GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Galaxy Digital Commits $5 Million to Advance Bitcoin Quantum-Resistance Initiative

According to Decrypt, Galaxy Digital has officially launched the "Bitcoin Quantum Readiness Initiative," with three core pillars including: providing up to $5 million in post-quantum cryptography research grants to developers, publishing specialized research reports through Galaxy Research, and establishing a quantum advisory committee composed of scholars from multiple top universities. The initiative targets "Q-Day"—the critical moment when quantum computers utilize Shor's algorithm to crack Bitcoin's elliptic curve encryption, forge signatures, and steal wallet assets. Project Eleven predicts that quantum computers capable of cryptographic threats may emerge as early as 2030, at which point approximately 6.9 million BTC will face exposure risks. The Coinbase Quantum Advisory Committee has also called on developers to immediately initiate migration work. Meanwhile, Trump has signed an executive order setting the deadline for the U.S. federal government to complete post-quantum cryptography migration to December 2031.

Two hackers today spent a total of 11.718 million DAI to purchase 6,454.7 ETH

: According to monitoring by on-chain analyst Yu Jin, the hacker (0x18B...E66) who stole funds from a Coinbase user spent 7.378 million DAI early this morning to buy 4,049.7 ETH at a price of $1,822. Meanwhile, the address (0xa13...628) that received ETH from Tornado Cash last November had previously transferred out 4,978 ETH and exchanged them for 16.294 million DAI at a price of $3,273. Today, two hours ago, this address spent 4.34 million DAI to repurchase 2,405 ETH at a price of $1,804.

CertiK Hack3D Report: Web3 Losses Exceed $1.3 Billion in the First Half of 2026, Attacks Accelerate Towards High-Value Targets

Odaily, Web3 security firm CertiK has released the "Hack3D: First Half of 2026 Report." The report shows that the Web3 ecosystem experienced 344 security incidents in the first half of 2026, with cumulative losses of approximately $1.32 billion. Although this figure represents a 46.8% decrease compared to the same period last year, excluding the impact of the $1.45 billion security incident involving Bybit, the scale of losses in the first half of this year actually increased by approximately 28% year-on-year, indicating that the overall security environment in the industry has not materially improved.The report points out that wallet theft has become the attack type causing the greatest financial loss, accounting for approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks fell by more than 50% year-on-year, the loss amount only decreased by approximately 10.8%, reflecting that attackers are shifting towards high-net-worth individuals and institutional targets, carrying out more targeted high-value attacks.Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running legacy smart contracts that lack re-audits. The report also shows that mega-attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents alone causing approximately $577 million in losses, accounting for 44% of the total losses in the first half of the year. Looking at the number of incidents, the impact of single attacks, and the changing attack patterns, the Web3 industry is facing more complex and continuously escalating security challenges.

Trump’s Financial Disclosures Fuel Crypto Ethics Controversy; Democrats Demand Inclusion of Restrictive Clauses

U.S. President Trump’s newly released 927-page financial disclosure document reveals income including hundreds of millions of dollars in crypto-related earnings. Among these are millions of dollars in revenue linked to World Liberty Financial, the DeFi project launched by the Trump family in 2024. This disclosure has heightened the urgency of congressional negotiations over ethics provisions within the Clarity Act, the crypto market structure bill.Currently, bipartisan lawmakers are negotiating the Clarity Act, which aims to establish the first comprehensive federal crypto regulatory framework in the United States. A key focus of the negotiations is whether to include ethics restrictions preventing the President, Vice President, members of Congress, and other federal officials from profiting from digital assets while in office.Following the document's release, Democratic lawmakers reiterated that the bill must contain strict ethics clauses. Senator Angela Alsobrooks stated that such restrictions should apply to the President, Vice President, and all members of Congress. She noted that ordinary Americans should benefit from digital assets in a fair and honest manner, rather than allowing political figures to profit through corruption and institutional loopholes.Senator Kirsten Gillibrand also indicated that both parties are still advancing stringent ethics reforms, proposing to prohibit the President, Vice President, and lawmakers from using crypto assets for personal gain. Meanwhile, Elizabeth Warren argued that if the Clarity Act fails to prevent the President, members of Congress, and their families from profiting from the crypto industry, the bill would further fuel controversies surrounding Trump-related crypto corruption.Republicans, for their part, stated that ethics clauses remain part of the bipartisan negotiations. With the July window for advancing the Clarity Act approaching, the disclosure of Trump family crypto income could become a key variable influencing the final text of the bill and the level of Democratic support.

