GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

BTCPay Temporarily Restricts Lightning Network Remote Access Due to LND Vulnerability

According to Cointelegraph, BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes due to attackers exploiting a critical vulnerability in LND (Lightning Network Daemon) to steal node credentials and transfer funds. Version 2.4.2 has upgraded to LND 0.21.1 and automatically rotates macaroon credentials in standard installations. The project team reminds operators to check for abnormal payments, channel closures, and balance changes as soon as possible; if nodes are exposed via self-built reverse proxies, Tor services, or port forwarding, relevant credentials must also be manually replaced. Currently, Foundation and Citadel21 have reported node fund losses, but the specific scale of losses has not yet been disclosed.

Russia Closes Down 9 Unregistered Crypto Exchanges in Moscow, FSB Alleges Money Laundering of Fraudulent Funds

Odaily News: Russia's Federal Security Service (FSB) conducted surprise raids on 9 unregistered cryptocurrency exchange service providers in Moscow, alleging they were involved in transferring funds obtained through fraud abroad via crypto assets. More than 20 employees were detained at the Moscow International Business Center.The FSB stated that these exchanges converted stolen funds from Russian phone scam victims into cryptocurrency and transferred them to accounts of what it claims are Ukrainian processors. The operation was carried out jointly by the FSB and the Russian Ministry of Internal Affairs.Russia's Ministry of Internal Affairs has launched a criminal investigation into large-scale fraud, which under Russian law carries a maximum sentence of 10 years in prison. The FSB said it is continuing to identify victims and assess potential compensation. (Cointelegraph)

Zeus Wallet Urgently Taken Offline After Cyber Attack, States Customer Funds Safe

According to Cointelegraph, Bitcoin Lightning Network self-custodial wallet Zeus Wallet voluntarily took its infrastructure offline following a cybersecurity attack on Wednesday and is currently conducting a comprehensive audit of the system, with services to be restored upon completion. Zeus founder Evan Kaloudis stated that the attack was contained within hours, no customer fund losses were found, and there was no evidence that the Lightning node software was affected; the scope of the incident was limited to Zeus's own infrastructure. For users forced to close LSP channels during this incident, Zeus promised to provide replacement channels after services are restored. The company has not yet disclosed the specific nature of the attack or a timeline for resuming operations. Zeus stated that this incident will further drive its security development on Trusted Execution Environment (TEE) and Validating Lightning Signer (VLS) projects.

Coldcard vulnerability investigation escalates: At least 15 attackers identified, a single victim's findings reveal 12 BTC stolen

Galaxy Digital Head of Research Alex Thorn stated that based on new victim reports received following the incident, the number of attackers exploiting the Coldcard vulnerability has reached at least 15.Thorn noted that information provided by victims helped the research team uncover previously unidentified attack activity. Unlike thefts from centralized exchanges, correlations between the attackers in this vulnerability exploit require confirmation through on-chain analysis and victim feedback.He added that a single victim reporting less than 1 BTC stolen helped the team discover a previously unknown attack, which siphoned approximately 12 BTC from 126 addresses.According to Galaxy Research's earlier estimates, the Coldcard vulnerability has led to at least three rounds of attacks, with losses amounting to approximately $100 million in BTC. Additionally, Galaxy has identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million.Meanwhile, the incident has also sparked discussions regarding the security of Bitcoin self-custody. Dragonfly Managing Partner Haseeb Qureshi stated that "AI security hardening costing around $2" could potentially have prevented this vulnerability, and noted that some AI models were able to rediscover related vulnerabilities within a relatively short timeframe. However, industry insiders pointed out that current claims about the speed of AI discovering vulnerabilities lack rigorous blind testing and verification.Researchers believe that as AI model capabilities improve, the costs of vulnerability discovery and attacks in the crypto industry may continue to decline, requiring wallet developers to further strengthen code audits and security protections. (Cointelegraph)

Kraken Chief Security Officer: Coldcard Vulnerability Leads to Over $90 Million in Bitcoin Stolen, Hardware Wallet Industry Testing Mechanisms Require Urgent Overhaul

