GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Lazarus Group hackers are active again, transferring 244.148 BTC worth $19.42 million an hour ago

Odaily News: According to Lookonchain monitoring, Lazarus Group hackers transferred 244.148 BTC, worth $19.42 million, an hour ago.

Bitcoin ETFs See 8 Consecutive Days of Net Inflows Totaling $2.8 Billion, Strongest Inflow Streak in 10 Months

Odaily News: Bitcoin News posted on X platform that U.S. spot Bitcoin ETFs have recorded net inflows for 8 consecutive days, totaling $2.8 billion. August has become the strongest month for capital inflows since 2026.As Bitcoin and gold rise in tandem, investors are increasingly seeking to hedge against risks including a weakening U.S. dollar, persistent inflation, and the widening U.S. fiscal deficit. Gold funds have also seen record demand.This shift is beginning to reflect in ETF trading. IBIT and GLD have rejoined the list of the top 10 most-traded ETFs, after semiconductor funds dominated for most of the summer.BlackRock noted that another significant source of demand comes from existing Bitcoin holders moving their tokens into ETFs. The company has so far processed approximately $5 billion in deferred-tax Bitcoin transfers into ETFs, and the minimum conversion amount has recently been lowered from $25 million to $1 million."As we continue to expand access, this scale will continue to grow," said Robbie Mitchnick, Head of Digital Assets at BlackRock.Mitchnick pointed out that incidents such as kidnappings, ransomware attacks, and custody failures are driving some Bitcoin holders to shift toward ETF custody.Bitcoin and gold are once again aligning with the core of the same macroeconomic logic, as the currency debasement trade makes a comeback.

SlowMist: Malicious GitHub Repository Disguised as Qwen Model Discovered

Odaily News – SlowMist security team has disclosed the discovery of a GitHub repository impersonating the Qwen 3.8 27B local quantized model. The repository claims the model size exceeds 16 GB, but the actual downloaded content is only about 487 KB, containing disguised files, a LuaJIT interpreter, and obfuscated Lua scripts. SlowMist emphasized that the official Qwen project has not been compromised. According to SlowMist's analysis, once executed, the malicious program collects host data, captures screenshots, and sends them to the attacker's C2 server. When the hardcoded server becomes inactive, it reads a backup C2 address from a contract on the Polygon chain, allowing attackers to rotate infrastructure through on-chain transactions. Subsequent payloads can steal browser login credentials, cookies, browsing history, email accounts, WinSCP and Steam credentials, as well as wallet-related files and extension data. SlowMist also discovered at least 23 GitHub repositories and 29 similar archive files using the same Lua delivery chain.

MANTRA Discloses Security Incident Post-Mortem: ~721M MANTRA Tokens Transferred, Chain Offline for 30 Hours

MANTRA has released a complete review of the August 20 security incident. The incident stemmed from an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency, cosmos/evm. Without requiring privileged access, the attacker transferred a combined total of 720,923,967.99 MANTRA tokens from a burn address and a legacy genesis multisig address, amounting to approximately $3.6 million at pre-incident prices.

OneKey Reproduces Transaction Replacement Vulnerability in Legacy Ledger Ethereum App in the Lab

According to Cointelegraph, open-source wallet provider OneKey stated that its security team successfully reproduced a "transaction replacement attack" targeting the legacy Ledger Ethereum app version 1.22.1 in a laboratory environment. This vulnerability could allow attackers to replace transactions awaiting signature while users review legitimate ones, though successful exploitation requires controlling communication between the device and the host, such as through malware, compromised wallet software, or malicious websites.

Privacy Pools vulnerability fixed in March; 0xbow.io awards $5,000 bounty to researcher ross.wei

Odaily News: 0xbow.io, a privacy and regulatory compliance tool supported by the Ethereum Foundation, has awarded a $5,000 bounty to researcher ross.wei for disclosing a vulnerability in the Privacy Pools v1 SDK. The vulnerability reduced the entropy of user account master key generation and was fixed in March. The team has provided a migration process, and no user funds were lost.

