Scan to download
BTC $77,078.95 +2.73%
ETH $2,417.67 +2.99%
BNB $643.11 +1.31%
XRP $1.47 +2.15%
SOL $88.80 +0.01%
TRX $0.3275 +0.15%
DOGE $0.0993 +0.42%
ADA $0.2577 -0.23%
BCH $453.11 -0.82%
LINK $9.60 +0.83%
HYPE $44.70 +1.04%
AAVE $114.46 -0.80%
SUI $0.9950 -0.57%
XLM $0.1729 +2.79%
ZEC $333.93 -1.97%
BTC $77,078.95 +2.73%
ETH $2,417.67 +2.99%
BNB $643.11 +1.31%
XRP $1.47 +2.15%
SOL $88.80 +0.01%
TRX $0.3275 +0.15%
DOGE $0.0993 +0.42%
ADA $0.2577 -0.23%
BCH $453.11 -0.82%
LINK $9.60 +0.83%
HYPE $44.70 +1.04%
AAVE $114.46 -0.80%
SUI $0.9950 -0.57%
XLM $0.1729 +2.79%
ZEC $333.93 -1.97%

cio

Slow Fog: Pay attention to checking for malicious versions of axios and the exposure risk of global installation history for OpenClaw npm

Slow Fog has once again issued a security reminder stating to pay attention to checking for malicious versions of axios and the exposure risk of OpenClaw npm global installation history. [email protected] and [email protected] have been confirmed as malicious versions, both of which have injected the dependency [email protected], delivering cross-platform malicious payloads through the postinstall script.The impact of OpenClaw is assessed based on scenarios: source code builds are not affected, as the locked versions in the lock file are 1.13.5/1.13.6; however, users who installed via npm install -g [email protected] face historical exposure risks due to the presence of optionalDependencies.axios@^1.7.4 in the dependency chain, which may resolve to [email protected] during the time window when the malicious version is still online. Currently, npm has reverted the resolution to [email protected], but environments that were installed during the attack window are still advised to be checked. Slow Fog has provided inspection commands and IoC paths for various platforms; if the plain-crypto-js directory is found, even if the package.json has been cleaned, it should still be regarded as high-risk execution traces. It is recommended that affected hosts immediately rotate credentials and conduct host-side inspections. Previously, Slow Fog founder Yu Xian reminded that OpenClaw version 3.28 may introduce a toxic version of axios, and users need to urgently check.

Bitwise CIO: Bitcoin could reach $1 million in the long term, with potential stemming from its "digital gold" positioning

Bitwise Chief Investment Officer Matt Hougan stated that the price of Bitcoin could potentially reach $1 million per coin in the future. He believes that when viewed from the perspective of the global "Store of Value" market, Bitcoin's long-term potential becomes clearer, as it is gradually competing with gold for the status of a digital value storage asset.In his latest memo titled "How Bitcoin Gets to $1 Million," Hougan pointed out that the current global value storage market is approximately $38 trillion, with about $36 trillion coming from gold, while Bitcoin is around $1.4 trillion, accounting for less than 4% of that market. Hougan believes that many investors underestimate Bitcoin's potential because they overlook the growth rate of the value storage market itself. For example, when the first gold ETF was launched in the U.S. in 2004, the global gold market was only about $2.5 trillion, and it has now approached $40 trillion, with a compound annual growth rate of about 13%. This growth has been primarily driven by increasing government debt, geopolitical uncertainty, and loose monetary policies.If the value storage market continues to expand at a similar pace over the next decade, its size could reach approximately $121 trillion. In this scenario, Bitcoin would only need to capture about 17% of the market share for its price to reach $1 million. Hougan also noted that the development of the crypto market in recent years has laid the groundwork for this outlook. For instance, a few years ago, there was no Bitcoin spot ETF in the U.S., but now Bitcoin spot ETFs have become one of the fastest-growing ETF products in history. At the same time, institutional investors, including Harvard University's endowment fund and the Abu Dhabi sovereign wealth fund, have begun to allocate Bitcoin.
app_icon
ChainCatcher Building the Web3 world with innovations.