According to Cointelegraph, Coinkite, the manufacturer of Coldcard hardware wallets, disclosed that its devices have contained a random number generator (RNG) vulnerability persisting for up to five years since March 2021. The vulnerability stemmed from a firmware upgrade that mistakenly routed wallet seed generation to a less secure MicroPython pseudo-random number generator (PRNG), rather than the originally designed true random number generator (TRNG). Since code reviews only verified the existence of TRNG code without confirming whether it was actually invoked, the vulnerability remained undetected for a long period. To date, over 4,500 addresses have been compromised, with nearly $90 million worth of Bitcoin stolen. Kraken Chief Security Officer Nick Percoco stated that this incident should serve as a "wake-up call" for the hardware wallet industry, calling for the introduction of independent third-party testing mechanisms to mandate verification of whether the entropy sources actually invoked by production firmware are certified. Coinkite has suspended all device shipments and destroyed affected inventory after confirming the vulnerability, and stated it will cooperate with law enforcement agencies across multiple countries to trace the responsible parties.

Coinkite Issues Coldcard Mk3 Security Warning, Suspected to Be Related to $38 Million Bitcoin Theft Incident

据 Cointelegraph 报道,加拿大比特币硬件钱包制造商 Coinkite 警告 Coldcard Mk3 用户立即迁移资金,受影响固件版本为 2021 年 3 月发布的 4.0.1 至最终版本 5.0.3,Mk4、Q 及 Mk5 不受影响。与此同时,比特币安全专家正在调查一起涉及 594.48 枚 BTC(约 3830 万美元)的异常清仓事件,涉及 1324 个 UTXO 在三个区块内通过 500 笔交易被转移,所有地址均为单签名地址。

Triple-A Treasury Wallet Hacked, Approximately $11.8 Million Lost

According to Cointelegraph, Singapore stablecoin payment company Triple-A confirmed its treasury wallet was accessed without authorization, with on-chain investigator Specter estimating losses at approximately $11.8 million. The company stated that customer funds are held in separate trust accounts and were not affected by this incident, and the relevant losses will be covered by the company's own financial reserves. Triple-A has currently restored all services and is collaborating with cybersecurity experts, blockchain forensic agencies, and the Singapore Police Force to investigate and track the stolen assets.

Garden Finance Hacked, Loss of Approximately $450,000 USDT

According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.

Coinbase: Over 95% of Code Now Written or Assisted by AI, AI Agent Workload Equivalent to 1,200 Employees

Rob Witoff, Platform Leader at Coinbase, stated that currently, over 95% of the company's code is written or completed with the assistance of AI, a significant increase from the 40% figure announced in February this year. In an interview with Cointelegraph, Coinbase Platform Leader Rob Witoff said: "In fact, 100% of Coinbase employees use AI every day." Witoff noted that most Coinbase engineers currently run 5 to 10 AI Agents simultaneously. The combined work capability of these AI Agents is equivalent to approximately 1,200 employees.He predicts that by 2030, Coinbase's AI Agents could handle a workload equivalent to 100,000 employees. However, he stated that key areas such as core cryptography will still require human involvement, with AI primarily used for code testing, vulnerability checking, and prototyping. (Cointelegraph)

The MCSA in the US no longer opposes the CLARITY Act, shifting its stance to neutral

the Major County Sheriffs of America (MCSA), in a letter to U.S. Senate Banking Committee Chairman Tim Scott and Senator Elizabeth Warren, stated that after some of its concerns regarding Section 604 of the bill were addressed, it has shifted its stance on the CLARITY Act to "neutral." Section 604, concerning the Blockchain Regulatory Certainty Act, aims to protect developers from liability for illegal activities conducted by users on their decentralized platforms. The MCSA had previously stated that Section 604 could provide loopholes for criminals to exploit, making it more difficult for law enforcement to investigate crypto-related crimes. The MCSA indicated that it still hopes the CLARITY Act will amend Section 309 to include state law enforcement agencies. This section requires the U.S. Treasury Department to study decentralized finance and illicit finance risks. (Cointelegraph).

