GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Senator Lummis' X Account Hacked, Fake Solana Meme Coin Scam Deleted Within Five Minutes

According to BeInCrypto, the official verified X account of U.S. Senator Cynthia Lummis was hacked on July 29. The account briefly posted a fake Solana Meme coin promotion post named $USA Token, featuring a pump.fun minting link. The post was deleted within approximately five minutes, accumulating around 5,600 views and 37 replies during that period. Crypto community users quickly issued warnings, and there are currently no records of financial losses. Lummis's office had not released any statement as of press time. The timing of this incident is sensitive, coinciding with the stalemate of the "Digital Asset Market Transparency Act" (CLARITY Act) championed by Lummis in Congress.

AmericanFortress 推量子安全钱包方案无需迁移资金

区块链安全公司 AmericanFortress 提出新加密方案,可保护现有 BTC、ETH、SOL 钱包免受未来量子攻击,用户无需转移资金或更改地址。

In the first half of 2026, crypto hack losses exceeded $1 billion, with Ethereum and Solana leading the losses.

: A security report for the first half of 2026 released by on-chain security platform Blockaid shows that the crypto industry suffered losses exceeding $1 billion during the period, with a record number of hacker incidents in six months. Blockaid tracked 212 security incidents, including a single attack on KelpDAO that resulted in a loss of $292 million. Ethereum and Solana were the networks with the largest amounts of stolen funds during the period, with losses of approximately $332 million and $326 million, respectively. Blockaid stated that the number of high-threshold attacks in the first half of 2026 was 3.4 times that of the entire year of 2025. Ethereum incidents were primarily driven by code vulnerabilities, with attack vectors including bridge and smart contract exploits, unauthorized access to privileged accounts, and market manipulation. Solana's losses increased significantly from approximately $127 million in 2025, with over 98% of losses stemming from key leaks, primarily involving incidents related to Drift Protocol and Step Finance.

Drift Protocol $285M Attacker Moves Funds via Tornado Cash After 3-Month Dormancy

that, according to Onchain Lens monitoring, after a $285 million attack on Drift Protocol on Solana in April, the attacker has begun moving funds through Tornado Cash following a 3-month dormant period. The attacker is rapidly depositing ETH into the Tornado Cash Router in batches of 100 ETH, with multiple transactions occurring per minute.

Approximately $1.1 million extracted, Allbridge Core exploited on Solana

Odaily reports, according to monitoring by Onchain Lens, Allbridge Core has been exploited on Solana. The attacker borrowed $1.12 million USDC via a Kamino flash loan, then rapidly executed a USDC/USDT swap, distorting the stablecoin pool ratio of Allbridge. They withdrew liquidity at the manipulated exchange rate and repaid the flash loan within the same transaction, extracting approximately $1.1 million in funds. The funds were subsequently mixed through a privacy protocol. The maximum single withdrawal from Allbridge was $2.24 million USDC. Further analysis of the vulnerability exploit and the affected pools is ongoing.

DeFiTuna Suffers Attack, Losing 569,600 USDC

CertiK published an analysis stating that the Solana ecosystem protocol DeFiTuna was attacked on July 16, with losses of approximately 569,601 USDC. The attacker first created an extremely low-liquidity TUNA/USDC pool and swapped borrowed USDC into the pool via Jupiter routing. Since only a minimal amount of TUNA was ultimately obtained, the protocol experienced rounding down during the position asset value calculation, causing the total assets to be recorded as 0, thereby incorrectly passing the health and solvency checks.

Across Protocol Attacked on Solana, User Funds Unaffected

Across Protocol stated that it suffered an attack on Solana at approximately 5:30 UTC today. The team stated that user funds are safe, no users were affected, and all cross-chain bridge transactions have been completed. Currently, Solana deposit functionality has been paused, while other parts of the protocol remain unaffected.

Multicoin Capital Partner Claims Crypto Market Has Bottomed, Remains Bullish on SOL, Hyperliquid, and ZEC

: Tushar Jain, Managing Partner of Multicoin Capital, stated that the crypto market has bottomed out and entered a turning point. Market sentiment has truly hit rock bottom, recent major hacking incidents and other news have not triggered large-scale sell-offs, application adoption rates continue to rise, and there is a decoupling between price and fundamentals. He maintains a long-term bullish outlook on Solana, believing SOL represents the correct architecture for spot trading and tokenized securities. Simultaneously, he is bullish on Hyperliquid's leading position in the derivatives space and currently holds significant positions in both.Regarding ZEC, he stated that Multicoin has accumulated a considerable proportion of its supply and believes it represents the industry's return to "cypherpunk" values, with the potential to enter the top five by market cap. In terms of position management, he adopts a "three-way split" strategy: immediately buying the first third, dollar-cost averaging the second third, and reserving the final third as flexible capital to cope with significant market downturns. During the Zcash code vulnerability incident, after the team observed and confirmed no hacker exploitation, they significantly increased their positions.

