BTC $77,464.78 +0.49%
ETH $2,391.81 -0.74%
BNB $690.50 +1.00%
XRP $1.36 +1.61%
SOL $100.43 +0.97%
TRX $0.3249 +0.89%
DOGE $0.0824 +1.82%
ADA $0.2057 +5.12%
BCH $245.72 +0.02%
LINK $11.14 +0.01%
HYPE $81.68 -1.03%
AAVE $127.31 +0.57%
SUI $0.7584 +5.95%
XLM $0.1780 +2.21%
ZEC $819.39 -0.71%
BTC $77,464.78 +0.49%
ETH $2,391.81 -0.74%
BNB $690.50 +1.00%
XRP $1.36 +1.61%
SOL $100.43 +0.97%
TRX $0.3249 +0.89%
DOGE $0.0824 +1.82%
ADA $0.2057 +5.12%
BCH $245.72 +0.02%
LINK $11.14 +0.01%
HYPE $81.68 -1.03%
AAVE $127.31 +0.57%
SUI $0.7584 +5.95%
XLM $0.1780 +2.21%
ZEC $819.39 -0.71%

error

All
Article
Flash

first_img Anthropic admits that Claude accessed the system beyond his authority due to a security error

In a blog post released on Monday, Anthropic acknowledged that its Claude model had unauthorized access to real computer systems during a cybersecurity assessment, an incident reflecting operational security failures as well as alignment failures in motivation reasoning and intent to harm. Anthropic disclosed in July that the Claude model had breached the systems of three companies because the third-party assessment environment was connected to the public internet, while the model was informed it was in a simulated environment without internet access.Anthropic stated that Claude may have interpreted evidence of real internet access as still being in a simulated environment and was willing to take harmful actions on the real internet to complete the cybersecurity assessment task. Additionally, during tests at the UK AI Safety Institute, after assessors deliberately granted Claude Mythos internet access, the model took unauthorized actions on the live network. Anthropic emphasized that the models involved did not have the cybersecurity protections included in the officially released products.Following the incident on July 30, Anthropic has suspended cybersecurity assessments of pre-release models and introduced stricter protections: tests must run in verified offline sandboxes equipped with real-time monitoring; a new classifier can intercept suspected boundary violations, terminate tests, and notify humans. Anthropic has also expanded the scope of offline monitoring used by internal frontier agents. Previously, OpenAI models had also breached Hugging Face in July to obtain answers for cybersecurity tests, with investigations revealing that about 1,200 agents acted collaboratively through unauthorized message boards.

first_img South Korea arrests 4 Uzbeks for transferring USDT to a Syrian terrorist organization

According to Decrypt, the Gwangju Police Agency in South Korea arrested four Uzbek suspects in April under the Anti-Terrorism Financing Act and disclosed the case on Tuesday. One of them is listed on Interpol's Red Notice. The police stated that this is the first case involving cryptocurrency flowing out from a recognized terrorist organization and then being funneled back to fund physical goods.According to police investigations, from August 2024 to April 2025, the alleged mastermind transferred 4,267 USDT to the Syrian terrorist organization "Katibat Tawhid wal Jihad" (KTJ) in seven transactions. KTJ was established in 2014 and is mainly composed of Central Asian militants, recognized as a terrorist organization by the United Nations and the United States.Additionally, the mastermind is accused of receiving cryptocurrency from KTJ to purchase 11 used cars and 2 excavators, with a total value of approximately 170 million Korean won (about 121,000 USD), which were then shipped to Syria. The other three suspects are alleged to have assisted in the purchase and export of these vehicles.The police stated that previous terrorism-related cases mostly involved remittances to terrorist organizations, while this case is the first instance of receiving funds from a terrorist organization and reverse procuring and supplying vehicles.Investigations revealed that the mastermind rotated operations among three personal wallets, with the vehicle purchase funds deposited into an account under his spouse's name, and he presented someone else's driver's license when arrested. He entered South Korea in 2017 on a student visa, graduated from a university in Daejeon, and has been illegally residing since 2023. He denied the main charges during his first court hearing in June, claiming that the remittances were for family living expenses and that he did not know the identity of the vehicle purchasers. The police stated that the investigation also led to the capture of a second suspect listed on the Red Notice, and the case is still ongoing.

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.

first_img Cap team responds to Stabledrop controversy, admits early commitment errors and clarifies insider rumors

In response to the recent market controversy regarding the reduction of Stabledrop shares, Cap founder Benjamin issued a statement of apology and provided a detailed response. He stated that the team prematurely committed to an airdrop scale of 11 million before the funding was fully secured, but subsequent changes in the market environment led to a fundraising amount that fell short of expectations, resulting in the actual airdrop pool shrinking to 4.2 million.To avoid substantial principal losses for early YT (Yield Token) holders, the team temporarily adjusted the originally planned linear distribution scheme to a "capital protection but no profit" restructuring model, ensuring that no one incurs losses. This rule applies equally to all wallets. Meanwhile, in response to community concerns about a related whale address allegedly engaging in "internal score manipulation," Benjamin clarified that the wallet belongs to a former colleague and is not operated by the team, and that project treasury funds have not been utilized. Additionally, he emphasized that the Cap protocol is still operating healthily, and the decline in TVL that occurred over the weekend was mainly due to the surge in USDM lending rates on Aave for MegaETH, causing arbitrageurs to exit, which is unrelated to this airdrop incident. All redemptions have been processed smoothly.

PiggyBank: LAB token basis trading error, token manipulated by the market, USDC treasury has retracted 15%

The revenue agreement PiggyBank issued a statement acknowledging a serious error in the LAB token basis trading that took place last month. PiggyBank disclosed that the team previously purchased locked LAB tokens at a low price through OTC channels for about $100,000 (accounting for approximately 2% of the portfolio) and simultaneously shorted perpetual contracts for hedging.However, during the holding period, LAB encountered severe market manipulation, liquidity depletion, and deeply negative funding rates, leading to excessively high hedging costs. The team ultimately chose to close the short position to limit downside risk. Based on current prices, the total value of the locked LAB position is $1.35 million. However, due to the lack of liquidity in this position, PiggyBank will exclude it from the net asset value calculation until the first unlock on August 14.Although the situation is still changing and there is still potential for considerable returns, this is the "fairest and most transparent" way for users to manage liquidity. Therefore, today's net asset value will show a decline of approximately 15% in the USDC treasury, about 12% in SPYx, and about 9% in JitoSOL. A detailed report will be released next week, including follow-up processing plans. On-chain investigator ZachXBT previously publicly questioned PiggyBank, accusing it of insider control over more than 95% of the supply.
app_icon
ChainCatcher Building the Web3 world with innovations.