The U.S. partially eases export restrictions on Anthropic, marking a new phase of tiered AI regulation liberalization

the U.S. Department of Commerce has made differentiated adjustments to export restrictions on frontier models from AI company Anthropic, signaling that global AI regulation has entered a new phase of "tiered liberalization." The policy shows that the official ban on exporting Claude Mythos 5 has been lifted, allowing specific compliant and controlled users to resume using this cybersecurity model. Meanwhile, another high-end model, Fable 5, remains under export restrictions, with related policy consultations still ongoing.Industry analysts indicate that this layered control model—loosening restrictions in some areas while tightening in others—reflects the U.S. balancing act between national security, data sovereignty, and international AI competition. As the global AI race continues to accelerate, specialized models capable of vulnerability exploitation are facing increasingly stringent scrutiny from various countries. Multiple nations have initiated discussions on establishing a unified cross-border regulatory framework for frontier AI capabilities. (Forbes)

Anthropic's Restricted Spillover Effect Emerges: Asian AI Companies Simultaneously Launch Rival Frontier Models

as Anthropic faces export restrictions limiting the global availability of its advanced models, multiple Asian AI companies are accelerating efforts to fill the market gap. Chinese cybersecurity firm 360 Security Technology has reportedly launched an AI tool called "Tulongfeng," claiming it can directly compete with Anthropic's high-end model "Mythos." Meanwhile, its more restricted version, "Fable 5," also falls within the scope of relevant export controls.In the same week, Japanese AI startup Sakana AI released a new model named "Fugu," taken from the Japanese word for pufferfish. It is positioned as a frontier model designed for agents. The company stated that the model's capabilities are comparable to Fable 5 and Mythos Preview, and it supports coordinating multi-model calls via API to enable agent orchestration.Sakana AI emphasized that the timing of this release and the U.S. export restrictions are "purely coincidental," but the product's official website still clearly promotes "providing frontier capabilities without the risk of export controls." Company co-founder David Ha stated that future AI development will shift from competition among single large models to "model orchestration systems," adding that "access can disappear at any time, and distributed intelligence is a realistic hedge against the risks of centralization."On the other hand, Chinese 360 founder Zhou Hongyi views AI vulnerability detection capabilities as a "national strategic asset" and warns of the so-called "one-way transparency" risk, where certain entities may monopolize advanced security capabilities.According to reports, the U.S. export restrictions on Anthropic's advanced models have been in place for about two weeks. Against this backdrop, Asian manufacturers are accelerating the launch of local alternatives. Although some companies still emphasize the importance of American models in the Asian market, the trend of differentiation within the regional AI ecosystem has begun to emerge. (TechCrunch)

Taiko Releases Security Incident Update: Launches Fix Testing, Full Collateral for Bridged Assets to Be Restored Before Reopening

Ethereum Layer 2 project Taiko has released the latest update on a security incident, stating that this incident will not result in any user fund losses. Currently, bridged assets are under-collateralized, and the team will complete supplementary collateral for all assets before reopening the bridge, ensuring that each user's balance is supported on a 1:1 basis, identical to the state before the incident. Since the security incident occurred, cautious measures have been taken, including controlling the scope of impact, determining the root cause, and collaborating with the board to develop a plan to protect user assets.Furthermore, the CEO of Taiko has submitted a formal report to relevant authorities in Singapore, and the team will fully cooperate in tracing the responsible parties. Users are currently not required to take any action. The completed fix is now being tested, and Taiko will reopen the chain and bridge services as soon as it is deemed safe. Meanwhile, users are reminded to be vigilant against scams. The Taiko team will not proactively message users, and there are no claim or refund websites. Any links offering such services are fraudulent.