A Solana OG had 181,000 SOL stolen, and the hacker swapped them for 7,918 ETH

According to Lookonchain monitoring, a Solana OG had 181,000 SOL stolen. The hacker sold all 181,000 SOL, bridged the funds to Ethereum, and exchanged them for 7,918 ETH, worth $14.2 million.

ZachXBT: Suspected Attack on Early Solana Whale, Approximately 180,900 SOL Transferred

on-chain detective ZachXBT disclosed in a personal channel post that a whale suspectedly suffered an asset theft a few hours ago, with approximately 180,900 SOL (worth about $14.2 million) being abnormally transferred. ZachXBT stated that he collaborated with another on-chain security analyst, Specter, to analyze the related transactions, identifying unusual unstaking activities and fund transfers from the Solana network across to Ethereum. It is reported that the address belongs to one of Solana's early participants and is associated with the Genesis block allocation. This unusual operation involves a large amount of SOL assets. The specific attack method, destination of the funds, and whether it was due to a private key leak have not yet been confirmed.

BonkDAO 遭恶意治理提案攻击,约 2000 万美元 BONK 被盗

据官方消息,BonkDAO 表示,其 DAO 金库 因一项恶意治理提案遭攻击,约价值 2000 万美元的 BONK 代币被盗。调查显示,相关地址曾在提案发起前通过交易所钱包购买 BONK。BonkDAO 正与交易所、跨链桥及 Solana 基金会合作处理此事,执法部门已获通知,后续将继续推进资金追回及责任追查。

After 5 months of silence, Step Finance attacker sells $21.4 million in SOL and transfers to Tornado Cash

According to Lookonchain, the Step Finance attacker, after 5 months of inactivity, sold all 261,933 SOL, worth $21.4 million. The funds were then bridged to Ethereum to purchase 12,128 ETH, which were subsequently deposited into Tornado Cash to launder the money.

StarkWare Releases Starknet Quantum Resistance Roadmap

zero-knowledge scaling company StarkWare has released a Starknet quantum resistance roadmap, stating that the roadmap is divided into three phases to address the risk of future quantum computing attacks. StarkWare CEO Eli Ben-Sasson stated that Starknet can leverage its architectural advantages to achieve quantum resistance, as its underlying cryptography is based on zero-knowledge STARK proofs. According to reports, the first phase of the roadmap includes replacing part of the existing secure mathematical mechanism, Pedersen hash, with a quantum-resistant version, and adding quantum-resistant signatures; the second phase focuses on migration tools, upgrading existing smart contracts without requiring developers to manually rebuild applications; the third phase involves dependencies that Starknet cannot solve alone, primarily relying on Ethereum's quantum upgrade roadmap. Circle, Ethereum, Solana, Tezos, and Algorand have all proposed quantum resistance roadmaps. (Cointelegraph)

Multiple law enforcement agencies jointly oppose key provisions of the Clarity Act; negotiations continue

According to Crypto in America, the National District Attorneys Association, the National Association of Assistant U.S. Attorneys, the International Association of Chiefs of Police, and the National Sheriffs’ Association jointly sent a letter to Acting Attorney General Todd Blanche and Patrick Witt, Executive Director of the White House Crypto Council, expressing strong opposition to Section 604 of the “Clarity Act”—the Blockchain Regulatory Certainty Act (BRCA). Law enforcement groups argue that this provision could create regulatory loopholes exploitable by criminals for illicit activities including drug trafficking, fraud, child exploitation, sanctions evasion, and terrorist financing. Meanwhile, cryptocurrency-backed candidates achieved sweeping victories in primary elections across Maryland, New York, and Utah. Fairshake—a pro-crypto super PAC—has collectively spent over $7.6 million supporting these candidates, including $5.5 million backing Adrian Boafo, the candidate for Maryland’s 5th congressional district. Miller Whitehouse-Levine, founder of the Solana Policy Institute, warned that August 7, 2026, may be the final window for Congress to pass cryptocurrency market structure legislation. He stated that the industry is willing to make limited revisions to the BRCA provisions to address law enforcement concerns—but firmly opposes any fundamental changes that would weaken the core protections enshrined in the provision. Additionally, the House Financial Services Committee held a hearing on “The Future of Payments” the same day.

Opinion: Trump Signs Quantum Security Executive Order, Potentially Boosting Bitcoin Post-Quantum Security R&D

US President Trump signed two executive orders on Monday aimed at accelerating the nation's quantum computing capabilities and advancing the migration of government systems to post-quantum cryptography. While the orders do not directly mention Bitcoin, industry insiders believe this could benefit blockchain post-quantum security research and development.The two executive orders focus on defending against advanced cryptographic attacks and driving the frontier of quantum innovation. This includes a clear timeline: advancing quantum sensor construction by September 2028, and requiring federal high-value assets and high-impact systems to complete their post-quantum cryptography migration by the end of 2031.Alex Pruden, CEO of Project Eleven, stated that this means the US government will allocate funds and time to achieve post-quantum security goals. It may also extend these requirements to the entire federal contractor system, not just government agencies, thereby accelerating the practical application of post-quantum cryptographic technology.This policy comes amid growing attention within the blockchain industry to quantum threats. The Ethereum Foundation, Solana Foundation, and others have already begun advancing post-quantum security R&D, while the Bitcoin community is also discussing potential risks. Some Bitcoin held in publicly exposed addresses is considered vulnerable to private key derivation attacks once sufficiently powerful quantum computers emerge.Pruden noted that this executive order sets a clear deadline of 2031 for the adoption of post-quantum cryptography, which is more enforceable than the previous US government guidance which only proposed phasing out traditional cryptographic systems by 2035. For Bitcoin and the broader crypto industry, government-level investment in post-quantum security could accelerate the maturation of related tools, standards, and migration pathways.

