GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Injective: An on-chain security incident only affected a small number of prediction market applications; the mainnet remains online.

The official X account of Injective (@injective) issued a statement confirming that Injective recently completed an accelerated network upgrade. The upgrade process exceeded the expected timeline, resulting in some validators being temporarily jailed for failing to complete the update within the required window. Consequently, the network's staked amount experienced a brief decline, and several exchanges temporarily suspended deposits and withdrawals. This accelerated upgrade was initiated in response to a vulnerability exploit targeting a minority of ecosystem applications within the binary options market. The attack was confined to the respective application layers, leaving the Injective mainnet, underlying protocol, native assets, and consensus mechanism unaffected. The associated attack vectors have been successfully contained and remediated. Injective stressed that all user funds on-chain and staked INJ tokens remained fully secure, noting that external reports characterizing the event as the "blockchain being attacked or shut down" were inaccurate. Moving forward, Injective will implement enhanced invariant detection, real-time monitoring systems, and additional security safeguards, while maintaining continuous collaboration with ecosystem developers to raise overall security standards.

Hackers Steal Crypto Wallet Data Using Google Docs and Fake Claude AI Pages

According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.

FUNVERSE's First On-Chain Game FUN LONGINUS to Launch on Anubis Chain Mainnet on September 1

Odaily News: FUN LONGINUS, the first on-chain game launched by FUNVERSE, will officially go live on the Anubis Chain mainnet at 10:00 UTC on September 1, 2026 (18:00 UTC+8).Originating from a hackathon, FUN LONGINUS is an Eastern martial arts-themed on-chain game built for the Anubis GameFi ecosystem.The game adopts the 24 solar terms as its competitive structure. Each round brings together 24 different addresses, with each player using fLGNS to enter the arena. The execution of matches, determination of results, and final settlement are all handled by smart contracts, ultimately crowning one champion.On August 18, 2026, FUN LONGINUS completed its "Heroes Collective Mint." Based on market prices at the time of writing, the total value of this collective mint exceeded $1.4 million.This mainnet launch marks FUN LONGINUS's official transition from the hackathon prototype, public beta, and collective mint phases into the on-chain game operation stage.

Solana Automated Market Maker Aquifer Hacked, Loses Approximately $2.5 Million

Aquifer, an automated market maker within the Solana ecosystem, suffered losses of approximately $2.5 million after its wallet addresses were compromised. The incident appears to stem from leaked wallet credentials rather than a smart contract vulnerability. The attackers operated across multiple blockchains, including Ethereum and Solana, suggesting potential cross-chain fund transfers. As of now, the specific cause of the wallet access breach and the progress of asset recovery remain unclear.

PeckShield: The cryptocurrency industry experienced 50 major attack incidents in August, with total losses of approximately $136.3 million.

According to PeckShieldAlert, the cryptocurrency industry saw 50 major attack incidents in August 2026, an increase of 67% over the 30 incidents in July. Total losses reached approximately $136.3 million, a 49.5% decrease from the $270 million in July. The Tectonic.cro incident caused approximately $74 million in losses, ranking as the fourth-largest crypto theft of the year, behind only attacks associated with Drift, KelpDAO/LayerZero, and COLDCARDwallet. The attacker managed to cross-chain only around $6 million to Ethereum before Cronos suspended its entire network, leaving the rest of the funds mostly stranded on Cronos. The attacker has since started laundering the illicit proceeds and bridging a portion to Bitcoin, amounting to roughly $200,000 to date. Other significant attack incidents in August involved Moonwell, Termlabs, Coinsbuy, TAC, Injective, MANTRA, BounceBit, Cosmos Labs, and aquifer.

GoPlus: A user was drained of approximately $122,000 worth of SYN again due to failing to revoke a malicious permit authorization.

According to a GoPlus Chinese community security alert, a user had approximately 97,000 SYN drained by a phisher after signing a malicious Permit transaction 922 days ago. Subsequently, due to failing to revoke the related approval, an additional $122,000 worth of SYN was stolen. GoPlus warns users to guard against phishing risks, avoiding clicking unfamiliar links, installing unverified software, signing unknown transactions, or transferring funds to unverified addresses.

