GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Cryptocurrency May Become Primary Target of Quantum Computing Attacks, Governance Speed Poses Greatest Risk

According to CoinDesk, Eddy Zervigon, CEO of quantum computing security infrastructure company Quantum Xchange, stated that cryptocurrencies, due to their decentralized nature, will become the "canary in the coal mine" for quantum computing attacks—that is, the area where vulnerabilities will be exposed first. Latest assessments by Google researchers show that the number of physical qubits required to break Bitcoin's elliptic curve encryption has decreased 20-fold compared to previous estimates, and multiple institutions have brought forward the expected date of "Q-Day" (the day quantum computers can break existing encryption systems) to 2029. Deutsche Digital Assets pointed out that the real risk lies not in the encryption technology itself, but in the speed of governance—Bitcoin upgrades require 90% miner consensus, which has historically triggered hard forks (such as the 2017 SegWit upgrade leading to the birth of Bitcoin Cash), whereas traditional financial institutions only need a board resolution to complete encryption infrastructure migration. Additionally, experts caution that the quantum threat is not a binary event that "arrives suddenly on a certain day"; even if quantum computers require months to crack data, as long as the cracking is completed while the data is still valuable, the threat is established.

Cardano wallet SecondFi announces shutdown after hack attack

According to CoinDesk, the Cardano wallet SecondFi was attacked due to a vulnerability in its transaction signing software. A total of 16.1 million ADA (approximately $2.4 million) across 374 wallets was stolen, and the platform has announced permanent closure. The vulnerability allowed attackers to derive private keys from transaction data visible on-chain. The Cardano network itself was not affected, nor were hardware wallet users. An investigation by Groom Lake, a blockchain intelligence company hired by EMURGO, revealed that the primary attackers were sophisticated and well-funded. Some indications point to North Korea's Lazarus Group, but this has not yet been officially confirmed. SecondFi plans to release a wallet export tool in early August and launch a zero-knowledge recovery portal later in the month. EMURGO has established an asset recovery wallet, with the specific distribution time to be determined.

Algorithmic Stablecoin Balance Coin Suffers Oracle Attack, Plummets 99%

According to CoinDesk reports, algorithmic stablecoin Balance Coin suffered an oracle price manipulation attack on July 22. The coin price plummeted from near the $1 peg to about $0.0014, a drop of over 99%, and the nominal market cap of about $3.5 million nearly went to zero. According to analysis by security firm SlowMist, the attacker fed abnormally low false Bitcoin prices into the protocol, bypassing price rationality checks and liquidation delay mechanisms. They forcibly liquidated multiple ineligible collateral vaults in a single transaction, subsequently exchanged the acquired collateral for arbitrage, and ultimately profited about $912,000 from the protocol governance entity 42DAO.

Ethereum Foundation: AI Discovers Vulnerability That Could Cause Validator Nodes to Go Offline, But Manual Verification Still Required

According to CoinDesk, the Ethereum Foundation recently disclosed that its security team used AI agents to test the software running on Ethereum validator nodes and successfully discovered a vulnerability that could be triggered remotely, causing node crashes. However, researchers emphasized that amidst the large volume of security reports generated by AI, manual review remains a key step in distinguishing real vulnerabilities from false positives. Reportedly, the vulnerability discovered resides in the Ethereum network message propagation protocol gossipsub, where attackers can remotely trigger the node software into an abnormal computation state, causing the program to crash and shut down, taking the validator node offline until the operator manually restarts it. The vulnerability has been fixed and registered under the number "CVE-2026-34219". Nikos Baxevanis, a member of the Ethereum Foundation Protocol Security Team, stated that the truly surprising aspect of this incident was not the AI's ability to discover vulnerabilities, but the significant amount of time the team spent distinguishing which vulnerabilities were real and which were merely plausible "hallucinations".

