GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

BNB Chain to Launch Pasteur Hard Fork on August 25

Odaily News: BNB Smart Chain (BSC) has announced that the Pasteur hard fork will officially go live on the mainnet at 10:30 AM Beijing time on August 25 (02:30 UTC on August 25). Node operators are required to upgrade their clients to v1.7.7 in advance.This upgrade includes three improvements—BEP-682, BEP-695, and BEP-675—focusing on enhancing cross-chain security, validator governance mechanisms, and network throughput. Among them, BEP-682 will strengthen the BNB Chain cross-chain bridge verification mechanism, preventing permission bypass risks caused by duplicate signature counting by validators, thereby improving the security of cross-chain asset transfers. BEP-695 optimizes the validator key rotation mechanism, ensuring that old keys no longer retain management privileges after exit, while also fixing potential vulnerabilities related to slashing and governance voting.In terms of performance, BEP-675 reduces the time consumption caused by validators repeatedly executing transactions by optimizing the block construction process. In BNB Chain's internal QANet test environment, this solution increased throughput from 1,237 TPS to 2,324 TPS. While maintaining the 450-millisecond block time and the 100 million Gas block limit unchanged, the average Gas usage per block rose from 46.35 million to 84.15 million.BNB Chain stated that this upgrade is primarily aimed at validators and block builders, designed to provide greater capacity during network peak periods and advance the throughput expansion goals outlined in BNB Chain's roadmap for the second half of 2026.

Operations Ceased, SecondFi Wallet Migration Tool Launches August 13, Affected Asset Recovery Portal Expected by September 10

: Cardano ecosystem wallet project SecondFi has announced the launch of a wallet migration tool and revealed a recovery plan for assets affected by the June 2026 security incident. As the project will cease operations, users are required to migrate remaining assets still held in SecondFi wallets. The migration tool is expected to go live on August 13, supporting the transfer of eligible ADA, Cardano native tokens, and NFTs to new Cardano wallets created with service providers of the users' choosing. Currently, the tool only supports Cardano network assets; non-Cardano assets must be transferred separately through corresponding network and wallet processes. SecondFi stated that the migration tool has passed an independent security assessment by security firm Bitdefender. For affected assets, SecondFi plans to launch a recovery portal before September 10, where users can verify wallet ownership via zero-knowledge proofs (ZK Proof) and submit asset claims. SecondFi reminds users to only rely on information published through official channels, including @secondfiapp, @secondfi_jp, and the official support website, to guard against phishing sites and impersonating accounts.

Harmony Release Incident Update: Team Has Fixed Vulnerability and Is Proceeding with Rollback Plan

Harmony released an incident update stating that on August 12, 2026, Beijing time, an unauthorized issuance event of the native token ONE occurred on the Harmony mainnet. Officials confirmed that the initial abnormal issuance volume was 4 billion ONE, completed through two empty block entries; additionally, on-chain reconstruction results show that the total forged cross-shard issuance volume could reach 3.0100001 trillion ONE, involving 6 forged cross-shard transactions and 4 attacker wallets, and the team is still further verifying the two sets of data.

Trezor Logistics Partner Suffers Data Breach, Nearly 14,000 Customer Records Leaked

According to Decrypt, Trezor's logistics partner ShipMonk suffered a data breach, leaking the personal information of a total of 13,689 customers. Among them, the names, phone numbers, email addresses, and home addresses of 11,742 individuals were fully obtained, while partial information of another 1,947 individuals was affected. The affected users were all customers who placed orders between May 10 and August 8 in the US, UK, Sweden, Colombia, Brazil, Italy, or Portugal. Trezor emphasized that its own system was not compromised, and devices, private keys, and wallet backups were all unaffected. It reminded users to be vigilant against phishing attacks and never enter wallet backup information online.