Multiple law enforcement agencies jointly oppose key provisions of the Clarity Act; negotiations continue

According to Crypto in America, the National District Attorneys Association, the National Association of Assistant U.S. Attorneys, the International Association of Chiefs of Police, and the National Sheriffs’ Association jointly sent a letter to Acting Attorney General Todd Blanche and Patrick Witt, Executive Director of the White House Crypto Council, expressing strong opposition to Section 604 of the “Clarity Act”—the Blockchain Regulatory Certainty Act (BRCA). Law enforcement groups argue that this provision could create regulatory loopholes exploitable by criminals for illicit activities including drug trafficking, fraud, child exploitation, sanctions evasion, and terrorist financing. Meanwhile, cryptocurrency-backed candidates achieved sweeping victories in primary elections across Maryland, New York, and Utah. Fairshake—a pro-crypto super PAC—has collectively spent over $7.6 million supporting these candidates, including $5.5 million backing Adrian Boafo, the candidate for Maryland’s 5th congressional district. Miller Whitehouse-Levine, founder of the Solana Policy Institute, warned that August 7, 2026, may be the final window for Congress to pass cryptocurrency market structure legislation. He stated that the industry is willing to make limited revisions to the BRCA provisions to address law enforcement concerns—but firmly opposes any fundamental changes that would weaken the core protections enshrined in the provision. Additionally, the House Financial Services Committee held a hearing on “The Future of Payments” the same day.

Taiko Updates on Theft Investigation: Root Cause Identified, Cooperating with CEX and Security Firms to Recover Funds

Odaily Taiko officially posted on X, stating: "We have identified the root cause of the attack and are currently developing a fix patch to restore the blockchain's online operation as soon as possible. Meanwhile, we are working closely with major exchanges and security partners to track and freeze the hacker's assets. The remaining funds in the cross-chain bridge are currently safe, and we will announce the next steps in an upcoming update. To focus on fixing the vulnerability and protecting user assets, we will pause updates for a few hours."Previously, Taiko's cross-chain bridge was attacked, with potential losses reaching up to $1.7 million.

Anthropic Model Safety Controversy Escalates, Amazon Accused of Being the "Hidden Force" Triggering Regulatory Intervention

the U.S. government's export controls and access restrictions on Anthropic's models, Fable 5 / Mythos 5, were partly driven by Amazon's cybersecurity research and AWS CEO Andy Jassy's communications with the White House.It is understood that research submitted by Amazon indicated that through a series of prompt tests, researchers could induce Fable 5 to output sensitive information potentially usable for cyberattacks, raising security concerns. Subsequently, Andy Jassy reported these findings to the U.S. government level, prompting the White House to implement further restrictions, including banning foreign users from accessing the model.Meanwhile, former U.S. Commerce Department official Kate Koren revealed that the White House's existing policy stance towards Anthropic may have also influenced this decision. This is because Anthropic has disagreements with the White House over the boundaries of AI safety, including refusing to use its models for mass surveillance or lethal autonomous weapons systems. Although the two sides had eased tensions and expanded cooperation earlier this year, this incident could reignite strained relations between them. (The Wall Street Journal)

Humility Security Incident Update: $36 Million Stolen, Police Investigation Launched to Recover Funds

Humility Protocol released a security incident update on the X platform, stating that its H token suffered a coordinated attack on the Ethereum and BSC chains yesterday, with confirmed losses exceeding $36 million in stolen and dumped assets.Preliminary investigations indicate the incident originated from a compromised employee computer, which led to the leakage of private keys for the multi-signature wallet controlling the Hyperlane Bridge ProxyAdmin. Specifically, the attacker obtained 3 out of 6 private keys of the Gnosis Safe wallet on the Ethereum chain, transferred ownership of the ProxyAdmin to a wallet under their control, upgraded the bridge contract to a malicious implementation, and subsequently transferred approximately 141.2 million H tokens in a single transaction.Simultaneously, the attacker also gained control of 3 out of 5 private keys of the Safe wallet on the BSC chain, took over the ProxyAdmin using the same method, deployed a malicious contract with unlimited minting functionality, and minted 200 million H tokens in two separate transactions to their own wallet.Humility stated that it has suspended all deposit and withdrawal operations on the affected bridge services and is collaborating with partners such as exchanges to mitigate losses. Meanwhile, it is cooperating with the police investigation and attempting to recover part of the stolen funds.

Humanity hacker has minted 300 million H and cashed out $34 million

According to monitoring by on-chain analyst Ember, the "private key leak" has allowed the minting and dumping of H to continue for 13 hours. The so-called "hacker" is still able to mint H on the BSC chain and sell it off, draining every last cent from the pools. The "hacker" has minted 300 million H and sold a total of approximately 450 million H, cashing out $34 million (ETH+BNB). The H pool on BSC has been drained to just $13 in liquidity, and the price of H has plummeted 99.9% to $0.0009. Meanwhile, the perpetual contract price on CEX stands at $0.09, a 100x difference. In essence, they have de-pegged into two unrelated tokens.