Serious Vulnerability Exposed on Aptos Blockchain, $70 Billion in Assets Once Faced Systemic Risk

According to CoinDesk, researchers at blockchain security company Hexens discovered an "expired cache" type confusion vulnerability in the Aptos blockchain Move virtual machine. Attackers require only about $3,000 in server costs to launch attacks in a simulated environment with a success rate of nearly 90%, without needing validator privileges or internal knowledge. Researchers ran approximately 20 attacks in simulated tests, succeeding 17-18 times, and verified the potential ability to control management permissions of cross-chain protocols such as LayerZero, Wormhole, and USDC CCTP. Hexens assessed that the vulnerability directly threatens protocols on the Aptos chain such as DeFi, stablecoins, and liquid staking, involving assets in the low single-digit billions of dollars; if spread through paths such as cross-chain bridges, stablecoin minting, and centralized exchanges, the systemic risk exposure could reach up to $70 billion. The Aptos team completed the fix and deployed it to the mainnet within hours after receiving the vulnerability report on February 25, and currently no user funds have been compromised.

Ukraine Seizes $8.3 Million in Crypto Assets, Potentially Paving the Way for a Strategic Crypto Reserve

OdailyOdaily reports that the Prosecutor General's Office of Ukraine stated it has, for the first time, transferred approximately $8.3 million worth of USDT crypto assets into the national asset management system, marking the country's first official takeover of seized crypto assets. The funds originate from an investigation into an international hacking group, which is alleged to have laundered money through high-value real estate and other assets. The assets were received by the Asset Recovery and Management Agency (ARMA) of Ukraine, with the transfer completed pursuant to a court order.Officials stated that this operation marks a significant step for Ukraine in the regulation and management of crypto assets, and aligns with ongoing discussions regarding the establishment of a strategic crypto reserve. Previous data indicates that Ukraine ranked among the top in Europe in terms of crypto transaction volume between 2024 and 2025.However, the relevant assets are currently in a "custodial" state and have not been legally forfeited; subsequent judicial conviction procedures are still required. Analysts believe that the mechanism of this move is similar to the path of the United States using criminally forfeited crypto assets to build a potential strategic reserve. (CoinDesk)

Aave Founder Responds to Payward Acquisition Rumors: Will Not Sell AAVE at a 70% Discount

Aave founder Stani Kulechov has responded to reports suggesting Kraken's parent company Payward is interested in acquiring a 15% stake in the Aave protocol, stating that AAVE is "not going to be sold at a 70% discount."Prior reports from CoinDesk indicated that Payward was in talks to acquire a 15% stake in Aave at a valuation of $385 million. If calculated at this valuation, it would represent only approximately 30% of AAVE's fully diluted valuation, significantly below the market valuation.In a post on X, Kulechov stated that the relevant reports were not entirely accurate. He did not completely deny the possibility of Aave Labs selling a portion of its held AAVE tokens, but noted that Aave Labs does have a certain allocation of AAVE, and that multiple market participants have discussed purchasing either directly or indirectly, or engaging in deeper collaboration centered around long-term partnerships.Aave is the largest decentralized lending protocol on the Ethereum ecosystem. Kulechov stated that Aave currently generates an annualized revenue of approximately $134 million, with the relevant revenue flowing to the Aave DAO. He has also previously proposed a governance plan to redirect revenue from Aave Labs, the protocol, and its products to the Aave DAO and token holders.These rumors emerge at a time when Aave is experiencing certain pressures. Following the Kelp DAO incident in April, Aave's TVL saw a significant decline. Although Aave itself was not directly attacked, the KelpDAO cross-chain bridge attacker utilized Aave to convert the stolen rsETH into other assets.

Standard Chartered Bank: Aave is expected to rise to $3,500 by 2030, an increase of approximately 50x from its current price.

