GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Online/Update

News linked to both this project and an event.

BIS Publishes Working Paper: Exploring Blockchain-Based Verification Solutions for Official Statistical Data

According to BIS Working Paper 1374 released by the Bank for International Settlements (BIS), the BIS, together with several researchers, has proposed a verifiable framework that binds official statistical data to the blockchain. The solution computes cryptographic fingerprints for SDMX datasets and anchors the digest values to the XRP Ledger, enabling independent verification of data provenance and integrity while leaving existing data publication workflows unaffected. Prototype tests show a data publication latency of approximately 3–5 seconds and a verification latency of approximately 1–2 seconds, meeting the requirements for real-time interactions and automated systems. Since only fingerprints, rather than raw data, are stored on-chain, data confidentiality is preserved. Cost modeling indicates that on-chain fees become negligible after batch processing, with a single ledger record capable of covering thousands of datasets. The study also provides an open-source reference implementation and reserves capacity for future integration of zero-knowledge proofs and AI-driven automated verification.

Hackers Steal Crypto Wallet Data Using Google Docs and Fake Claude AI Pages

According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.

Ripple Plans to Advance XRP Ledger Post-Quantum Upgrade in Phases

Ripple stated that it is developing a long-term upgrade plan for the XRP Ledger to address the threat of quantum computing, aiming to prevent future quantum computers from potentially breaking existing cryptographic mechanisms and exposing private keys. The plan consists of four phases, including assessing network risks, testing post-quantum cryptography solutions, running existing security mechanisms alongside post-quantum alternatives in parallel, and initiating a complete network migration when necessary.

Ledger Ethereum App Version 1.22.1 Contains Transaction Replacement Vulnerability — Users May Review One Transaction While Signing Another

Odaily News: OneKey Anzen has reproduced the Ledger vulnerability and discovered that Ledger Ethereum app version 1.22.1 contains a transaction replacement vulnerability. When an affected user is attacked, the hardware screen still displays transaction A under review, but the device may sign transaction B, which the user never viewed. OneKey Anzen stated that the issue stems from a race condition between the transaction display logic and the underlying buffer, with the attack requiring the host side to already be compromised by a malicious DApp or intermediary software. Ledger's CTO previously responded that a fix had been rolled out approximately two weeks ago, and users simply needed to update the app. Public information shows that the official tag for version 1.22.2 on Ledger's GitHub appeared on August 24. Ledger's official website states that the issue has been fixed through app-level checksums and SDK-layer patches, with Ledger Secure SDK v26.6.1 released on August 21, and the related apps have been rebuilt and republished. Users need to update the app via Ledger Live — updating only the device firmware will not complete the fix. Ledger stated that there is currently no evidence that this vulnerability has been actively exploited.

Independent verification scope expanded, Sparrow Wallet releases v2.5.4 security update

Odaily News: Sparrow Wallet v2.5.4 has been released following an extensive AI-assisted review, featuring multiple security hardening updates aimed at reducing users' reliance on external servers such as Electrum.Additionally, this version strengthens Ledger, Keycard, Trezor, Payjoin, PSBT, and multi-signature handling, removes Bitcoin Core credentials and other sensitive information from debug logs, restricts permissions for existing wallet and backup directories to owner-only access, closes residual local DNS resolution leaks when using Tor, and reinforces validation for wallet import, signing, downloads, and server responses. The update expands Sparrow Wallet's scope of independent verification for transaction data, hardware devices, and other inputs, reducing dependence on data provided by external servers. (Bitcoin News)

Vulnerability fixed; Ledger Ethereum app users can obtain protection by updating device firmware and apps

Odaily News: Ledger Chief Technology Officer Charles Guillemet stated that a smart contract security company recently claimed to have discovered a vulnerability in the Ledger Ethereum app. The Ledger Ethereum app did previously contain a vulnerability related to certain Clear Signing processes, but it was identified by Ledger's in-house security research team, Donjon, using an AI-driven vulnerability research tool, and was fixed and deployed two weeks ago. The security company in question only contacted Ledger's bug bounty program after the fix had already been completed, failing to follow responsible disclosure procedures and without communicating with the bug bounty team, then published content implying that the issue remained unresolved. Guillemet stated that users who promptly update their Ledger device firmware, Ledger apps, and related software will receive the latest security fixes.

