GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Research teams including the Ethereum Foundation use AI to optimize algorithms, reducing the resource threshold for quantum cracking of BTC and ETH by 50%

Odaily News: Researchers from institutions including the Ethereum Foundation, Theta Labs, and StarkWare have jointly published a paper, using AI coding agents to deeply optimize the core operations of Shor's algorithm. The computing resources required for a potential quantum attack on Bitcoin and Ethereum (secp256k1 cryptographic system) have been reduced by more than 50% compared to Google's benchmark in March of this year. The number of logical qubits required for the circuit has been compressed to 1,151, and later versions have even been reduced to 813. Although current quantum hardware still cannot directly break public chains, the research shows that pure algorithmic optimization is significantly narrowing the time window for the quantum threat. The researchers emphasize that quantum-resistant upgrades take a long time and cannot be applied retroactively, and the industry needs to prepare defenses in advance. (Coindesk)

OpenAI appoints AI safety researcher Paul Christiano to the board of directors.

According to TechCrunch, AI alignment researcher Paul Christiano has officially joined the board of directors of the OpenAI Foundation and will serve as a member of its Safety and Security Committee. Christiano stated that he believes the rapid acceleration of AI capabilities poses a significant risk of "catastrophic and irreversible loss of control," and that the AI industry, including OpenAI, is not currently on track to effectively mitigate this risk. His appointment comes against the backdrop of several recent security incidents at OpenAI involving AI agents breaching constraints and infiltrating external computer systems, prompting widespread scrutiny of its safety protocols. Christiano is one of the core developers of the reinforcement learning (RLHF) technology. After leaving OpenAI in 2021 to found the Alignment Research Center (ARC), he will also continue to serve as an AI safety advisor to the U.S. government, though he will recuse himself from OpenAI-related matters and model evaluation work.

Biden’s Son Meme Coin LAPTOP: No Utility or Development Roadmap, Foundation Signs Loan Agreement with G20 and GSR

According to disclosures from the Phoenix Veritas Foundation, the Hunter Biden laptop-themed cultural token, LAPTOP, has been issued on the Base chain with a total supply of 1 billion tokens and an initial circulating supply of 350 million tokens (35%) at TGE. Token allocation consists of 30% for founders (including Hunter Biden), 30% for the prediction mechanism, 20% for the community airdrop, 10% for liquidity, 10% for the foundation treasury, and 5% for charity. Founder tokens are subject to a six-month lock-up period followed by linear unlocking over 24 months. LAPTOP provides no utility, positioned strictly as a cultural digital collectible with its value driven entirely by community sentiment. The token contract underwent a security audit by Hacken in April 2026, revealing no major vulnerabilities. Regarding market maker arrangements, the foundation has entered into a lending agreement with G20 and GSR totaling 20.5 million tokens.

G7 urges immediate migration to post-quantum cryptography; Bitcoin, Ethereum, and Solana developers have tested defense solutions

: The G7 cybersecurity working group stated in its latest report that quantum computing poses both a security threat and an economic threat to public and private institutions, and related organizations should immediately begin migrating to post-quantum cryptography (PQC).The working group noted that the migration process could take several years, as attackers can already collect and store encrypted data today and decrypt it once sufficiently powerful quantum computers emerge. Quantum computing could also break digital signatures, leading to identity theft and exposing companies and their supply chains.The report did not mention cryptocurrencies, but similar public-key cryptography is used for blockchain wallets and transaction authorization. Current quantum computers are not yet capable of breaking Bitcoin's cryptography, but developers are considering post-quantum solutions such as BIP-360.Ethereum researchers plan to replace multiple cryptographic components used by accounts, validators, and applications. The Solana Foundation has tested post-quantum signatures on its testnet and launched an optional hash-based vault. The G7 working group also urged governments to support related research, public-private cooperation, and national PQC strategies. (Decrypt)

Mainnet paused; Fogo blocks further movement of stolen funds

SVM Layer 1 network Fogo stated that after detecting unauthorized activity, it has taken precautionary measures to temporarily halt the Fogo mainnet in order to prevent the continued transfer of affected assets. During the mainnet suspension, Fogo will upgrade the network and restrict addresses associated with the incident. The team stated that further updates will be released once more information is confirmed, and reminded users to obtain relevant information only through Fogo's official channels. At present, the cause of the incident, the scale of affected assets, and the timeline for mainnet restoration have not yet been disclosed. Previously, the Fogo Foundation was breached by an unknown attacker, with approximately 400 million FOGO tokens transferred to the attacker's address. The foundation stated that it had immediately notified relevant trading platforms and is in communication with law enforcement agencies and forensic experts.

