GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

A whale suffered an alleged personal intimidation attack, resulting in losses of $6.7 million

according to monitoring by Specter Analyst, a high-net-worth investor holding significant assets on Kraken and Coinbase exchanges fell victim to an alleged personal intimidation attack, resulting in total losses of approximately $6.7 million across various assets.The attacker withdrew 1,554 ETH (approximately $3.3 million) and 10.5 BTC from the user's Kraken account. Simultaneously, the attacker also breached the user's Coinbase defenses, withdrawing 34.1 cbBTC. Subsequently, the attacker directly deposited over $5.3 million of the stolen funds into the privacy protocol Tornado Cash to obfuscate the transaction trail. (financefeeds)

Threshold Network: Successfully Thwarted Attempt to Maliciously Mint tBTC

Threshold Network posted on platform X, stating that on May 18, 2026, a malicious attacker attempted to mint tBTC without depositing the underlying Bitcoin. The attempt was unsuccessful; no invalid tBTC was issued, and user funds were not at risk.As a precautionary measure against high-frequency malicious activity in the broader crypto ecosystem, Optimistic Minting has been temporarily suspended. Currently, minting operations are conducted through the liquidation mechanism, with typical minting times increasing from approximately 1.5 hours to around 6 to 7 hours.

Bitcoin ATM operator Bitcoin Depot files for bankruptcy amid regulatory tightening and security vulnerabilities that rendered its business unsustainable

According to The Block, Bitcoin Depot (BTM), a Nasdaq-listed Bitcoin ATM operator, filed for Chapter 11 bankruptcy protection on the 18th in the U.S. District Court for the Southern District of Texas, announcing an orderly liquidation and asset sale. CEO Alex Holmes stated that increasingly stringent state-level compliance requirements, transaction limit restrictions, and operational bans in certain regions have rendered the company’s existing business model unsustainable. Previously, the company suffered a security breach in April 2026, resulting in a $3.7 million loss; its Q1 2026 revenue declined 49.2% year-on-year, with a net loss of $9.5 million. Currently, all over 9,000 Bitcoin ATMs operated globally by Bitcoin Depot have been taken offline, and its overseas entities—including those in Canada—will also be shut down.

Binance Research: Cryptocurrencies Are Not an Illegal Financial Haven—Confiscation Rate in 2025 Is 55 Times That of Fiat Currency

According to a research report released by Binance Research, approximately 11% of illicit cryptocurrency transaction volume was seized in 2025—55 times the global fiat recovery rate (less than 1%). Even after excluding the single Prince Group case involving roughly $15 billion worth of BTC, the remaining seized amount still stands at about 10 times the fiat baseline. Data from on-chain security firms SlowMist and PeckShield shows that between 8.3% and 13.2% of stolen funds were recovered or frozen in 2025, reflecting continuously improving collaboration efficiency among exchanges, stablecoin issuers, and law enforcement agencies. Binance Research notes that blockchain’s inherent transparency is being fully leveraged by regulators and investigators, and the notion that “cryptocurrency is a breeding ground for illicit activity” is gradually becoming an outdated misconception.

Lombard Gradually Phasing Out LayerZero, Plans to Migrate Over $1 Billion in BTC Collateral Assets to Chainlink

following the $292 million exploit of Kelp DAO's LayerZero bridge, the security of cross-chain infrastructure has once again come under scrutiny. DeFi protocols Kelp DAO, Solv Protocol, Re, and crypto exchange Kraken have all taken similar migration measures, with the total value of this outflow reaching approximately $4 billion.Decentralized finance protocol Lombard has become the latest project to join the migration wave, announcing a gradual phase-out of LayerZero and the migration of over $1 billion in Bitcoin collateral assets to Chainlink's Cross-Chain Interoperability Protocol (CCIP). Bitcoin-related tokens issued by Lombard include LBTC and BTC.b. It is reported that Lombard's initial migration assets cover the Solana, Etherlink, Berachain, Corn, and TAC chains, while the use of LayerZero on Morph and Swell will also be terminated. As of now, LayerZero has not responded to requests for comment. (CoinDesk)

ZachXBT: Suspected Address in 185 BTC Social Engineering Theft Transfers Another $2.59 Million in Crypto Assets

on-chain detective ZachXBT stated that the hacker "Dritan Kapplani Jr" transferred approximately $2.59 million in assets today, including 1.99 million DAI and 259 ETH. The funds were moved from address 0x4487...bba6 to address 0x67ec...125d. The stolen funds currently remain dormant.ZachXBT stated that on May 12, they published an investigation detailing the connection between Dritan Kapplani Jr and Trenton (Trent) Johnson in a social engineering theft involving 185 Bitcoin (approximately $13 million).

