News linked to both this project and an event.
According to CoinDesk, Bitcoin Core 32.0 entered its final testing phase on September 14, with its official release scheduled for October 10. This update adds a transaction fee estimator based on real-time mempool status, enabling fee estimates to be lowered more quickly once network congestion subsides. It also enables multi-threaded parallel reading of transaction data to speed up node blockchain synchronization, defaulting to 8 threads. Security-wise, it resolves a wallet naming vulnerability on non-Windows systems since version 24.0 that allowed attackers to execute arbitrary commands on the node host via a specially crafted wallet name. Additionally, it patches an out-of-memory vulnerability in the newly added built-in web server; testing indicates that 16 unauthenticated connections can spike node memory usage from 46MB to roughly 3GB in approximately one minute. This update does not include any changes to Bitcoin's consensus rules.
Odaily News: Bitcoin Core 32.0 entered its final testing phase on September 14, with the official version planned for release on October 10.This version will improve fee estimation, speed up block processing, and make PSBT version 2 the default option for multiple wallet commands, without changing Bitcoin's consensus rules.Developers also fixed a command execution vulnerability affecting certain wallet configurations, as well as a memory exhaustion vulnerability in the new web server. (CoinDesk)
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
According to CoinDesk, OpenAI said it will provide subsidized access to the $1 billion Daybreak cybersecurity model over the next six months, along with training and technical support, to help organizations defend against AI-driven cyberattacks, including potential zero-day exploits. Daybreak is divided into two tiers, Blue and Red, tailored for routine defense and more sensitive cybersecurity tasks, respectively, with about 2,000 organizations already using it.
According to CoinDesk, US cybersecurity firm CrowdStrike has partnered with federal law enforcement agencies to successfully dismantle the Russian botnet Sality, which has been operating for over two decades. Over the past eight years, the network has continuously stolen cryptocurrency through clipboard hijacking; its core payload, "EggJagger," resides on infected machines, monitoring the user's clipboard. Once a Bitcoin or Ethereum wallet address is detected, it is replaced with the attacker's address, causing victims to unknowingly complete transfers. Sality employs a decentralized P2P architecture with no central server, checking node online status every 40 minutes, and self-propagates via network-shared drives and USB devices. By exploiting an authentication vulnerability, CrowdStrike replaced legitimate node addresses with those of its own servers, successfully severing the network connections of over 15,000 infected machines. The operation was demonstrated live at the Day Zero summit in Las Vegas. Estimates indicate that the attackers stole at least 12.1 million rubles (approximately $150,000) over the eight-year period. Undisturbed crypto assets appreciated alongside the broader market, reaching a value of roughly $1.35 million by early 2025. Security experts advise users to always verify the first and last characters after pasting a wallet address to defend against such attacks.
According to CoinDesk, several prominent figures in the cryptocurrency industry and CoinDesk employees received numerous unsolicited password reset emails via the X platform on Tuesday, with some users receiving up to 10 within a few hours. Crypto investor Nic Carter urged users to enable X's "password reset protection" feature as soon as possible. Currently, there is no evidence that the X system has been breached or that accounts were hijacked en masse, and X has not issued an official statement regarding the incident.
According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.
