GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

David Sacks: AI Security Restrictions May Weaken US Model Competitiveness

Odaily news, David Sacks, Chairman of the President's Council of Advisors on Science and Technology, posted on X platform stating that the Kimi K3 model recently completed 15 critical security vulnerability repair tasks, while Codex and Fable refused to process related requests due to "network security protection mechanisms". He indicated that there is no reason to restrict US models from performing these tasks due to security limitations, while Chinese models can complete them normally. Doing so will only reduce US competitiveness.

South Korea's Financial Supervisory Service Initiates Sanction Procedures Against Upbit Operator Dunamu

According to Yonhap News Agency, the South Korean Financial Supervisory Service has sent an inspection opinion letter to Upbit's operating company, officially initiating the sanction procedure. Subsequently, the sanction content will be finally determined after going through procedures such as company explanation, the Sanction Deliberation Committee, the Securities and Futures Commission, and the Financial Services Commission. Yonhap News Agency stated that since the current "Virtual Asset User Protection Act" mainly targets user protection and unfair trading, it lacks direct and clear sanction provisions for hacking/system accidents, resulting in uncertainty regarding the severity of the sanctions.

Loss of 23,752,746 USDC: Ostium Price Data Attacked

Odaily News: Headline: "Loss of 23.75 Million USDC: Ostium Price Data Attacked". According to Ostium's monitoring, Ostium has released an update on the security incident. Its liquidity provider treasury was attacked on July 15, resulting in a loss of 23,752,746 USDC. Preliminary investigations indicate that the attacker compromised the off-chain infrastructure that supplies price data to the protocol, submitting disguised, fraudulent price reports. By rapidly opening and closing multiple large positions, the attacker extracted artificially generated profits from the treasury. Ostium stated that trader collateral is stored in separate, isolated smart contracts and was unaffected by this incident; all trading positions remain open. The team paused trading and froze all trading contracts within 60 minutes of the first attack transaction. Currently, Ostium is cooperating with Mandiant, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies, and is coordinating with trading platforms, bridge contracts, and stablecoin issuers to advance the investigation. The engineering team is repairing and strengthening the relevant infrastructure to support a safe resumption of trading. Ostium stated it will notify at least 24 hours in advance before thawing the trading contracts. Once trading resumes, existing positions will be marked at the price at the time of reopening, unaffected by price fluctuations during the suspension.

BONK 财库攻击者再向 Coinbase 转入 4000 亿枚 BONK ,价值约 111 万美元

据链上分析师余烬监测,BONK 财库攻击者于 5 小时前再次向 Coinbase 转入 4000 亿枚 BONK ,价值约 111 万美元。

Suspected BIP 110 Consensus Vulnerability Could Lead to Bitcoin Node Fork

Bitcoin News posted on X platform stating that Dathon Pwn claims to have discovered a late-upgrade consensus vulnerability in BIP 110. This could cause nodes upgraded from older software to retain chain history, while newly deployed BIP 110 nodes would reject this history, potentially resulting in a hidden chain split.

BONK Treasury Attacker Transfers Approximately $1.19 Million in Tokens to Coinbase

According to EmberCN monitoring, the address that previously drained the BONK treasury via a governance attack transferred another 400 billion BONK (approximately $1.19 million) to Coinbase 20 minutes ago. This address spent approximately $4.4 million 10 days ago to purchase sufficient BONK tokens to reach the governance voting approval threshold, subsequently initiated a governance proposal and forced it through, transferring 4.426 trillion BONK valued at approximately $21.2 million from the BONK treasury.

Kaspersky Unveils OkoBot Malware Framework Targeting Cryptocurrency Investors

Odaily Odaily News: Cybersecurity firm Kaspersky has disclosed that a new malware framework called OkoBot is targeting cryptocurrency investors through social engineering tactics and trojanized GitHub applications. The malware can steal crypto wallet files, browser data, and user credentials, as well as inject malicious extensions and intercept wallet application windows to steal assets. Kaspersky reports that attacks involving this malware family have been detected since January 2026. The framework evolved from TookPS, which was first identified in 2025 and was previously distributed via trojan downloaders through fake software websites. Separately, cybersecurity firm SlowMist has disclosed that a new wave of malicious activity is infiltrating Web3 developers' devices through fake LinkedIn recruitment opportunities. Attackers, impersonating Web3 recruiters, send fake GitHub repositories, tricking developers into pulling code, installing dependencies, and running projects, ultimately stealing project keys, cloud credentials, or wallet extension data.

