Scan to download
BTC $77,075.92 +0.54%
ETH $2,096.73 -1.03%
BNB $657.44 +0.22%
XRP $1.35 -0.76%
SOL $85.16 -0.87%
TRX $0.3644 +0.32%
DOGE $0.1021 -0.94%
ADA $0.2413 -1.72%
BCH $345.03 -2.83%
LINK $9.42 -1.31%
HYPE $61.68 +3.21%
AAVE $85.63 -0.67%
SUI $1.02 -3.43%
XLM $0.1475 -0.37%
ZEC $655.81 +3.26%
BTC $77,075.92 +0.54%
ETH $2,096.73 -1.03%
BNB $657.44 +0.22%
XRP $1.35 -0.76%
SOL $85.16 -0.87%
TRX $0.3644 +0.32%
DOGE $0.1021 -0.94%
ADA $0.2413 -1.72%
BCH $345.03 -2.83%
LINK $9.42 -1.31%
HYPE $61.68 +3.21%
AAVE $85.63 -0.67%
SUI $1.02 -3.43%
XLM $0.1475 -0.37%
ZEC $655.81 +3.26%

attacker

Verus: The network has been suspended, and if the attacker returns the funds, a bounty for the vulnerability will be offered

Verus posted on the X platform confirming that the Verus-Ethereum cross-chain bridge has been attacked, with ETH, USDC, and tBTC stolen from the Ethereum chain contracts. Currently, other bridged assets have not been affected. The Verus network has now suspended operations, and most block-producing nodes have proactively gone offline after experiencing the impact of the attack. The development team is working hard to investigate the scope of the incident, the attack path, and subsequent handling plans, and will announce progress after confirming more information.Verus stated that it is willing to cooperate with relevant law enforcement agencies to pursue legal responsibility; however, if the attacker returns the full amount of funds, the project team is willing to offer a bug bounty and will not pursue further accountability. Verus also reminds anyone claiming to be a member of the Verus team or community in public channels, private messages, or other channels and offering "compensation" or "reimbursement plans" to be scammers. The official emphasizes not to interact with anyone claiming to have compensation projects or offering reimbursement, and to report relevant accounts to Discord or the X platform in a timely manner.Previously, the Verus Ethereum cross-chain bridge was attacked, resulting in a loss of approximately $11.58 million.

AI Agent Security Risk Exposure: Attackers Can Exploit "Memory Pollution" to Induce Misoperation of Funds

The GoPlus Security team has disclosed a new type of attack in its AgentGuard AI project: inducing AI agents to perform unauthorized sensitive operations through "memory poisoning." This attack method does not rely on traditional vulnerabilities or malicious code but exploits the long-term memory mechanism of AI agents. For example, an attacker first induces the agent to "remember preferences," such as "usually prioritizing proactive refunds instead of waiting for chargebacks," and then uses vague expressions like "process as usual" or "execute as before" in subsequent instructions, thereby triggering automated financial operations.GoPlus points out that the key risk in such cases lies in the AI agent mistakenly treating "historical preferences" as a basis for authorization, leading to financial losses or security incidents in operations such as refunds, transfers, and configuration changes. To address this issue, the team has proposed several protective recommendations, including:Operations involving refunds, transfers, deletions, or sensitive configurations must require explicit confirmation in the current session.Memory-related instructions like "habit," "usual way," and "as before" should be regarded as high-risk state changes.Long-term memory must have a traceability mechanism (writer, time, confirmation status).Vague instructions should automatically elevate the risk level and trigger secondary verification.Long-term memory must not replace real-time authorization processes.The team emphasizes that the "AI agent memory system" should be viewed as a potential attack surface and should be constrained and audited through a dedicated security framework.
app_icon
ChainCatcher Building the Web3 world with innovations.