GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Binance Alpha 2.0 will support Nesa (NES) contract replacement, with trading resuming at 16:00 today.

Binance Wallet announced that following a security incident involving the Nesa (NES) token contract, Binance Alpha 2.0 will support NES contract swaps on BNB Smart Chain (BEP20) and provide compensation arrangements for eligible users: first, balances held by users as of 14:51 UTC on August 24, 2026, and maintained through to 04:00 UTC on September 5, 2026, will be swapped to the new contract at a 1:1 ratio; subsequent purchases will not be eligible for the swap and will be refunded separately. Second, users with net purchases of NES between 14:51 UTC on August 24, 2026, and 04:00 UTC on September 5, 2026, will receive an email detailing the specific refund plan within seven working days. Trading of NES on Binance Alpha 2.0 is expected to resume on September 10, 2026, at 08:00 UTC.

UK NCA warns criminals are "innovatively" using crypto assets to launder money

According to Decrypt, the UK National Economic Crime Centre (NECC) stated in its annual report that criminals are "innovatively" leveraging crypto asset products to evade detection and transfer illicit funds at scale, while also highlighting AI alongside cryptocurrencies as an emerging threat method. Crypto assets have been ranked third among the nine priority economic crime areas jointly designated by NECC, the FCA, and the Treasury. NECC stated it will build more proactive, intelligence-driven crypto capabilities to actively identify targets for enforcement action. Previously, the NCA, in collaboration with the US Secret Service, Coinbase, Binance, Kraken, and Tether, conducted "Operation Atlantic," which identified 20,000 phishing attack victims and resulted in the freezing of $12 million in assets this March.

The Sandbox Launches SAND Compensation Claims

The Sandbox stated that it will provide full compensation to affected users for the SAND vulnerability incident on Base and BNB Smart Chain that occurred on August 22. Any wallet that legitimately held cross-chain SAND at the time of the snapshot prior to the incident will receive SAND compensation on the Ethereum network at a 1:1 ratio.

SlowMist: Approximately 62.28 BNB Lost in Attack on a Router on BNB Chain

According to Odaily, as monitored by SlowMist, per the SlowMist TI security alert, a Router contract has been exploited due to security flaws in its Swap entry point and uniswapV3SwapCallback, resulting in losses of approximately 62.28 BNB. The Router fails to verify whether the caller is a legitimate V3 Pool, nor does it bind the payer in the callback to the original transaction context. The attacker forged a V3 Pool/adapter and injected a victim's address as the payer, exploiting users' existing ERC-20 approvals granted to the Router to execute transferFrom() and transfer assets. Users who have previously granted sufficient token approvals to this Router may see their approved assets transferred out, even without further interaction on their part.

Harmony's preliminary ONE shortage narrows to 6.581 billion after cross-exchange reconciliation

: Harmony has released an update on the exchange reconciliation progress following the August 11 incident. It has verified on-chain deposits/withdrawals and cross-platform fund flows with Binance, Gate, KuCoin, MEXC, OKX, and Binance.US, prioritizing the coordination of restoring ONE deposits, withdrawals, and trading, with specific timelines to be announced separately by each exchange.Harmony stated that after matching 295 cross-exchange transfers totaling approximately 3.493 billion ONE and adjusting for circular transfers and returned funds, the preliminary shortage has been reduced from approximately 10.234 billion ONE to 6.581 billion ONE, a decrease of about 3.653 billion ONE. This change reflects an adjustment in reconciliation methodology and does not equate to newly recovered funds.Among these, Binance's data remains a preliminary upper-bound estimate, while some data from Gate and OKX are still pending final verification. Exchange teams have already frozen significant ONE balances and hacker proceeds. These efforts will be coordinated with the ONE migration and validator transition proposal, and validators may cease operations starting 22:00 Beijing time on September 10.

Binance Wallet Saves Users from $540 Million in Potential Losses in H1

Odaily News: Binance stated that in the first half of 2026, the Binance Wallet Security Center helped users avoid approximately $540 million in potential losses, filtering about 206 million spam transfers, identifying 4.93 million high-risk transactions, and approximately 996,000 malicious authorizations during the period. Binance noted that AI is being used by attackers to mass-generate malicious code, phishing websites, and fake identities, shifting attacks from broad-based approaches to more targeted fraud.

Argentine Prosecutor's Office Conducts Specialized Training on Crypto Asset Tracking and Confiscation

According to CriptoNoticias, Argentina's Public Prosecutor's Office (MPF) conducted a specialized training course titled "Virtual Assets: Financial Analysis, Tracking, Detection and Confiscation" via Zoom on August 19 and September 2, 2026, for internal staff, officials, and judges. Led by anti-money laundering specialist Carmen Chena, the curriculum covered digital wallet asset analysis, domestic and international legal frameworks, the cryptocurrency ecosystem, and practical case studies on preservation measures. Previously, Argentina's judiciary had already accumulated extensive experience in cryptocurrency-related cases, including the freezing of 3 million USDT in December 2024 and the 2022 ruling ordering Binance to return stolen BTC.