Odaily News - The U.S. Internal Revenue Service (IRS) has issued a warning about an advanced email phishing campaign targeting cryptocurrency holders in the United States. Attackers are using forged official tax letters to trick users into scanning malicious QR codes, aiming to steal crypto wallet credentials and private keys.According to reports, the attackers are impersonating the IRS by sending physical letters that create a sense of urgency under the guise of "tax compliance" or "account verification," and include QR codes within the correspondence. Once users scan these codes, they may be redirected to counterfeit websites, potentially exposing wallet login information, recovery phrases, or private keys, ultimately leading to the theft of digital assets.The IRS reminds taxpayers that official agencies will never request users to provide crypto wallet private keys, recovery phrases, or perform similar "wallet verification" procedures through unofficial channels. Cryptocurrency holders should remain vigilant against any suspicious emails or letters that ask them to scan QR codes, connect wallets, or submit sensitive information.As the number of crypto asset holders continues to grow, social engineering attacks targeting digital wallets are on the rise. Regulatory and security agencies are stepping up efforts to raise awareness and prevent such fraudulent activities. (CoinDesk)
Odaily News: Sheldon Lee, founder of cryptocurrency exchange BitMart, stated that a post on X claiming users were unable to withdraw funds and that some employees had not received their July salaries is a "fabricated rumor," adding that the exchange's Chinese-language account had been hacked. Critics, including users and on-chain investigator ZachXBT, have demanded that BitMart resume withdrawals or undergo an independent third-party audit. BitMart is gradually winding down operations, with the final trading day set for August 26. Troubled investment firm Echo Base said it had proposed a funded restructuring plan to BitMart but received no response. The firm warned that resolving a large volume of customer claims may require proceedings through the courts. (CoinDesk)
Odaily News: Decentralized lending protocol Compound Finance has completed a leadership overhaul and approved a record $52 million budget. The protocol's total value locked has fallen from a peak of $12 billion in 2021 to $1.2 billion, and it is now seeking to restore growth. Compound Finance is pivoting to serve institutional clients, developing real-world asset products, partner integration solutions, and credit infrastructure to meet the compliance and technical standards of traditional finance. Industry executives say Compound Finance's new leadership team and substantial budget align with the broader shift within the decentralized finance sector toward serving financial institutions. The sector's overall assets had previously declined due to market weakness and security breach incidents. (CoinDesk)
Odaily News: Bits of Gold, Israel's largest crypto brokerage, stated that hackers obtained the personal information of approximately 200,000 customers through a data breach at a third-party data analytics service provider. The compromised information includes names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details, and public wallet addresses, but does not include funds, passwords, private keys, or ID scans. The incident is part of a recent wave of data breaches in the crypto industry, following similar incidents at SafePal and Trezor, which were also compromised through breaches at external vendors. (CoinDesk)
Odaily News: Following the full implementation of the EU's MiCA regulation on July 1, over 1,700 unlicensed crypto platforms have been ordered to cease operations and guide users toward licensed platforms; currently, only 323 companies hold valid authorizations. Approximately 10 million users need to migrate their assets, and scammers are taking advantage of this by impersonating regulators and licensed exchanges, sending fake migration notices to lure users into transferring assets to fraudulent platforms. The French Financial Markets Authority (AMF) stated that scammers have been posing as its employees to defraud funds under the guise of collecting "management fees." The European Securities and Markets Authority (ESMA) confirmed that its identity and logos have been misused. The Dutch Authority for the Financial Markets (AFM) warned that migration from unlicensed exchanges has itself become an attack surface, advising users to verify service providers through ESMA's official register and to remain vigilant against unsolicited contact requesting fund transfers.
According to CoinDesk, the S&P 500 index has risen 3.12% this month, adding approximately $2.1 trillion in market value (equivalent to the total market cap of the entire crypto market), reaching a record high total market cap of $70.5 trillion, but Bitcoin has only risen about 2% this month, hovering near $64,600. Analysts point out that this round of stock market rise is mainly driven by AI and semiconductor individual stock narratives, rather than a broad-based recovery in risk appetite at the macro level, and Bitcoin lacks direct beneficial exposure to this. Meanwhile, the crypto market also faces multiple internal pressures: the Coldcard platform suffered a $120 million exploit, the prospects of the "Clarity Act" remain uncertain, MicroStrategy has reduced its BTC holdings for three consecutive months, and stablecoin supply continues to shrink—USDT's market cap dropped from $190 billion in April to $183 billion, and USDC's dropped from $79.5 billion to $72 billion.
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.
According to CoinDesk, the 30-day implied volatility index BVIV, which measures expected volatility in the Bitcoin options market, has continued to decline, now falling to 36%, the lowest level since May 31, significantly down from the high near 60% in early June. Recent influencing factors include the Coldcard wallet attack incident involving tens of millions of dollars, weak institutional demand, and uncertainty in the regulatory and macroeconomic environment, but there are no obvious signs of panic in the market. However, volatility has mean-reverting characteristics. When the indicator falls to historical lows, a rebound often follows. Currently, BVIV has approached levels that have previously formed support multiple times. If volatility rebounds quickly in the future, it may be accompanied by a significant directional move in Bitcoin; whether up or down, traders need to remain vigilant.
