauthorized access to its Brevo account. To date, no emails have been sent through the account, and the company is currently investigating the scope of information that may have been accessed.

Crypto brokerage platform Cascade announces shutdown

Odaily reports: Crypto brokerage platform Cascade (formerly Perennial) announced on X that it is officially ceasing operations after approximately 5 years.Cascade stated that this was a difficult decision. Users can claim remaining funds from Cascade CLS and their trading accounts through the officially designated page, and users are reminded to only use the official claim portal.Previously in July, the Cascade CLS vault was suspected to have suffered a security exploit, resulting in approximately $1.3 million in user fund losses.

North Korea uses third-country IT workers to pass interviews at US companies, then takes over the positions after hiring

North Korea is using remote IT workers from third countries such as Iran and Lebanon to infiltrate US companies in order to obtain funding to support its weapons programs. After the relevant individuals pass interviews, their positions are usually taken over by North Korean personnel.The US government and multiple foreign agencies issued warnings in July stating that North Korean IT workers seek contracts and send salaries back to their affiliated North Korean organizations, while also posing insider threats to companies, involving data leaks, cryptocurrency theft, and the theft of sensitive information.Some third-country IT workers are recruited through LinkedIn, and some of them work part-time as "interview facilitators," earning $500 in cryptocurrency per month.Data from cybersecurity company CrowdStrike shows that in 2025, cryptocurrency losses caused by North Korea state-linked hackers and threat actors exceeded $2 billion, an increase of 51% year over year. South Korea's central bank estimates that North Korea's GDP grew 3.5% in 2025. (Cointelegraph)

North Korean hackers exploit third-country nationals to infiltrate US companies and acquire cryptocurrency.

North Korea leverages foreign technicians from Iran and Lebanon to infiltrate US companies through an "interview assistant" model, involving data theft and crypto asset theft. CrowdStrike data shows it caused over $2 billion in crypto losses last year.

US House Ways and Means Committee Schedules September 16 Markup of Cryptocurrency Tax Rules

The U.S. House Ways and Means Committee is scheduled to hold a markup on September 16 of a series of digital asset tax bills, moving crypto tax legislation toward a full House vote. The markup focuses on two core issues: when miners and stakers should be taxed on newly created tokens, and whether wash sale rules applicable to stocks should extend to digital assets.The two key bills are the "Mining and Staking Tax Clarity Act" H.R. 9175 and the "Applying Existing Tax Anti-Abuse Rules to Digital Assets Act" H.R. 9172. The former provides that miners and stakers need not pay tax immediately upon receiving new tokens, and can instead pay tax as ordinary income when the tokens are actually sold; the latter extends wash sale and constructive sale rules to actively traded digital assets, closing a tax loophole that crypto traders have exploited for years.

SlowMist Discloses Liquid Vulnerability Details: Attacker Minted 3,998.5 L-BTC Without Collateral, Approximately 598.5 BTC Still Not Returned

SlowMist has disclosed that the Liquid Network was attacked on September 6 via a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without collateral — with no corresponding BTC peg-in — and then within minutes converted them to BTC on the Bitcoin mainnet via peg-out. After the incident, approximately 3,400 BTC was returned to the Liquid Federation peg wallet, but approximately 598.5 BTC remains under the attacker's control.SlowMist noted that the root cause of the vulnerability lies in the fact that the Rangeproof verification cache key in Elements did not include length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to potentially generate the same cache key. The attacker triggered a cache collision by constructing transactions, causing nodes to hit a "verification passed" cached result, thereby bypassing secp256k1_rangeproof_verify and the minimum amount check, ultimately accepting outputs not backed by real assets and completing the L-BTC minting. SlowMist stated that it has traced the fund flows on the Bitcoin side and completed its analysis of the incident.

SlowMist: ether.fi Attacked, Losing Approximately 15.45 ETH

SlowMist issued a security alert stating that it had previously privately contacted the ether.fi team to disclose the relevant issues. This incident resulted in a loss of approximately 15.45 ETH. The root cause was that AtomicQueue.solve() lacked access control for the solver provided by the caller, failing to verify solver == msg.sender, and did not perform signature, registration, or consent verification.

74% drop after SILV incident, sunrise warns users not to interact with tokenized silver asset issued by Dominion_Market

According to SolanaFloor monitoring, sunrise has warned users not to interact with SILV, the tokenized silver asset issued by Dominion_Market, after a previous attack led to the compromise of Dominion's treasury wallet, causing SILV to drop 74% following the incident.

Blockstream Refuses to Pay Ransom, Vows to Recover Stolen Bitcoin from Liquid Network

Blockstream officially announced on the X platform that Liquid Network has suffered a Bitcoin theft incident. The company explicitly stated its refusal to pay any ransom and characterized the act as a crime rather than a white-hat disclosure. Blockstream has collaborated with law enforcement agencies, exchanges, forensic experts, and other parties to trace the stolen assets through on-chain tracking and other means. It also called on current holders to voluntarily return the Bitcoin, warning that they will face full legal action otherwise.