PeckShield: THORChain Suffers Attack, Losing Approximately $10 Million in Cryptocurrency Assets

According to on-chain analyst PeckShield (@PeckShieldAlert), THORChain has been hacked, resulting in losses of approximately $10 million in crypto assets, including 36.75 BTC (around $3 million) and roughly $7 million in assets from BNB Chain, Ethereum, and Base.

THORChain Suspected of Suffering an Attack, Losses Exceed $7.4 Million

On-chain investigator ZachXBT stated that THORChain appears to have been attacked on the Bitcoin, Ethereum, BSC, and Base networks, resulting in losses exceeding $7.4 million.

Gate Research: Crypto Market Warms Up in April with RWA and On-Chain Capital Flow in Focus

Odaily Odaily News Gate Research recently released its "April 2026 Cryptocurrency Market Review" report, indicating that the overall cryptocurrency market saw a volatile upward trend in April, with total market capitalization significantly higher than in March. BTC and ETH ETF trading volumes maintained high volatility overall. The report shows continued divergence in activity across major public chain ecosystems. Solana's daily transaction volume remained in the range of approximately 90 million to 110 million transactions, maintaining its leading position.Regarding trending sectors, the report notes that Pokemon TCG RWA has become one of the fastest-growing on-chain RWA sub-sectors, entering a second explosive growth phase in April. Major trading platforms saw monthly trading volumes exceed $220 million, with weekly revenue briefly approaching $6 million, setting new historical records. Meanwhile, Aave experienced its most severe liquidity crisis ever in April, with TVL outflows reaching tens of billions of dollars within a few days and net outflows exceeding $9 billion for the entire month.In terms of fundraising and security incidents, the Web3 industry completed 51 financing rounds in April, totaling approximately $834 million, with capital further concentrating on leading financial and infrastructure tracks. Among these, Payward ranked first for the month with a $200 million financing round. On the security front, Web3 security incidents in April resulted in losses of approximately $306 million, a month-over-month increase of about 858%, primarily driven by a single cross-chain infrastructure attack on Kelp DAO worth approximately $293 million. The report suggests that against the backdrop of a recovering market, on-chain activity and capital liquidity are both increasing simultaneously. However, the security risks associated with cross-chain infrastructure and high-leverage protocols remain worthy of continued attention.

ZachXBT: US 18-Year-Old Hacker Dritan Allegedly Involved in $19 Million Crypto Theft and Money Laundering

on-chain detective ZachXBT has exposed US threat actor Dritan Kapllani Jr., alleging his involvement in social engineering thefts targeting crypto users, totaling approximately $19 million.ZachXBT stated that Dritan has long been flaunting luxury cars,名牌 watches, private jets, and nightclub lifestyles on social media. On April 23, 2026, during a "Band 4 Band (B4B)" voice call on Discord, in an attempt to prove he was wealthier than another hacker, he publicly displayed an Exodus wallet containing $3.68 million in assets.The relevant ETH address is: 0x4487db847db2fc99372a985743a26f46e0b2bba6ZachXBT's tracking revealed that this address is linked to a social engineering theft incident on March 14, 2026, involving 185 BTC (approximately $13 million). The following day, Dritan's Exodus wallet received about $5.3 million from that theft. By the time of the B4B call six weeks later, approximately $1.6 million had already been spent or laundered.On May 11, the US Department of Justice unsealed a criminal indictment against Trenton Johnson, charging him with participation in the theft of 185 BTC. He faces a potential maximum sentence of 40 years in prison. The indictment refers to "Co-Conspirator 1 (CC-1)," believed to be Dritan, who has not yet been formally charged.ZachXBT also noted that Dritan is connected to hacker John Daghita (Lick), who was previously arrested for stealing $46 million from the US government. John had previously exposed Dritan's old wallet address on Telegram. On-chain analysis shows that this address is linked to multiple high-confidence social engineering thefts in 2025, with a cumulative total exceeding $5.85 million.ZachXBT stated that Dritan has long been active in the "The Com" hacker circle and had seemingly avoided formal prosecution due to being a minor. Now that he has turned 18, his "borrowed time may finally be over."

