GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Gnosis Safe Wallet Hacked, $7.8M Worth of rsETH Stolen

According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.

EU's Cyber Resilience Act Takes Effect: Crypto Wallet Vulnerabilities Must Be Reported Within 24 Hours

The EU's Cyber Resilience Act has taken effect. Cryptocurrency hardware and software wallet providers must submit an initial early warning within 24 hours after discovering actively exploited vulnerabilities or severe security flaws in their products, and submit a full notification within 72 hours.Manufacturers must submit a final report within 14 days after corrective or mitigating measures become available; serious incidents must be reported within one month. Companies that violate the relevant regulations may face fines of up to €15 million or 2.5% of global annual turnover, whichever is higher; providing false, incomplete, or misleading information may result in fines of up to €5 million. (Cointelegraph)

Binance Alpha 2.0 will support Nesa (NES) contract replacement, with trading resuming at 16:00 today.

Binance Wallet announced that following a security incident involving the Nesa (NES) token contract, Binance Alpha 2.0 will support NES contract swaps on BNB Smart Chain (BEP20) and provide compensation arrangements for eligible users: first, balances held by users as of 14:51 UTC on August 24, 2026, and maintained through to 04:00 UTC on September 5, 2026, will be swapped to the new contract at a 1:1 ratio; subsequent purchases will not be eligible for the swap and will be refunded separately. Second, users with net purchases of NES between 14:51 UTC on August 24, 2026, and 04:00 UTC on September 5, 2026, will receive an email detailing the specific refund plan within seven working days. Trading of NES on Binance Alpha 2.0 is expected to resume on September 10, 2026, at 08:00 UTC.

Binance Wallet Saves Users from $540 Million in Potential Losses in H1

Odaily News: Binance stated that in the first half of 2026, the Binance Wallet Security Center helped users avoid approximately $540 million in potential losses, filtering about 206 million spam transfers, identifying 4.93 million high-risk transactions, and approximately 996,000 malicious authorizations during the period. Binance noted that AI is being used by attackers to mass-generate malicious code, phishing websites, and fake identities, shifting attacks from broad-based approaches to more targeted fraud.

SlowMist: iOS Safari DarkSword Attack Can Steal Wallet Inputs, Zero-Click Trigger with Six-Vulnerability Chain

Odaily News, According to a disclosure by the SlowMist security team, they have detected an attack campaign disguised as a free VPS service, specifically targeting iPhone Safari browsers running iOS versions 18.4 to 18.6.2. The attackers exploited a chain of six vulnerabilities codenamed DarkSword to form a complete attack sequence, covering WebKit remote code execution, sandbox escape, and kernel read/write operations. This allows them to access app container files and keychain data without user awareness, and record keyboard inputs while wallets such as imToken, TokenPocket, or TronLink are in the foreground.The SlowMist team stated that all six aforementioned vulnerabilities have been patched by Apple, and the current attack constitutes reuse of an n-day vulnerability chain. Merely visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen, and device forensics is still required for confirmation. iOS/iPadOS users are advised to upgrade their systems to version 18.7.3 or 26.3 and above as soon as possible.

Fake GTA 6 Leak Website Can Steal Users' Crypto Wallet Assets

Malwarebytes researchers discovered a website disguised as a Grand Theft Auto VI (GTA 6) fan countdown page that lured users into purchasing the so-called leaked version of the game and loaded a wallet drainer program after users connected their cryptocurrency wallets. The malicious code checks wallet balances, identifies tokens and NFTs, and transfers assets once users approve transactions or grant authorizations.

Fake Claude Desktop App Distributes RevStealer Malware, Capable of Stealing Over 50 Types of Cryptocurrency Wallet Data

According to Cointelegraph, cybersecurity firm Morphisec has revealed that a counterfeit desktop application masquerading as Anthropic’s "Claude Opus 5 Free Desktop" is being leveraged to distribute the Windows malware RevStealer. The malicious program can exfiltrate data from over 50 cryptocurrency wallets, while simultaneously harvesting sensitive information including browser passwords, cookies, VPN configurations, message logs, and screenshots. RevStealer incorporates anti-detection measures, performing system environment checks on the target device prior to execution. If traces of debugging or virtualized environments are detected, it aborts its operation. Additionally, Russian cybersecurity company Kaspersky has disclosed OkoBot, a novel malware framework targeting crypto investors capable of harvesting wallet files, injecting malicious extensions, and capturing wallet application windows to siphon assets.

Hackers Steal Crypto Wallet Data Using Google Docs and Fake Claude AI Pages

According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.