According to CoinDesk, Geoff Kendrick, Head of Digital Asset Research at Standard Chartered Bank, released a report initiating coverage of the decentralized lending protocol Aave, with a target price of $3,500 by end-2030—approximately 50 times its current price of around $70—and expects Aave to outperform both Bitcoin and Ethereum. Kendrick stated that Aave has recovered from the April 2026 KelpDAO rsETH bridge vulnerability incident, during which attackers used approximately $290 million worth of stolen tokens as collateral to borrow real assets on Aave, exposing the protocol to up to $230 million in potential losses. Assets have now begun flowing back onto the platform, and Aave’s dominant position in on-chain lending remains solid. Looking ahead, Standard Chartered forecasts that the value of tokenized assets actively used in DeFi applications will grow 37-fold by 2030. Aave—whose revenue model is directly tied to lending activity—is poised to benefit directly. Additionally, Aave’s Horizon initiative (enabling tokenized real-world asset lending in permissioned environments) and the potential relaunch of its token buyback program are viewed as key catalysts.

Aave Founder Calls Protocol "Resilient" Despite $8.45 Billion Deposit Run Exposing Risks

in April this year, KelpDAO's LayerZero bridge was exploited in a $292 million vulnerability attack, triggering an $8.45 billion deposit run on Aave within 48 hours, marking the largest capital outflow event in decentralized finance (DeFi) history. Aave founder Stani Kulechov stated that the design of Aave V3 withstood the market test, demonstrating the network's "resilience." However, independent data indicates that Aave's survival primarily relied on $300 million in emergency rescue, including a 25,000 ETH guarantee from the Aave DAO and a personal injection of 5,000 ETH (approximately $8.4 million) by Kulechov.Kulechov attributed the vulnerability to third-party infrastructure rather than core smart contracts. However, analysts pointed out that this incident exposed deficiencies in Aave's risk architecture and insurance mechanisms, leading the platform to incur significant bad debt (approximately $123.7 million in wETH). To prevent future bridge failures from triggering systemic bank runs, Aave V4 will adopt a modular "hub-and-spoke" architecture, enabling local risk auto-adjustment and collateral freezing. (CoinDesk)

Analysis: AI Will Accelerate Quantum Computing Threats, Crypto Industry May Enter an Era of Persistent Security Arms Race

multiple blockchain and post-quantum cryptography researchers have warned that artificial intelligence (AI) is accelerating the development of quantum computing and could potentially impact the security systems of mainstream blockchains, including Bitcoin and Ethereum, earlier than anticipated.Alex Pruden, CEO of Project Eleven, a firm focused on quantum-resistant infrastructure, stated that the combination of AI and quantum computing is fundamentally reshaping the future security landscape. "People will no longer be able to rely on existing security assumptions as they have in the past," he said.Researchers point out that AI is already being used to optimize quantum error correction, which is one of the key technical bottlenecks in the development of quantum computing. Illia Polosukhin also noted that AI has been accelerating scientific breakthroughs for years, and in the future, there may even be a circular acceleration effect where "AI helps build the next generation of quantum computers."One of the industry's biggest current concerns is the "Harvest Now, Decrypt Later" strategy, where governments or advanced attackers begin mass-collecting encrypted data now, waiting to decrypt it all at once once quantum computing matures. Polosukhin warned that if quantum computers become viable within a few years, "most of today's important data on the internet could be decrypted in the future."Given that most blockchain networks and internet infrastructure currently rely on elliptic curve cryptography (ECC), a sufficiently powerful quantum computer could theoretically derive a private key from a public key, directly breaking wallets and on-chain systems. Simultaneously, AI itself is strengthening hacking capabilities. Pruden stated that AI models are becoming increasingly adept at discovering software vulnerabilities and cryptography implementation flaws, and may even be able to crack some encryption algorithms directly in the future.However, AI is also being used by developers for code auditing, formal verification, and testing post-quantum security systems, creating a "long-term security arms race" with simultaneous upgrades on both the offensive and defensive sides. Researchers believe the most significant change brought by AI and quantum computing together is that the core assumption of "long-term cryptographic reliability" in the digital age is being challenged. Future security systems may shift from "static upgrades" to continuous dynamic evolution. (CoinDesk)

Data: ETH lending protocol TVL has dropped from its year-to-date high of $32 billion to $23 billion.

