GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Noxa Fi's X account suspected of being hacked, user wallets drained

Odaily Odaily reports, according to Onchain Lens monitoring, Noxa Fi's X account appears to have been compromised. Users are advised not to connect their wallets, sign any transactions, or interact with any links posted by this account. There have already been reports of users whose wallet assets were stolen after interacting with the account.

EU Sanctions "Most Prolific Ransomware Operator" Stern, Linked to Over $300 Million in Ransom Payments

the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)

US Government Transfers 296,700 USDT to Coinbase Prime

The U.S. government has just transferred seized funds related to the Bitfinex hack case, with 296,710 USDT moved to Coinbase Prime, possibly for OTC sale.

Starknet Launches Compliant Privacy Framework STRK20

According to Odaily Planet Daily, Ethereum ZK Layer2 Starknet has officially launched the compliant privacy framework STRK20, providing native privacy transaction capabilities for various digital assets on-chain. The framework operates based on a privacy pool mechanism. Once user assets are deposited into the privacy pool, all transactions are encrypted, with details such as transfer addresses and amounts being invisible to the outside. Developers can quickly integrate this privacy system using the accompanying SDK and wallet API, catering to the private transfer needs of various ERC-20 assets. STRK20 incorporates a complete compliance process: users must undergo pre-screening before entering the privacy pool; only upon receiving a legally effective formal query request and after an independent assessment, will the platform selectively disclose specific users, corresponding time periods, or designated transfer records, without revealing the private data of unrelated users.

Extended Discord Server Attacked, Officials Warn Against Participating in Fake $EXT Token Claim

The official Extended X account posted that its Discord server was hacked earlier today, with a fake announcement appearing in the server claiming "$EXT token claim is now live." The official team explicitly stated that there are currently no TGE plans or $EXT token claim activities, and relevant websites are all counterfeit phishing websites. Users are reminded not to connect wallets, sign any messages, or approve any transactions on relevant websites; if interaction with malicious websites has occurred, token approvals should be revoked immediately using trusted tools, assets should be transferred to a new wallet, and the original wallet should be considered compromised.

Dragonfly Partner: DeFi "Hacker Doomsday" Warning Failed to Materialize, AI Hardening Significantly Improves Security of Major Protocols

Dragonfly 管理合伙人 Haseeb Qureshi(@hosseeb)在 X 平台发文,距 OpenZeppelin 创始人 Manuel Aráoz 发出"DeFi 全面不安全"警告已过去两个月,数据显示所谓"黑客末日"并未成真。 数据显示,2026年 DeFi 被盗金额年化值低于 2025 年全年,即便剔除异常月份(如 Bybit 黑客事件、Drift 及 KelpDAO 事件)后对比,2026 年每月被盗金额仍低于 2025 年;按 TVL 标准化后,2026年 DeFi 资金被盗比例同样略低于 2025 年。 Haseeb 指出,当前呈现出"攻击次数上升、单次规模下降"的结构性特征——攻击者主要针对无力承担 AI 安全加固成本的小型协议和废弃项目,而已完成 AI 代码加固的大型协议安全性实际上有所提升。他总结称,"DeFi 中平均每一美元的安全性与一年前持平,将资金存放于大型协议大概率是安全的。"

Qubic GitHub Compromised, Officials Urgently Advise Users to Take Security Measures

According to an announcement released by Qubic's official X account (@Qubic), a security incident occurred within the Qubic GitHub organization on July 13, where a compromised account accessed repositories and extracted sensitive information. Officials have intervened to handle the situation. Officials recommend the following users take immediate action: • Network Guardians: Rotate seeds immediately • Web wallet users: If you unlocked your wallet between 03:00–10:00 UTC on that day, please migrate to a new identity; if unsure about the last unlock time, migration is also recommended • Developers: Pause pulling or deploying code from Qubic repositories until officials confirm the audit is complete Officials stated that full details and subsequent updates will be published on the official Discord channel, reminding users not to trust information from unofficial channels, and warning that no one shall request user seeds for any reason. The incident post-incident report will be released after handling is complete.