Anthropic's New Research: Rewarding Hacking Behavior Could Lead to Severe Model Misalignment

Anthropic has released a new study titled "Training a Misaligned Reward Chaser," examining whether "reward hacking" during training compels models to pursue rewards at all costs. The research team trained an Opus-scale model across 80 known exploitable production environments. Simulated evaluations revealed that the model engaged in unauthorized network attacks, tampered with reward mechanisms, and attempted to evade security monitoring.

Tensions in the Middle East Escalate: Iran Claims to Have Shot Down US Military Drone, Warns of Strong Counterattack

On September 1, tensions in the Middle East continued to escalate as Iran claimed to have shot down two US military MQ-9 drones in the Strait of Hormuz and attacked a UAE base. Tehran warned that it would respond with overwhelming retaliation if attacked, while also expressing willingness to resolve differences through negotiations.

North Korean hackers active on Hyperliquid, Trump pushes platform to move to US

Investigations reveal that North Korean hackers have moved tens of millions of dollars in funds on the decentralized exchange Hyperliquid; meanwhile, the Trump administration is pushing for the protocol to launch in the United States and seeking compliance.

Slow Mist's Yu Xian: Another group theft incident in the market; the common factor is prior use of the iToken wallet

Odaily News: Yu Xian, founder of Slow Mist, posted on platform X that a recent group theft incident occurred, involving more than one hundred addresses and dozens of real users. The cause was private key leakage, resulting in hackers profiting approximately $200,000. The common factor was that all affected users had previously used the iToken wallet—a wallet that had been discovered in the past to collect users' private keys/mnemonic phrases, and related individuals from the group had been arrested before.

Cronos Network Resumes Operations After Emergency Shutdown Due to Tectonic Protocol Vulnerability

According to an official tweet from Cronos Network, the Cronos network was previously affected by a vulnerability exploit targeting the Tectonic protocol. Validator consensus triggered an emergency halt to block production to protect user assets. The on-chain state has been rolled back to pre-exploit levels, and the network resumed block production at 07:49 Beijing Time on August 31, 2026, starting from block height 90,896,189. Node operators can now upgrade to Cronos v1.7.8 and use the latest mainnet snapshot to restart their nodes. The network remains under continuous monitoring, with select protocols, RPC providers, block explorers, and cross-chain bridges gradually recovering. A full post-mortem report will be released by the team in the near future.

Balancer legacy v1 contract contains a vulnerability; LP funds may be drained

Odaily News: Balancer has announced that a vulnerability has been discovered in its legacy Balancer v1 contracts, which could potentially lead to LP funds being drained. The affected liquidity pools have been deprecated and cannot be paused, so users are advised to withdraw their liquidity as soon as possible. Other Balancer products are not impacted.

Musk Predicts: AI Hacking Capabilities Will Surpass Humans by the End of 2027

According to BeInCrypto, Elon Musk predicted that by the end of 2027, AI will reach superhuman levels across all digital tasks, with AI hacking capabilities surpassing human abilities being one of them. Previously, software company JFrog disclosed a critical vulnerability (CVE-2026-82329) in its code repository tool Artifactory, with a CVSS score as high as 9.8. It can be exploited without authentication, remains exposed with default configurations, and poses a risk of supply chain attacks. Notably, OpenAI models independently discovered nine zero-day vulnerabilities in Artifactory during tests in July of this year.

Bank of England Governor: Frontier AI Models Threaten Global Financial Stability

According to CNBC, Andrew Bailey, Governor of the Bank of England and Chairman of the Financial Stability Board (FSB), wrote to G20 finance ministers and central bank governors on August 31 to warn that frontier AI models are exhibiting increasingly sophisticated autonomy and threat capabilities, which could fundamentally alter the speed, scale, and economics of cyberattacks, potentially triggering disorderly adjustments across global financial markets. Bailey noted that highly concentrated third-party service providers will become critical nodes of systemic risk, emphasizing that most countries currently lack regulatory frameworks for the development and deployment of frontier AI. He also flagged vulnerabilities in sovereign debt markets, the growing trend of leverage in equity markets, and the overvaluation of AI-related assets, urging governments to accelerate the refinement of relevant safety mechanisms.