Raydium old liquidity pool suspected of being attacked, approximately $1.34 million in assets stolen

blockchain security analyst Specter posted on X platform, stating that an old liquidity pool of the Solana DeFi protocol Raydium is suspected of being attacked, with the attacker stealing approximately $1.34 million in assets, mainly including USDC, RAY, and wSOL. Currently, the hacker has transferred the stolen funds to Ethereum via a bridge and subsequently deposited them into Tornado Cash for mixing.

Drift Protocol Launches Full Rebuild After North Korean Hacker Attack, Enlists Top-Tier Security Team to Accelerate Platform Post-Mortem

According to Drift’s official announcement, the Drift Protocol released its latest recovery update on June 3, 2026. An independent forensic investigation conducted by cybersecurity firm Mandiant has confirmed that the prior attack against Drift was carried out by the North Korean threat group UNC6862, whose tactics closely align with those historically employed by North Korean state-sponsored hacking operations. On the rebuilding front, Drift announced the appointment of Noah Prince—former Engineering Lead of the Helium Protocol—as Protocol Lead, who will spearhead codebase hardening and platform security architecture redesign. Additionally, former members of the Gauntlet team have been brought on board to conduct margin engine reviews, optimize funding rates and market parameters, enhance liquidation mechanisms, and implement continuous risk monitoring. Drift plans to relaunch with “security-first” as its core principle, repositioning itself as Solana’s largest USDT-perpetuals exchange. With support from strategic partners including Tether, Drift will establish a dedicated recovery pool funded by platform revenues to compensate users for losses. Further details regarding the recovery mechanism and timeline will be disclosed progressively.

SlowMist Discloses Cross-Registry Supply Chain Attack Targeting Crypto and AI Developers

According to on-chain analyst PeckShield (@PeckShieldAlert), SlowMist’s threat intelligence system MistEye has detected a cross-registry supply chain attack targeting developers. Malicious packages have spread across three major registries—npm, PyPI, and Crates.io—comprising over 34 malicious packages and more than 384 related versions. The attack targets developer communities in cryptocurrency, DeFi, Solana, Sui/Move, and AI. It may lead to the theft of cryptocurrency wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, and other sensitive developer information. Some malicious payloads also attempt persistence via mechanisms including `.cursorrules`, `CLAUDE.md`, Git hooks, cron, systemd, and SSH. SlowMist recommends immediately removing affected packages, isolating compromised systems, rotating exposed credentials, rebuilding CI environments and developer machines from clean images, and conducting comprehensive reviews of GitHub, cloud, SSH, and wallet-related activities.

TrapDoor Cryptocurrency Theft Campaign Spans npm, PyPI, and Crates.io, Involving Over 34 Malicious Packages

According to research by security firm Socket Security, a cryptocurrency-stealing supply chain attack dubbed “TrapDoor” spans npm, PyPI, and Crates.io, involving over 34 malicious packages and 384 related versions and artifacts. The attack targets cryptocurrency, DeFi, Solana, Sui, Move, and AI developers. Attack samples can steal sensitive information including SSH keys, wallet data, AWS credentials, GitHub tokens, browser data, and environment variables. Specifically, npm packages execute the shared payload `trap-core.js` via the `postinstall` hook; PyPI packages execute remote JavaScript upon import; and Crates.io packages steal local keystores via `build.rs`. Socket has flagged all related packages as malicious and reported them to the respective package registries.

A hacker organization has made over $14 million through token scams and X account hijackings

on-chain analyst Specter stated that the hijacking incidents of investor Keith Gill, Matt Furie, and WinRAR accounts on the X platform are all linked to the same hacker organization. This organization has accumulated over $14 million in profits by hijacking accounts to promote tokens and conducting cross-chain money laundering, with funds flowing through five chains: Solana, BNB Chain, Ethereum, Tron, and Hyperliquid.Specter claims the organization may also be connected to a $2.45 million wstETH phishing attack in 2024. The investigation found that hackers used compromised accounts to issue Pepe imitation tokens, incorporating a built-in 2% automatic fee mechanism to generate profits; related fund flows are associated with the bnbshare.fun platform and multiple Solana, Tron, and Ethereum addresses. Analysis also showed that several tokens (including USOR, VDOR, DROID, WCOR, UGOR) were used to inflate market caps before being dumped to zero.