Dragonfly Partner: No "Hacker Apocalypse" in DeFi; Annualized Stolen Value in 2026 Estimated at $1.89 Billion

Haseeb posted on X, stating that with models like GLM 5.2, Fable, and GPT 5.6 already launched and actively used by attackers, DeFi has not experienced the anticipated "hacker apocalypse." Chart data shows that based on the current year's data and running rate, the annualized amount stolen from DeFi in 2026 is approximately $1.89 billion. The cumulative stolen amount for the year is around $986 million, lower than the 2025 level and still within the historical range. Haseeb noted that the deeper change now is that while the number of hacker attacks has increased, the scale of individual attacks is declining more rapidly. Attackers are increasingly targeting smaller protocols and abandoned projects, while large protocols have implemented more security enhancements. As a result, overall fund security has not significantly deteriorated.

Trump threatens to strike Iran's "Mount Khao" underground nuclear facility

Trump stated in an interview that the U.S. will strike Iran's "Mount Khao" underground nuclear facility and warned that it will continue to launch fierce airstrikes against Iran. Trump said, "We will destroy 'Mount Khao.' Tell the Iranians to be prepared." He noted that the U.S. has been closely monitoring the facility, adding, "There's no activity there right now. Their nuclear program is not progressing well. Every time we detect something, we blow it up. We might strike 'Mount Khao' very soon." Reportedly, "Mount Khao" is located near Iran's Natanz uranium enrichment facility and contains two deep underground tunnel complexes. It is considered one of Iran's most fortified underground nuclear facilities, potentially capable of withstanding attacks from even the most powerful U.S. bunker-buster bombs currently in service. Trump also reiterated that the U.S. will continue its heavy strikes against Iran tonight and tomorrow, stating, "We will hit them hard tonight and hit them hard tomorrow. There's nothing they can do about it." (Jin Shi)

Lumi Finance Suspected to Be Attacked, Current Losses Approximately $270,000

According to Blockaid monitoring, the Lumi Finance protocol on Arbitrum is under attack, and approximately $270,000 in funds have been transferred out so far.

Multicoin Capital Partner Claims Crypto Market Has Bottomed, Remains Bullish on SOL, Hyperliquid, and ZEC

: Tushar Jain, Managing Partner of Multicoin Capital, stated that the crypto market has bottomed out and entered a turning point. Market sentiment has truly hit rock bottom, recent major hacking incidents and other news have not triggered large-scale sell-offs, application adoption rates continue to rise, and there is a decoupling between price and fundamentals. He maintains a long-term bullish outlook on Solana, believing SOL represents the correct architecture for spot trading and tokenized securities. Simultaneously, he is bullish on Hyperliquid's leading position in the derivatives space and currently holds significant positions in both.Regarding ZEC, he stated that Multicoin has accumulated a considerable proportion of its supply and believes it represents the industry's return to "cypherpunk" values, with the potential to enter the top five by market cap. In terms of position management, he adopts a "three-way split" strategy: immediately buying the first third, dollar-cost averaging the second third, and reserving the final third as flexible capital to cope with significant market downturns. During the Zcash code vulnerability incident, after the team observed and confirmed no hacker exploitation, they significantly increased their positions.

Token Pocket Chief Business Officer: Robinhood Founder's Seed Phrase Leaked During Live Stream, Address Now Frozen

Michael, Chief Business Officer of Token Pocket, stated on platform X that Robinhood founder's seed phrase was leaked during a live stream. After gaining control of the address, the hacker used it and associated addresses to heavily purchase the Meme token $1, prompting thousands of investors to follow suit. In a short time, the token's market cap quickly surged from approximately $500,000 to $14 million.Subsequently, the price of the $1 token dropped sharply, with two-hour trading volume reaching around $20 million. After the address was frozen, the hacker quickly moved to the BNB Chain, using the address and its associated addresses to issue a new token. They created trading activity through tactics like wash trading, ultimately dumping the tokens for profit.Currently, Robinhood's RPC has frozen the address, and the node does not allow transactions originating from this address to be packaged, making transfers, purchases, or sales impossible.

Hackers hack into SpaceXAI and Starlink accounts to promote SCATMAN, profiting approximately $125,000

According to Lookonchain monitoring, hackers hacked into the SpaceXAI and Starlink accounts to issue and promote SCATMAN. The hacker's wallets (0xfee...a8ba, 0xdd...ba89) minted 10 trillion SCATMAN and exchanged all of them for 59 ETH, worth $108,000; another wallet under their control also exchanged 59.28 million SCATMAN for 14.7 ETH, worth $27,000. The hackers profited a total of approximately $125,000.