StarkWare Releases Starknet Quantum Resistance Roadmap

zero-knowledge scaling company StarkWare has released a Starknet quantum resistance roadmap, stating that the roadmap is divided into three phases to address the risk of future quantum computing attacks. StarkWare CEO Eli Ben-Sasson stated that Starknet can leverage its architectural advantages to achieve quantum resistance, as its underlying cryptography is based on zero-knowledge STARK proofs. According to reports, the first phase of the roadmap includes replacing part of the existing secure mathematical mechanism, Pedersen hash, with a quantum-resistant version, and adding quantum-resistant signatures; the second phase focuses on migration tools, upgrading existing smart contracts without requiring developers to manually rebuild applications; the third phase involves dependencies that Starknet cannot solve alone, primarily relying on Ethereum's quantum upgrade roadmap. Circle, Ethereum, Solana, Tezos, and Algorand have all proposed quantum resistance roadmaps. (Cointelegraph)

Base Discloses Causes of Two Recent Outages, Identified as Sequencer Vulnerabilities

the Coinbase Layer 2 network Base experienced two block production outages last week, with the root cause identified as a vulnerability in the sequencer's block construction logic. This vulnerability allowed outdated log states to persist after transaction validation failed, preventing the sequencer and validator nodes from processing invalid blocks until sequencing was restored.The first incident lasted 116 minutes, while the second, caused by a race condition following a system reset that prevented the sequencer from keeping up, lasted 20 minutes. The team has since fixed the issue by applying a patch to the sequencer, with future plans to improve protocol fuzz testing and build a graceful recovery mechanism. (Cointelegraph)

Fidelity refutes claims that Bitcoin’s security declines post-halving, stating miners’ revenue increases as Bitcoin price rises.

According to Cointelegraph, Fidelity Digital Assets has rebutted concerns in a new research report that Bitcoin’s long-term security will deteriorate as mining rewards decline, asserting that the network’s economic incentives remain sufficient to secure the blockchain over the long term. Authored by Fidelity research analyst Daniel Gray, the report reiterates that Bitcoin’s security depends not only on block rewards but also on transaction fees and market-driven economic incentives, which will continue to motivate miners to protect the network—and render sustained attacks prohibitively costly. The report challenges a longstanding critique that Bitcoin’s security is weakened every four years by the halving event, which reduces new coin issuance. It notes that since April 20, 2024, Bitcoin miners have received a subsidy of 3.125 BTC per block—down from 6.25 BTC in the previous halving cycle—but this reduction in issuance has not translated into diminished miner incentives, as Bitcoin’s price appreciation has more than offset the decline in block rewards. Gray points out that average daily miner revenue has surged from approximately $26,300 during Bitcoin’s first halving cycle to over $40.2 million today. The report also notes that although Fidelity views the long-term incentive structure as sound, many publicly listed mining companies are currently facing financial pressure, with some diversifying into artificial intelligence and high-performance computing. VanEck recently

Taiko bridge attack may result in losses up to $1.7 million

Ethereum Layer 2 blockchain Taiko has stated its chain state verification mechanism has been compromised, and the security assumptions of all bridges deployed on Taiko can no longer be relied upon. It urges users to immediately withdraw funds from the relevant bridges. Taiko says it is coordinating with partners to control the incident and has suspended the affected systems.Crypto security firm Blockaid stated that the root cause appears to be a flaw in the way Taiko's bridge validates source signals. Attackers can submit message proofs on Ethereum that lack legitimate proof from the Taiko chain, thereby registering and withdrawing fraudulent bridge messages. This leads to the unauthorized release of assets from the ERC20 treasury. Blockaid estimates at least $1 million was stolen, while Lookonchain and PeckShield believe the value of stolen assets could be as high as $1.7 million.PeckShield reported that the attacker has transferred approximately 1.99 million TAIKO tokens to MEXC, valued at around $189,000. Data from blockchain intelligence firm Arkham shows that the Taiko attacker's wallet holds approximately $1.5 million in assets, primarily in Ether. (Cointelegraph)

Well-known MEV bot Jaredfromsubway.eth suffers reverse attack, losing over $7.5 million

Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)

Aave survives $8.45 billion withdrawal pressure, but DeFi hidden risks come under renewed scrutiny