Coldcard incident boosts BitBox credit card sales by ~10x, while Trezor and OneKey see rising demand

Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)

Ripple stablecoin RLUSD market cap surpasses $2 billion, with nearly $1 billion issued on XRP Ledger

Odaily News - Ripple's stablecoin RLUSD has surpassed a $2 billion market cap, becoming one of the fastest-growing projects in the stablecoin market.Data shows that RLUSD's total issuance currently stands at approximately $2 billion, with about $963 million deployed on the XRP Ledger and approximately $1.1 billion issued on the Ethereum network. Ripple previously stated that RLUSD will integrate with its global payment network to provide enterprises and financial institutions with more efficient on-chain liquidity solutions. (CoinDesk)

Taurus Integrates with Swift’s Blockchain Ledger, First Clients Going Live Within Days

Odaily News Digital asset infrastructure provider Taurus has connected its tokenization and custody platform to Swift's blockchain-based ledger, allowing clients to use bank-issued tokenized deposits for payments through their existing digital asset infrastructure.Taurus stated that the first client integrations are expected to go live within days, with the first distributed ledger technology transaction facilitated by its platform expected to be completed within weeks.International payment network Swift announced in July that its ledger was ready for initial use, with 17 banks from six continents piloting real-time transactions using tokenized deposits. Standard Chartered and HSBC have completed the first real-time cross-border transaction on the ledger. (Cointelegraph)

Standard Chartered and HSBC Complete First Real-Time Cross-Border Transaction via SWIFT Blockchain Ledger

Odaily News: Standard Chartered and HSBC have completed the first real-time cross-border transaction executed via the Society for Worldwide Interbank Financial Telecommunication (SWIFT) blockchain ledger. The transaction exchanged payment messages through the SWIFT ledger, with the corresponding debts recorded respectively on HSBC's Tokenised Deposit Service and Standard Chartered's tokenised deposit infrastructure.The SWIFT ledger matches and nets off the debts of both parties before final settlement, with the ultimate settlement still completed through existing payment systems. The ledger is designed to connect tokenised deposits issued across different banking infrastructures, supporting round-the-clock cross-border payments while retaining existing settlement, compliance, and risk control mechanisms. (Cointelegraph)

Cash App Expands Crypto Support via MoonPay, 50 Million Users Can Buy ETH, SOL, XRP, and USDT

Odaily News: Payment app Cash App is expanding its cryptocurrency services through crypto payment platform MoonPay, allowing 50 million users to purchase tokens such as ETH, SOL, XRP, and USDT. Additionally, users can top up major wallets like Ledger, BitPay, Trust Wallet, MetaMask, and Uniswap through Cash App. Previously, Cash App's crypto services only supported Bitcoin, with USDC support added earlier this year. (CoinDesk)

Sui Hashi Testnet Handles Over 1.1 Million Bitcoin Deposits in Three Weeks, 25 Institutions Participate in Stress Testing

Odaily News: Since the launch of Sui's Hashi Bitcoin lending protocol testnet on July 22, it has processed over 1.1 million Bitcoin deposits and 165,000 withdrawals within three weeks. As of last week, more than 25 institutions had participated in the system's stress testing. Participating institutions include digital asset custodian BitGo, trading firm Cumberland, as well as Swissborg, Fluid, and Ledger, covering areas such as trading, custody infrastructure, and wealth management platforms. Hashi allows users to deposit native Bitcoin, which is confirmed by Sui validators before minting hBTC for on-chain lending and stablecoin borrowing. Deposits utilize a 2-of-2 multi-signature mechanism with MPC validator signatures, while withdrawals require review by the Guardian Layer; the project team will proceed with the 2026 mainnet launch only after this security layer completes its security audit. (Bitcoin.com News)

DefiLlama delays mobile app launch due to phishing impersonators on Apple's App Store

Odaily News, DefiLlama founder 0xngmi, of the crypto data analytics platform, stated that the team spent months asking Apple to remove phishing apps impersonating DefiLlama from the App Store, which delayed the mobile app's launch until all such counterfeit apps had been removed. 0xngmi noted that after the team downloaded one of the malicious apps and documented a small crypto wallet being stolen, Apple removed it within days. In 2024, the App Store also saw counterfeit apps impersonating Rabby Wallet and Curve Finance; in November 2023, a fake Ledger Live app on the Microsoft Store siphoned off $588,000 across 38 transactions. (Cointelegraph)

Approximately 233,000 Bitcoin moved as a precaution, with around $15 billion involved following the Coldcard exploit

Odaily News: After a firmware vulnerability in Coldcard hardware wallets was exploited, approximately 2,100 Bitcoin were stolen, with losses nearing $130 million. On-chain data shows that in the days surrounding the incident, wallets held by long-term holders transferred out approximately 233,000 Bitcoin, valued at around $15 billion. Casa CEO Nick Neuman stated that some of the transferred funds came from Coldcard users migrating to multi-signature wallets, with Ledger and Trezor users also taking similar measures after the event. During the same period, approximately 22,000 Bitcoin were transferred into exchanges. Coinkite has advised users who generated seed phrases using firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and immediately migrate to new seed phrases. These versions cover the period from March 2021 to July 2026. (Decrypt)