Immunefi: DeFi Attack Losses Down 74% from 2022 Peak, AI Accelerates Security Arms Race

Web3 security company Immunefi's latest "2026 Ecosystem Vulnerability Audit Report" shows that losses from DeFi protocol hacks have fallen 74% from a peak of $2.62 billion in 2022 to approximately $680.3 million in 2025.The report notes that the median loss per individual attack has also significantly decreased, from $6 million in 2022 to $1.5 million in 2025, reflecting an overall improvement in security standards. Meanwhile, the share of bridge exploits in total DeFi losses has dropped sharply from 73% in 2022 to 3% in 2025, and the proportion of flash loan attacks has fallen from 54% to less than 1%.The proportion of risks at the infrastructure level (such as private key leaks and database attacks) also decreased from 30.7% in 2022 to 10.3% in 2025. Immunefi stated that this reflects continuous optimization in oracle design, reentrancy attack protection, and access control standards, making the DeFi ecosystem "generally becoming safer."However, the report also notes that losses slightly rebounded to $680.3 million in 2025, primarily due to increased complexity in multi-chain systems and a few high-severity incidents. At the same time, the number of independent security incidents continues to rise, indicating the attack surface is still expanding. (The Block)

THORChain: Asgard Vault Breach Results in Approximately $10.7 Million Loss; User Cross-Chain Transactions Unaffected for Now

According to Odaily, THORChain has issued an emergency announcement stating that after discovering a suspected breach of an Asgard vault, the network has suspended trading operations to respond to the security incident. Preliminary information indicates that user funds remain unaffected, with losses primarily concentrated on the protocol's own capital.The official statement noted that the system automatically detected anomalous behavior and halted signing operations, thereby alerting the community and preventing further asset outflow. The investigation is currently ongoing to determine the root cause of the vulnerability and the full scope of the impact.Known information indicates that this incident involves one of the six Asgard vaults, with estimated losses of approximately $10.7 million. Meanwhile, staked RUNE on the affected nodes has been slashed due to a penalty mechanism triggered by unauthorized outgoing transactions. The network has paused churn operations and delayed the launch of new chains and related features until system stability is restored.THORChain stated that no user cross-chain transactions have been affected so far and has requested node operators to thoroughly inspect their infrastructure, secure key management, and anomalous behavior, and to submit relevant logs to assist the investigation.

CertiK CEO: AI Is Turning DeFi Defense into an "Unfair Game"

Ronghui Gu, co-founder and CEO of CertiK, stated that AI tools are exacerbating the imbalance between attack and defense in DeFi security, making it easier for attackers to discover vulnerabilities and replicate attack paths across different protocols.He pointed out that the DeFi security situation was particularly severe in April of this year, with only 3 days that month free from hacker attacks, resulting in cumulative losses exceeding $690 million for DeFi protocols. Excluding the Bybit attack in February 2025, April has become the month with the highest losses from DeFi hacks since March 2022.Ronghui Gu believes that attackers can concentrate significant computing power to repeatedly test a single protocol, whereas security companies need to serve multiple clients simultaneously with dispersed resources, putting the defense side at a natural disadvantage. Meanwhile, the focus of recent attacks is also shifting from smart contract vulnerabilities to operational security and weak points in the supply chain.He emphasized that even if AI fails to find vulnerabilities over an extended period, it does not prove the code is completely secure; under current technical conditions, formal verification remains a more reliable method for ensuring security.

Gate Research: Crypto Market Warms Up in April with RWA and On-Chain Capital Flow in Focus