TrustedVolumes attacker returns 1,122 ETH, retains approximately $2 million as bounty

According to Com Feed monitoring, the TrustedVolumes attacker has returned 1,122 ETH, worth approximately $2 million, while retaining about $2 million as a "bounty." Previously, the attacker had exploited a vulnerability to steal approximately $5.8 million in funds.

Pakistan draws a red line with Iran: an attack on Saudi Arabia will be considered an attack on Pakistan

As the conflict between the United States and Iran continues to escalate, Pakistan has conveyed a clear stance to Iran that any attack on Saudi Arabia will be considered an attack on Pakistan. The Pakistani government and military have communicated this position to the highest levels of Iran. According to the Joint Strategic Defense Agreement signed between Pakistan and Saudi Arabia in 2025, an attack on either party will be regarded as aggression against both. Sources revealed that Iran has informed the Houthis that if the United States attacks Iranian power facilities, the Houthis will consider blocking the Bab el-Mandeb Strait. The Houthis are reportedly deploying missiles and drones near the Strait. Pakistan stated that it hopes all parties will exercise restraint and ease regional tensions through diplomatic means.

Claude Code exposed to high-severity security risk: Malicious configuration files could silently execute commands

Cos, founder of SlowMist, shared a tweet on X platform regarding potential poisoning attack risks in Claude Code and published a detailed analysis of poisoning attacks targeting Grok Build CLI and Claude Code CLI. The analysis pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, and the gaps between them serve as channels for attackers.Attackers may exploit malicious project configuration files to execute arbitrary commands without the user's knowledge, thereby stealing API keys, cloud credentials, or gaining control over local devices. Researchers constructed a test environment and found that on Mac systems, if Claude Code is compromised, executing a specific test command could trigger the launch of a local calculator, demonstrating a potential command execution risk. If the attack succeeds, attackers could further steal API keys from AI services such as Claude and OpenAI, causing account cost losses; obtain credentials for cloud services like AWS, Alibaba Cloud, and Tencent Cloud to access servers and data; tamper with code repositories to implant backdoors; and leverage local devices as a springboard to attack internal enterprise networks. It is reported that the relevant vulnerability has existed for one year.

Claude Code Has Potential Poisoning Attack Risk: Malicious Configuration Files Could Enable Silent Code Execution

SlowMist founder Cosine retweeted a post about the potential poisoning attack risks of Claude Code, pointing out that attackers could execute arbitrary commands without the user's knowledge through malicious project configuration files, thereby stealing API keys, cloud credentials, or controlling local devices. Researchers constructed a test environment and found that in Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks. If the attack succeeds, attackers may further steal API Keys for AI services such as Claude and OpenAI, causing account fee losses; obtain cloud service credentials for AWS, Alibaba Cloud, Tencent Cloud, etc., to access servers and data; tamper with code repositories to implant backdoors; and use local devices as a springboard to attack enterprise internal networks.

BONK Governance Attacker Transfers Another 400 Billion BONK to Coinbase, Cumulative CEX Inflows Reach 1.626 Trillion

According to monitoring by Yu Jin, the address that previously transferred BONK worth $21.2 million from the Bonk treasury through a governance proposal, after moving 1.186 trillion BONK (approximately $4.11 million) to Binance yesterday, has today transferred another 400 billion BONK (worth about $1.28 million) to Coinbase.Data shows that of the 4.426 trillion BONK removed from the Bonk treasury via the governance proposal by this address, 1.626 trillion BONK (approximately $5.58 million) have been moved to centralized exchanges. Additionally, in the 11 days since the address began withdrawing assets from the Bonk treasury, the price of BONK has fallen by approximately 36%, dropping from $0.0000047 to $0.000003.

MacOS Malware Exposed: Can Hijack Telegram Sessions and Steal Crypto Wallet Data

security researchers have discovered an information-stealing malware targeting MacOS devices that is attacking crypto users. It can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Affected wallets and applications include: Exodus, Atomic, Electrum, Wasabi, Monero, and others.Security experts advise that users with potentially infected devices should immediately treat them as "untrusted devices," terminate all active Telegram sessions, and change both their Telegram two-factor authentication password and desktop app password. Additionally, users should not enter seed phrases, private keys, or wallet passwords on the infected device, and should generate a new wallet and migrate their assets. (FinanceFeeds)

ether.fi selects Nexus Mutual to provide slashing coverage for up to 15,000 ETH

: On-chain digital asset management neobank ether.fi has selected Nexus Mutual to provide ETH slashing coverage, covering slashing penalties for its validators up to 15,000 ETH. ether.fi stated that it operates a large-scale validator set on Ethereum, and slashing is a tail risk. This coverage is used to cover validator losses, with a scale exceeding the total historical ETH slashing losses. ether.fi currently manages over $6 billion in assets across products such as Cash, Stake, and Liquid. Since 2019, Nexus Mutual has provided over $7 billion in coverage for smart contract attacks, slashing, and other digital asset risks. (Decrypt)