Sparrow Wallet Releases Version 2.5.4, AI-Assisted Code Review Fixes Multiple Security Vulnerabilities

According to Decrypt, privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on August 28. Developer Craig Raw stated that the update was driven by an AI-assisted code review, with the majority of fixes originating from it. This review was prompted by the recent seed generation code vulnerability exploit affecting Coldcard, as well as the release of unrestricted AI models in China, which has significantly enhanced vulnerability scanning capabilities across large codebases. Key updates include: validating the authenticity of transactions returned by Electrum servers, enforcing stricter BitBox02 hardware wallet security requirements (firmware v9.4.0 or higher required), patching local DNS leaks, and masking sensitive credentials in debug logs. Raw noted that there are no indications of any exploits being leveraged, user funds remain secure, and he still advises all users to update at their earliest convenience.

IRS Warns of New Crypto Phishing Scam: Fake Letters Using QR Codes to Steal Wallet Private Keys

Odaily News - The U.S. Internal Revenue Service (IRS) has issued a warning about an advanced email phishing campaign targeting cryptocurrency holders in the United States. Attackers are using forged official tax letters to trick users into scanning malicious QR codes, aiming to steal crypto wallet credentials and private keys.According to reports, the attackers are impersonating the IRS by sending physical letters that create a sense of urgency under the guise of "tax compliance" or "account verification," and include QR codes within the correspondence. Once users scan these codes, they may be redirected to counterfeit websites, potentially exposing wallet login information, recovery phrases, or private keys, ultimately leading to the theft of digital assets.The IRS reminds taxpayers that official agencies will never request users to provide crypto wallet private keys, recovery phrases, or perform similar "wallet verification" procedures through unofficial channels. Cryptocurrency holders should remain vigilant against any suspicious emails or letters that ask them to scan QR codes, connect wallets, or submit sensitive information.As the number of crypto asset holders continues to grow, social engineering attacks targeting digital wallets are on the rise. Regulatory and security agencies are stepping up efforts to raise awareness and prevent such fraudulent activities. (CoinDesk)

Rabby Wallet Fixes Silent Signature Extraction Vulnerability, Users Need to Update Plugin Promptly

As disclosed by security researcher V12 (@v12sec), the Rabby Wallet browser extension contains a silent signature extraction vulnerability that allows attackers to extract wallet signatures via malicious websites without user awareness, thereby draining wallet assets. The conditions required to trigger this vulnerability are extremely limited: users must simultaneously meet two conditions—connecting to a malicious website and manually setting the auto-lock timer to 10 minutes. Other timer settings are unaffected, and the mobile app is also unaffected. Rabby Wallet officially stated that a fix update was released on August 11 following the vulnerability's discovery. No actual exploitation cases have been detected so far. Users are advised to confirm as soon as possible that the extension has been updated to the latest version.

BitBox Discloses Two Severe Hardware Wallet Vulnerabilities, Fixed in Firmware v9.26.5

Odaily News - Bitcoin News announced on the X platform that BitBox has disclosed two severe hardware wallet vulnerabilities, stating there is currently no evidence that these vulnerabilities have been exploited or led to user fund theft. All disclosed issues have been fixed in firmware v9.26.5, and BitBox urges all users to update immediately. An internal security audit uncovered two severe vulnerabilities, along with new details regarding a previously fixed bootloader vulnerability. One vulnerability affecting BitBox Multi devices could allow a malicious host to execute arbitrary code and install malicious firmware on devices that have not yet completed setup. Another vulnerability in Silent Payments could allow an attacker to exploit a malicious host device to redirect funds to unintended addresses, resulting in Bitcoin being locked and potentially enabling extortion attacks. BitBox also disclosed that the previously fixed bootloader vulnerability could allow attackers to trick users into installing malicious firmware capable of stealing funds.

SafePal Discloses Order Plugin Security Incident: Information of Approximately 39,800 Users Exposed; Wallet Private Keys and Seed Phrases Unaffected

Odaily News: Crypto wallet service provider SafePal recently issued a security announcement stating that the company discovered a vulnerability in its order tracking plugin, which led to unauthorized access to certain customer information.SafePal stated that the incident affects approximately 39,798 users, involving customers who placed orders between March 2, 2025, and April 11, 2026. The leaked information includes names, email addresses, shipping addresses, phone numbers, and order-related data such as purchase records.The company emphasized that the incident did not involve users' wallet security data, including seed phrases, private keys, wallet passwords, other wallet credentials, bank account information, payment card numbers, and government-issued identification documents, all of which remain unaffected.SafePal stated that the relevant vulnerability has now been fixed, and additional security measures have been implemented to strengthen the order system's protection. Affected users have received individual notifications via email. Users can also check whether they have been affected through the official page by entering their order number and shipping country.SafePal reminds users to remain vigilant, not to disclose seed phrases, private keys, or passwords to anyone, and to be cautious of phishing emails or fraudulent activities such as impersonated customer service that may arise in connection with this incident.