According to CoinDesk, the total value locked (TVL) in ETH lending protocols has declined from a year-to-date high of $32 billion to $23 billion—a drop of approximately 28%. The oracle vulnerability incident involving KelpDAO triggered a market confidence crisis, and combined with overall bearish market sentiment, led to roughly $9 billion in outflows from the DeFi lending sector.

Elliptic CEO: Cryptographic security is evolving into an AI arms race, and compliance teams struggle to keep up with transaction volumes at machine speed

According to CoinDesk, Simone Maini, CEO of blockchain analytics firm Elliptic, stated that the biggest emerging risk to crypto security is not larger-scale hacking attacks, but rather AI-driven financial activity operating at a speed and scale that human compliance teams cannot keep up with. As AI lowers the barriers to hacking, scams, and fraud, security firms like Elliptic are responding by deploying AI agents to analyze on-chain data in real time—sparking an automated arms race between adversaries and defenders. Maini noted that current compliance systems remain heavily reliant on manual review, and the global pool of compliance analysts specializing in digital assets is simply insufficient to meet future demand. Elliptic has raised $120 million in funding—including from Nasdaq and Deutsche Bank—to build an “agent-based compliance system” that leverages AI to automate transaction monitoring and investigation workflows, thereby reducing the cost per alert and per investigation.

Lombard Gradually Phasing Out LayerZero, Plans to Migrate Over $1 Billion in BTC Collateral Assets to Chainlink

following the $292 million exploit of Kelp DAO's LayerZero bridge, the security of cross-chain infrastructure has once again come under scrutiny. DeFi protocols Kelp DAO, Solv Protocol, Re, and crypto exchange Kraken have all taken similar migration measures, with the total value of this outflow reaching approximately $4 billion.Decentralized finance protocol Lombard has become the latest project to join the migration wave, announcing a gradual phase-out of LayerZero and the migration of over $1 billion in Bitcoin collateral assets to Chainlink's Cross-Chain Interoperability Protocol (CCIP). Bitcoin-related tokens issued by Lombard include LBTC and BTC.b. It is reported that Lombard's initial migration assets cover the Solana, Etherlink, Berachain, Corn, and TAC chains, while the use of LayerZero on Morph and Swell will also be terminated. As of now, LayerZero has not responded to requests for comment. (CoinDesk)

BAYC floor price doubles within a month, signaling signs of NFT market recovery

According to CoinDesk, the floor price of Bored Ape Yacht Club (BAYC) NFTs has risen from approximately 5 ETH to over 10 ETH in the past month, while ApeCoin (APE) rebounded from below $0.10 to around $0.16 during the same period, with trading volume notably expanding. Meanwhile, repeated security vulnerabilities and persistently declining yields in the DeFi sector have driven some capital toward the NFT market. The financialization trend of NFTs is also intensifying: a recent $2.8 million loan collateralized by a CryptoPunk attracted widespread attention, with the lender expected to earn roughly $138,000 in interest over 90 days. Blue-chip collections such as Pudgy Penguins have also strengthened concurrently, and market expectations surrounding a potential token launch by OpenSea have further boosted sentiment.

US Judge Approves Aave to Proceed with Transfer of $71 Million in ETH Linked to North Korean Hackers

Odaily News: Margaret Garnett, a U.S. District Judge in Manhattan, has approved Aave's asset recovery proposal, allowing the transfer of approximately $71 million in ETH previously frozen on Arbitrum and linked to North Korean-linked attacks, to a wallet controlled by Aave LLC, while preserving the legal claims of terrorism victim plaintiffs over the funds. The ruling also amended the earlier freeze notice against the Arbitrum DAO, permitting the transfer to be executed through an on-chain governance vote and exempting those who propose, vote on, or participate in the transfer from liability under the freeze order. The transfer is still subject to an official vote by Arbitrum's on-chain governance. (CoinDesk)

Consensus Miami: Institutional Investors Remain Cautious Toward Perpetual DEXs; Security Risks and KYC Compliance Are Core Barriers