Starkware completes quantum-resistant transaction on Bitcoin mainnet without soft fork

: Blockchain technology company Starkware stated that on August 26, a transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) scheme was mined on the Bitcoin mainnet, without requiring a soft fork, hard fork, or modification of consensus rules.The transaction consumed 10,000 sats and was processed through MARA Foundation's Slipstream service, as the non-standard format typically cannot propagate through Bitcoin's public mempool. The test consumed several hours of GPU computation, costing approximately $150 to $200.QSB employs hash-based quantum-resistant spending conditions and reduces quantum attack risks through signature trial mining, but still requires users to proactively migrate funds and cannot protect assets whose public keys have already been exposed. Starkware CEO Eli Ben-Sasson still supports introducing a protocol-level solution via a soft fork. (Bitcoin.com News)

Approximately 400 Million FOGO Tokens Transferred, Fogo Foundation Suffers Attack

Odaily News: An unknown attacker breached the Fogo Foundation, resulting in the transfer of approximately 400 million FOGO tokens to a malicious address. The Fogo Foundation has notified major exchanges and is in communication with law enforcement and blockchain forensics experts. This incident will not affect the Fogo blockchain itself, and the network remains operational. The Fogo Foundation will provide further updates as more information becomes available.

Privacy Pools vulnerability fixed in March; 0xbow.io awards $5,000 bounty to researcher ross.wei

Odaily News: 0xbow.io, a privacy and regulatory compliance tool supported by the Ethereum Foundation, has awarded a $5,000 bounty to researcher ross.wei for disclosing a vulnerability in the Privacy Pools v1 SDK. The vulnerability reduced the entropy of user account master key generation and was fixed in March. The team has provided a migration process, and no user funds were lost.

KITE to Migrate Token Contracts at 1:1 Ratio, Attacker Addresses Excluded

Odaily News: The KITE Foundation has provided an update on the handling of a token security incident. A new KITE ERC-20 contract has been deployed on the Ethereum mainnet, with the total token supply remaining unchanged. Old KITE tokens will be migrated to the new contract at a 1:1 ratio. Addresses confirmed to be controlled by the attacker will be excluded and will not receive new tokens.The migration snapshot is based on Ethereum mainnet block height 25,692,498. Regular self-custody wallet users will receive the new tokens directly without needing to redeem or authorize anything. Exchange users will have their migration coordinated between the exchange and the KITE team. Cross-chain channels will remain paused until migration and verification are complete.Previously, KITE detected abnormal transfers on August 6 and confirmed it had been attacked by hackers. The team stated that this incident did not result in any asset losses for users or the project, and the impact is currently under control.

Nearly 200,000 XRP Stolen, Coreum Cross-Chain Bridge Attacked

Odaily News: The cross-chain bridge connecting XRP Ledger and Coreum was attacked on August 9. The attacker exploited a validation logic vulnerability to steal approximately 199,900 XRP, reducing the bridge's asset balance from roughly 200,400 XRP to 493.5 XRP. The attack did not involve private key leaks and did not target the XRP Ledger protocol itself. The attacker forged deposit operations, causing the bridge system to recognize them as legitimate deposits and triggering the bridge wallet on the other end to send real XRP. On-chain data shows that the attacker completed the fund transfer through 94 multi-signature authorization transactions within 97 minutes. These transactions required signatures from 17 of the 28 relay node keys, allowing the attacker to bypass the bridge's validation mechanism. As of August 11, the Coreum cross-chain bridge remains suspended, and the Coreum Development Foundation has not yet released an official incident report. The XRP mainnet and user private keys remain unaffected and secure.