UK National Crime Agency Freezes Millions in Sorare Assets

The UK National Crime Agency announced the freezing of assets belonging to NFT platform Sorare, seizing approximately £1 million in funds. The case involves cryptocurrency fraud and money laundering using proceeds from the Binance hack.

Binance Will Discontinue Support for BounceBit (BB) Mainnet

Binance announced that due to a hack on BounceBit and the project team's decision to permanently shut down the chain, Binance will stop supporting the BounceBit (BB) mainnet. Binance has suspended deposits and withdrawals of BB on the BounceBit mainnet as of 10:00 (UTC+8) on August 20, 2026, and will reopen deposits and withdrawals via the BNB Smart Chain (BEP20) network starting at 15:00 on September 1, 2026. BB will be migrated from the original mainnet to the BNB Smart Chain at a 1:1 ratio. During the migration, spot, margin, futures, and Earn services will remain unaffected.

CZ Comments on Justin Sun’s Emotional and Property Dispute: Industry Should Avoid Personal Attacks and Raise Its Own Standards

Binance founder CZ stated on social media that while marketing can be more aggressive, it should not involve exploitation or escalate into personal attacks that could even undermine others' future career prospects. He noted that directly addressing the issue through legal channels would be more appropriate than disclosing unnecessary details, and urged all parties to resolve the matter amicably and with mutual respect. CZ later added that the industry should hold itself to higher standards. In response, Justin Sun replied expressing his gratitude and agreement, stating, “With mutual respect and a proper resolution, the rest will be left to the courts. I have nothing further to say.”

The Sandbox plans 1:1 compensation, approximately $700K in SAND stolen in bridge vulnerability exploit

blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)

GoPlus: Realio Platform Signing Key Compromised, Approximately 127.9 Million RIO Tokens Transferred

GoPlus Security released a security alert stating that on August 25, realio[.]fund, a project under Realio Network, was attacked. The attacker took control of the platform's signing system and moved treasury and custody wallet assets across Ethereum, BNB Chain, Algorand, Stellar, and the Realio native chain. A total of approximately 127.9 million RIO tokens worth around $6.2 million were affected, with the attacker having cashed out approximately $317,000 so far.

1:1 compensation for legitimate holders prior to the vulnerability incident; The Sandbox will reimburse cross-chain SAND using treasury funds

Odaily News, The Sandbox has released a post-mortem report on the August 22 vulnerability incident. The report shows that attackers exploited vulnerabilities in contracts related to cross-chain configurations on Base and BNB Smart Chain (BSC), stealing 14,742,341.84 SAND from the Ethereum treasury, accounting for approximately 0.5% of the maximum supply, with an estimated economic impact of approximately $1.4968 million, of which about $987,000 was actually retained by the attackers. The Ethereum mainnet and Polygon network were not affected. Until further notice, please do not purchase or send SAND on Base or BNB Smart Chain. Contracts deployed on Base and BNB Smart Chain have been permanently deactivated and will not be reopened. The Sandbox stated that the team has reported the attacker's wallet address to blockchain analysis firms TRM Labs and Chainalysis, and has communicated directly with relevant exchanges. The Sandbox also announced a compensation plan, which will compensate wallets that legitimately held cross-chain SAND on Base or BSC prior to the incident at a 1:1 ratio in Ethereum SAND. Compensation funds will come from The Sandbox treasury, with no new tokens issued. The claim process will open within the next two weeks and remain open for two weeks.

The Sandbox cross-chain bridge exploited to mint 14.9 billion unbacked SAND, Coinbase to delist SAND futures

Odaily News: Metaverse gaming platform The Sandbox has confirmed a vulnerability in its cross-chain bridge, allowing attackers to mint unbacked SAND on Base and BNB Smart Chain. Blockchain security firm PeckShield detected on August 21 that two addresses had collectively minted approximately 14.9 billion SAND. The Sandbox subsequently shut down bridging functionality on both networks.The Sandbox stated that the affected assets are bridged assets on Base and BNB Smart Chain, while SAND on Ethereum and Polygon, user wallet assets, and the Ethereum-locked assets backing the token remain unaffected. The proportion of genuinely collateralized assets involved in this incident is less than 0.01% of the total SAND supply.The Sandbox is developing a compensation plan for affected liquidity providers and advises users not to trade SAND on Base or BNB Smart Chain until bridging is restored. Coinbase plans to delist 10 perpetual futures contracts, including SAND, on August 26, with open positions to be automatically settled at that time. (Bitcoin.com News)

