Scan to download
BTC $74,656.06 -0.50%
ETH $2,319.17 -1.59%
BNB $628.09 +0.49%
XRP $1.43 +1.40%
SOL $87.50 +2.43%
TRX $0.3256 -0.06%
DOGE $0.0966 +0.13%
ADA $0.2524 +0.96%
BCH $447.69 +0.99%
LINK $9.35 +0.43%
HYPE $43.56 -4.49%
AAVE $111.81 +5.16%
SUI $0.9759 +0.44%
XLM $0.1647 +2.79%
ZEC $331.48 -3.11%
BTC $74,656.06 -0.50%
ETH $2,319.17 -1.59%
BNB $628.09 +0.49%
XRP $1.43 +1.40%
SOL $87.50 +2.43%
TRX $0.3256 -0.06%
DOGE $0.0966 +0.13%
ADA $0.2524 +0.96%
BCH $447.69 +0.99%
LINK $9.35 +0.43%
HYPE $43.56 -4.49%
AAVE $111.81 +5.16%
SUI $0.9759 +0.44%
XLM $0.1647 +2.79%
ZEC $331.48 -3.11%

vulnerabilities

Security Company: AI agent's encrypted payment infrastructure has significant security vulnerabilities, LLM router has led to the theft of a $500,000 wallet

According to CoinDesk, researchers from the University of California, Santa Barbara, the University of California, San Diego, blockchain security company Fuzzland, and World Liberty Financial have jointly published a paper warning that "LLM routers"—intermediary services located between users and AI models—have become a significant security risk for crypto assets.The researchers found that 26 LLM routers are secretly injecting malicious tool calls and stealing user credentials, with one incident leading to the emptying of a customer's crypto wallet worth $500,000.Additionally, the researchers were able to control about 400 downstream hosts within hours by "polluting" the router ecosystem. Since sensitive data such as private keys and API credentials are often transmitted in plaintext through these routers, users are effectively exposing their assets to risk without their knowledge.The researchers pointed out that as McKinsey predicts AI agents will mediate $30 trillion to $50 trillion in global consumer spending by 2030, Binance founder Changpeng Zhao also predicts that the payment volume of AI agents will be a million times that of humans. The current infrastructure security is severely lagging behind the pace of industry development, and the risk of the "weakest link" could trigger a systemic chain crisis.

The Ministry of Industry and Information Technology of China issued a risk alert regarding the timely update of specific iOS versions to prevent the exploitation of vulnerabilities

The Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) of the Ministry of Industry and Information Technology of China has monitored and found that attackers are using exploit tools targeting Apple Inc.'s terminal products to carry out cyber attack activities, which can lead to serious harms such as information theft and system control. The affected range includes Apple terminal products such as iPhone and iPad running iOS 13 to 17.2.1.Attackers induce users to use the Safari browser to visit web pages containing malicious code through methods such as SMS, email, or web poisoning, comprehensively utilizing security vulnerabilities present in the terminal devices to implant remote control Trojans into the victim's terminal products, stealing sensitive user information, gaining maximum privileges, and taking control.It is recommended that users of Apple terminal products conduct risk assessments, and promptly fix vulnerabilities through version upgrades and patch installations (refer to the Apple Security Updates). Pay attention to system update notifications and the latest security update announcements released by Apple, upgrade to the latest secure version in a timely manner, strengthen security awareness, avoid clicking on unknown links, and prevent the risk of cyber attacks.

Vitalik reiterated Ethereum's mission: to reduce external dependency vulnerabilities through resilience, allowing people to gain sovereign freedom

Ethereum founder Vitalik reiterated the purpose of Ethereum, stating, "The creation of Ethereum is not to make finance more efficient or applications more convenient, but to give people freedom." This is an important and controversial statement from the "Unpermissioned Manifesto" that deserves our re-examination and a better understanding of its meaning. Words like "efficient" and "convenient" imply improving the average situation in an already quite good context. Efficiency refers to allowing the world's best engineers to pour their souls into reducing latency from 473 milliseconds to 368 milliseconds, or increasing the yield from 4.5% APY to 5.3% APY.Convenience means enabling people to register in 20 seconds instead of 1 minute with just one click instead of three. These things may be well done. But we must understand that we can never outplay the corporate players in Silicon Valley in this game.Therefore, the main underlying game that Ethereum must play must be a different game. This game is resilience. Resilience is not about 4.5% APY versus 5.3% APY, but about minimizing your risk of suffering -100% APY. Resilience means that if you become politically unpopular and get banned, or your application developers go bankrupt or disappear, or Cloudflare goes down, or a cyberwar breaks out, your 2000 milliseconds of latency still remains at 2000 milliseconds. Resilience is that anyone, anywhere in the world can access the network and become a top-tier participant.Resilience is sovereignty, in the sense of "digital sovereignty" or "food sovereignty"—actively reducing vulnerability to external dependencies that can be arbitrarily stripped away at any time. This is the game that Ethereum is suited to win. Ethereum must first and foremost be a decentralized, permissionless, and resilient block space—then make it rich.
app_icon
ChainCatcher Building the Web3 world with innovations.