GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Binance: Platform and User Assets Unaffected by Vercel Security Incident

According to an official announcement, in response to the security incident involving the frontend platform Vercel and related supply-chain security risks, Binance’s security team immediately initiated an emergency response, conducted a comprehensive risk assessment across all frontend products within the Binance ecosystem, and directly contacted Vercel to verify each point individually. Binance stated that its platform and user assets are not affected by this incident.

Curve Finance Suspends LayerZero Cross-Chain Bridging Functionality in Response to rsETH Infrastructure Hack

According to an official announcement from Curve Finance, due to a hacker attack on the rsETH LayerZero infrastructure, Curve Finance has suspended its LayerZero infrastructure for security reasons, pending further investigation into the root cause before resuming operations. This suspension affects the following: cross-chain bridging of CRV tokens from BNB Chain, Sonic, Avalanche, Fantom, Etherlink, and Kava (chains using native bridges remain unaffected), as well as the crvUSD fast bridge functionality (the L2 slow bridge remains fully operational). Meanwhile, KelpDAO is also reported to have suffered a vulnerability exploit involving approximately $291 million; the exact extent of losses is still under investigation.

Curve Finance Suspends LayerZero Infrastructure

According to an official announcement, Curve Finance has suspended its LayerZero infrastructure as a precautionary measure following a hacker attack on rsETH’s LayerZero infrastructure, pending further investigation into the root cause. This adjustment affects cross-chain CRV bridging initiated from chains including BNB, Sonic, Avalanche, Fantom, Etherlink, and Kava; bridging from other chains remains unaffected and continues to use native bridges. Additionally, the crvUSD fast bridge is impacted, while the slower bridge to L2s remains fully operational.

An address deposited 978,000 ZRO tokens to Binance, valued at approximately $1.57 million.

According to on-chain analyst Yujin (@EmberCN), ZRO—the native token of LayerZero, the cross-chain bridge exploited by hackers in today’s rsETH vulnerability incident—fell 18% on the day, dropping from $1.90 to $1.50. Twenty minutes ago, a Polymarket user with the address “greenrooibos” deposited 978,000 ZRO tokens to Binance, valued at approximately $1.57 million. These ZRO tokens were withdrawn from Binance two weeks ago, when they were worth roughly $2.04 million; this deposit thus corresponds to a loss of approximately $470,000.

Hyperbridge: Losses from the vulnerability increased to approximately $2.5 million; some funds have been traced to Binance.

According to an official disclosure by Hyperbridge, the losses from the Token Gateway vulnerability incident on April 13 have been revised upward from an initial estimate of $237,000 to approximately $2.5 million. The increase stems primarily from losses incurred in incentive pools on Ethereum, Base, BNB Chain, and Arbitrum. The attacker extracted roughly 245 ETH from related contracts, then bypassed the MMR proof verification mechanism by forging cross-chain messages, minting 1 billion bridged DOT tokens and dumping them onto illiquid markets. Currently, some of the stolen funds have been traced on-chain to Binance. Hyperbridge is collaborating with Binance’s compliance team and law enforcement agencies to investigate the incident. Polkadot-native DOT and products such as Intent Gateway remain unaffected. The Token Gateway and bridged DOT contracts on the four affected EVM chains remain suspended. An external audit of the patched MMR verification logic is underway, and bridging functionality will be restored upon completion of the audit.

Major Security Vulnerability Found in AI Agent Crypto Payment Infrastructure; LLM Router Leads to $500,000 Wallet Theft

According to CoinDesk, researchers from the University of California, Santa Barbara; the University of California, San Diego; blockchain security firm Fuzzland; and World Liberty Financial jointly published a paper warning that “LLM routers”—intermediary services positioned between users and AI models—have become a major threat to cryptocurrency asset security. The researchers discovered that 26 LLM routers are secretly injecting malicious tool calls and stealing user credentials, with one incident resulting in the complete draining of a customer’s cryptocurrency wallet worth $500,000. Additionally, by “poisoning” the router ecosystem, the researchers were able to gain control of approximately 400 downstream hosts within hours. Since sensitive data—including private keys and API credentials—is frequently transmitted in plaintext through these routers, users unknowingly expose their assets to risk. The researchers note that as McKinsey forecasts AI agents will mediate $3–5 trillion in global consumer commerce by 2030—and Binance founder Changpeng Zhao predicts AI agents’ payment volume will be one million times greater than that of humans—the current infrastructure’s security lags far behind the pace of industry development. The “weakest link” risk could thus trigger systemic, cascading crises.

Aethir Prevents Cross-Chain Bridge Vulnerability Attack and Promises Compensation

Decentralized GPU cloud computing infrastructure platform Aethir confirmed that its Ethereum-related bridge contract was attacked. The team promptly disconnected the affected contract and, in collaboration with major exchanges, blacklisted the hacker’s wallet, limiting losses to under $90,000. Earlier, blockchain security firm PeckShield estimated losses at $400,000. The attacker exploited Aethir’s cross-chain smart contract, AethirOFTAdapter, to transfer stolen funds from BNB Chain to Tron. Aethir stated that its Ethereum mainnet ATH token supply remains unaffected. It plans to release a detailed compensation plan and incident analysis next week and will collaborate with exchanges including Binance, Upbit, and Bithumb to freeze funds. Web3 security platform ZeroShadow is assisting with the investigation. In 2025, Aethir achieved $127.8 million in revenue and deployed over 440,000 GPU containers globally.

He Yifa’s long article lists Xu Mingxing’s “Six Crimes,” accusing him of deliberately manipulating public opinion to suppress Binance.

He Yi also firmly responded to external attacks targeting her personally at the end of the article, stating: “You’re clearly well-versed in attacking a professional woman—just stigmatize her by claiming, ‘She only got where she is today thanks to men,’ deliberately fabricate salacious rumors, and reduce me to a ‘trophy.’” She emphasized: “My identity isn’t granted by anyone—I forged it myself. I came, I saw, I conquered—true for my career, and equally true for my relationships.”

UK-Led “Atlantic Action” Freezes Over $12 Million in Cryptocurrency Fraud Assets

According to Cointelegraph, the joint U.S., U.K., and Canadian law enforcement operation “Operation Atlantic” concluded in March this year, led by the U.K.’s National Crime Agency (NCA). The operation froze over $12 million in assets suspected to be proceeds of fraud, identified more than 20,000 victims, and involved total fraud losses exceeding $45 million. The operation focused on authorized phishing attacks—a scam technique that tricks users into signing malicious authorizations, thereby granting attackers permission to transfer tokens from their wallets. Binance participated in the operation, providing account screening and fraud intelligence support; however, no funds were frozen from its platform.