GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

The Sandbox Launches SAND Compensation Claims

The Sandbox stated that it will provide full compensation to affected users for the SAND vulnerability incident on Base and BNB Smart Chain that occurred on August 22. Any wallet that legitimately held cross-chain SAND at the time of the snapshot prior to the incident will receive SAND compensation on the Ethereum network at a 1:1 ratio.

Suspected collective theft incident hits Lootbot subscribers, losses surpass $600,000 and continue to grow

Odaily News On-chain analyst SomaXBT stated on the X platform that suspected Lootbot users have experienced a collective wallet theft incident, with losses now exceeding $600,000 (approximately 245 ETH). Preliminary information shows that about 50% of the victims are Lootbot subscribers.It is worth noting that Lootbot is one of the projects founded by dexter, the founder of gm.ai, a project previously involved in a soft rug pull. Lootbot was originally a trading bot platform within the Telegram ecosystem.

SlowMist: Approximately 62.28 BNB Lost in Attack on a Router on BNB Chain

According to Odaily, as monitored by SlowMist, per the SlowMist TI security alert, a Router contract has been exploited due to security flaws in its Swap entry point and uniswapV3SwapCallback, resulting in losses of approximately 62.28 BNB. The Router fails to verify whether the caller is a legitimate V3 Pool, nor does it bind the payer in the callback to the original transaction context. The attacker forged a V3 Pool/adapter and injected a victim's address as the payer, exploiting users' existing ERC-20 approvals granted to the Router to execute transferFrom() and transfer assets. Users who have previously granted sufficient token approvals to this Router may see their approved assets transferred out, even without further interaction on their part.

Tectonic hit by oracle manipulation attack, $120.4 million in assets stolen

According to the post-incident report released by Tectonic, the Cronos blockchain lending protocol Tectonic suffered an oracle manipulation attack at 12:49 UTC on August 30, 2026. By repeatedly borrowing and re-collateralizing TONIC tokens 98 times within a single transaction, the attacker drove up the TONIC collateral price by approximately 195 times. Leveraging this artificially inflated value, they subsequently extracted assets with a nominal value of $120.4 million from nine lending markets, spanning USDC, USDT, WBTC, WETH, and other assets. The attacker then bridged the stablecoins to Ethereum and converted them to ETH, while selling the remaining assets for CRO on the Cronos chain before withdrawing them. Approximately $9.19 million in total successfully escaped before the network halt. At 14:32 UTC, Cronos validators emergency-paused the network, rolling back the on-chain state to pre-attack conditions and restoring assets still held on Cronos. Currently, Tectonic's supply and borrowing functions remain suspended, while withdrawal and repayment capabilities continue normally. Tracing efforts for the stolen funds are being coordinated by blockchain forensics firms, law enforcement agencies, and stablecoin issuers, with freeze requests already filed with the relevant issuers.

Biden’s Son Meme Coin LAPTOP: No Utility or Development Roadmap, Foundation Signs Loan Agreement with G20 and GSR

According to disclosures from the Phoenix Veritas Foundation, the Hunter Biden laptop-themed cultural token, LAPTOP, has been issued on the Base chain with a total supply of 1 billion tokens and an initial circulating supply of 350 million tokens (35%) at TGE. Token allocation consists of 30% for founders (including Hunter Biden), 30% for the prediction mechanism, 20% for the community airdrop, 10% for liquidity, 10% for the foundation treasury, and 5% for charity. Founder tokens are subject to a six-month lock-up period followed by linear unlocking over 24 months. LAPTOP provides no utility, positioned strictly as a cultural digital collectible with its value driven entirely by community sentiment. The token contract underwent a security audit by Hacken in April 2026, revealing no major vulnerabilities. Regarding market maker arrangements, the foundation has entered into a lending agreement with G20 and GSR totaling 20.5 million tokens.