BTCPay Server Hit by Critical Vulnerability Exploit, Supporters Launch Up to 3 BTC Bounty to Recover Stolen Funds

According to The Block, open-source Bitcoin payment processor BTCPay Server disclosed a critical security vulnerability being actively exploited last Friday and urgently requested users to upgrade to version 2.4.2. The vulnerability affects all versions prior to 2.4.2; attackers can use it to steal administrator macaroon authentication credentials of LND nodes, thereby fully controlling the connected Lightning Network wallets. Users such as Foundation and Citadel21 have confirmed that their Lightning node funds were drained, but BTCPay has not publicly disclosed the total amount stolen or the number of affected nodes. Currently, the official release version 2.4.2 has fixed this vulnerability, and on-chain hot wallets are not affected. The BTCPay Server Foundation has donated 0.21 BTC each to security researcher Craig Raw and Bitcoin Red Team to commend their responsible private disclosure of the vulnerability. Meanwhile, BTCPay supporters have promised to provide a bounty incentive of "10% of recovered funds," capped at 3 BTC.

BTCPay Temporarily Restricts Lightning Network Remote Access Due to LND Vulnerability

According to Cointelegraph, BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes due to attackers exploiting a critical vulnerability in LND (Lightning Network Daemon) to steal node credentials and transfer funds. Version 2.4.2 has upgraded to LND 0.21.1 and automatically rotates macaroon credentials in standard installations. The project team reminds operators to check for abnormal payments, channel closures, and balance changes as soon as possible; if nodes are exposed via self-built reverse proxies, Tor services, or port forwarding, relevant credentials must also be manually replaced. Currently, Foundation and Citadel21 have reported node fund losses, but the specific scale of losses has not yet been disclosed.

BTCPay Server Temporarily Restricts Public Remote Connections to LND Nodes, Vulnerability Causes Credential Leakage and Fund Theft

Bitcoin payment processing service BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. Attackers exploited a severe vulnerability to obtain credentials and transfer funds. The number of affected operators and the total amount stolen have not yet been disclosed. This restriction affects external wallets such as Zeus that connect via BTCPay Server domains or Tor onion addresses in Docker deployments, but Lightning Network payments can still continue. BTCPay Server stated that remote access functionality will be restored once security is confirmed. BTCPay Server 2.4.2 will install LND 0.21.1 and automatically regenerate macaroon credentials during standard installation. Foundation and Citadel21 have respectively disclosed that funds from their Lightning Network nodes were swept. Foundation stated that hot wallets were not affected, and the specific amounts of losses have not been disclosed.

Ethereum Foundation Recruiting Protocol Security Researcher

The Ethereum Foundation (EF) is globally recruiting Protocol Security Researchers (Remote Full-time), a role within the Protocol Security team. The team is responsible for identifying and intercepting vulnerabilities before they reach mainnet, with work covering Execution Layer/Consensus Layer security reviews, AI-assisted vulnerability discovery, fuzzing, specification audits, and coordinating vulnerability disclosure. Candidates are required to have deep experience with the Ethereum protocol, be familiar with EL/CL specifications and client implementations, and be proficient in languages such as Go, Rust, Java, C#, Nim, or Python. There are no hard requirements on years of work experience, with technical depth being the core consideration.

Kite Foundation: KITE Token Attacked on Ethereum Mainnet, Incident Quickly Contained with No Token Loss

The Kite Foundation stated that it detected attacks targeting KITE tokens. After the security system discovered abnormal KITE token transfer activity on the Ethereum mainnet, the team immediately initiated the incident response mechanism and suspended KITE token transfers and cross-chain bridging on the Ethereum mainnet. The Foundation stated that the affected tokens have been frozen in place, cannot be transferred, and will not flow into the secondary market. Currently, the scope of the incident is limited to the Ethereum mainnet, and the relevant tokens have not moved since then.

One week after the NVIDIA-led AI Safety Alliance OSAA was established, it has already gathered over 120 companies.

