BTC $86,707.13 +3.47%
ETH $2,749.10 +1.74%
BNB $778.55 +1.16%
XRP $1.54 +3.23%
SOL $121.85 +3.55%
TRX $0.3348 +0.70%
DOGE $0.0968 +2.19%
ADA $0.2569 +3.64%
BCH $315.04 +1.88%
LINK $14.36 -0.43%
HYPE $90.69 +0.70%
AAVE $181.83 +10.59%
SUI $1.18 +1.79%
XLM $0.2244 +1.00%
ZEC $1,380.46 -1.60%
AAPL $332.17 +0.12%
AMZN $251.29 -0.11%
GOOGL $341.31 -2.36%
MSFT $517.96 -0.22%
META $732.29 +0.53%
NVDA $235.80 +2.36%
TSLA $356.92 -0.07%
SNDK $1,776.06 +1.54%
INTC $123.54 +3.36%
SPCX $149.69 -1.02%
MU $1,105.98 +4.71%
AMD $631.91 +2.97%
BTC $86,707.13 +3.47%
ETH $2,749.10 +1.74%
BNB $778.55 +1.16%
XRP $1.54 +3.23%
SOL $121.85 +3.55%
TRX $0.3348 +0.70%
DOGE $0.0968 +2.19%
ADA $0.2569 +3.64%
BCH $315.04 +1.88%
LINK $14.36 -0.43%
HYPE $90.69 +0.70%
AAVE $181.83 +10.59%
SUI $1.18 +1.79%
XLM $0.2244 +1.00%
ZEC $1,380.46 -1.60%
AAPL $332.17 +0.12%
AMZN $251.29 -0.11%
GOOGL $341.31 -2.36%
MSFT $517.96 -0.22%
META $732.29 +0.53%
NVDA $235.80 +2.36%
TSLA $356.92 -0.07%
SNDK $1,776.06 +1.54%
INTC $123.54 +3.36%
SPCX $149.69 -1.02%
MU $1,105.98 +4.71%
AMD $631.91 +2.97%

attack

All
Article
Flash

first_img Core Lightning warns that old version nodes are under attack and urges operators to upgrade immediately

The Core Lightning team, which develops the open-source Bitcoin Lightning Network node software, has issued an urgent alert stating that reports indicate attackers are targeting nodes that have not installed patches, urging operators still running old versions to upgrade immediately. The team stated: "Emergency security update: If you are using version 26.06.7 or earlier, please upgrade to the latest release as soon as possible."Prior to this, Core Lightning began investigating a potential issue that could affect its experimental features and, in turn, impact user funds on September 16, and approximately six days later, version 26.06.8 was released. This update not only fixed several defects but also provided patches for security vulnerabilities reported responsibly by multiple parties, thanking the Bitcoin Red Team and 12 other individuals and organizations in the release notes, while also acknowledging anonymous reporters.According to the changelog, this round of fixes covers a bug that could cause sender nodes to crash, requests that could exhaust REST interface memory, and a vulnerability that could result in user funds facing confiscation losses when closing payment channels. To provide operators with ample upgrade windows and prevent attackers from taking advantage of reverse engineering and exploitation, this version intentionally obscured some testing content. Additionally, in August of this year, the project initiated a collaborative fixing process after reviewing a large number of AI-generated general vulnerability disclosure reports, and two days later released version 26.06.7 to close confirmed vulnerabilities.

Bitget CEO live-streamed a response to the platform's first security incident in eight years: the attack originated from a vulnerability in a third-party security product, and the losses will be covered by the user protection fund

In today's community live broadcast, Bitget CEO Gracy responded to recent security incidents and the platform's financial status. She candidly stated that this is the first security incident encountered since Bitget was established 8 years ago. After a complete trace, it was found that hackers exploited vulnerabilities in third-party security products to steal internal network access credentials, forged withdrawal commands to the wallet system, and deceived the wallet into executing abnormal transfers that bypassed risk checks. Gracy emphasized that no private keys were leaked, and cold wallets were unaffected; specific technical details will be disclosed in the formally released security report.Gracy pointed out that the verified losses from this incident are within the coverage of the protection fund, and user funds are not affected. The platform's own funds exceed $1.4 billion, which includes approximately $464 million in the user protection fund. The platform will continue to uphold the security commitments made when the protection fund was established in 2022, planning to replenish the fund to the baseline of $300 million within a week."The protection fund is not just a slogan, but an important mechanism that provides tangible security for users in the event of extreme security incidents," Gracy stated. In the face of sudden security challenges, the platform's comprehensive strength and its ability to take responsibility are important criteria for measuring its risk response capability and long-term credibility. Bitget will continue to uphold its long-term commitment to prioritize user interests.

Cosmos Hub: 1.227 million ATOM has been recovered from the Neutron attack case, with funds temporarily stored at a 4/6 multi-signature address

Cosmos Labs disclosed that on September 22, Neutron encountered a governance attack that led to the theft of liquidity from protocols such as Astroport, with approximately 1.73 million ATOM subsequently transferred by the attacker to Cosmos Hub. The Cosmos Hub itself was not attacked, and user funds were not affected. To prevent the stolen ATOM from being transferred out, Hub validators temporarily paused the network for about 24.5 hours and resumed block production on September 23 based on the patched Gaia v28.3.0.Cosmos Labs stated that during the pause, 1.227 million ATOM remained in the attacker's Hub address. When the network was restored, these were transferred to a 4/6 multi-signature address composed of Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu through a one-time change. Previously, about 500,000 ATOM had been exchanged for ETH via THORChain and could not be recovered; another 169,000 ATOM entered the attacker's address after the network was restored due to THORChain refunds and were sold after being transferred to Osmosis. The current multi-signature address holds approximately 1.227 million ATOM, which can only be returned after authorization from a Cosmos Hub governance proposal. The related funds will not be staked, lent, or traded. The Neutron team expects to submit a recovery plan and related governance proposals next week.
app_icon
ChainCatcher Building the Web3 world with innovations.