Liquid Network preparing to restart, Blockstream has deployed updated software

Odaily News, according to Bitcoin News, Blockstream stated that Liquid Federation members are preparing to coordinate a network restart, with the updated software already deployed. Previously, a security incident occurred on the Liquid Network, resulting in fund transfers. Blockstream noted that its team remains focused on further strengthening the network and ensuring asset restitution. Blockstream thanked the Bitcoin community for its patience, support, suggestions, and assistance, and stated that more updates will be released in the future.

Liquid Network white hat hacker returns 3,400 BTC, keeps about 598 BTC as bounty

According to on-chain monitoring by analyst PeckShield (@PeckShieldAlert), the Liquid Network was targeted by white-hat hackers. Approximately 4,000 BTC (roughly $320 million) were transferred from a Liquid Federation wallet. The funds were consolidated into address bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, accompanied by an on-chain message: "We are white hats, please contact us on-chain." Subsequently, the hackers completed on-chain negotiations with Blockstream, returning 3,400 BTC (approximately $315 million, or 85% of the total) while retaining around 598.5 BTC (about $47.38 million) as a bug bounty.

Harmony's preliminary ONE shortage narrows to 6.581 billion after cross-exchange reconciliation

: Harmony has released an update on the exchange reconciliation progress following the August 11 incident. It has verified on-chain deposits/withdrawals and cross-platform fund flows with Binance, Gate, KuCoin, MEXC, OKX, and Binance.US, prioritizing the coordination of restoring ONE deposits, withdrawals, and trading, with specific timelines to be announced separately by each exchange.Harmony stated that after matching 295 cross-exchange transfers totaling approximately 3.493 billion ONE and adjusting for circular transfers and returned funds, the preliminary shortage has been reduced from approximately 10.234 billion ONE to 6.581 billion ONE, a decrease of about 3.653 billion ONE. This change reflects an adjustment in reconciliation methodology and does not equate to newly recovered funds.Among these, Binance's data remains a preliminary upper-bound estimate, while some data from Gate and OKX are still pending final verification. Exchange teams have already frozen significant ONE balances and hacker proceeds. These efforts will be coordinated with the ONE migration and validator transition proposal, and validators may cease operations starting 22:00 Beijing time on September 10.

CZ clarifies X account was not hacked: Unfollowed accounts inactive for over 30 days

CZ retweeted on X platform to clarify that his account was not hacked, stating that he had simply unfollowed some accounts that had been inactive for over 30 days, adding "that's all."

Binance Wallet Saves Users from $540 Million in Potential Losses in H1

Odaily News: Binance stated that in the first half of 2026, the Binance Wallet Security Center helped users avoid approximately $540 million in potential losses, filtering about 206 million spam transfers, identifying 4.93 million high-risk transactions, and approximately 996,000 malicious authorizations during the period. Binance noted that AI is being used by attackers to mass-generate malicious code, phishing websites, and fake identities, shifting attacks from broad-based approaches to more targeted fraud.

U.S. Department of Justice Prosecutes Group in $240 Million Bitcoin Theft Case, Ringleader Expected to Plead Guilty

According to the Associated Press, the U.S. Department of Justice has charged Ma Long Ram and 17 other defendants in connection with a Bitcoin theft scheme valued at over $240 million. Prosecutors allege that the group carried out a social engineering attack on a Washington resident by impersonating employees of Google and cryptocurrency exchange Gemini, thereby gaining control of their accounts and security codes to steal more than 4,100 Bitcoin. The suspects subsequently laundered the proceeds through multiple trading platforms and spent the money on sports cars, mansions, luxury watches, private jet services, and nightclub expenses.