The Sandbox plans 1:1 compensation, approximately $700K in SAND stolen in bridge vulnerability exploit

blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)

Grayscale Research: Bitcoin Is Returning to Its "Currency Depreciation Trade" Attribute, Zcash May Become One of the Biggest Beneficiaries

According to the latest report released by Grayscale Research Director Zach Pandl, as U.S. federal debt surpasses $40 trillion, Bitcoin's 90-day correlation with the Nasdaq 100 Index has dropped from over 60% to approximately 33%, while its correlation with gold has risen from near zero at the start of the year to above 50%, indicating that Bitcoin is shifting from a high-beta risk asset to an inflation-resistant store of value. Grayscale believes that expanding fiscal deficits and rising long-end interest rates will drive investors toward scarce alternative assets, positioning Bitcoin, Ethereum, and Zcash as primary beneficiaries. Among them, Zcash, featuring financial privacy, quantum resistance, and cross-chain interoperability, is considered to have the potential to challenge Bitcoin's network effect, despite its market capitalization currently accounting for less than 1% of Bitcoin's. Additionally, Grayscale notes that the current Bitcoin bear market has persisted for roughly 10 months, approaching the historical average bear market cycle of 11–12 months. Coupled with a macroeconomic environment that is becoming increasingly supportive, it suggests that current prices may represent a favorable entry point for long-term investors.

Ledger Ethereum App Version 1.22.1 Contains Transaction Replacement Vulnerability — Users May Review One Transaction While Signing Another

Odaily News: OneKey Anzen has reproduced the Ledger vulnerability and discovered that Ledger Ethereum app version 1.22.1 contains a transaction replacement vulnerability. When an affected user is attacked, the hardware screen still displays transaction A under review, but the device may sign transaction B, which the user never viewed. OneKey Anzen stated that the issue stems from a race condition between the transaction display logic and the underlying buffer, with the attack requiring the host side to already be compromised by a malicious DApp or intermediary software. Ledger's CTO previously responded that a fix had been rolled out approximately two weeks ago, and users simply needed to update the app. Public information shows that the official tag for version 1.22.2 on Ledger's GitHub appeared on August 24. Ledger's official website states that the issue has been fixed through app-level checksums and SDK-layer patches, with Ledger Secure SDK v26.6.1 released on August 21, and the related apps have been rebuilt and republished. Users need to update the app via Ledger Live — updating only the device firmware will not complete the fix. Ledger stated that there is currently no evidence that this vulnerability has been actively exploited.

Sparrow Wallet Releases Version 2.5.4, AI-Assisted Code Review Fixes Multiple Security Vulnerabilities

According to Decrypt, privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on August 28. Developer Craig Raw stated that the update was driven by an AI-assisted code review, with the majority of fixes originating from it. This review was prompted by the recent seed generation code vulnerability exploit affecting Coldcard, as well as the release of unrestricted AI models in China, which has significantly enhanced vulnerability scanning capabilities across large codebases. Key updates include: validating the authenticity of transactions returned by Electrum servers, enforcing stricter BitBox02 hardware wallet security requirements (firmware v9.4.0 or higher required), patching local DNS leaks, and masking sensitive credentials in debug logs. Raw noted that there are no indications of any exploits being leveraged, user funds remain secure, and he still advises all users to update at their earliest convenience.

CrowdStrike CEO: AI Accelerates Cyberattacks, Traditional Security Tools Struggle to Keep Up

As reported by CNBC, CrowdStrike CEO George Kurtz stated that the rapid rise of AI is exposing vulnerabilities in corporate cybersecurity defenses, making it difficult for even heavily invested companies to remain secure. He noted that the emergence of Anthropic's Mythos model has made cyberattacks faster and more complex, driving a significant surge in market demand for cybersecurity platforms. Consequently, shares of both CrowdStrike and Palo Alto Networks have risen approximately 100% year-to-date.

OpenAI, Anthropic, and over 100 other institutions issue a joint open letter calling for strengthened global cyber defense in the AI era

Odaily News: OpenAI co-founder Greg Brockman reposted the open letter, with over 100 institutions including Anthropic, AWS, Google, Microsoft, OpenAI, and Oracle jointly calling for strengthened global cyber defense to address the rapidly evolving threat of AI-powered cyberattacks.The open letter states that AI-driven cyberattacks are expected to become more prevalent and sophisticated in the coming months, posing higher risks to critical systems such as hospitals, water treatment facilities, and internet infrastructure. All parties should seize the current window of opportunity in which AI can equally enhance defensive capabilities, accelerate the closure of long-standing security vulnerabilities, and prioritize AI tools with cybersecurity capabilities for critical infrastructure defense teams.The open letter also calls on companies, cybersecurity firms, governments, and frontier AI companies to jointly invest tools, funding, and technical support to strengthen threat intelligence sharing, vulnerability remediation, and continuous security monitoring.