According to CoinDesk, Eddy Zervigon, CEO of quantum computing security infrastructure company Quantum Xchange, stated that cryptocurrencies, due to their decentralized nature, will become the "canary in the coal mine" for quantum computing attacks—that is, the area where vulnerabilities will be exposed first. Latest assessments by Google researchers show that the number of physical qubits required to break Bitcoin's elliptic curve encryption has decreased 20-fold compared to previous estimates, and multiple institutions have brought forward the expected date of "Q-Day" (the day quantum computers can break existing encryption systems) to 2029. Deutsche Digital Assets pointed out that the real risk lies not in the encryption technology itself, but in the speed of governance—Bitcoin upgrades require 90% miner consensus, which has historically triggered hard forks (such as the 2017 SegWit upgrade leading to the birth of Bitcoin Cash), whereas traditional financial institutions only need a board resolution to complete encryption infrastructure migration. Additionally, experts caution that the quantum threat is not a binary event that "arrives suddenly on a certain day"; even if quantum computers require months to crack data, as long as the cracking is completed while the data is still valuable, the threat is established.
According to CoinDesk, the Cardano wallet SecondFi was attacked due to a vulnerability in its transaction signing software. A total of 16.1 million ADA (approximately $2.4 million) across 374 wallets was stolen, and the platform has announced permanent closure. The vulnerability allowed attackers to derive private keys from transaction data visible on-chain. The Cardano network itself was not affected, nor were hardware wallet users. An investigation by Groom Lake, a blockchain intelligence company hired by EMURGO, revealed that the primary attackers were sophisticated and well-funded. Some indications point to North Korea's Lazarus Group, but this has not yet been officially confirmed. SecondFi plans to release a wallet export tool in early August and launch a zero-knowledge recovery portal later in the month. EMURGO has established an asset recovery wallet, with the specific distribution time to be determined.
According to CoinDesk reports, algorithmic stablecoin Balance Coin suffered an oracle price manipulation attack on July 22. The coin price plummeted from near the $1 peg to about $0.0014, a drop of over 99%, and the nominal market cap of about $3.5 million nearly went to zero. According to analysis by security firm SlowMist, the attacker fed abnormally low false Bitcoin prices into the protocol, bypassing price rationality checks and liquidation delay mechanisms. They forcibly liquidated multiple ineligible collateral vaults in a single transaction, subsequently exchanged the acquired collateral for arbitrage, and ultimately profited about $912,000 from the protocol governance entity 42DAO.
According to CoinDesk, the Ethereum Foundation recently disclosed that its security team used AI agents to test the software running on Ethereum validator nodes and successfully discovered a vulnerability that could be triggered remotely, causing node crashes. However, researchers emphasized that amidst the large volume of security reports generated by AI, manual review remains a key step in distinguishing real vulnerabilities from false positives. Reportedly, the vulnerability discovered resides in the Ethereum network message propagation protocol gossipsub, where attackers can remotely trigger the node software into an abnormal computation state, causing the program to crash and shut down, taking the validator node offline until the operator manually restarts it. The vulnerability has been fixed and registered under the number "CVE-2026-34219". Nikos Baxevanis, a member of the Ethereum Foundation Protocol Security Team, stated that the truly surprising aspect of this incident was not the AI's ability to discover vulnerabilities, but the significant amount of time the team spent distinguishing which vulnerabilities were real and which were merely plausible "hallucinations".
According to CoinDesk, researchers at blockchain security company Hexens discovered an "expired cache" type confusion vulnerability in the Aptos blockchain Move virtual machine. Attackers require only about $3,000 in server costs to launch attacks in a simulated environment with a success rate of nearly 90%, without needing validator privileges or internal knowledge. Researchers ran approximately 20 attacks in simulated tests, succeeding 17-18 times, and verified the potential ability to control management permissions of cross-chain protocols such as LayerZero, Wormhole, and USDC CCTP. Hexens assessed that the vulnerability directly threatens protocols on the Aptos chain such as DeFi, stablecoins, and liquid staking, involving assets in the low single-digit billions of dollars; if spread through paths such as cross-chain bridges, stablecoin minting, and centralized exchanges, the systemic risk exposure could reach up to $70 billion. The Aptos team completed the fix and deployed it to the mainnet within hours after receiving the vulnerability report on February 25, and currently no user funds have been compromised.