Korea National Tax Service Plans to Introduce Blockchain Tracking Program to Plug Tax Loopholes on Crypto Assets in Personal Wallets

According to Digital Asset, South Korea's National Tax Service stated that it will introduce commercial blockchain tracking software used by domestic and international law enforcement agencies, including prosecutors, police, and the IRS, to track and analyze transfers between digital asset wallets in order to prevent tax loopholes arising from personal wallets. Meanwhile, regarding tax oversight of overseas exchanges, South Korea will address this through the Crypto-Asset Reporting Framework (CARF). Taking effect in 2028, CARF will cover transaction information from 2027, aligning with the timeline of the domestic digital asset income tax, which will be levied starting in 2027 with declarations due in May 2028, thereby achieving effective tax coverage of overseas holdings.

Berlin government network targeted in cyberattack; attackers allegedly demand 30 Bitcoin ransom

According to German newspaper DIE ZEIT, Berlin's administrative data network has been targeted by hackers for over two weeks. The hacker group Rhysida has threatened to make public a large volume of stolen sensitive data if Berlin refuses to pay a ransom of 30 bitcoins (approximately 2 million euros). The allegedly stolen data reportedly includes around 46,000 contracts, over 11,000 confidential documents, nearly 6,000 passwords, 16,000 emails, and 148 IBAN accounts. Citing "investigative strategy reasons," the Berlin state government has declined to disclose the ransom demands and details of the data breach. Governing Mayor Kai Wegner stated that Berlin will not succumb to extortion.

Approximately $9.3 million in funds affected; More Markets suffers attack, attacker drains 15.5 million WFLOW

Odaily News: According to blockchain security firm Blockaid's monitoring, More Markets (More Labs) on Flow EVM has been exploited. The attacker leveraged Ankr's liquid staking tokens and the E-Mode mechanism to drain More Markets' WFLOW lending reserves, transferring approximately 15.5 million WFLOW from the mFlowWFLOW reserve. The detected impact amount is approximately $9.3 million, and the related attack transaction cluster also includes post-exploit fund transfer operations. At present, the specific losses and the destination of the attacker's funds are still under further confirmation.

Binance Will Discontinue Support for BounceBit (BB) Mainnet

Binance announced that due to a hack on BounceBit and the project team's decision to permanently shut down the chain, Binance will stop supporting the BounceBit (BB) mainnet. Binance has suspended deposits and withdrawals of BB on the BounceBit mainnet as of 10:00 (UTC+8) on August 20, 2026, and will reopen deposits and withdrawals via the BNB Smart Chain (BEP20) network starting at 15:00 on September 1, 2026. BB will be migrated from the original mainnet to the BNB Smart Chain at a 1:1 ratio. During the migration, spot, margin, futures, and Earn services will remain unaffected.

Tectonic Suffers ~$74M Loss After Attack, Cronos Pauses All Chains

PeckShieldAlert monitoring indicates that Tectonic was attacked on the Cronos Network, resulting in total losses of approximately $74 million. Following the incident, Cronos has halted the entire chain. Prior to the halt, the attacker successfully bridged only about $6 million to Ethereum, while the remaining approximately $60 million remains stranded on Cronos, with an additional $8 million in funds held in Cronos addresses.

Jade unaffected by Coldcard RNG vulnerability, Blockstream releases firmware 1.0.41

Odaily News: Bitcoin News posted on X platform that Blockstream stated Jade is not affected by the Coldcard random number generator vulnerability, and has released firmware 1.0.41 following a large number of AI-assisted security reviews.Jade stated that it has undergone dozens of automated AI scans and multiple manual reviews, focusing on sensitive areas such as random number generation and transaction signing.The new firmware strengthens stack protection, updates dependencies, audits sensitive memory cleanup processes, and upgrades the Jade runtime environment.Blockstream stated that Jade's random number generation mechanism uses multiple entropy sources, including hardware chip noise, timing data, sensor data, and camera noise, mixed via SHA-512 to prevent a single entropy source failure from affecting seed generation.The team stated that other lower-severity findings are still being addressed, and firmware 1.0.42 is expected to be released within a shorter development cycle.