GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Approximately $30 million stolen in the first 10 minutes, Coldcard vulnerability attacker prioritized highest-value wallets first

Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.

PancakeSwap's OLPC/LABUBU trading pool was attacked, with approximately $1.1 million in assets stolen

according to PeckShield monitoring, the OLPC/LABUBU liquidity pool on BNB Chain's PancakeSwap was attacked. The attacker stole approximately $1.1 million worth of assets. After the incident, the attacker cross-chain transferred the stolen funds to Ethereum and subsequently deposited 633.4 ETH into the mixing protocol Tornado Cash. Additionally, the attacker sent 0.0221 BNB and 0.0411 ETH to a deprecated address. Relevant attack details and fund flows are still under continuous tracking.

Trading Protocol’s treasury attacked, suffering losses of approximately $398,000

According to on-chain analyst PeckShield (@PeckShieldAlert), the YieldCore-3rd-deal treasury under Trading Protocol was attacked, resulting in losses of approximately $398,000. The attack exploited a vulnerability in the contract—specifically, a missing caller permission check—which allowed the attacker to bypass the authorization mechanism and withdraw all funds from the treasury. Relevant on-chain transaction records have now been disclosed.