Odaily Aave, a DeFi lending protocol, successfully maintained operations after experiencing capital outflows totaling approximately $8.45 billion. However, the incident has simultaneously triggered renewed market discussion regarding its risk structure and the fragility of the DeFi system.This stress event originated from a vulnerability exploit on the KelpDAO rsETH cross-chain bridge in April 2026, resulting in the theft of approximately $292 million in assets. This triggered market concerns over the safety of rsETH collateral. As this asset was widely used as collateral on Aave, panic spread rapidly, leading to concentrated withdrawals by users.During the capital outflow process, liquidity in certain lending markets was quickly depleted, with utilization rates briefly approaching 100%. Aave managed the situation by adjusting risk parameters and activating emergency mechanisms, although localized withdrawal restrictions did occur.Nevertheless, Aave's core smart contracts were not compromised. Protocol founder Stani Kulechov stated that the event validated the system's stability and resilience under extreme stress conditions.However, analysts pointed out that this incident exposed structural risks within DeFi: high coupling of assets across protocols, reliance on external bridged assets for collateral, and the potential for liquidity to rapidly evaporate in extreme scenarios.Industry observers believe that while DeFi's "composability" enhances efficiency, it also accelerates risk transmission, potentially causing a single asset event to trigger systemic cascading effects. Although Aave successfully navigated this stress test, the outcome does not equate to the elimination of risk.Overall, this event is viewed as a genuine extreme stress test for the DeFi lending system: the system can function, but its stability remains highly dependent on the quality of external assets and the market liquidity environment. (Cointelegraph)

G7: Calls for Joint Action Against North Korean Cryptocurrency Theft and Cybercrime

leaders of the Group of Seven (G7) issued a statement at the G7 summit in Évian-les-Bains, France, once again calling for joint action to combat North Korean cryptocurrency theft and cybercrime. United Nations security researchers have linked North Korea's cryptocurrency theft to the funding of its weapons programs.Previously, attacks suspected to be linked to North Korean hackers included a $285 million attack on Drift Protocol in April and a $36 million breach on Humanity Protocol in June. According to Chainalysis data, North Korean hackers stole at least $2 billion in cryptocurrency in 2025, bringing their historical total theft amount to at least $6.75 billion. (Cointelegraph)

Cybersecurity Leaders Jointly Call for Lifting Restrictions on Anthropic’s Mythos Model

According to Cointelegraph, cybersecurity leaders led by former Facebook Chief Security Officer Alex Stamos jointly penned a letter urging the Trump administration to lift restrictions on the use of Anthropic’s Mythos model. They argue that these restrictions harm defenders far more than attackers, hindering the overall development of the cybersecurity ecosystem.

Zcash Founder Says Claude Mythos Audit Found No Critical Vulnerabilities

Odaily Zcash founder Zooko Wilcox posted on X stating that a security audit conducted by Anthropic's Claude Mythos AI model did not find any "more severe vulnerabilities" in the Zcash protocol. The audit was commissioned by Shielded Labs, a Swiss non-profit organization supporting Zcash development. On June 3, Zcash developers temporarily paused Orchard transactions after discovering a vulnerability in the shielded pool, restoring functionality through an emergency upgrade the same day. The issue stemmed from a four-year-old forging vulnerability in the Orchard shielded pool, identified by security researcher Taylor Hornby with the assistance of Anthropic's Claude Opus 4.8 model. The Zcash Foundation stated there is no evidence that the vulnerability was exploited, nor was any unauthorized value creation detected, and user privacy remained unaffected.Anthropic released the first public version of the Claude Mythos model, Fable 5, on Tuesday, and stated on Friday that it has suspended access to the Fable 5 and Mythos 5 AI models due to export control directives issued by the U.S. government citing national security concerns. (Cointelegraph)

Anthropic Mythos AI Audit of Zcash Finds No New Critical Vulnerabilities

According to Cointelegraph, Zcash founder Zooko Wilcox stated that a security audit of the Zcash protocol—commissioned by Shielded Labs and conducted using Anthropic’s Mythos AI model—did not uncover any new critical vulnerabilities. Previously, security researcher Taylor Hornby discovered, using Claude Opus 4.8, a four-year-old forgery vulnerability in the Orchard shielded pool, prompting developers to urgently suspend Orchard transactions on June 3 and complete the fix the same day. The Zcash Foundation confirmed there is no evidence the vulnerability was ever exploited, and user privacy remained unaffected.