Blockstream notifies white hat hackers that vulnerability has been fixed, approximately 4,000 BTC pending return

Odaily News: Blockstream has notified white hat hackers that the vulnerability fix is complete and the approximately 4,000 BTC can be safely returned. The hacker who previously withdrew funds from the Liquid network expressed willingness to return them, but requested that the vulnerability be fixed first. Both parties have been negotiating publicly through Bitcoin OP_RETURN messages.The hacker initially proposed returning "most" of the BTC, but later changed their stance, demanding that the vulnerability be fixed first: "Ensure every node has been patched, and once the fix is confirmed, we will securely return the funds." The hacker also sent encrypted vulnerability details to Blockstream. About two hours ago, Blockstream responded via a PGP-signed OP_RETURN message stating that nodes have been patched. Currently, 3,998.5 BTC remain under the hacker's control.

Coldcard Wave 3 Attacker Has Transferred Approximately 45% of Stolen Bitcoin

According to Galaxy Research, in the Coldcard wallet attack incident, the Wave 3 attacker has transferred approximately 45% of the stolen Bitcoin, with the related funds routed to Ethereum via THORChain or entering CoinJoin transactions to increase tracking difficulty. Galaxy stated that the attacker previously created 293 2-of-2 multisig vaults to hold victim funds, draining them from largest to smallest amount, and the funds in the 11 largest vaults have now been fully transferred out.

Loss of approximately $104,000: Secured Finance lending market suffers attack

Odaily News: The decentralized lending protocol Secured Finance's lending market was attacked on September 5, resulting in a loss of approximately $104,000. The root cause was that collateral was priced based on the average execution price of the order book for the current block, allowing attackers to influence the price through self-trading, causing fraudulent lending positions to be counted as valid collateral. The attacker initially deployed the contract but did not execute immediately, then used flash loans and self-trading to inflate the price and withdraw USDC. The original attacking wallet was rolled back due to insufficient gas fees; approximately 48 seconds later, the general-purpose sandwich bot coffeebabe took about 0.9 WBTC, worth approximately $72,000, and transferred about 28.8 ETH of it to the ultra sound money builder, keeping only about $29 for itself. Subsequently, another bot took part of the USDC.

Cozy Finance Suffers Ongoing Attack on Optimism, Approximately $170,000 in Assets Stolen

Odaily News DeFi risk management protocol Cozy Finance is currently facing an ongoing attack on its Optimism deployment, with attackers having stolen approximately $170,000 in assets so far. Blockaid has subsequently released preliminary attack information and flagged the attacking transactions along with related attacker addresses. Multiple attacker addresses have now been confirmed, along with a token address suspected to have been exploited in the attack. It remains unclear whether the attack is still ongoing, and users should exercise caution when interacting with contracts associated with Cozy Finance.

Vitalik refutes Silicon Valley investor's "AI will kill BTC" argument: The probability of hash algorithms or PoW being broken is extremely slim

Odaily News Silicon Valley angel investor Liron Shapira (@liron) posted on X this morning: "I predict (with 50% confidence): due to AI shaking the security and stability guarantees people once believed Bitcoin possessed, BTC's price will plummet more than 50% within the next two years."Ethereum co-founder Vitalik Buterin rebutted this, stating: "I hold the exact opposite view. My basic reasoning is that, in the long run, I am quite optimistic about network security. I believe the main challenge lies in smoothly navigating the transition period. Moreover, I think BTC can at least properly handle all problems that do not require social consensus (such as upgrading clients, mining pools, etc., to counter network-level attacks — these fall into this category). Additionally, I believe the probability of hash algorithms or proof-of-work mechanisms being genuinely broken is extremely slim. I would have wanted to bet with you, but considering my current asset allocation (I guess you hold the same view regarding Ethereum ETH), I have already staked about 90% of my net worth on this bet."

