BTC $85,021.54 +0.97%
ETH $2,687.92 +0.29%
BNB $773.28 +0.89%
XRP $1.50 +1.27%
SOL $119.74 +2.04%
TRX $0.3357 +0.34%
DOGE $0.0949 +0.98%
ADA $0.2519 +2.45%
BCH $311.01 +1.46%
LINK $14.17 -0.86%
HYPE $89.34 +2.68%
AAVE $183.76 +9.86%
SUI $1.15 +1.44%
XLM $0.2211 +1.09%
ZEC $1,369.52 +1.59%
AAPL $333.18 +1.50%
AMZN $250.96 +1.32%
GOOGL $343.67 +1.58%
MSFT $514.28 +0.10%
META $730.06 +0.21%
NVDA $235.35 +1.83%
TSLA $371.22 +4.28%
SNDK $1,724.17 -2.17%
INTC $121.47 +1.17%
SPCX $157.24 +4.38%
MU $1,079.98 +1.81%
AMD $630.41 +2.94%
BTC $85,021.54 +0.97%
ETH $2,687.92 +0.29%
BNB $773.28 +0.89%
XRP $1.50 +1.27%
SOL $119.74 +2.04%
TRX $0.3357 +0.34%
DOGE $0.0949 +0.98%
ADA $0.2519 +2.45%
BCH $311.01 +1.46%
LINK $14.17 -0.86%
HYPE $89.34 +2.68%
AAVE $183.76 +9.86%
SUI $1.15 +1.44%
XLM $0.2211 +1.09%
ZEC $1,369.52 +1.59%
AAPL $333.18 +1.50%
AMZN $250.96 +1.32%
GOOGL $343.67 +1.58%
MSFT $514.28 +0.10%
META $730.06 +0.21%
NVDA $235.35 +1.83%
TSLA $371.22 +4.28%
SNDK $1,724.17 -2.17%
INTC $121.47 +1.17%
SPCX $157.24 +4.38%
MU $1,079.98 +1.81%
AMD $630.41 +2.94%

tac

All
Article
Flash

first_img Core Lightning warns that old version nodes are under attack and urges operators to upgrade immediately

The Core Lightning team, which develops the open-source Bitcoin Lightning Network node software, has issued an urgent alert stating that reports indicate attackers are targeting nodes that have not installed patches, urging operators still running old versions to upgrade immediately. The team stated: "Emergency security update: If you are using version 26.06.7 or earlier, please upgrade to the latest release as soon as possible."Prior to this, Core Lightning began investigating a potential issue that could affect its experimental features and, in turn, impact user funds on September 16, and approximately six days later, version 26.06.8 was released. This update not only fixed several defects but also provided patches for security vulnerabilities reported responsibly by multiple parties, thanking the Bitcoin Red Team and 12 other individuals and organizations in the release notes, while also acknowledging anonymous reporters.According to the changelog, this round of fixes covers a bug that could cause sender nodes to crash, requests that could exhaust REST interface memory, and a vulnerability that could result in user funds facing confiscation losses when closing payment channels. To provide operators with ample upgrade windows and prevent attackers from taking advantage of reverse engineering and exploitation, this version intentionally obscured some testing content. Additionally, in August of this year, the project initiated a collaborative fixing process after reviewing a large number of AI-generated general vulnerability disclosure reports, and two days later released version 26.06.7 to close confirmed vulnerabilities.

first_img Zcash released Udon, incorporating the Tachyon scaling code into Zakura Common

According to CoinDesk, Zcash developers are integrating part of the proposed scaling upgrade code, Tachyon, into the software already in use to prepare for a large number of privacy transactions in the future. This component is named Udon, originally developed as part of Project Tachyon.According to Sean Bowe, the head of Project Tachyon, Udon was released on Monday to Zakura Common, which is a cryptographic library shared by Zakura and other Zcash projects. Common is responsible for handling some of the heavy mathematical computations behind creating and verifying privacy transactions, with Zakura being jointly developed by Bowe's team and Dev Ojha's Valar Group.Zcash wallets need to prove the validity of a privacy payment without disclosing the payer, payee, or amount, and the computers running the network subsequently verify that proof. According to CoinDesk's report in August, previous improvements to Common have reduced the time to create a privacy transaction from over 3 seconds to under 200 milliseconds in some tests.If privacy payments become more common, these computers will need to handle more data. Udon brings some of the computational requirements for the proposed scaling upgrade of Tachyon into Common, allowing developers to continue building on the already accelerated code. Udon has been released as software, but the upgrade has not yet been activated on Zcash.Bowe and Ojha's long-term goal is to exceed 50,000 payments per second. At this rate, they estimate that current cryptography will allow each Zcash node to receive over 500 MB of data per second.

first_img Patent company Taction won the lawsuit, and Apple was ordered to pay 5.7 billion dollars

A federal jury in San Diego, USA, ruled on Friday that Apple must pay over $5.7 billion in damages for using patented technology from the haptic patent company Taction Technology, according to Caixin. This is the highest patent compensation amount in U.S. history. Taction sued Apple in 2021, claiming that its sales of devices infringing on touch technology improperly utilized related innovations; the case was dismissed in 2023 but was later reinstated by the Federal Circuit Court of Appeals.Apple issued a statement strongly opposing the verdict and the amount of damages, stating that the ruling lacks factual basis. Apple stated that its haptic engine is fundamentally different from Taction's technology, and tests conducted during the trial confirmed this, asserting that it did not use Taction's technology and would appeal. Taction's chief attorney, Lance Yang, thanked the jury and mentioned that the company waited five and a half years for the case to go to trial.The core of the lawsuit revolves around two vibration-based haptic sensor technologies designed to allow users to perceive the device's response to input. Taction claims that Apple’s haptic engine in the Apple Watch and iPhone used its inventions without authorization. Apple's haptic engine was launched in 2014 with the Apple Watch and was used in the iPhone 6s and iPhone 6s Plus the following year, replacing the older vibration motors. Since Apple insists on appealing, the amount of damages will need to be determined first by the presiding judge before entering the appeals process for final confirmation.

Bitget CEO live-streamed a response to the platform's first security incident in eight years: the attack originated from a vulnerability in a third-party security product, and the losses will be covered by the user protection fund

In today's community live broadcast, Bitget CEO Gracy responded to recent security incidents and the platform's financial status. She candidly stated that this is the first security incident encountered since Bitget was established 8 years ago. After a complete trace, it was found that hackers exploited vulnerabilities in third-party security products to steal internal network access credentials, forged withdrawal commands to the wallet system, and deceived the wallet into executing abnormal transfers that bypassed risk checks. Gracy emphasized that no private keys were leaked, and cold wallets were unaffected; specific technical details will be disclosed in the formally released security report.Gracy pointed out that the verified losses from this incident are within the coverage of the protection fund, and user funds are not affected. The platform's own funds exceed $1.4 billion, which includes approximately $464 million in the user protection fund. The platform will continue to uphold the security commitments made when the protection fund was established in 2022, planning to replenish the fund to the baseline of $300 million within a week."The protection fund is not just a slogan, but an important mechanism that provides tangible security for users in the event of extreme security incidents," Gracy stated. In the face of sudden security challenges, the platform's comprehensive strength and its ability to take responsibility are important criteria for measuring its risk response capability and long-term credibility. Bitget will continue to uphold its long-term commitment to prioritize user interests.
app_icon
ChainCatcher Building the Web3 world with innovations.