Trezor customer data exposed due to ShipMonk security breach, affecting users in 7 countries

Odaily News: Bitcoin News posted on X platform that Trezor stated its customer data was exposed due to a security breach at logistics provider ShipMonk. Customers who received orders within 90 days before August 8 in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal may be affected. The exposed data includes full names, shipping addresses, phone numbers, email addresses, and order numbers. Trezor stated that its systems were not compromised and devices remain secure, but reminded affected customers to beware of sophisticated phishing attacks leveraging the leaked information.

Nearly 200,000 XRP Stolen, Coreum Cross-Chain Bridge Attacked

Odaily News: The cross-chain bridge connecting XRP Ledger and Coreum was attacked on August 9. The attacker exploited a validation logic vulnerability to steal approximately 199,900 XRP, reducing the bridge's asset balance from roughly 200,400 XRP to 493.5 XRP. The attack did not involve private key leaks and did not target the XRP Ledger protocol itself. The attacker forged deposit operations, causing the bridge system to recognize them as legitimate deposits and triggering the bridge wallet on the other end to send real XRP. On-chain data shows that the attacker completed the fund transfer through 94 multi-signature authorization transactions within 97 minutes. These transactions required signatures from 17 of the 28 relay node keys, allowing the attacker to bypass the bridge's validation mechanism. As of August 11, the Coreum cross-chain bridge remains suspended, and the Coreum Development Foundation has not yet released an official incident report. The XRP mainnet and user private keys remain unaffected and secure.

Network paused, Oraichain cross-chain vulnerability leads to unauthorized minting of ORAI

Odaily News, Oraichain stated that yesterday's incident stemmed from a vulnerability in the EVM cross-chain transfer path, resulting in the unauthorized minting of ORAI. Since 04:00 UTC on August 9, the network has been suspended, with bridge contracts, cross-chain paths, and public interfaces also restricted. The relevant vulnerability path has been identified and addressed, and associated fund transfer routes have been restricted. The team is working with partners and centralized exchanges to limit further movement of funds and protect affected assets. Currently, investigations and account reconciliations are still ongoing, and the team is preparing to restore the standard supply of ORAI, including burning unauthorized minted balances, as well as reconciling and repairing affected protocol states.

Coinsbuy Confirms Security Vulnerability, $7.9 Million in Cryptocurrency Stolen

Coinsbuy confirmed a security incident on August 9 involving unauthorized withdrawals from the platform wallet. The company stated it has covered customer losses with its own reserves and offered a $100,000 bounty.

Donald Trump earned over $1.4 billion from crypto businesses in 2025, while CLARITY Act identified with five major flaws

Odaily News: On August 5, the minority staff of the U.S. Senate Committee on Banking, Housing, and Urban Affairs stated that the July 22 version of the CLARITY Act fails to meet five minimum standards. The bill, numbered H.R. 3633, aims to divide digital asset regulatory authority between the U.S. Securities and Exchange Commission (SEC) and the U.S. Commodity Futures Trading Commission (CFTC). The analysis suggests that the bill's two-tier system could remove certain blockchain assets from SEC oversight, allowing issuing companies to self-certify exemptions from securities regulation. Healthy Markets and five labor organizations have raised concerns over pension protections and securities law loopholes, while minority staff also noted that investors' private right of action and state and tribal enforcement powers could be weakened. Minority staff stated that DeFi-related companies could be exempt from anti-illegal financing obligations even if they earn millions of dollars from platform transactions; some crypto mixers may circumvent U.S. sanctions by exploiting the "Tornado Cash loophole." The Independent Community Bankers of America (ICBA) and the Conference of State Bank Supervisors (CSBS) warned that stablecoin yields could drain deposits from community banks, and the Systemic Risk Council has flagged related banking activities as potential bailout risks. Minority staff noted that Donald Trump alone earned over $1.4 billion from crypto businesses in 2025, with related enforcement solely under the purview of his Attorney General, and that obligations would terminate upon his departure from office. Elizabeth Warren and Richard Blumenthal, citing $3.8 billion in investor losses, have separately called on the SEC to investigate Trump memecoin. The Senate is scheduled to hold a cloture vote on September 15 on the motion to proceed, with the bill needing 60 votes to advance. (Bitcoin.com News)