About 678,000 individuals' and businesses' data stolen: French tax authorities hacked, potentially endangering Bitcoin holders' personal safety

Bitcoin News posted on X platform, stating that France disclosed this month that its tax administration had been hacked, with data of approximately 678,000 individuals and businesses stolen. The stolen data allegedly includes names, addresses, income, and property information. Analysis of the alleged database found 26,805 records showing income exceeding €100,000, including 386 records exceeding €1 million. According to CertiK data, out of 52 verified cryptocurrency wrench attacks globally in the first half of 2026, France accounted for 33. French prosecutors have also accused a tax department employee of using government databases to identify cryptocurrency investors and selling personal information to criminals involved in physical assaults and extortion. The latest data breach has no publicly linked physical attacks yet, but sensitive financial and location data of hundreds of thousands of people may now no longer be under government control.

Trump says he is not worried about Russia attacking NATO countries.

U.S. President Trump publicly stated that he is not currently concerned about Russia launching a military attack against NATO member states. This stance reflects core geopolitical positions and will directly impact global risk-off sentiment and macro asset pricing logic.

Cumulative losses exceed $3.63 billion, with nearly 60% of attacks on crypto platforms involving completed security audits

Odaily News: Between January 2025 and July 2026, a total of 245 security incidents were recorded. The top ten attack events accounted for over 72.5% of stolen funds. Supply chain and infrastructure vulnerabilities remain the primary security risks facing both CEXs and DEXs, with related losses exceeding $1.8 billion. Private key leakage is the most common risk for CEXs, while DApps lost approximately $546 million due to smart contract vulnerabilities. Among the 147 incidents involving platforms that had completed independent security audits, stolen funds accounted for 88.44% of total losses. Most attacks fell outside the scope of traditional audit coverage, with common causes including external infrastructure, unaudited code updates, and governance attacks. Only about 11% of incidents involved smart contract defects within audit scope.

Analyst: Address poisoning attacks on Tron have resulted in 15 victims losing $9.4 million over the past 4 weeks

Odaily News: On-chain analyst Specter has disclosed that a series of address poisoning attacks on the Tron network over the past 4 weeks have caused 15 victims to lose approximately $9.4 million in total. Among them, two victims each had $2.5 million stolen, while another lost $2 million. After succeeding, the attackers quickly converted all stolen assets into the stablecoin USDD and transferred them to a collection address, where all funds currently remain. Specter calls on wallet service providers in the Tron ecosystem to implement interception measures as soon as possible and reminds users to carefully verify addresses when making transfers.

GoPlus: Realio Platform Signing Key Compromised, Approximately 127.9 Million RIO Tokens Transferred

GoPlus Security released a security alert stating that on August 25, realio[.]fund, a project under Realio Network, was attacked. The attacker took control of the platform's signing system and moved treasury and custody wallet assets across Ethereum, BNB Chain, Algorand, Stellar, and the Realio native chain. A total of approximately 127.9 million RIO tokens worth around $6.2 million were affected, with the attacker having cashed out approximately $317,000 so far.

Moonwell on the Base chain suffers a suspicious attack, losing over $4 million in cbBTC

According to monitoring by Blockaid, its vulnerability detection system detected suspicious activity on Moonwell on Base. The attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market. To date, approximately 50.6 cbBTC (valued at over $4 million) have been observed being transferred. More details remain to be disclosed.

1:1 compensation for legitimate holders prior to the vulnerability incident; The Sandbox will reimburse cross-chain SAND using treasury funds

Odaily News, The Sandbox has released a post-mortem report on the August 22 vulnerability incident. The report shows that attackers exploited vulnerabilities in contracts related to cross-chain configurations on Base and BNB Smart Chain (BSC), stealing 14,742,341.84 SAND from the Ethereum treasury, accounting for approximately 0.5% of the maximum supply, with an estimated economic impact of approximately $1.4968 million, of which about $987,000 was actually retained by the attackers. The Ethereum mainnet and Polygon network were not affected. Until further notice, please do not purchase or send SAND on Base or BNB Smart Chain. Contracts deployed on Base and BNB Smart Chain have been permanently deactivated and will not be reopened. The Sandbox stated that the team has reported the attacker's wallet address to blockchain analysis firms TRM Labs and Chainalysis, and has communicated directly with relevant exchanges. The Sandbox also announced a compensation plan, which will compensate wallets that legitimately held cross-chain SAND on Base or BSC prior to the incident at a 1:1 ratio in Ethereum SAND. Compensation funds will come from The Sandbox treasury, with no new tokens issued. The claim process will open within the next two weeks and remain open for two weeks.

1inch Publishes H1 2026 Bug Bounty Report via HackenProof

1inch and HackenProof have jointly released the first-half 2026 Bug Bounty Report. The report shows that from January to June 2026, 1inch received a total of 1,055 submissions from security researchers across its 6 core bug bounty programs on HackenProof, of which 32 were rewarded.