GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Liquid Network Vulnerability Disclosure Handling Sparks Public Dispute Between Samson Mow and Bitcoin Red Team

Bitcoin News posted on X stating that Samson Mow and Bitcoin Red Team researcher Calle are engaged in a public dispute over whether security warnings related to a Liquid Network exploit were properly handled. Calle claims that Blockstream did not act on the Red Team's email, ultimately resulting in a loss of 600 BTC; Mow responded by saying "no email was ignored." Calle stated that once Blockstream restores normal Liquid operations and publishes a post-mortem report, the Red Team will release a full account of the disclosure process. Mow separately warned against blindly trusting AI-generated security reports, saying that unverified fixes could introduce new vulnerabilities, and criticized researchers who prioritize pursuing "clout" over protecting Bitcoin.

Argentine Prosecutor's Office Conducts Specialized Training on Crypto Asset Tracking and Confiscation

According to CriptoNoticias, Argentina's Public Prosecutor's Office (MPF) conducted a specialized training course titled "Virtual Assets: Financial Analysis, Tracking, Detection and Confiscation" via Zoom on August 19 and September 2, 2026, for internal staff, officials, and judges. Led by anti-money laundering specialist Carmen Chena, the curriculum covered digital wallet asset analysis, domestic and international legal frameworks, the cryptocurrency ecosystem, and practical case studies on preservation measures. Previously, Argentina's judiciary had already accumulated extensive experience in cryptocurrency-related cases, including the freezing of 3 million USDT in December 2024 and the 2022 ruling ordering Binance to return stolen BTC.

Ledger Ethereum App Version 1.22.1 Contains Transaction Replacement Vulnerability — Users May Review One Transaction While Signing Another

Odaily News: OneKey Anzen has reproduced the Ledger vulnerability and discovered that Ledger Ethereum app version 1.22.1 contains a transaction replacement vulnerability. When an affected user is attacked, the hardware screen still displays transaction A under review, but the device may sign transaction B, which the user never viewed. OneKey Anzen stated that the issue stems from a race condition between the transaction display logic and the underlying buffer, with the attack requiring the host side to already be compromised by a malicious DApp or intermediary software. Ledger's CTO previously responded that a fix had been rolled out approximately two weeks ago, and users simply needed to update the app. Public information shows that the official tag for version 1.22.2 on Ledger's GitHub appeared on August 24. Ledger's official website states that the issue has been fixed through app-level checksums and SDK-layer patches, with Ledger Secure SDK v26.6.1 released on August 21, and the related apps have been rebuilt and republished. Users need to update the app via Ledger Live — updating only the device firmware will not complete the fix. Ledger stated that there is currently no evidence that this vulnerability has been actively exploited.

Hackers Exploit macOS Screen Sharing Vulnerability to Gain Root Access and Mine Monero

Odaily News: The Dutch National Cyber Security Centre (NCSC) has reported that attackers are exploiting a vulnerability in Apple's macOS Screen Sharing feature to take control of devices and install Monero mining programs. Multiple systems with port 5900 exposed to the internet have been compromised, with attackers gaining root access. The vulnerability, tracked as CVE-2026-65400, has a severity score of 7.1 out of 10. It stems from a state management error in the authentication process, allowing remote attackers to bypass login verification without valid credentials. Public proof-of-concept code has already been circulated. Apple has addressed the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The NCSC advises users to update their systems promptly and avoid exposing the Screen Sharing service directly to the internet. (Decrypt)

French Tax Data Breach Affects Nearly 678,000 People, Potentially Heightening Violent Attack Risks Against Crypto Holders

Odaily News: The French Finance Minister has confirmed that hackers breached the systems of the French Public Finance Directorate in late June and stole taxpayer data belonging to individuals and businesses. According to FrenchBreaches, a platform that tracks cyberattacks in France, this incident affects approximately 678,437 people, roughly 1% of France's population, though the exact number is still under investigation and has not been finalised.The compromised data reportedly includes sensitive information such as names, dates of birth, home addresses, phone numbers, email addresses, tax identification details, and income data. Among those affected, nearly 27,000 individuals had taxable income of at least €100,000, 386 exceeded €1 million, and another 8 surpassed €10 million.Reports indicate that the database has been listed for sale on dark web marketplaces for several thousand euros. The attacker, going by the name ZeroBytes, claims to have extracted the records using an internal search tool before being detected and having access cut off.The incident has raised concerns within the crypto industry, as France has seen a noticeable increase in "wrench attacks" targeting crypto holders in recent years. If high-income individuals' addresses and contact details are exposed, it could provide criminals with a more precise list of targets.

BTCPay Server Temporarily Restricts Public Remote Connections to LND Nodes, Vulnerability Causes Credential Leakage and Fund Theft

Bitcoin payment processing service BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. Attackers exploited a severe vulnerability to obtain credentials and transfer funds. The number of affected operators and the total amount stolen have not yet been disclosed. This restriction affects external wallets such as Zeus that connect via BTCPay Server domains or Tor onion addresses in Docker deployments, but Lightning Network payments can still continue. BTCPay Server stated that remote access functionality will be restored once security is confirmed. BTCPay Server 2.4.2 will install LND 0.21.1 and automatically regenerate macaroon credentials during standard installation. Foundation and Citadel21 have respectively disclosed that funds from their Lightning Network nodes were swept. Foundation stated that hot wallets were not affected, and the specific amounts of losses have not been disclosed.

BitGo CEO Issues Public Challenge to Anthropic, Claims 100 BTC Deposited in Public Address

BitGo CEO Mike Belshe posted on social media stating that rather than hyping the narrative of "creating a hacker monster," it is better to conduct real verification. He stated that he has deposited 100 Bitcoins into a BitGo wallet, made the wallet address public, and issued a public challenge to Anthropic.