TrustedVolumes: Attacker Has Laundered Approximately $278,000 in Stolen Funds

According to on-chain analyst PeckShield (@PeckShieldAlert), the TrustedVolumes attacker has laundered approximately $278,000 of stolen funds to date, including depositing 10.2 ETH (approx. $23,600) into Tornado Cash and swapping 110 ETH (approx. $250,000) for BTC via THORChain. Additionally, the attacker attempted to deposit 0.5 ETH into Railgun but subsequently withdrew it. TrustedVolumes was attacked on May 7, resulting in losses of approximately $6.7 million.

Solv Abandons LayerZero, Migrates $700M in Tokenized Bitcoin Assets to Chainlink CCIP

Solv Protocol has announced the migration of over $700 million in tokenized Bitcoin assets to Chainlink's cross-chain protocol CCIP, and will gradually phase out LayerZero's bridging support across multiple chains. The migration involves core assets such as SolvBTC and xSolvBTC. Solv stated that the decision is based on the latest security reviews and recent cross-chain security incidents, and CCIP will become its standard cross-chain infrastructure. This move follows Kelp DAO's migration of approximately $290 million in assets to Chainlink, further strengthening the trend of "cross-chain infrastructure shifting toward security-first migration." (CoinDesk)

Santiment: BTC Social Sentiment Bullish Ratio Hits Four-Month High

According to on-chain data platform Santiment (@SantimentData), as Bitcoin’s price reclaimed the $80,000 level, the ratio of bullish-to-bearish comments on social media rose to 1.37:1.00—the highest in nearly four months—signaling a notable surge in market optimism. However, Santiment cautions that historically, sharp increases in bullish sentiment often serve as warning signs rather than buy signals. When retail FOMO dominates social media discussions, traders tend to enter positions late in the trend, raising the likelihood of local tops, profit-taking, and sudden price volatility. Santiment notes that peak market euphoria frequently coincides with the onset of waning momentum. By comparison, following the Kelp DAO vulnerability incident in mid-April, social sentiment plunged into deeply bearish territory; the exit of “weak-handed investors” instead laid a healthier foundation for the current rally. With sentiment now having reversed dramatically, Santiment advises traders to remain vigilant against potential risks stemming from excessive leverage and overly concentrated positions.

Bitcoin Core Developers Disclose High-Risk Vulnerability CVE-2024-52911, Approximately 43% of Nodes Still Affected

: Bitcoin Core developers have disclosed a high-risk vulnerability numbered CVE-2024-52911, affecting versions 0.14.1 through 28.4. Attackers can exploit this vulnerability by constructing a special block to remotely crash other nodes and execute code. The vulnerability was discovered and privately reported by developer Cory Fields in November 2024. The fix was merged in December 2024 and officially launched in the v29 release in April 2025.Currently, support for the last vulnerable version in the 28.x series ended on April 19, 2026. However, since upgrading Bitcoin nodes is voluntary, it is estimated that approximately 43% of nodes are still running vulnerable old versions, posing a potential security risk.

Wasabi Protocol attacker has deposited all stolen funds into Tornado Cash

According to monitoring by on-chain analyst Specter, the Wasabi Protocol attacker has deposited all stolen funds into Tornado Cash, moving approximately $5.9 million into Tornado Cash. Additionally, North Korean hacking groups have also used Tornado Cash to launder stolen funds from KelpDAO and LayerZero. Their process involved first cross-chaining the assets to Bitcoin, then routing them through Wasabi Mixer, extracting and cross-chaining back to Ethereum, depositing into Tornado Cash, subsequently withdrawing to new wallets and dispersing across multiple addresses. The new wallets then deployed tokens, used the stolen funds to buy in, removed liquidity from the deployment wallet, cross-chained to Tron (USDT), held for several hours or days, and finally sent to OTC-related wallets.

