BTC $84,544.69 -0.23%
ETH $2,665.84 -1.30%
BNB $766.53 -0.58%
XRP $1.48 -1.10%
SOL $118.35 +0.12%
TRX $0.3343 -0.21%
DOGE $0.0922 -1.95%
ADA $0.2418 -1.60%
BCH $308.75 -0.14%
LINK $13.73 -3.91%
HYPE $87.33 +0.28%
AAVE $180.64 +5.34%
SUI $1.12 -4.28%
XLM $0.2139 -2.28%
ZEC $1,288.63 -3.06%
AAPL $333.24 +0.83%
AMZN $251.15 +0.98%
GOOGL $342.97 +1.10%
MSFT $517.59 +0.52%
META $727.26 +0.19%
NVDA $233.98 +1.10%
TSLA $370.93 +4.33%
SNDK $1,715.97 -3.58%
INTC $119.16 -0.77%
SPCX $158.69 +6.67%
MU $1,069.71 -1.83%
AMD $632.60 +2.71%
BTC $84,544.69 -0.23%
ETH $2,665.84 -1.30%
BNB $766.53 -0.58%
XRP $1.48 -1.10%
SOL $118.35 +0.12%
TRX $0.3343 -0.21%
DOGE $0.0922 -1.95%
ADA $0.2418 -1.60%
BCH $308.75 -0.14%
LINK $13.73 -3.91%
HYPE $87.33 +0.28%
AAVE $180.64 +5.34%
SUI $1.12 -4.28%
XLM $0.2139 -2.28%
ZEC $1,288.63 -3.06%
AAPL $333.24 +0.83%
AMZN $251.15 +0.98%
GOOGL $342.97 +1.10%
MSFT $517.59 +0.52%
META $727.26 +0.19%
NVDA $233.98 +1.10%
TSLA $370.93 +4.33%
SNDK $1,715.97 -3.58%
INTC $119.16 -0.77%
SPCX $158.69 +6.67%
MU $1,069.71 -1.83%
AMD $632.60 +2.71%

vulnerabilities

All
Article
Flash

QCP Capital: The current surge in Bitcoin is mainly driven by spot funds, but the current market structure still has vulnerabilities

QCP Capital released the latest market analysis stating that BTC has broken through the previous trading range of $82,500 to $85,700 that lasted for a week, reaching a high of $86,913 during the day, the highest since September 23. It is currently trading around $85,900, up 14.6% from the low of $74,968 on September 15. QCP pointed out that during this round of increase, the annualized funding rate for perpetual contracts was only 5.4%, indicating that the market was mainly driven by spot funds rather than leveraged trading. QCP believes that this round of BTC's rise diverges from traditional macro market signals. In September, the yield on the 30-year U.S. Treasury bond rose to 5.62%, and the 10-year yield reached 5.29% at one point, while gold recorded its worst month of the year. Although rising real interest rates typically put pressure on gold and risk assets, BTC still rose.QCP believes that this market trend is more consistent with concentrated capital trading driven by institutional fund inflows, regulatory catalysts, and technical improvements, rather than purely a currency depreciation trading logic. Regarding institutional funds and regulatory factors, the U.S. Bitcoin spot ETF recorded net inflows of approximately $3.5 billion and $2.6 billion in August and September, respectively. QCP noted that the innovative exemption policy released by the U.S. SEC on September 17 provided a new regulatory catalyst for the market, but since the CLARITY Act failed to pass in the Senate earlier, market structure legislation may be delayed until 2027. Therefore, current regulatory support comes more from the administrative level, and long-term policy certainty remains limited.In the options market, yesterday's options trading nominal amount was approximately $2.5 billion, involving 54 transactions with a nominal amount exceeding $5 million each. Among them, one client sold in batches call options expiring on October 30 with a strike price of $90,000, totaling over 4,000 contracts with a nominal amount of $346 million; at the same time, they actively bought call options with the same strike price expiring on November 27. QCP believes that this operation reflects that some traders are rolling their positions from October to November to position for the U.S. midterm elections, quarterly Treasury refinancing, and market volatility around the December Federal Reserve meeting.On the macroeconomic front, the Federal Reserve will hold a monetary policy meeting from October 27 to 28. QCP stated that after Federal Reserve official Williams said there was no need to rush to adjust policies further, and with the August core PCE coming in below expectations, market expectations for maintaining interest rates in October have warmed. However, the market still expects an approximately 80% probability of a 25 basis point rate hike in December. The U.S. non-farm payroll report for September, to be released tonight, will be an important short-term test, with the market expecting an increase in non-farm payrolls of 84,000 to 93,000, an unemployment rate holding at 4.1%, and an average hourly wage year-on-year growth rate expected to be 3%.On the technical front, the support level of $82,500 has been tested three times in the past week, while $87,400 is the location of the September high and is a key resistance for BTC to further challenge $90,000. The implied volatility term structure in the options market is in a contango state, with a 7-day implied volatility of 30.3 and a 90-day implied volatility of 37.1; the 30-day risk reversal indicator is approximately -2.5 volatility points, indicating an increase in demand for short-term put protection. QCP believes that although BTC shows resilience in a macro environment of rising real interest rates, the market is still mainly driven by capital flows and position changes, and it cannot yet be considered that macro risks have been eliminated. U.S. employment data, Treasury supply, and the intensive policy events in the coming weeks may still trigger market volatility.

