BTC $79,223.11 -0.47%
ETH $2,486.19 -0.46%
BNB $704.70 -0.32%
XRP $1.41 -1.10%
SOL $105.50 +1.58%
TRX $0.3390 +0.88%
DOGE $0.0863 -1.95%
ADA $0.2070 -2.68%
BCH $262.69 -1.93%
LINK $11.69 -0.47%
HYPE $82.93 +0.71%
AAVE $124.67 -1.90%
SUI $0.7552 -0.52%
XLM $0.1823 -1.82%
ZEC $791.01 +0.89%
BTC $79,223.11 -0.47%
ETH $2,486.19 -0.46%
BNB $704.70 -0.32%
XRP $1.41 -1.10%
SOL $105.50 +1.58%
TRX $0.3390 +0.88%
DOGE $0.0863 -1.95%
ADA $0.2070 -2.68%
BCH $262.69 -1.93%
LINK $11.69 -0.47%
HYPE $82.93 +0.71%
AAVE $124.67 -1.90%
SUI $0.7552 -0.52%
XLM $0.1823 -1.82%
ZEC $791.01 +0.89%

ln

All
Article
Flash

Core Lightning, the Bitcoin Lightning Network software, issued an emergency warning due to the discovery of multiple real vulnerabilities in an AI report

According to CoinDesk, the developers of the Bitcoin Lightning Network payment software Core Lightning (CLN) issued an urgent warning to node operators after the team received a large number of AI-generated security reports, revealing several real vulnerabilities. The development team advised operators not to directly shut down the machine power but to restart the software in "--offline" mode, which stops communication with other Lightning Network nodes while still keeping it operational to continuously monitor the Bitcoin blockchain and protect the funds in the payment channels.The Core Lightning team began receiving a large number of AI-generated vulnerability reports since early August, some of which have been confirmed to be valid. Developers will keep the details confidential for two weeks to complete the patch development and plan to release a signed patch version for operators to verify the source. The source code and vulnerability details will be made public after the confidentiality period ends.This is the second AI-related security incident in the Lightning Network this month. Earlier in early August, BTCPay Server experienced a vulnerability that led to the leakage of credentials for some Lightning Network nodes and theft of funds. Additionally, the "Bitcoin Red Team," composed of 16 developers, used AI models to scan 390 Bitcoin code repositories at the end of July, discovering nearly 5,000 issues, 85 of which were rated as critical.

Ledger CTO responds to vulnerability FUD: The issue was fixed before it was disclosed, and users can safely use it by updating in a timely manner

Ledger's Chief Technology Officer Charles Guillemet stated that there has recently been "FUD" targeting Ledger in the market, as a smart contract security company claimed to have discovered vulnerabilities in the Ledger Ethereum application. Guillemet mentioned that there indeed were vulnerabilities related to certain Clear Signing processes in the Ledger Ethereum application, but these vulnerabilities were discovered by Ledger's security research team Donjon using AI-driven vulnerability research tools, and the fixes were completed and deployed two weeks ago. Users can obtain protection by timely updating their Ledger device firmware and applications.The relevant security company contacted Ledger's bug bounty program only after the fixes were completed, did not follow responsible disclosure processes, and did not communicate with the bug bounty team, yet implied in subsequent content that the issue had not been resolved. This approach is not true security research but rather a way to create panic for attention. AI is changing the cybersecurity landscape, and both attackers and defenders can enhance efficiency with AI, but AI-driven security research can only truly enhance the security of the entire ecosystem when basic security principles such as responsible disclosure and pre-release verification are followed.Guillemet finally reminded Ledger users to keep their device firmware, Ledger applications, and related software up to date to automatically receive the latest security fixes and research results. Users should not be influenced by the related "FUD" and should timely update their software and maintain safe habits.

first_img Linera opens pre-registration for the LNRA community round, subscription from September 1 to 8

The real-time market application underlying protocol Linera announces the opening of pre-registration for the $LNRA community round, aimed at traders, badge recipients, community members, and external participants, allowing for token purchases before Season 1 and TGE. Pre-registration is open from now until September 1 UTC, with the subscription period from September 1 to 8 UTC. Participants can join at a fixed price / FDV using USDC on Base through sale.linera.net, with round pricing and scale to be announced on August 28.This round is divided into a reserved pool for badge holders and an open pool for all registered users. Badges can be earned daily through trading and social activities on app.linera.xyz and claimed at portal.linera.net. Higher levels and points determine the priority order for the reserved pool; the open pool is allocated proportionally, with a single wallet limit of $100,000. For every $1 committed, 1 Commitment Credit is earned, which can be used for fee-free trading volume in Season 1 on app.linera.xyz, with refunds also counted.It is reported that 65% of the total supply belongs to the community (including reserves and this pre-sale), while investors and early contributors hold a total of 25%, with a three-year vesting period from distribution. Linera claims there are currently about 50,000 traders, over 80 million predictions, and over 2 billion test trades, nearing the launch of the mainnet.

BounceBit Chain update on vulnerability attack progress: will permanently halt the chain and migrate to BNB Chain

The cross-chain yield protocol BounceBit has released a security incident announcement stating that its blockchain network experienced a protocol-level vulnerability attack from August 19, 21:02 UTC to August 20, 01:54 UTC. The attacker exploited an authorization flaw in the underlying architecture of Evmos to transfer BB tokens from 9 mainnet accounts without the account owners' authorization. According to the announcement, the attacker transferred approximately 286.5 million BB through 14 transactions.The impact of the incident is limited to the BounceBit Chain itself and does not involve issues related to private key leakage, signature forgery, wallet, hardware device, or exchange account security. BounceBit's CeDeFi Strategy, Promo Vaults, Prime, and RWA products were not affected.BounceBit stated that the vulnerability originated from a defect in the authorization verification of the protocol's native module within the Evmos architecture. The attacker bypassed the security checks that were supposed to verify the authorization relationship of the funding source account when calling the relevant module through a smart contract, allowing them to designate any account as the source of funds.After the incident, the BounceBit Chain stopped block production at block height 20,702,857. The team then decided not to upgrade the chain but to permanently shut down the BounceBit Chain and reissue BB as a BEP-20 token based on the BNB Chain. BounceBit stated that the new BB token supply will be based on an on-chain snapshot taken before the first abnormal transfer (block height 20,697,260), and the 286,543,148 BB transferred by the attacker will not be included in the new token balance.Users do not need to submit applications or migrate wallets; the official plan is to automatically distribute the new BB to the corresponding BNB Chain addresses. For staked BB, BounceBit stated that it will be restored at the snapshot time, and holders do not need to perform unbinding or redemption operations. Currently, BounceBit has submitted requests for freezing and assistance to relevant exchanges and has reminded users to be vigilant against scams and not to click on any BB migration or claim links that have not been officially confirmed. The team stated that they will announce the new BEP-20 BB contract address and reissuance progress in the future.
app_icon
ChainCatcher Building the Web3 world with innovations.