After fixing the vulnerability, Liquid's white hat hacker said they would return most of the 4,000 BTC

According to Odaily, monitoring by Galaxy's Head of Research revealed that Liquid's white hat hacker stated they would return most of the 4,000 BTC after the Liquid Network vulnerability is patched. The hacker communicated with Blockstream through OP_RETURN messages and PGP-encrypted text: In block 965,822, a Blockstream address sent 1,000 satoshis with the message "Please contact the security team via the Blockstream website"; in block 965,865, the hacker sent an encrypted message to their own key, accompanied by a detached PGP signature that can be verified using the key published by Blockstream; in block 965,869, the hacker sent 1,000 satoshis to the Liquid federation peg-in wallet via a self-spend transaction with the message "Can we return the majority of the funds to the federation address?"; in block 965,875, the hacker conducted another self-spend transaction, sending 1,000 satoshis to the federation peg-in wallet and leaving an OP_RETURN message: "Please fix the vulnerability first. As of the latest commit, there is risk on-chain. Please ensure every node completes the patch update. Once the fix is confirmed, we will securely transfer the funds back." Relevant technical details were encrypted via PGP messages to the key published by Blockstream, readable only by Blockstream.

SlowMist Alert: Two Attackers Are Replicating the Notional Finance Vulnerability on BSC

According to monitoring by blockchain security firm SlowMist (@SlowMist_Team), two attackers are replicating the recent Notional Finance vulnerability exploit on the BSC chain. Having completed the pre-attack phase, they have created malicious fCash positions using the same vulnerability pattern. The attack has not yet been fully executed; the malicious positions are currently awaiting maturity. Once mature, the attackers may settle the positions and withdraw assets from the protocol. The potentially vulnerable address is 0x0795E2cd771788572b61BeA45Abd6E9a8FC8D9F0. SlowMist strongly recommends that relevant projects take immediate mitigation measures before the positions mature. Previously, the Notional Finance V1 contract was exploited on September 5, resulting in approximately $1.7 million in user funds lost. The affected contracts have been paused.

Approximately 45% of stolen assets have entered coin mixing or cross-chain paths, Coldcard attacker continues to move funds

Odaily News: The attacker behind the Coldcard "Wave 3" exploit continues to move stolen funds. In this phase, the attacker created 293 separate 2-of-2 multisig vaults for each victim's assets. On September 2, the first batch of funds was bridged to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attacker is processing the largest holdings in descending order by stolen amount, having already transferred vaults ranked 1 through 11 in sequence. The next 10 vaults yet to be transferred collectively hold 30.81 BTC, while vaults ranked 61 through 293 collectively hold 33.77 BTC.To date, the attacker has moved approximately 45% of the assets stolen in this exploit, with funds either flowing to Ethereum or entering CoinJoin mixing transactions. This latest transfer activity has also revealed a previously unknown vault: 58 addresses jointly spent funds via a 2-of-2 multisig setup in the same format as Wave 3, with the Wave 3 attacker subsequently routing them to a jump address that funds CoinJoin transactions.This vault is currently marked with "cause = open," but it is highly likely to belong to Coldcard victims as well, which could bring the total number of vaults involved in Wave 3 to 294 and push the previously disclosed total stolen in the Coldcard exploit to approximately 1,806 BTC. At present, roughly 82% of the stolen BTC remains in addresses initially controlled by the attacker, while approximately 18% has been moved, with fund flows suggesting it may be undergoing laundering.

White-Hat Hacker Withdraws Approximately 4,000 BTC from Liquid Network; Side Chain Suspends Operations

According to an announcement from the official Liquid Network X account (@Liquid_BTC), a suspected whitehat hacker withdrew approximately 4,000 BTC worth around $320 million from a Liquid Federation wallet using a SideSwap PAK (Peg-out Authorization Key). The official statement indicated that the key itself was not leaked, and the Blockstream team is attempting to contact the party through on-chain signed messages. Following the incident, exchanges have paused or are about to pause LBTC deposit and withdrawal services. Bridge nodes have been temporarily shut down, and the Liquid sidechain is currently suspended, unable to submit new transactions. Officials emphasized that other Liquid assets such as USDT, DePix, and RWA remain unaffected by this incident, while Federation members are actively working to resolve the issue to restore normal network operations as soon as possible.