According to TechCrunch, the Open Safety AI Alliance (OSAA), led by Nvidia, has exceeded 120 member companies just one week after its establishment, including tech and financial giants such as Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa. During the Black Hat Cybersecurity Conference held in Las Vegas this week, the alliance established a working group named "Shared AI Findings Exchange" (SAFE) and has submitted multiple proposals open for public comment, managed by the Linux Foundation. The proposals cover confidential reporting mechanisms for AI cybersecurity incidents, alert processes for affected parties, and no-fault attribution analysis frameworks. Meanwhile, member companies are also actively contributing open-source technologies: Nvidia open-sourced the LLM vulnerability scanning tool Garak, Amazon contributed the agent building tool Strands Agents and authorization language Cedar, and Okta and Red Hat are advancing agent identity authentication and governance technologies respectively. Notably, Anthropic, OpenAI, and Google have not yet joined the alliance, although OpenAI and Google previously co-signed the open letter that spurred the creation of the alliance.

Coldcard vulnerability-related losses may reach $130 million, hardware wallet manufacturers warn of increased phishing attacks

Odaily News: Hardware wallet manufacturers Trezor and Foundation have warned that following the disclosure of a Coldcard firmware vulnerability, phishing attempts targeting hardware wallet holders have increased, with attackers soliciting recovery phrases and luring victims into downloading malware. Security firm Proofpoint has detected phishing emails impersonating Coldcard, inviting users to complete a "hardware audit" with links to a cloned website. After clicking, users download a batch file hosted on GitHub that installs the remote access tool ScreenConnect. Proofpoint stated that the fraudulent website also features a customer service chat window, where real people guide victims through the installation process. This remote access tool can provide attackers with a pathway to steal data and funds, or further deploy malicious programs such as ransomware. Galaxy Research has confirmed three rounds of theft since July 30, with high-confidence losses of 1,596 BTC, exceeding $100 million; if a fourth round not yet confirmed with victims is included, total losses could reach $130 million.

Midnight Foundation: Wanchain Cardano<>BNB Bridge Attacked, Multiple Exchanges Jointly Freeze Related Assets

According to an official post from Midnight Foundation (@midnightfdn), the Wanchain Cardano<>BNB cross-chain bridge suffered a security attack. Currently, multiple major exchanges including KuCoin, Kraken, Binance, Bybit, OKX, and MEXC have responded rapidly, taking preventive measures to restrict the flow of stolen assets, including freezing relevant accounts and addresses, blacklisting the attacker's wallets, and suspending NIGHT token deposit and withdrawal services. The exchanges confirmed that this incident is an isolated third-party bridge vulnerability and is unrelated to the Midnight Network mainnet and the NIGHT asset itself.

Midnight:Multiple Exchanges Including Binance Freeze Funds Involved in Cross-Chain Bridge Attack

the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.

Cambridge Study: US Hosts ~31% of Ethereum Nodes; Over One-Third Nodes Offline Could Impact Finalization

Odaily Odaily A new study by the Cambridge Centre for Alternative Finance reveals that approximately 31% of Ethereum node activity is located in the United States, with another 39% distributed across EU countries excluding the UK, indicating that the geographic distribution of Ethereum nodes remains relatively concentrated in Western nations.Lead researcher Alexander Neumuller stated that while node distribution is not currently concentrated in any single country, it is heavily reliant on a few major cloud service providers, including Hetzner, Amazon AWS, and OVH. Notably, the Ethereum network does not require half of its validators to fail for problems to arise. If more than one-third of validators go offline simultaneously, the network may be unable to finalize block checkpoints (finalization). Neumuller pointed out that nodes and validators do not have a one-to-one correspondence; a single node may run multiple validators. Therefore, it is currently impossible to precisely assess the actual impact on the validator network from the failure of a specific node or service provider.Furthermore, the study reassessed the energy consumption of Ethereum following The Merge. Data shows that Ethereum's current annual energy consumption is approximately 7.9 GWh, equivalent to a continuous power draw of about 1 MW. This represents only about 0.02% of pre-merge levels, a reduction of approximately 99.98%. Currently, over 56% of the energy used by the Ethereum network comes from sustainable sources, exceeding the global average.The study also noted that client software diversity is another potential risk. If a dominant client software has a vulnerability, it could affect a large number of network participants. The report was published by the Cambridge Centre for Alternative Finance and supported by the Ethereum Foundation. (The)