The Sandbox confirms SAND cross-chain bridge vulnerability, cross-chain functionality on Base and BSC networks suspended

The Sandbox has officially confirmed and fully secured the recent SAND cross-chain bridge vulnerability affecting the Base and BNB Smart Chain (BSC) networks. Attackers exploited the flaw to mint uncollateralized SAND tokens across both networks, but the impact remains limited, accounting for less than 0.01% of the total SAND supply. SAND on Ethereum and Polygon, along with user wallets, remain unaffected. The Sandbox has since disabled cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable and non-redeemable. The official team advises users to avoid buying, selling, or trading SAND on the aforementioned networks.

BounceBit:将永久停止 BounceBit Chain,按攻击前快照在 BNB Chain 重新发行 BB

BounceBit Chain 已于 8 月 20 日 02:36:37(UTC)在区块高度 20,702,857 停止出块。团队决定永久停止 BounceBit Chain,不再进行网络升级,并将在 BNB Chain 上以 BEP-20 代币形式重新发行 BB。新 BB 余额将依据 8 月 19 日 21:02:35(UTC)区块高度 20,697,260 的快照确定,攻击期间被转移的 286,543,148 枚 BB 不会计入重新发行代币。

Rapid7 discloses crypto phishing campaign targeting 885,000 phone numbers and involving 5,576 Binance accounts

Odaily News Rapid7, a cybersecurity firm, has disclosed a crypto phishing campaign named Operation Asterix that targets approximately 885,000 phone numbers across multiple countries, redirecting victims to fraudulent wallet service websites. A total of 5,576 phone numbers have been matched with Binance user accounts and placed on the attack queue.The attackers steal seed phrases through fake apps impersonating Ledger, Trezor, and Exodus, while also contacting victims via fraudulent customer support emails and phone calls. Rapid7 also found that among over 316,000 phone numbers in Germany, 43,066 were matched with crypto trading accounts, representing a hit rate of approximately 13.6%.The related attacks also include a bulk phone number verification tool targeting Kraken accounts, and the investigation revealed that AI tools are being widely used in phishing operations. According to data from blockchain security firm Hacken, phishing attacks and social engineering scams caused $306 million in losses in the first quarter of this year, accounting for the majority of the $482 million total losses in the crypto industry. (Cointelegraph)

Binance Security Team Prevents Potential $1.2 Million Governance Attack

The Binance Security Team recently independently discovered a malicious governance proposal targeting a project's Decentralized Autonomous Organization, which could put approximately $1.2 million worth of treasury tokens at risk. Binance notified the project team to vote against the proposal less than 48 hours before its execution and coordinated with relevant centralized exchanges to suspend deposits of the affected tokens to reduce the risk of potential fund transfers. Ultimately, the malicious proposal was rejected, the attack was not executed, and no funds were lost.

CZ issues SafePal security incident alert: beware of phishing attacks, YZi Labs is a minority shareholder

Odaily News: CZ posted a SafePal security incident alert on platform X, reminding the community to beware of phishing attacks. He also disclosed that SafePal is one of YZi Labs' (formerly Binance Labs) portfolio companies, and YZi Labs is currently a minority shareholder of SafePal.

BNB Chain to Launch Pasteur Hard Fork on August 25

Odaily News: BNB Smart Chain (BSC) has announced that the Pasteur hard fork will officially go live on the mainnet at 10:30 AM Beijing time on August 25 (02:30 UTC on August 25). Node operators are required to upgrade their clients to v1.7.7 in advance.This upgrade includes three improvements—BEP-682, BEP-695, and BEP-675—focusing on enhancing cross-chain security, validator governance mechanisms, and network throughput. Among them, BEP-682 will strengthen the BNB Chain cross-chain bridge verification mechanism, preventing permission bypass risks caused by duplicate signature counting by validators, thereby improving the security of cross-chain asset transfers. BEP-695 optimizes the validator key rotation mechanism, ensuring that old keys no longer retain management privileges after exit, while also fixing potential vulnerabilities related to slashing and governance voting.In terms of performance, BEP-675 reduces the time consumption caused by validators repeatedly executing transactions by optimizing the block construction process. In BNB Chain's internal QANet test environment, this solution increased throughput from 1,237 TPS to 2,324 TPS. While maintaining the 450-millisecond block time and the 100 million Gas block limit unchanged, the average Gas usage per block rose from 46.35 million to 84.15 million.BNB Chain stated that this upgrade is primarily aimed at validators and block builders, designed to provide greater capacity during network peak periods and advance the throughput expansion goals outlined in BNB Chain's roadmap for the second half of 2026.