first_img Google disclosed the AI security agent PageBreak, which has identified over 500 vulnerabilities

The Google Product Security Team has disclosed an internal AI agent called PageBreak, used to test the security of its first-party web applications. This agent is built on Google's Gemini model and began a pilot program in November 2025, transitioning to a formal project in January 2026, with the goal of autonomously scaling vulnerability discovery and reducing manual input.Unlike common AI scanning tools, PageBreak hands over hypotheses to specialized validators after discovering suspicious defects, attempting actual exploitation in a real-time running copy of the application, and only reports once confirmed exploitable, with a false positive rate close to zero. Google claims that PageBreak has identified over 500 XSS vulnerabilities in its first-party web applications, which can be used to hijack login sessions, steal data, or impersonate users.Google stated that the security team has been overwhelmed in recent years by a large number of AI-generated vulnerability reports that appear reasonable but are not valid, making it a major challenge to distinguish real defects from hallucinations. When testing applications built using the next-generation high-assurance framework, PageBreak found only two vulnerabilities. The next step for Google is to integrate PageBreak with the automated remediation agent CodeMender, providing confirmed vulnerabilities with accompanying fixes.

Binance Security Announcement: Please iPhone users check if FomoPeek is installed, as it can exploit iOS vulnerabilities to gain maximum access to the device

Binance Wallet Security Announcement: iPhone users please check if you have installed the FomoPeek application. Binance has noted a recent security incident disclosed by the community. According to security companies such as SlowMist, the third-party application FomoPeek (versions 1.1-1.2) contains malicious code that can exploit vulnerabilities in the iOS system to gain maximum permissions on the device and may access sensitive data stored on the device, including private keys, mnemonic phrases, login credentials, chat records, files, etc. Please note that such malware directly attacks the device itself. If the attack is successful, all application data on the affected device may be accessed.Please check the following:Are you using an iPhone or iPad running iOS 26.x or earlier?Have you installed the FomoPeek application?If both of the above apply to you, it is recommended to take the following steps immediately:Delete the FomoPeek application and do not reinstall it.Update the iOS system to the latest version.For users with self-hosted wallets: Create a new wallet on a device that has never installed the application and transfer assets to the new wallet address.If you notice any unusual asset activity, please retain the affected device and relevant evidence, and contact customer service for further investigation.At the same time, all users are reminded: Do not install applications from untrusted sources and keep your device software up to date.

first_img The EU Cyber Resilience Act comes into effect, requiring cryptocurrency wallet providers to report vulnerabilities within 24 hours