Pepe creator Matt Furie's account linked to 3 meme coins within a week, later claims account was hacked

Odaily News: After a 9-month silence, the X account of renowned artist and Pepe creator Matt Furie became active again in early August, posting content and contract addresses related to HOODRAT, DORK, and BOYZ within a single week. Most of these posts were subsequently deleted. On August 9, the account posted a statement claiming it had been hacked, stating it does not endorse any altcoins, and adding that a relevant notice had previously appeared on its official website. On-chain analyst @StandartXBT noted that after the HOODRAT-related post was published, the token's market cap surged briefly before the price declined; following the DORK deployment, the deployer completed bundled purchases, removed liquidity, and sold off, extracting significant ETH profits from the initial raise. @StandartXBT discovered through web archives that Matt Furie's official website had not previously contained such a notice, and no prior trace was found on the X platform, casting doubt on the credibility of the statement.

Approximately $720,000 in Assets Stolen as Bifrost's Liquidity Mining Incentive Vulnerability Exploited by Hackers

According to Bifrost's monitoring, at 19:47 Beijing time on August 8, hackers exploited a vulnerability in the liquidity pool, stealing approximately $720,000 worth of assets from the vDOT single-asset pool and the vASTR/ASTR and vMANTA/MANTA pools. The stolen assets were subsequently deposited into HitBTC and eventually flowed into Binance. Bifrost has contacted Binance's security department to submit a fund freeze request and has filed a report along with a chain of custody evidence package, including transaction tracking, wallet addresses, and timestamps, with law enforcement authorities. Currently, Bifrost has halted all liquidity mining rewards and is conducting a comprehensive security review.

Bitcoin new wallet count hits a 2026 high, Coldcard firmware vulnerability causes over $116 million in losses

Odaily News: Bitcoin added 2.27 million new wallets this week, with active wallet count reaching 751,000, marking the highest on-chain activity in months. On July 31, active addresses briefly approached 978,000—approximately 1.6 times the July daily average—while the first week of August averaged around 751,000 daily, up from July's average of roughly 610,000. Daily average exchange inflows stood at approximately $1.55 billion, down from July's $1.67 billion, with fund movements not accompanied by significant exchange buying activity. This surge in activity is linked to a firmware vulnerability in Coldcard devices from hardware wallet manufacturer Coinkite. The vulnerability affects certain Mk3, Mk4, Mk5, and Q models, where seed generation utilizes a software random number generator, reducing the actual randomness of some devices to approximately 40 or 72 bits. Since July 30, related bitcoin losses have exceeded $116 million. Holders of affected devices have transferred funds to new addresses and replaced them with unaffected hardware devices. Coinkite has released firmware patches and entropy remediation disclosure documents. This vulnerability stems from a random number generation issue in device firmware, not a flaw in the Bitcoin protocol layer.

Coldcard vulnerability pushes Bitcoin's 7-day hot supply up 98% in a week, with approximately 890,000 BTC moved

Odaily Odaily News: K33 Head of Research Vetle Lunde stated that the Coldcard attack likely drove the movement of approximately 890,000 BTC within 7 days, setting the highest 7-day active supply record for 2026. K33 estimates that around 7,300 addresses had approximately 1,596 BTC stolen at the time the report was prepared. The incident stems from a firmware flaw introduced by Coinkite in March 2021 in Coldcard hardware wallets, which may generate wallet seeds with insufficient randomness. Since July 30, coordinated transfers have removed approximately 1,600 BTC from thousands of addresses, worth over $100 million, and a possible fourth wave of attacks has pushed the total to nearly 2,000 BTC. On-chain data shows that Bitcoin's 7-day hot supply rose from 403,101.95 BTC on July 28 to 797,407.72 BTC on August 4, an increase of approximately 394,306 BTC in one week, or 98%. Sani from Timechainindex.com stated that since the Coldcard hack on Friday, exchanges have seen net inflows of 22,052 BTC. From July 30 to August 5, 39 dormant addresses moved a total of 1,486.09044782 BTC, worth over $95 million. Among them, one address created in 2010 moved 50 BTC, and five addresses created in 2013 collectively moved 620.00100547 BTC.