Odaily Odaily News Gate Research recently released its "April 2026 Cryptocurrency Market Review" report, indicating that the overall cryptocurrency market saw a volatile upward trend in April, with total market capitalization significantly higher than in March. BTC and ETH ETF trading volumes maintained high volatility overall. The report shows continued divergence in activity across major public chain ecosystems. Solana's daily transaction volume remained in the range of approximately 90 million to 110 million transactions, maintaining its leading position.Regarding trending sectors, the report notes that Pokemon TCG RWA has become one of the fastest-growing on-chain RWA sub-sectors, entering a second explosive growth phase in April. Major trading platforms saw monthly trading volumes exceed $220 million, with weekly revenue briefly approaching $6 million, setting new historical records. Meanwhile, Aave experienced its most severe liquidity crisis ever in April, with TVL outflows reaching tens of billions of dollars within a few days and net outflows exceeding $9 billion for the entire month.In terms of fundraising and security incidents, the Web3 industry completed 51 financing rounds in April, totaling approximately $834 million, with capital further concentrating on leading financial and infrastructure tracks. Among these, Payward ranked first for the month with a $200 million financing round. On the security front, Web3 security incidents in April resulted in losses of approximately $306 million, a month-over-month increase of about 858%, primarily driven by a single cross-chain infrastructure attack on Kelp DAO worth approximately $293 million. The report suggests that against the backdrop of a recovering market, on-chain activity and capital liquidity are both increasing simultaneously. However, the security risks associated with cross-chain infrastructure and high-leverage protocols remain worthy of continued attention.

BAYC floor price doubles within a month, signaling signs of NFT market recovery

According to CoinDesk, the floor price of Bored Ape Yacht Club (BAYC) NFTs has risen from approximately 5 ETH to over 10 ETH in the past month, while ApeCoin (APE) rebounded from below $0.10 to around $0.16 during the same period, with trading volume notably expanding. Meanwhile, repeated security vulnerabilities and persistently declining yields in the DeFi sector have driven some capital toward the NFT market. The financialization trend of NFTs is also intensifying: a recent $2.8 million loan collateralized by a CryptoPunk attracted widespread attention, with the lender expected to earn roughly $138,000 in interest over 90 days. Blue-chip collections such as Pudgy Penguins have also strengthened concurrently, and market expectations surrounding a potential token launch by OpenSea have further boosted sentiment.

LayerZero: Multi-Sig Security Mechanism Updated

LayerZero Labs posted on platform X, stating that the internal RPC used by LayerZero Labs had been attacked by the Lazarus Group over the past three weeks, compromising the true source of its DVN (Decentralized Verifier Network). Meanwhile, external RPC providers experienced DDoS attacks. The incident affected 0.14% of applications and approximately 0.36% of asset value. LayerZero Labs stated that assets are currently secure, and over $9 billion in funds have been bridged through the protocol since April 19.In response to the security risk, LayerZero Labs has ceased providing services for its DVN in a 1/1 configuration. Default configurations for all pathways will migrate to a multi-DVN model of at least 3/3 or 5/5 signatures. Additionally, regarding an incident from three years ago where a multi-sig holder mistakenly used a hardware wallet for personal transactions, LayerZero Labs has removed that signer and replaced the wallet, while developing a custom OneSig multi-sig system. LayerZero Labs advises developers to lock configurations to avoid reliance on default settings and plans to launch an asset management platform, Console, to enhance security monitoring.

TrustedVolumes: Stolen Amount Approximately $6.7 Million, Willing to Engage in Constructive Communication with the Attacker

1inch market maker TrustedVolumes confirmed on the X platform that it had been attacked, disclosing that the stolen funds are currently held in three addresses, with a total amount of approximately $6.7 million. Two of the addresses each hold about $3 million in assets, while another address holds approximately $700,000 in assets. Meanwhile, TrustedVolumes expressed its willingness to engage in constructive communication with the attacker regarding a bug bounty and mutually acceptable solutions.

North Korea denies involvement in crypto theft allegations, accused of stealing over $570 million this year

North Korea has denied allegations of its involvement in cryptocurrency theft, calling the claims "absurd slander" and a "political tool." The statement, issued by state-run media, emphasized that necessary measures will be taken to safeguard national interests. However, data from blockchain analytics firm TRM Labs shows that in the first four months of 2026, hacker groups linked to North Korea have stolen approximately $577 million, accounting for about 76% of global crypto theft losses during the same period. This includes two major attacks on KelpDAO (approximately $292 million) and Drift Protocol (approximately $285 million).TRM pointed out that the attacks are primarily associated with the Lazarus Group and its sub-organizations. Since 2017, the cumulative scale of crypto theft linked to North Korea has exceeded $6 billion.U.S. and international agencies widely believe that such funds are used to support military and missile programs. Meanwhile, the U.S. Treasury Department has recently imposed sanctions on relevant individuals and entities, targeting approximately $800 million in illicit fund flows in 2024. (The Block)