DefiLlama delays mobile app launch due to phishing impersonators on Apple's App Store

Odaily News, DefiLlama founder 0xngmi, of the crypto data analytics platform, stated that the team spent months asking Apple to remove phishing apps impersonating DefiLlama from the App Store, which delayed the mobile app's launch until all such counterfeit apps had been removed. 0xngmi noted that after the team downloaded one of the malicious apps and documented a small crypto wallet being stolen, Apple removed it within days. In 2024, the App Store also saw counterfeit apps impersonating Rabby Wallet and Curve Finance; in November 2023, a fake Ledger Live app on the Microsoft Store siphoned off $588,000 across 38 transactions. (Cointelegraph)

Operations Ceased, SecondFi Wallet Migration Tool Launches August 13, Affected Asset Recovery Portal Expected by September 10

: Cardano ecosystem wallet project SecondFi has announced the launch of a wallet migration tool and revealed a recovery plan for assets affected by the June 2026 security incident. As the project will cease operations, users are required to migrate remaining assets still held in SecondFi wallets. The migration tool is expected to go live on August 13, supporting the transfer of eligible ADA, Cardano native tokens, and NFTs to new Cardano wallets created with service providers of the users' choosing. Currently, the tool only supports Cardano network assets; non-Cardano assets must be transferred separately through corresponding network and wallet processes. SecondFi stated that the migration tool has passed an independent security assessment by security firm Bitdefender. For affected assets, SecondFi plans to launch a recovery portal before September 10, where users can verify wallet ownership via zero-knowledge proofs (ZK Proof) and submit asset claims. SecondFi reminds users to only rely on information published through official channels, including @secondfiapp, @secondfi_jp, and the official support website, to guard against phishing sites and impersonating accounts.

Sui Co-Founder Leases Factory to Mass-Produce Quantum-Safe Hardware Wallet Cards, Targeting Key Cost Below $10 Per Card

Odaily News: Kostas Chalkias, co-founder and chief cryptographer of Mysten Labs, the development company behind the Sui blockchain, stated that he has leased a dedicated factory at a secret location and plans to scale up production of quantum-safe hardware wallet cards for Sui. The project aims to keep the cost of a single quantum card key under $10, with NFC quantum signing expected to take 1 to 2 seconds. Chalkias noted that the project is being advanced in his personal time outside of work and may include funding to provide cards for users who cannot afford them. The initiative is partly driven by a recent incident involving Coldcard hardware wallets, though the vulnerability was not a quantum attack. Coldcard manufacturer Coinkite disclosed that a firmware vulnerability in Coldcard, traceable to a 2021 update, bypassed the hardware random number chip and generated keys using a predictable software process linked to device serial numbers. Attackers have been moving funds since July 30, with losses climbing to approximately 2,055 BTC, affecting over 7,700 addresses and nearing a value of $130 million. At the protocol level, Sui plans to integrate two quantum-resistant signature schemes approved by the U.S. National Institute of Standards and Technology (NIST), designed for everyday accounts and high-value Move vaults, respectively. Existing accounts can be rotated to quantum-safe keys based on their original recovery phrases, without needing to migrate to new wallets. (Bitcoin.com News)

Dormant Bitcoin Wallet Moves $3.2 Million in BTC After 15 Years

Odaily News – A long-dormant Bitcoin wallet moved nearly 50 BTC, worth approximately $3.2 million, on Thursday. The wallet received 49.97 BTC back in 2011, when Bitcoin was trading at around $10 per coin. The BTC was sent to a SegWit address that has previously transferred Bitcoin to institutional broker FalconX and received funds from wallets linked to Nexo and Prime Trust. The newly transferred BTC has not left this address. The transfer comes amid long-term holders rechecking their old storage setups following a major vulnerability exploit in Coldcard hardware wallets. There is currently no evidence linking the 2011 wallet to this vulnerability.

Zeus Wallet Urgently Taken Offline After Cyber Attack, States Customer Funds Safe

According to Cointelegraph, Bitcoin Lightning Network self-custodial wallet Zeus Wallet voluntarily took its infrastructure offline following a cybersecurity attack on Wednesday and is currently conducting a comprehensive audit of the system, with services to be restored upon completion. Zeus founder Evan Kaloudis stated that the attack was contained within hours, no customer fund losses were found, and there was no evidence that the Lightning node software was affected; the scope of the incident was limited to Zeus's own infrastructure. For users forced to close LSP channels during this incident, Zeus promised to provide replacement channels after services are restored. The company has not yet disclosed the specific nature of the attack or a timeline for resuming operations. Zeus stated that this incident will further drive its security development on Trusted Execution Environment (TEE) and Validating Lightning Signer (VLS) projects.

$120 Million Coldcard Wallet Hack Sparks Bitcoin Mempool Activity

Odaily News: The Coldcard wallet hack involves approximately $120 million. The related transactions briefly made the Bitcoin mempool highly active.

CertiK:与 Coldcard Wallet 攻击相关资金经 THORChain 跨链后转入 Tornado Cash

CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。