According to Cointelegraph, the European Union's Cyber Resilience Act (CRA) officially came into effect on September 11, requiring cryptocurrency hardware and software wallet providers to submit early warning reports within 24 hours upon discovering actively exploited vulnerabilities or serious security flaws, and to submit complete notifications within 72 hours. Manufacturers must also submit final reports within 14 days after taking corrective or mitigating measures, while serious incidents must be reported within one month.The European Commission stated that the new reporting requirements aim to better protect consumers and businesses from cyber threats, applicable to all "products with digital elements" sold in the EU market, and are built upon the EU's broader cybersecurity strategy. According to the penalty provisions of the final draft, companies that fail to comply with Articles 13 and 14 may face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing incorrect, incomplete, or misleading information may also incur fines of up to €5 million.Before the implementation of this measure, several hardware wallet manufacturers recently disclosed incidents of user data breaches. On September 4, Trezor revealed that a data breach involving its logistics provider ShipMonk affected approximately 67,000 U.S. customers, exceeding the initial estimate of 14,000; this week, Trezor and BitBox also warned users to be cautious of phishing emails disguised as urgent security notifications. In June, the Layer-1 blockchain network Zilliqa warned of vulnerabilities in its Ledger application, where attackers could exploit publicly available on-chain data to recover user private keys.

first_img OpenAI's new model Astra can autonomously discover and exploit software vulnerabilities, rated as "critical" in cybersecurity capability level

OpenAI stated that its upcoming Astra model can autonomously discover previously unknown software vulnerabilities and convert them into usable attack vectors without human intervention, making it the company's first model to reach the "Critical" cybersecurity capability level threshold. In a blog post released on Tuesday, OpenAI mentioned that according to its Preparedness Framework, reaching this level means the model can discover zero-day vulnerabilities and develop usable exploit code in hardened real systems without human involvement, or design and execute attacks based solely on a high-level objective.In testing, Astra achieved a 100% score in benchmark tests for developing exploit code based on known vulnerabilities and discovered two previously unknown vulnerabilities in another internal test. Additionally, the model successfully broke through a hardened browser sandbox and executed commands on the host machine, while gaining root access by exploiting multiple weaknesses in the operating system. OpenAI stated that it has delayed some of Astra's development progress to enhance security measures and plans to make its advanced cybersecurity capabilities available only to selected testers.This capability is particularly relevant to the cryptocurrency industry, as software vulnerabilities can be converted into financial losses within minutes. CoinDesk reported in June that increasingly powerful AI models can compress the process of searching code, discovering misconfigurations, and assembling attacks from days or weeks to machine speed. Security researchers noted at the time that the significant change was not the emergence of new categories of attacks, but rather the dramatically increased speed at which existing vulnerabilities are discovered and exploited.

first_img Polygon has fixed security vulnerabilities through two hard forks, which were previously deployed privately

Polygon Labs disclosed that it has fixed a batch of security vulnerabilities in its proof-of-stake network through two hard forks, with the related fixes privately deployed before public disclosure. According to a forum post released on Wednesday, the team packaged the fixes into the Austin hard fork of the Bor client and the Kyoto hard fork of the Heimdall client, both of which followed the standard process for fixing issues that affect consensus: first validated on the Amoy testnet, and then publicly disclosed once the mainnet was activated and the network was secure.The Austin fork fixed two denial-of-service paths in block processing, including a vulnerability where malicious block producers could crash peer nodes by filling them with oversized field data. The Kyoto fork addressed a broader range of consensus hardening issues, with the most severe vulnerability allowing an attacker to force the entire validator set to perform costly and coordinated work with just one crafted transaction—the cost of constructing the transaction is low, but the network processing cost is high. Polygon emphasized that none of the vulnerabilities were observed to be exploited on the mainnet and have been proactively addressed. The two upgrades are now mandatory for node operators and have taken effect without the need for state migration or resynchronization.This disclosure comes at a critical transformation period for Polygon, which has completed the migration of the traditional MATIC token to POL as part of a comprehensive overhaul of its network architecture. The news did not boost the price of POL; according to CoinGecko data, POL traded at approximately $0.09983 on Sunday, down 2.3% in 24 hours, down about 6.8% over the past week, and down about 60.8% over the past year, with a market capitalization of approximately $1.07 billion.
app_icon
ChainCatcher Building the Web3 world with innovations.