Luxembourg to Include Crypto Exchanges in FIU Alert System

Odaily News: Luxembourg has passed a new law authorizing the Financial Intelligence Unit (FIU) to send cross-institutional fraud alerts to traditional banks and cryptocurrency exchanges, with the relevant measures taking effect on August 8. The bill, numbered 8722, requires cryptocurrency exchanges operating in Luxembourg to receive alerts in sync with banks and payment institutions. The bill aims to close the loophole that allows fraudulent funds to move rapidly between traditional financial institutions and digital assets. Under previous rules, banks could only block transactions of flagged accounts within their own systems and were unable to notify another financial institution or cryptocurrency exchange to prevent funds from entering or leaving. Max Braun, head of Luxembourg's FIU, stated that incorporating cryptocurrency exchanges into the cross-departmental alert system will make it more difficult to cash out from flagged accounts. According to data from Luxembourg's Ministry of Justice, police recorded 6,382 fraud cases in the country in 2024, and financial practitioners submitted more than 18,000 reports of fraud and scams.

Trump: Talks with Iran Underway, to Proceed in Two Phases

Odaily News – On August 3 local time, U.S. President Trump answered reporters' questions at the White House, stating that negotiations with Iran are currently underway. Trump said that regarding talks with Iran, the first phase is the reopening of the Strait of Hormuz, and the second phase is denuclearization. Trump emphasized that the U.S. maintains a firm stance: Iran cannot possess nuclear weapons. Additionally, Trump disclosed progress in the negotiations concerning the reopening of the Strait of Hormuz. Trump stated that the Strait of Hormuz could potentially be reopened as soon as tomorrow. He also noted that the talks were initiated at Iran's request, with support from Saudi Arabia, the UAE, Qatar, and several other countries. He said that originally, "the U.S. was going to strike Iran with overwhelming force—more severe than any previous attack," but then Iran called, and Saudi Arabia, the UAE, and Qatar also called. Iran did not want to be hit, so it said it wanted to negotiate; they wanted to discuss the issue of the strait. Trump said, "This is Iran's last chance." Trump also said he would not allow Iran to charge fees for vessels passing through the Strait of Hormuz. (CCTV News)

FBI Agent Charged with Stealing Approximately $1 Million in Crypto Assets, Reportedly Used ChatGPT to Plan Fund Usage and Departure from the U.S.

Odaily News: FBI agent Patrick Yaroch was arrested last Friday for allegedly stealing approximately $1 million in crypto assets from a "hostile crypto account." According to an affidavit filed on August 1, Yaroch is suspected of transferring the assets starting around late 2024 or early 2025.Yaroch told investigators that he discovered certain keys that allowed him to transfer funds from digital wallets to himself. He claimed he was frustrated by his inability to further prevent individuals associated with "hostile nations" from using cryptocurrency, and conducted approximately a dozen transfers.Department of Justice documents show that Yaroch admitted to a DOJ employee that he had "made some very bad decisions" regarding crypto wallet issues. In another interview with federal agents, he also admitted that he had "screwed up."Yaroch previously served as a supervisory special agent in the FBI's Counterintelligence and Espionage Division at headquarters, and earlier worked at the FBI's Boston field office. The FBI terminated his employment on July 31.The investigation also alleges that Yaroch mixed personal funds with crypto assets and used ChatGPT to ask how to handle the funds, including how to spend or invest $1 million, and whether to leave the U.S. for a European country.