ZachXBT: PolyArb is a fake prediction market product equipped with a wallet stealer.

On-chain investigator ZachXBT replied that PolyArb is a fake prediction market product whose website contains a wallet-stealing script. Previously, PolyArb claimed on X that the Hyperliquid HIP-4 outcome market achieved $6.15 million in daily BTC trading volume within 48 hours. William LeGate, Head of User Growth, questioned its claims regarding Polymarket’s fee structure. ZachXBT warned that replying to the relevant account could generate further exposure and increase the number of potential victims.

Paradigm researcher proposes timestamp escape mechanism to protect early Bitcoin from quantum computing threats

Paradigm researcher Dan Robinson proposed a new scheme called PACT (Prove Address Control with Timestamp), aimed at protecting long-dormant Bitcoin, including Satoshi Nakamoto's early addresses, from future quantum computing attacks.The mechanism allows users to prove control over an address via a timestamp without transferring assets or exposing on-chain activity. Should a future quantum attack occur, assets can be recovered based on this proof within a quantum-resistant version of the Bitcoin network.Compared to mandatory migration schemes such as BIP-361, PACT avoids the privacy exposure issues caused by proactively transferring assets, offering long-term holders a more flexible proactive protection path.

North Korean hackers accounted for 76% of cryptocurrency theft losses in 2026, having stolen over $6 billion cumulatively since 2017.

According to The Block, blockchain intelligence firm TRM Labs released a report stating that North Korean hacker groups stole approximately $577 million in crypto assets during the first four months of 2026—accounting for 76% of global hacking losses over the same period. All these losses stemmed from two major incidents that occurred in April: KelpDAO was attacked by the TraderTraitor group, resulting in $292 million in losses; and Drift Protocol was compromised by another North Korean sub-group, suffering $285 million in losses. Preparations for the latter attack began as early as March 11, and funds were fully extracted within 12 minutes. The two incidents employed distinct money-laundering pathways: stolen funds from Drift remain largely dormant on Ethereum, whereas funds stolen from KelpDAO were rapidly swapped into BTC via THORChain, with subsequent laundering facilitated by Chinese intermediaries. TRM Labs noted that since 2017, North Korea’s cumulative crypto theft has exceeded $6 billion—and its share of global losses has risen steadily, from less than 10% in 2020 to 64% in 2025.

Bitcoin lending protocol Tropykus announces shutdown of its current version; deposit and lending functions are permanently discontinued.

According to an official announcement by Tropykus, the decentralized lending protocol Tropykus has initiated a phased shutdown of its current protocol version. Deposit and lending functionalities will be permanently discontinued. Users may withdraw funds and repay loans via tropykus.com until the deadline of July 27, 2026; thereafter, such operations will only be supported through direct interaction with smart contracts. The team stated that this shutdown decision stems from long-term strategic evolution—not from the security report previously received by Money on Chain, a partner of Tropykus. That report had prompted the protocol to proactively suspend deposits and new lending activities. However, the team emphasized that internal discussions regarding the shutdown predated the security incident, and the incident merely accelerated the decision. Technically, the team noted that the original architecture was designed for an earlier technological environment and is no longer capable of meeting long-term development needs in the face of emerging security challenges posed by technologies such as artificial intelligence. The team advises all users to complete withdrawals and settle their lending positions via tropykus.com before July 27, 2026. After this date, users will need technical proficiency to interact directly with smart contracts to perform these operations.

Developer proposes to fork Bitcoin eCash, reallocate Satoshi Nakamoto's BTC holdings

Paul Sztorc, a developer who has long focused on Bitcoin scaling solutions, proposed a Bitcoin hard fork named eCash, set to occur at block height 964,000 in August 2026. Users holding BTC at the time of the fork will receive eCash on a 1:1 basis, and the new chain will introduce the Drivechains sidechain architecture. The controversy mainly centers on the plan to pre-allocate a portion of the eCash corresponding to the Satoshi Nakamoto address on the new chain to early investors, a move that has drawn criticism from the community, with some accusing it of "stealing" tokens. Paul Sztorc stated that this initiative aims to provide incentives for development and collaboration before the project's launch.