News linked to both this project and an event.
The SlowMist security team stated that approximately 16.6 WETH were stolen from an unverified contract due to an unrestricted low-level call vulnerability. The attacker exploited the contract's existing ERC20 allowance to bypass owner checks and complete unauthorized transfers.
Odaily news "On-chain detective" ZachXBT posted in his personal channel, stating that Telegram continues to allow scam advertisements to be displayed to subscribers in his channel, impacting user experience and posing potential security risks.ZachXBT stated that if users are Telegram Premium members and wish to support upgrading his channel, they can help it reach the required level by using the channel's Boost function, thereby unlocking the ability to disable ads. Currently, the channel needs to reach Level 50 to enable the ad-disabling option.ZachXBT has long focused on scams, hacker attacks, and on-chain fund tracking within the crypto industry, and has repeatedly exposed incidents involving phishing attacks, fake projects, and fund theft.This time, he raised concerns about Telegram's advertising mechanism, arguing that the platform allowing scam advertisements to appear in crypto community channels may increase the risk of users encountering malicious links and fraudulent activities.
Odaily news: The Zcash Foundation has announced the release of Zebra 4.5.1 version update to fix a consensus-critical security vulnerability and strongly recommends that all node operators upgrade immediately. The vulnerability, identified as GHSA-2prc-cj5x-4443, involves a sigops (signature operation count) counting error in P2SH transactions, which could lead to potential consensus fork risks. This fix corrects an incomplete patch in the previously released 4.5.0 version, which was just released yesterday.The Zcash development team stated that the issue stems from discrepancies in sigop counting logic between different implementations, which could cause nodes to produce different results when verifying transactions, thereby affecting consensus consistency on the chain. The fix resolves this by reverting and adjusting the Rust implementation logic to ensure alignment with the expected protocol behavior.The Zcash Foundation emphasized that there is currently no workaround for this issue, and upgrading to 4.5.1 is the only method to ensure nodes remain on the correct chain and avoid potential fork risks.
The Zcash Foundation officially announced the release of Zebra 4.4.0, which addresses multiple critical consensus-level security vulnerabilities. All node operators are strongly advised to upgrade immediately. The vulnerabilities include a denial-of-service (DoS) flaw that could permanently halt the discovery of new blocks; a signature operation (sigop) counting error in block validation that may cause consensus divergence; abnormal handling of transparent transaction signature hashes; and a memory allocation amplification attack risk. The Zcash Foundation stated that some of these vulnerabilities could cause Zebra nodes to accept blocks rejected by zcashd, potentially triggering a chain fork. Without timely upgrades, nodes risk interruption of block discovery, consensus forks, and amplified resource consumption. No alternative mitigations are currently available.