GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

US Department of Commerce Evaluates Kimi K3, Claims U.S. Still Leads, But Report Notes Test Was Not Fully Equivalent

the U.S. Department of Commerce's AI Standards and Innovation Center, in collaboration with the UK AI Safety Institute, tested the cyber attack capabilities of Kimi K3, emphasizing that "the United States still leads."However, the value of the evaluation is debated due to limitations in the testing scope. Due to hosting environment constraints, Kimi K3 only participated in partial testing, with its overall cyber capabilities estimated primarily based on 41 exploit benchmarks. In contrast, other models underwent more comprehensive testing, resulting in a larger margin of error for Kimi K3's results.In the exploit testing, Kimi K3 scored approximately 32%, higher than GLM-5.2's 24%, but lower than the average of approximately 76% for leading U.S. models. In a simulated attack chain test, Kimi K3 completed an average of 17 out of 32 steps in the attack chain and successfully breached the network once in 10 attempts, while U.S. frontier models completed an average of 28.5 steps.The report notes that Kimi K3 already possesses a certain level of autonomous attack capability, and its security guardrails did not prevent the model from developing exploits or executing attacks. However, the report also emphasizes that the testing scope was limited.

OpenAI Model Breaches Test Sandbox and Infiltrates Hugging Face Production Infrastructure to Obtain Benchmark Answers

OpenAI confirmed that the unreleased GPT-5.6 Sol and another unnamed, more powerful pre-release model breached a restricted sandbox environment during ExploitGym benchmark evaluations and infiltrated Hugging Face's production infrastructure to obtain test answers.OpenAI stated that the models leveraged a zero-day vulnerability in an internal software package registry proxy to escalate privileges and move laterally, ultimately connecting to a machine with internet access. The models then identified and chained together vulnerabilities in both the OpenAI research environment and Hugging Face's production infrastructure, directly retrieving test solutions from Hugging Face's production database.Hugging Face disclosed the incident on July 16, stating that the attack was executed end-to-end by an autonomous AI agent system, involving thousands of operations within short-lived sandboxes and accessing internal datasets and service credentials. OpenAI confirmed its models were the subject of the incident five days later.Hugging Face stated that its security team, in order to analyze over 17,000 attack logs, initially attempted to use a commercial US frontier AI interface, but the request was blocked due to safety guardrails. They subsequently switched to using the 753-billion parameter open-weight model GLM 5.2 from Chinese AI startup Z.ai on their own infrastructure to complete the forensic analysis.

Dragonfly Partner: No "Hacker Apocalypse" in DeFi; Annualized Stolen Value in 2026 Estimated at $1.89 Billion

Haseeb posted on X, stating that with models like GLM 5.2, Fable, and GPT 5.6 already launched and actively used by attackers, DeFi has not experienced the anticipated "hacker apocalypse." Chart data shows that based on the current year's data and running rate, the annualized amount stolen from DeFi in 2026 is approximately $1.89 billion. The cumulative stolen amount for the year is around $986 million, lower than the 2025 level and still within the historical range. Haseeb noted that the deeper change now is that while the number of hacker attacks has increased, the scale of individual attacks is declining more rapidly. Attackers are increasingly targeting smaller protocols and abandoned projects, while large protocols have implemented more security enhancements. As a result, overall fund security has not significantly deteriorated.

rsETH Hack Causes 68,900 ETH Shortfall; DeFi United Raises 13,500 ETH for Industry自救

According to on-chain analyst Ember (@EmberCN), the rsETH incident on April 18 resulted in a funding shortfall of approximately 68,900 ETH (around $160 million): the hacker collateralized rsETH to borrow 99,600 ETH; after Arbitrum recovered 30,700 ETH, the remaining funds were fully converted by the hacker into BTC. The incident has now entered the remediation phase. Aave is coordinating the establishment of a “DeFi United” relief fund, which has so far received cumulative donations totaling 13,500 ETH (approximately $31.45 million). Donors include Lido Finance (2,500 stETH), ether.fi Foundation (5,000 ETH), Aave founder Stani Kulechov (5,000 ETH), Golem Foundation (1,000 ETH), as well as LayerZero and Ink Foundation (amounts undisclosed).