OKX.AI Launches Inaugural Trading Hackathon with $20,000 Total Prize Pool

Odaily News — According to official sources, OKX.AI has announced that registration for its inaugural trading hackathon is now open. Following the previous Genesis hackathon for Agent Service Providers (ASP), this hackathon focuses on AI Agent live trading capabilities. Participants are required to deploy their trading strategies as Trading ASPs and conduct live trading with no less than 300 USDT in equivalent funds. Rankings will be updated in real time based on yield (PnL %). The total prize pool is $20,000, with the champion receiving a $5,000 reward.It is reported that OKX.AI is an economic system built specifically for Agents, where users and Agents can discover and utilize professional services provided by ASPs. This event supports two development frameworks: Onchain OS and Agent Trade Kit. Registration runs from July 31 to August 11 at 12:00 (UTC+8), and the competition will take place from August 11 to August 25.

Bitgo CEO deposits ~$6.3M in BTC, challenges Claude to move the funds

: Bitgo CEO Mike Belshe deposited 100 BTC into a public Bitcoin address on August 1, worth approximately $6.3 million at the time, and invited Anthropic's Claude model to attempt to move the funds out of the address. On-chain records show the wallet received the funds on July 31, and the balance had not been transferred out as of August 2. Anthropic previously disclosed that during 141,006 cybersecurity assessment runs, 3 incidents were found, with 6 evaluation sessions involving 3 models inadvertently interacting with real organizational systems. The models involved include Claude Opus 4.7, Claude Mythos 5, and an unreleased internal research model. The cause was a configuration error by third-party testing partner Irregular, which led to the test environment being connected to the internet. Anthropic stated that Claude Opus 4.7, during one evaluation, located a real website with the same name as a simulated company, exploited weak passwords and exposed services to recover infrastructure credentials, and accessed a production database containing hundreds of records. The company said the model was attempting to complete assigned tasks, not actively breaking constraints or pursuing independent goals. Belshe's challenge involves Bitgo's institutional custody platform, which uses multi-signature or multi-party computation technology to distribute signing authority across multiple independent keys. As of August 2, Anthropic had not publicly responded to the challenge.

Coldcard security incident loses 1,359.882 BTC, attacker address receives 10% coin-mixing offer

Odaily News: In the Coldcard security incident involving hardware wallet company Coinkite, the amount of stolen bitcoin has risen to approximately 1,359.882 BTC. According to statistics from the Coldcard Sweep Watch dashboard, most of the identified bitcoin remains in a small number of addresses controlled by the attacker. On August 1, one of the attacker's holding addresses received a transaction containing an OP_RETURN message. The message publicly offered a 10% fee for "washing" bitcoin, KYC assistance, and withdrawal services for stolen funds, along with a Telegram contact. Coinkite has released an urgent firmware update to fix the weak random number generation issue that caused the original vulnerability. The company stated that the new firmware only protects wallets created in the future and cannot fix seeds already generated on affected versions. Some users have reported that after installing the update, their devices remain stuck on an error screen, fail to boot, or appear bricked. This mainly affects Mk4 and Q devices, though some Mk3 users have also reported similar issues. As of August 2, Coinkite has not publicly confirmed a widespread firmware defect.

Polymarket probability of "Next round of US-Iran peace talks before August 31" rises to 51%, up 17% in 24 hours

Monitoring from the PPP Prediction Market Tool shows that the probability of "Next round of US-Iran peace talks before August 31" on Polymarket has risen to 51%, up 17% in 24 hours; the probability of talks occurring before August 15 has risen to 27%, up 13% in 24 hours.Trump posted on social media today stating that he received a request from Iran to delay the attack and agreed to cancel the strike on Iran in exchange for an agreement. He noted that the U.S. is prepared to confront Iran with a level of military deterrence, strength, and capability unseen since World War II, as a framework for an agreement has already been reached. This framework includes the immediate, complete, and full reopening of the Strait of Hormuz, as well as ending Iran's nuclear threat. Based on this request, he agreed to cancel the attack for the future interests of the world and the survival of a successful and prosperous Iran, provided that an agreement can be reached promptly.Join the PPP Signal Push Community to stay ahead and seize the initiative.