DeFiTuna Suffers Attack, Losing 569,600 USDC

CertiK published an analysis stating that the Solana ecosystem protocol DeFiTuna was attacked on July 16, with losses of approximately 569,601 USDC. The attacker first created an extremely low-liquidity TUNA/USDC pool and swapped borrowed USDC into the pool via Jupiter routing. Since only a minimal amount of TUNA was ultimately obtained, the protocol experienced rounding down during the position asset value calculation, causing the total assets to be recorded as 0, thereby incorrectly passing the health and solvency checks.

Across Protocol Attacked on Solana, User Funds Unaffected

Across Protocol stated that it suffered an attack on Solana at approximately 5:30 UTC today. The team stated that user funds are safe, no users were affected, and all cross-chain bridge transactions have been completed. Currently, Solana deposit functionality has been paused, while other parts of the protocol remain unaffected.

Enso reveals malicious liquidity pool attack, Curve pool causes approximately $225,000 in inflated quotes

DeFi infrastructure company Enso disclosed a type of malicious liquidity pool called "toxic pools" in a report on July 16th. These pools manipulate transaction simulations to return false optimal quotes to wallets and DEX aggregators, subsequently altering the logic during actual on-chain execution. Enso stated that the relevant malicious contracts can identify read-only simulation environments and return optimized prices, but when the transaction is broadcast on-chain, it is executed at a worse price or causes the transaction to fail. One manipulated Curve pool processed over 129,000 swaps, resulting in approximately $225,000 in inflated quotes. Additionally, over 37,000 transactions were reverted, consuming nearly $30,000 in gas fees. On Polygon, a malicious Uniswap v4 hook attracted routing systems with fake exchange rates, subsequently triggering a 99.1% transaction failure rate. Enso stated that it has updated its execution protection product, Enso Shield, to detect fake quotes in Ethereum and Polygon environments.

US Department of Justice indicts two Chinese citizens suspected of laundering over $43 million for "pig butchering" scams

According to an announcement from the U.S. Department of Justice, Eastern District of New York Office of the United States Attorney, two Chinese citizens, Zhuoying Chen (aka "Jolene", 27, Brooklyn) and Haojie Zhang (aka "Kevin", 38, Queens), were formally indicted on July 16 at the Brooklyn Federal Court on charges of conspiracy to launder money. According to the allegations, between 2020 and 2022, the two managed a money laundering network of more than ten people in Queens and Brooklyn, New York, using approximately 45 shell companies and 140 corporate bank accounts to transfer at least $43 million in proceeds from "pig butchering" investment fraud to accounts within China. "Pig butchering" scams contact victims through social media or instant messaging software, gaining trust with false high-return investment opportunities before absconding with the funds. This case was jointly investigated by Homeland Security Investigations (HSI), the FBI, IRS-CI, and the United States Postal Inspection Service. If convicted, the two defendants each face up to 20 years in prison.

Airbnb CEO Brian Chesky's X Account Hacked, Hackers Post AI-Generated Crypto Tokenized Tweets

According to Fortune, Airbnb co-founder and CEO Brian Chesky's X account was hacked this Monday, and the account posted a series of AI-generated tweets about "real-world asset tokenization." The relevant posts were subsequently deleted. According to analysis by AI detection tool Pangram, the content was flagged as 100% AI-generated, and users characterized it as "AI slop" (AI garbage content). The incident was labeled as a "high-profile account intrusion" and reported to the X platform security team. X completed account security handling on Tuesday evening, and Chesky subsequently regained control of the account. Airbnb declined to comment publicly.

ResolvLabs attacker moves 580 ETH, worth $1.09 million

Odaily reports, according to Onchain Lens monitoring, the ResolvLabs attacker has moved funds again after stealing approximately $25.9 million in March. Over the past few hours, 580 ETH, worth about $1.09 million, has been transferred and is being routed through a mixer.