GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

ZKsync Announces EraVM Security Upgrade, Phasing Out Legacy Execution Environment Over the Next 6 Months

According to the official ZKsync X account (@zksync), ZKsync has announced a security upgrade for its EraVM chain. Core measures include introducing an instant upgrade framework, extending the proving delay from 3 hours to 24 hours, and deploying a second prover, EraBender, to defend against AI-driven vulnerability attacks. Over the next six months, all Boojum/EraVM chains will gradually phase out the legacy execution environment, with each chain formulating and publishing its own transition schedule. Users who hold funds directly in EOAs do not need to take any action at this time. Users who hold funds through smart contracts such as multisigs, smart accounts, DEXs, and lending protocols must take action as required once the transition plans for their respective chains are finalized. The ZKsync Atlas chain remains unaffected by this upgrade.

OpenAI Suffers Supply Chain Attack with Leaked Signing Certificates, macOS Client Mandatory Update Next Month

OpenAI has confirmed a supply chain attack targeting a malicious TanStack NPM package in its internal environment, infecting two employees' devices. While user data and core code were not affected, the attackers stole access credentials for some internal code repositories, including code signing certificates used for iOS, macOS, and Windows products.To prevent hackers from exploiting the stolen certificates to distribute counterfeit applications, OpenAI has initiated defensive certificate rotation and announced that all macOS users of ChatGPT desktop, Codex, and Atlas browsers must upgrade to the latest version by June 12, 2026. After this deadline, old certificates will be revoked, and system-level blocks will prevent the launch of older versions and new installations.OpenAI stated that the company had previously deployed stricter code package blocking policies, but the infected devices had not yet synchronized the latest configuration, allowing the malicious component to successfully infiltrate. Currently, the iOS and Windows clients are unaffected, and core data such as user account passwords and API keys have been confirmed secure.