Crypto Companies Send Joint Letter to AI Labs, Urging Access to Frontier Models for Bitcoin Developers

据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。

Nearly 200,000 XRP Stolen, Coreum Cross-Chain Bridge Attacked

Odaily News: The cross-chain bridge connecting XRP Ledger and Coreum was attacked on August 9. The attacker exploited a validation logic vulnerability to steal approximately 199,900 XRP, reducing the bridge's asset balance from roughly 200,400 XRP to 493.5 XRP. The attack did not involve private key leaks and did not target the XRP Ledger protocol itself. The attacker forged deposit operations, causing the bridge system to recognize them as legitimate deposits and triggering the bridge wallet on the other end to send real XRP. On-chain data shows that the attacker completed the fund transfer through 94 multi-signature authorization transactions within 97 minutes. These transactions required signatures from 17 of the 28 relay node keys, allowing the attacker to bypass the bridge's validation mechanism. As of August 11, the Coreum cross-chain bridge remains suspended, and the Coreum Development Foundation has not yet released an official incident report. The XRP mainnet and user private keys remain unaffected and secure.

Ledger 提示 BIP-110 分叉缺乏重放保护,建议暂勿领取分叉币

硬件钱包厂商 Ledger 就 BIP-110 分叉发布安全提醒称,BIP-110 是一项未内置重放保护(replay protection)的比特币软分叉方案,如果形成独立链,BTC 持有者可能在新链获得相同数量的对应资产,但两条链初期可能接受相同签名交易。 用户若尝试转移或出售 BIP-110 链上的资产,相关交易可能被“重放”至比特币主链,导致对应 BTC 同时被转出。

XRPL Plans to Introduce Privacy Transfer Feature, Targeting Tokenized Asset Market of Over $530 Million

Odaily News: The latest software version 3.3.0 of XRP Ledger (XRPL) introduces several upgrade proposals, including Confidential Transfers. This feature is designed for institutional users, supporting encrypted token balances and transfer amounts while preserving the visibility of accounts and token types. It is primarily applied to Multi-Purpose Tokens (MPT) on XRPL, including tokenized financial assets such as funds and bonds. Through cryptographic technologies like zero-knowledge proofs, the network can verify transaction validity without disclosing specific amounts. XRPL currently holds approximately $1.38 billion in on-chain real-world assets (RWA), including about $845.7 million in RLUSD. In addition to RLUSD, there are over $530 million in tokenized assets on XRPL, involving issuers such as Ondo, VERT Capital, Archax, and Societe Generale. XRPL 3.3.0 also includes five proposals—Batch, Sponsor, Permission Delegation, and Dynamic MPT—addressing institutional needs such as batch transactions, fee sponsorship, permission management, and dynamic adjustments to token attributes. The aforementioned upgrades have not yet been officially launched and will only be activated after receiving support from more than 80% of XRPL's trusted validator nodes for two consecutive weeks.

Ledger: Coldcard Vulnerability Losses Reach Approximately $130 Million, Hardware Wallet Security Needs to Adapt to AI

Odaily News: Hardware wallet manufacturer Ledger has stated that the recent Coldcard vulnerability indicates the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, as their recovery phrases are generated by a hardware random number generator built into a certified secure element. Coldcard manufacturer Coinkite disclosed last week that its air-gapped Coldcard Bitcoin hardware wallet contains a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, allowing certain private keys to be guessed, with related losses reaching approximately $130 million. Coinkite released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited — the flaw had existed in public code for over five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed. Charles Guillemet also said that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process has received independent certification.

Study shows Switzerland's cryptocurrency usage rate reaches 23%, twice that of Germany

According to Bitcoin.com, a recent survey report released by Bearingpoint shows that 23% of Swiss adults use cryptocurrency at least occasionally, far higher than 11% in Germany and 18% in Austria. The survey was conducted by YouGov in June 2026 among over 4,000 adults in Germany, Austria, and Switzerland. The report points out that Switzerland's leading advantage stems from its Distributed Ledger Technology Act (DLT Act) officially effective in 2021, which provides a clear legal framework for crypto assets, attracting a large number of enterprises to establish operations, and driving the expansion of the "Crypto Valley" ecosystem to 1,749 blockchain companies. Additionally, 37% of Swiss respondents consider cryptocurrency an asset worth investing in, and 45% support it becoming an international reserve currency, both leading Germany and Austria. In contrast, regarding Germany, although retail adoption rates lag behind, the "meinkrypto" platform under DZ Bank and Dekabank's crypto services for the savings bank network are expected to cover approximately 80 million customers, potentially gradually narrowing the gap with Switzerland.