Two hackers today spent a total of 11.718 million DAI to purchase 6,454.7 ETH

: According to monitoring by on-chain analyst Yu Jin, the hacker (0x18B...E66) who stole funds from a Coinbase user spent 7.378 million DAI early this morning to buy 4,049.7 ETH at a price of $1,822. Meanwhile, the address (0xa13...628) that received ETH from Tornado Cash last November had previously transferred out 4,978 ETH and exchanged them for 16.294 million DAI at a price of $3,273. Today, two hours ago, this address spent 4.34 million DAI to repurchase 2,405 ETH at a price of $1,804.

São Paulo State Court Orders Coinbase to Refund Nearly $100,000 to User Affected by Self-Custody Wallet Theft

Odaily reports: A court in the state of São Paulo, Brazil, has ordered Coinbase to refund nearly $100,000 to a user who claimed funds deposited in their Coinbase Wallet disappeared in an unauthorized transaction. Coinbase argued that the private keys to the wallet were entirely under the user's control. However, it failed to prove that the transaction was initiated by the wallet holder or that adequate security measures were in place to prevent the incident. The court ruled based on relevant provisions of the Consumer Protection Code and ordered Coinbase to return the full amount plus statutory interest. (Bitcoin.com News).

Suspected hacker wallet buys 6,358 ETH with 11.59 million DAI

据链上分析师 Onchain Lens(@OnchainLens)监测,两个疑似属于同一实体的钱包地址以 1159 万枚 DAI 买入 6358枚 ETH,成交均价约为 1823 美元。Onchain Lens 表示,相关资金可能与黑客有关。

Ethereum Foundation: AI Discovers Vulnerability That Could Cause Validator Nodes to Go Offline, But Manual Verification Still Required

According to CoinDesk, the Ethereum Foundation recently disclosed that its security team used AI agents to test the software running on Ethereum validator nodes and successfully discovered a vulnerability that could be triggered remotely, causing node crashes. However, researchers emphasized that amidst the large volume of security reports generated by AI, manual review remains a key step in distinguishing real vulnerabilities from false positives. Reportedly, the vulnerability discovered resides in the Ethereum network message propagation protocol gossipsub, where attackers can remotely trigger the node software into an abnormal computation state, causing the program to crash and shut down, taking the validator node offline until the operator manually restarts it. The vulnerability has been fixed and registered under the number "CVE-2026-34219". Nikos Baxevanis, a member of the Ethereum Foundation Protocol Security Team, stated that the truly surprising aspect of this incident was not the AI's ability to discover vulnerabilities, but the significant amount of time the team spent distinguishing which vulnerabilities were real and which were merely plausible "hallucinations".

Loss of approximately $9 million: Hedera ecosystem lending protocol Bonzo Finance suffers oracle attack

Bonzo Finance, a lending protocol based on Hedera, suffered an oracle attack, resulting in a loss of approximately $9 million. The attacker exploited collateral whose SAUCE token price had been artificially inflated to borrow assets far exceeding their actual value from the protocol. According to a preliminary incident report released by Bonzo Finance, the attacker deposited only 250 SAUCE tokens, then submitted a single price update that artificially inflated the token's price by approximately 12 orders of magnitude. Subsequently, the address borrowed 6.63 million USDC and 34.5 million wrapped HBAR from the lending pool.This attack was not due to a vulnerability in Bonzo Finance's smart contracts or the underlying Hedera network itself, but rather stemmed from a flaw in the on-chain oracle verifier of the oracle service provider Supra. It erroneously accepted a SAUCE price data point where the signature had been zeroed out. Supra has since confirmed the issue and completed a fix.

A Solana OG had 181,000 SOL stolen, and the hacker swapped them for 7,918 ETH

According to Lookonchain monitoring, a Solana OG had 181,000 SOL stolen. The hacker sold all 181,000 SOL, bridged the funds to Ethereum, and exchanged them for 7,918 ETH, worth $14.2 million.

Hedera Network suspected of being hacked, attacker has bridged $3.7 million to Ethereum

: According to on-chain detective Specter's monitoring, the Hedera Network is suspected of being hacked. The attacker has bridged over $3.7 million from the Hedera Network to Ethereum via LayerZero. The stolen funds are currently being swapped from WBTC to ETH. The theft addresses include 0x9A4966152F6e10b33Cb7a37975e8619816d6a494 and 0xaf20D792A19fD42dCf697ceBa6100291D96dD93e.