According to CoinDesk, at the “Perp DEX Explosion: Bullish Volumes and Bear Market Resilience” panel at Consensus Miami, several industry insiders stated that institutional investors are still largely avoiding decentralized exchanges offering perpetual futures (Perp DEXs). Veteran trader Wizard of SoHo pointed out that Drift’s recent multi-million-dollar hack highlights security vulnerabilities in the DeFi ecosystem, making secure onboarding of institutional capital a core competitive focus for major Perp DEXs. Anderson of Canary Labs expressed concern about DeFi’s current security posture, noting that large institutions face significantly greater challenges adopting decentralized exchanges compared to centralized platforms. Additionally, the structural tension between DeFi’s permissionless, open design and institutions’ stringent KYC compliance requirements is seen as a key barrier to scaling adoption. Michaël van de Poppe, founder of MN Fund, shared his views on AI-powered trading tools, stating that AI agents represent an evolutionary extension of algorithmic trading—and that trading will increasingly become fully automated.

Vitalik Buterin’s ~$4 token swap transaction was sandwiched by an MEV bot

According to CoinDesk, Ethereum co-founder Vitalik Buterin was sandwiched by the well-known MEV bot jaredfromsubway.eth on April 30 during a small token swap. On-chain data shows that Buterin exchanged 26,544 XDB tokens—valued at approximately $3.86—for 0.00197 ETH (worth about $4.56) in block 24993038. The bot then deployed roughly $1.14 million worth of WETH to manipulate prices across SushiSwap and Uniswap V2 to execute the sandwich attack. After deducting $5.14 in gas fees, the bot incurred an actual loss on this operation.

Solv Abandons LayerZero, Migrates $700M in Tokenized Bitcoin Assets to Chainlink CCIP

Solv Protocol has announced the migration of over $700 million in tokenized Bitcoin assets to Chainlink's cross-chain protocol CCIP, and will gradually phase out LayerZero's bridging support across multiple chains. The migration involves core assets such as SolvBTC and xSolvBTC. Solv stated that the decision is based on the latest security reviews and recent cross-chain security incidents, and CCIP will become its standard cross-chain infrastructure. This move follows Kelp DAO's migration of approximately $290 million in assets to Chainlink, further strengthening the trend of "cross-chain infrastructure shifting toward security-first migration." (CoinDesk)

Aave plans comprehensive upgrade of collateral and listing standards following KelpDAO security incident

Linda Jeng, Chief Legal and Policy Officer at Aave Labs, stated during Consensus Miami 2026 that Aave's previous risk framework overly focused on financial risks and price volatility. Looking ahead, the protocol will incorporate assessments of cross-chain interoperability, cybersecurity vulnerabilities, and underlying asset architecture.This reform directly stems from the rsETH incident that occurred in April. At that time, an attacker exploited a vulnerability in the KelpDAO cross-chain bridge to mint approximately 116,500 unbacked rsETH (valued at around $293 million), deposited it as collateral into Aave, and borrowed real WETH, leading to significant bad debt risks for the protocol.Jeng revealed that Aave will also release a formal "listing standards handbook" for asset issuers in the future, and will begin evaluating the correlation between DeFi protocols from a systemic risk perspective, rather than analyzing individual pools in isolation.Additionally, a "DeFi United" bailout plan involving Lido Finance, EtherFi, Ethena, and others has been launched to cover collateral shortfalls and prevent further proliferation of bad debt. (CoinDesk)

State Street: Recent DeFi Attacks Highlight Institutional-Grade Blockchain Security Needs

According to CoinDesk, Angus Fletcher, Head of Digital Assets at State Street, stated at Consensus Miami that recent DeFi attack incidents highlight traditional financial institutions’ need for blockchain asset security and risk management frameworks. He emphasized that before trillions of dollars worth of real-world assets (RWAs) are tokenized, the industry must urgently address cross-chain interoperability, legal ownership, and security safeguards.