BTC $78,004.12 -0.16%
ETH $2,433.96 -0.89%
BNB $686.56 -1.10%
XRP $1.36 -2.18%
SOL $102.70 -2.20%
TRX $0.3367 -1.22%
DOGE $0.0828 -2.54%
ADA $0.1956 -2.63%
BCH $246.74 +0.74%
LINK $11.27 -1.10%
HYPE $81.06 -2.46%
AAVE $123.31 -1.70%
SUI $0.7217 -2.59%
XLM $0.1764 -2.11%
ZEC $831.58 +0.08%
BTC $78,004.12 -0.16%
ETH $2,433.96 -0.89%
BNB $686.56 -1.10%
XRP $1.36 -2.18%
SOL $102.70 -2.20%
TRX $0.3367 -1.22%
DOGE $0.0828 -2.54%
ADA $0.1956 -2.63%
BCH $246.74 +0.74%
LINK $11.27 -1.10%
HYPE $81.06 -2.46%
AAVE $123.31 -1.70%
SUI $0.7217 -2.59%
XLM $0.1764 -2.11%
ZEC $831.58 +0.08%

ant

All
Article
Flash

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.

Cryptoquant Founder: The peak of this Bitcoin bull market cycle may be driven by global institutional and ETF demand

Cryptoquant founder and CEO Ki Young Ju stated that the peak of the current Bitcoin bull market cycle may be driven by institutional funds and ETF demand outside the United States. He pointed out that deeper stablecoin liquidity and tokenized asset infrastructure will expand global market participation. Using South Korea as an example, Ki Young Ju mentioned that the country currently does not have a spot Bitcoin ETF, retail investors cannot purchase overseas-listed spot Bitcoin ETFs, and most companies are unable to open trading accounts to buy BTC. South Korea has phased in corporate participation, with the Financial Services Commission (FSC) roadmap covering about 3,500 listed companies and qualified professional investors, but financial institutions and other companies are still excluded.Strategy's Bitcoin bank evaluated 25 major institutions covering trading, custody, digital asset products, financing, and corporate participation, with an overall adoption rate of 32%. RWA.xyz data shows that the global tokenized asset distributed asset value is $38.63 billion, an increase of 2.65% compared to 30 days ago. The Bank for International Settlements (BIS) stated that stablecoins have the potential to enable faster, programmable payments, but current designs may pose risks to financial integrity, liquidity, and currency. Ki Young Ju pointed out that the cumulative net inflow before the launch of the U.S. spot Bitcoin ETF was about $57 billion over two years, and the next phase will be global institutionalization, with more institutions adopting BTC as a strategic asset, and countries lacking ETFs will also improve related investment channels.

first_img Ripple has established a four-phase quantum-resistant migration plan for the XRP Ledger

Ayo Akinyele, Senior Director of Engineering at Ripple, stated that the company is developing a four-phase quantum-resistant migration plan for the XRP Ledger, aiming to complete the transition before quantum computers become a real threat. The plan includes assessing the network's exposure, testing quantum-resistant cryptographic solutions, running existing security systems in parallel with quantum-resistant alternatives, and preparing emergency response pathways for scenarios where quantum computing advances exceed expectations.Akinyele emphasized that migration is not just about replacing a cryptographic algorithm, but requires more flexible infrastructure, stronger key management, and clearer upgrade paths. The XRP Ledger has supported changing the keys that control accounts without altering the accounts themselves, a feature that is expected to reduce the difficulty of future migrations, but independent validators on the network still need to coordinate any broader rule changes.Meanwhile, Anthropic's model last month reduced the workload required to break leading post-quantum signature candidates by 67 million times, and Bitcoin and Ethereum developers also released their respective migration plans this week. Akinyele pointed out that AI and quantum computing are different technologies, but they are driving financial infrastructure to evolve in the same direction, as AI agents begin to trade and pay autonomously, raising new requirements for payment infrastructure that is always online and natively internet-based.

DWF Ventures: The rapid rise of social trading, platform competition is shifting from trade execution to social networks and information advantages