Lost approximately $336,000 in WBTC, Symbiosis attacked on BSC chain

Odaily News: Cross-chain liquidity protocol Symbiosis has been attacked on the BSC chain, resulting in an actual loss of approximately $336,000 in WBTC.

AI Lowers Quantum Attack Costs, Bitcoin's Post-Quantum Migration Window Narrows

According to Cryptopolitan, over 100 researchers used AI coding agents to reduce the quantum attack resource score for Bitcoin's secp256k1 elliptic curve point addition subroutine by 86.1% (from 10.75 billion to 1.496 billion). This optimization only targeted a single step within Shor's algorithm and did not crack any private keys or transfer funds; a full-scale attack still requires fault-tolerant quantum hardware that does not yet exist. However, each efficiency gain is compressing the time window for blockchains to complete their post-quantum migration. According to Glassnode data, approximately 6.04 million BTC (30.2% of the circulating supply) currently faces potential quantum risk due to publicly exposed on-chain public keys. Ethereum plans to achieve full quantum resistance before December 2029, while the Bitcoin community faces greater governance challenges, including how to handle approximately 1.7 million dormant coins held in P2PK addresses suspected to belong to Satoshi, which remains unresolved.

Brevo Login Breach Leads to Phishing Emails Sent to 347,000 Trezor Subscribers, BitBox and CoinTracking Accounts Also Affected

Odaily News: A vulnerability in email platform Brevo's login system allowed attackers to access 138 customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. Accounts belonging to BitBox and cryptocurrency portfolio and tax reporting platform CoinTracking were also used to send similar scam emails.Trezor stated that the phishing email was titled "Critical Security Alert: STM32 Entropy Vulnerability," with links pointing to an app that asked users to submit their wallet backups. Trezor disabled the relevant domain via DNS within 20 minutes, but approximately 2,500 people had visited the link, and the company has alerted all 347,000 subscribers to the risk.Brevo stated that attackers exploited a failure in single sign-on configuration permission boundaries to access all organizations reachable by invited users. Six accounts were used to send phishing emails, and contact data from 43 accounts was exported. BitBox and CoinTracking said they have found no evidence of leaked company credentials, funds, or recovery phrases, but are treating the affected email addresses as potentially compromised. (Cointelegraph)

Empowa Suffers Unauthorized Transfer Incident, Approximately 4.24 Million EMP and 143,700 ADA Stolen

Empowa, a Cardano ecosystem project, disclosed two interrelated unauthorized asset transfer incidents across its three project wallets. Between November 2025 and June 2026, approximately 143,710 ADA were transferred out of one project treasury wallet in 18 transactions. The corresponding Midnight airdrop for this wallet was also registered and claimed by an unknown party using the private key, with approximately 36,000 NIGHT already transferred away. From June 2026 to August 2026, a cumulative total of approximately 4.24 million EMP tokens were transferred out of the other two project wallets, with portions sold via platforms such as Minswap and VyFi. Empowa stated that the funds from both incidents ultimately flowed into the same intermediate wallet, indicating they are controlled by the same party, although the identity of the individuals operating these private keys cannot currently be confirmed. The team has hired a professional blockchain investigation firm and plans to seek KYC information from the centralized exchange where the related funds ultimately entered.

The Ethereum Glamsterdam upgrade is scheduled for activation on the Sepolia testnet on October 6, with the mainnet timeline remaining unclear.

According to reporting from Christine D. Kim (@christine_dkim), Ethereum developers confirmed at the ACDC #186 conference that the Glamsterdam upgrade will be activated on the Sepolia testnet on October 6 at 13:53 UTC. However, there is significant uncertainty surrounding this upgrade—the current latest private testnet, Glamsterdam-Devnet-9, has not yet stabilized. A severe vulnerability in the consensus layer could halt block production across the network, and a bug in the execution layer's EIP-8037 also requires fixing. Developers will release Devnet-10 in the coming weeks; if Devnet-10 remains unstable, the Sepolia upgrade date may be pushed back. Activation timelines for the Hoodi testnet and the mainnet have not yet been determined, and it remains uncertain whether the goal of launching on the mainnet before the end of the year will be met.

Liquid Network Vulnerability Disclosure Handling Sparks Public Dispute Between Samson Mow and Bitcoin Red Team

Bitcoin News posted on X stating that Samson Mow and Bitcoin Red Team researcher Calle are engaged in a public dispute over whether security warnings related to a Liquid Network exploit were properly handled. Calle claims that Blockstream did not act on the Red Team's email, ultimately resulting in a loss of 600 BTC; Mow responded by saying "no email was ignored." Calle stated that once Blockstream restores normal Liquid operations and publishes a post-mortem report, the Red Team will release a full account of the disclosure process. Mow separately warned against blindly trusting AI-generated security reports, saying that unverified fixes could introduce new vulnerabilities, and criticized researchers who prioritize pursuing "clout" over protecting Bitcoin.