BTC $77,683.73 -0.64%
ETH $2,419.23 -1.65%
BNB $684.62 -1.49%
XRP $1.35 -3.23%
SOL $101.75 -3.37%
TRX $0.3361 -1.20%
DOGE $0.0821 -3.52%
ADA $0.1933 -3.83%
BCH $243.55 -0.92%
LINK $11.12 -2.46%
HYPE $80.44 -3.19%
AAVE $122.10 -3.05%
SUI $0.7138 -3.68%
XLM $0.1751 -2.97%
ZEC $817.95 -2.04%
BTC $77,683.73 -0.64%
ETH $2,419.23 -1.65%
BNB $684.62 -1.49%
XRP $1.35 -3.23%
SOL $101.75 -3.37%
TRX $0.3361 -1.20%
DOGE $0.0821 -3.52%
ADA $0.1933 -3.83%
BCH $243.55 -0.92%
LINK $11.12 -2.46%
HYPE $80.44 -3.19%
AAVE $122.10 -3.05%
SUI $0.7138 -3.68%
XLM $0.1751 -2.97%
ZEC $817.95 -2.04%

attacker

All
Article
Flash

first_img Attackers stole over $1 million in user funds from the new Solana bank Avici

Solana's new bank Avici is facing ongoing attacks, with attackers having stolen over $1 million from users. The attackers' wallet holds 10,005.03 SOL (approximately $1.07 million) and about $11,600 in USDC and USDT. The attack method involves first calling the SubmitSignatures of the Avici authorization program, then calling the AddCollateralAdmin of the collateral program, and finally executing WithdrawCollateralAsset to withdraw the balance. Both of Avici's programs are upgradable and share the same standard Solana account instead of multi-signature upgrade permissions.Avici confirmed the incident 1 hour and 53 minutes after the first theft transaction, stating, "We are aware of the issue affecting card balance withdrawals and are working directly with all relevant partners to resolve it." Prior to this, users had reported stolen balances on social media. A real-time tracker established by anonymous on-chain analyst STACC recorded 125 different sending accounts, with transfer amounts ranging from approximately 9 USDC to over 26,000 USDT.As a result, the AVICI token fell 49.4% in 24 hours to $0.2175, with a market cap of approximately $2.84 million, hitting an all-time low. Avici raised funds through MetaDAO in October 2025, with an original cap of $3.5 million, but the final committed amount reached $34.2 million, and the team refunded 89.8% of the committed USDC.

Bubblemaps: Attackers stole 50 million USD in NES, but actually only profited 60,000 USD

Bubblemaps posted on platform X that attackers exploited a vulnerability in the Cosmos EVM shared module to steal $50 million worth of NES tokens, but ultimately only profited about $60,000. Previously, Cosmos Labs reported security vulnerabilities in its shared Cosmos EVM software, affecting multiple chains built on this module, including Nesa.According to disclosures, the main attacker with an address starting with 0x9AE7 previously spent $250,000 to purchase NES and cross-chain to Nesa Chain, then exploited the vulnerability to inflate the account balance by 200 times and transferred $50 million NES back to Ethereum, with the initial funds coming from Monero. The attacker then dispersed the tokens to multiple wallet addresses, exchanged NES for ETH on a DEX, and deposited the profits into a centralized exchange.Due to the rapid withdrawal of funds from the liquidity pool, most of the attacker’s exchange transactions encountered severe slippage, resulting in an actual expenditure of $255,000 to initiate the attack, cashing out only $315,000, with a net profit of about $60,000.Bubblemaps stated that although another Cosmos EVM chain had also suffered a similar attack of $1.4 million the day before, the differences in funding sources and operational methods suggest that the two incidents may have originated from different attackers. The report also mentioned that the price of NES tokens once plummeted by 90%, but has since significantly rebounded, with the team believing that the rebound is mainly due to arbitrage activities caused by price mismatches between DEX and CEX after the attack.

153 stolen addresses contain 132.95 BTC, and researchers are still unable to reproduce the Coldcard attacker's seed

According to monitoring by Bitcoin News, new research published by @PraveenPerera shows that Coldcard attackers seem to first identify addresses with vulnerabilities, then sort them by the amount of Bitcoin held, starting to transfer in batches from the addresses with the highest holdings. The transfer software used was relatively crude.One address had 225 spendable UTXOs, and the attackers extracted exactly the latest 200, leaving the earliest 25, which included a UTXO worth 0.16 BTC. This aligns perfectly with the limitation of a blockchain API investigated by researchers, which defaults to returning 200 records, indicating that the attackers may have failed to load the next page of data. The software even spent a UTXO of 294 satoshis, reportedly increasing the transaction fee by about 2040 satoshis, with the spent amount significantly higher than the value of the UTXO itself.The authors of the study believe that the builders of this tool may have a better understanding of the account balance system than of the Bitcoin UTXO model. Although the attackers seem to have obtained the complete seed of the victims, at least 75 BTC still remain in other addresses derived from the same seed. The biggest suspicion currently is that among the 153 stolen addresses, there are still 132.95 BTC, and researchers have been unable to reproduce the seed behind these addresses, so it cannot be ruled out that the attackers obtained undisclosed private device data or candidate data.
app_icon
ChainCatcher Building the Web3 world with innovations.