DWF Ventures released a report stating that as trading fees continue to approach zero, social trading is becoming a new direction for financial trading platforms to compete for users and build moats.The rise of social trading stems from users seeking validation from others and references for investment decisions. From early brokerage copy trading to investment communities like Reddit and Stocktwits, and now to platforms that combine real position verification, trading signals, and social relationships, social trading is evolving from a simple copy trading tool into a product form that integrates trading, content, and social interaction. As trade execution becomes increasingly homogenized, the future competitive advantage of platforms may come more from network effects, resources of well-known traders, and exclusive information and distribution capabilities.Analysis suggests that social trading platforms are forming a clear growth flywheel: platforms attract well-known traders and their fans, traders build reputations through public trading, fans amplify market influence by following trades, which in turn increases the visibility of traders and the user base of the platform. Public calls for trades may even generate a certain "self-fulfilling" effect in this process.Platforms also lower the entry barriers for users through one-click trading, low-threshold acceptance, trading competitions, and fee incentives, and leverage the social influence of top traders to facilitate user migration. In the future, the social trading ecosystem in the cryptocurrency and traditional stock sectors may further integrate, and platforms that master trader, user attention, and information flow are expected to form stronger network effects.However, social trading also faces significant structural risks. Data shows that among approximately 292,000 wallets analyzed by the Fomo platform over the past three months, only 6.16% achieved profitability based on realized gains. Followers lack independent investment logic and are easily influenced by herd behavior, while there may also be conflicts of interest between traders and followers.Furthermore, even if platforms can verify public positions, traders may still establish undisclosed positions through other wallets, making information asymmetry difficult to eliminate completely. Analysis suggests that as the boundaries between trading and entertainment continue to blur, platforms that can establish unique information layers, gather quality traders, and form network effects may gain an advantage in the competitive social trading market.

MANTRA announces the review of the attack incident: A down-scaling vulnerability led to the transfer of over 720 million tokens, with approximately 37.96 million tokens frozen

On August 20, MANTRA Chain released a complete review report of the security incident, confirming that the attacker exploited an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency cosmos/evm, unauthorizedly transferring a total of 720,923,967.99 MANTRA from two addresses, valued at approximately 3.6 million dollars based on the price before the attack. Among them, the attacker transferred 600,000,035.56 MANTRA from the on-chain burn address and 120,923,932.44 MANTRA from a genesis-era multi-signature address related to an early incentive program.MANTRA stated that this incident did not involve the leakage of validator keys, administrator privileges, governance control, or multi-signature signers; the attacker did not require privileged access and could complete the attack solely through unauthorized contract deployment and self-funded wallets. The first abnormal transfer occurred at 19:06 UTC on August 20, when the attacker transferred approximately 600 million MANTRA from the burn address; subsequently, at 22:59 UTC, another transfer of approximately 120.9 million MANTRA was made. The chain subsequently stopped operating at 23:13 UTC and resumed after upgrading to v8.4.0. The entire network interruption lasted for 30 hours and 13 minutes.This vulnerability was not an issue with MANTRA's self-developed code but originated from the cosmos/evm module, which is responsible for providing EVM functionality on the Cosmos SDK. The vulnerability allowed the attacker to execute unsigned balance deductions without checking if the balance was sufficient, causing an overflow of values and bypassing normal account authorization logic. MANTRA stated that as of today, no funds have been recovered, with approximately 37.96 million MANTRA (accounting for 5.27% of the total transferred) still remaining in the attacker's address, which has been frozen due to the chain's suspension and v8.4.0 restrictions. The remaining funds have flowed to related trading platforms, and the recovery efforts have entered the law enforcement investigation stage. In the future, monitoring of accounts that cannot normally authorize transfers, burn addresses, and other historically "non-transferable" addresses will be strengthened, and efforts will be made to promote improvements in the security vulnerability disclosure process within the Cosmos ecosystem.

first_img A U.S. judge ruled that the Trump administration illegally retaliated against Anthropic, lifting the ban and issuing a permanent injunction

U.S. Federal Judge Rita Lin issued a partial summary judgment in a 59-page ruling regarding Anthropic's lawsuit against the Trump administration, determining that the government's punishment of Anthropic for publicly refusing to allow the military to use its Claude large model for mass surveillance of U.S. citizens and lethal autonomous operations constituted illegal retaliation, violating the First Amendment, due process clause, and the Administrative Procedure Act. The judge also revoked the related designations and Defense Secretary Hegseth's injunction, issuing a permanent injunction.The controversy arose from the Pentagon's demand that Anthropic remove all usage restrictions and accept terms allowing "all lawful uses," while Anthropic maintained its last two bottom lines. On February 27, 2025, Trump ordered all federal agencies to cease using the company's technology, and Hegseth subsequently prohibited any military contractors from doing business with it. During this process, the government abandoned its core claims, acknowledging that Anthropic had no backdoor access to the deployed models and that the risks of Claude were no greater than those of other "black box" systems. Lin pointed out that the government's punishment under the guise of "national security" was not a blank check, and that the government had been operating under the preliminary injunction since March without indicating any harm.Anthropic did not achieve a complete victory, as its claim that Trump's directive exceeded presidential authority was dismissed. Anthropic informed the court that if the relevant measures continued, its defense-related revenue would decrease by 50% to 100%, resulting in a loss of billions of dollars in overall revenue by 2026.
app_icon
ChainCatcher Building the Web3 world with innovations.