Scan to download
BTC $62,236.65 +2.87%
ETH $1,633.80 +5.28%
BNB $596.79 +4.01%
XRP $1.13 +6.35%
SOL $65.45 +6.38%
TRX $0.3268 +1.73%
DOGE $0.0848 +5.17%
ADA $0.1633 +3.39%
BCH $225.21 +5.21%
LINK $7.75 +6.07%
HYPE $59.34 +3.90%
AAVE $62.95 +4.47%
SUI $0.7500 +6.05%
XLM $0.2070 +0.36%
ZEC $422.85 +17.12%
BTC $62,236.65 +2.87%
ETH $1,633.80 +5.28%
BNB $596.79 +4.01%
XRP $1.13 +6.35%
SOL $65.45 +6.38%
TRX $0.3268 +1.73%
DOGE $0.0848 +5.17%
ADA $0.1633 +3.39%
BCH $225.21 +5.21%
LINK $7.75 +6.07%
HYPE $59.34 +3.90%
AAVE $62.95 +4.47%
SUI $0.7500 +6.05%
XLM $0.2070 +0.36%
ZEC $422.85 +17.12%

omise

GitHub updates security incident investigation: An employee's device was compromised, involving a contaminated VS Code extension

GitHub has updated the details of the investigation into the unauthorized access incident of its internal repositories: GitHub detected and contained an incident yesterday involving an employee's device being compromised, which involved a maliciously implanted VS Code extension. GitHub removed the malicious extension, isolated the affected terminals, and immediately initiated an incident response. Current assessments show that only GitHub's internal repositories experienced data exfiltration, and the approximately 3,800 repositories claimed by the attackers are roughly consistent with the investigation results. GitHub has prioritized rotating critical credentials, is analyzing logs, verifying credential rotations, and monitoring subsequent activities, with a complete report to be released after the investigation is concluded.Additionally, Slow Mist's Chief Information Security Officer 23pds commented on this incident, stating: "By analyzing leaks from cybercrime forums, hackers may have used Anthropic's Mythos security AI to precisely breach GitHub's defenses and steal information from about 4,000 core internal repositories: including the source code for Copilot, the algorithms for CodeQL, the Actions runtime, and the entire billing system. Further analysis of this code could lead to subsequent attacks, having a profound security impact on the integration of the open-source community."

Bernstein: The compromise clause on the yield of the CLARITY Act will strengthen Circle's competitive advantage

Bernstein stated in its latest research report that the recently reached compromise on stablecoin yield in the U.S. CLARITY Act is structurally beneficial for Circle and the USDC ecosystem.The report indicates that the current version of the bill prohibits stablecoin issuers from paying interest to passive holders that is "economically equivalent" to bank deposits, but allows reward mechanisms related to real transactions, payments, and usage behaviors to continue. Bernstein believes this means that Circle's current model, which relies on partners like Coinbase to provide USDC reward programs, will gain regulatory recognition, while also limiting the industry's ability to compete for market share through high yields.Bernstein pointed out that the bill actually reinforces the positioning of stablecoins as "payment tools" rather than "deposit substitutes," which helps protect Circle's current business model that relies on reserve income. It continues to give Circle an "outperform" rating and a target price of $190.Data shows that the total supply of global dollar stablecoins has surpassed $300 billion, with USDT and USDC together accounting for about 97% of the market share. Bernstein noted that USDC's share in on-chain payments and wallet transfers is continuously increasing, with its payment share in the AI Agent payment protocol x402 exceeding 99%.Additionally, Bernstein mentioned that Circle's launched ARC chain has completed a total of 244 million testnet transactions, and its ARC token presale previously raised $222 million, with investors including a16z crypto, Apollo Funds, ARK Invest, and BlackRock among others.However, the report also pointed out that the CLARITY Act still needs to complete several legislative procedures before it can officially take effect, including a full Senate vote with 60 votes and coordination with the House version. Polymarket currently predicts a probability of about 62% for it to pass by 2026.

The CLARITY Act makes key progress: compromise reached on stablecoin yield rules, entering the countdown for review

According to Crypto In America, the U.S. CLARITY Act has reached a key compromise on the yield mechanism for stablecoins, clearing an important obstacle for the Senate Banking Committee to advance its review.Under the latest proposal, crypto companies can offer rewards (such as cashback or membership benefits) based on user transaction behavior, but are prohibited from paying interest yields (APY) on idle stablecoin balances. This compromise means that stablecoins will be explicitly positioned as payment tools, rather than as bank-like deposits or high-yield savings products. The industry generally believes that this provision strikes a balance between the crypto industry and traditional banks, but is overall more favorable to the banking system.Industry organizations, including Coinbase, have renewed their support for the bill, believing that although the yield restrictions have tightened, there is still room to earn rewards based on actual usage scenarios. Some industry insiders have pointed out that this move limits the financial attributes of stablecoins.In terms of the regulatory process, Senate Banking Committee Chairman Tim Scott is expected to schedule a markup of the bill soon, possibly as early as mid-May after Congress reconvenes. Additionally, discussions around DeFi regulation (such as defining developer responsibilities) and ethical provisions are still ongoing and may become important variables affecting the bill's final passage. The market generally believes that the next two weeks will be a critical window for whether the CLARITY Act can be implemented.

Syndicate Labs suffered a private key leak attack, approximately 18.5 million SYND were transferred, and they promised full compensation to users

According to official news, Syndicate Labs disclosed that its cross-chain bridge contract was maliciously upgraded on two chains due to a private key leak. The attacker transferred and sold approximately 18.5 million SYND (about $330,000) and around $50,000 worth of user tokens. The incident only affected specific chains, while others were not impacted.Syndicate Labs stated that this attack involved multi-stage reconnaissance, infrastructure mapping, and careful execution, demonstrating a high level of technical complexity, and ruled out the involvement of internal personnel. The root cause was that the private key was stored in a password management tool without an additional layer of encryption, and the upgrade process did not utilize multi-signature or hardware signature mechanisms, nor did it have early warning and circuit breaker measures for contract upgrades.Syndicate Labs announced that it will fully compensate all affected users, including returning 18.5 million SYND and providing additional compensation, while also fully compensating affected application chain clients. The company has initiated security upgrade measures, including strengthening private key encryption, tightening access permissions, and plans to introduce hardware or multi-signature mechanisms and upgrade path monitoring to prevent similar incidents from occurring again.
app_icon
ChainCatcher Building the Web3 world with innovations.