BTC $78,332.98 -1.42%
ETH $2,471.23 -0.74%
BNB $758.40 +1.85%
XRP $1.39 -1.29%
SOL $102.72 -1.76%
TRX $0.3380 +0.46%
DOGE $0.0889 -0.70%
ADA $0.2161 -0.73%
BCH $255.11 -0.26%
LINK $12.63 -4.83%
HYPE $83.94 -2.99%
AAVE $130.59 -2.09%
SUI $0.8113 +0.38%
XLM $0.1890 -0.26%
ZEC $1,120.63 -5.15%
BTC $78,332.98 -1.42%
ETH $2,471.23 -0.74%
BNB $758.40 +1.85%
XRP $1.39 -1.29%
SOL $102.72 -1.76%
TRX $0.3380 +0.46%
DOGE $0.0889 -0.70%
ADA $0.2161 -0.73%
BCH $255.11 -0.26%
LINK $12.63 -4.83%
HYPE $83.94 -2.99%
AAVE $130.59 -2.09%
SUI $0.8113 +0.38%
XLM $0.1890 -0.26%
ZEC $1,120.63 -5.15%

hac

All
Article
Flash

first_img Hacken Report: Half of USDT is controlled by only two signing keys

Blockchain security company Hacken released an assessment report indicating that approximately half of the circulating USDT (about $91.3 billion on the Tron network) is controlled by a 2-of-3 multi-signature contract, which lacks built-in delays, cancellation processes, or reliable revocation mechanisms. Attackers only need to compromise two signature keys to change contract ownership, mint tokens, freeze addresses, clear frozen balances, or set transfer fees without accessing any user wallets. Hacken also discovered that Tether reuses the same set of six signature keys across three chains: Ethereum, Avalanche, and Celo, posing a risk of cross-chain spread.Meanwhile, stablecoin rating agency Bluechip upgraded Tether's company rating from D to C, citing that KPMG's audit showed Tether's reserves exceeded liabilities by $6.8 billion as of December 31, 2025. This is the first time Bluechip has adopted the expanded SMIDGE methodology, which incorporates Hacken's technical risk analysis. However, Hacken only gave USDT a cybersecurity score of 3.3 out of 10 and pointed out that the USDT smart contract does not have automatic reserve proof checks or a token minting cap. Once signers authorize a transaction, the contract can mint an unlimited number of tokens without a bank reserve proof.Hacken stated that it has not yet completed an equivalent assessment of Circle's USDC, and Bluechip's previous B+ rating for USDC was based on an old methodology, which cannot be directly used for technical comparison.

X-Agent AI MCP Hackathon starts on September 2nd

X-Agent announced that the X-Agent AI MCP Hackathon 2026 will officially launch on September 2, calling for global developers and teams to submit practical, verifiable Agent and MCP applications. This event is an online global competition supported by OlaXBT.The hackathon features two tracks: the Open Innovation Track encourages participants to develop any practical API-driven Agent or MCP capabilities around AI, crypto assets, data, automation, and Agent infrastructure; the OlaXBT × X-Agent Trading Challenge allows participating teams to access the OlaXBT Nexus MCP, supporting their use of strategy development, backtesting, performance analysis, and market data capabilities to validate trading strategies and build related Agent or MCP applications.The total rewards for this event include USDT and X-Points. The first-place team in each track will receive a reward of 500 USDT; the top five teams in each track will collectively earn X-Points. X-Points can be used to participate in the X-Agent airdrop token $XAGT exchange. Award-winning and selected projects will also have the opportunity to receive support for MCP standardization, ecological exposure, market integration, and paid call commercialization. The registration and development period for the event is from September 2 to September 19, with technical reviews and evaluations taking place from September 20 to October 1, and the winners' list is expected to be announced between October 2 and 4. Participating projects must be submitted through the official GitHub repository.

first_img North Korean hackers transfer tens of millions of dollars at Hyperliquid, Trump promotes platform's entry into the U.S

According to Arkham blockchain data, wallets associated with the North Korean state-sponsored hacking organization Lazarus Group have sold over $30 million in Bitcoin on the decentralized perpetual contract trading platform Hyperliquid in the past three weeks, using the proceeds to purchase Ethereum and Solana, which were then transferred to centralized exchanges such as Kraken, LBank, and KuCoin. Kraken responded that it maintains an industry-leading compliance program, continuously monitoring on-chain activities to identify and block assets related to sanctioned wallets; LBank and KuCoin stated that the associated risks are a continuing challenge faced by the industry as a whole and emphasized that publicly available on-chain data may not reflect compliance measures at the platform level.At this time, the Trump administration is exploring ways to incorporate Hyperliquid into the regulated U.S. financial system. Trump stated earlier this month at a White House event that the chairman of the Commodity Futures Trading Commission, Mike Selig, is developing a path to bring Hyperliquid into the U.S. in a fully compliant and legal manner. According to Bloomberg, Kraken's parent company Payward is in deep negotiations with Hyperliquid Labs to offer perpetual contracts to U.S. traders.Hyperliquid is the leading platform in the decentralized perpetual contract space, allowing users to trade directly from their crypto wallets without the need for traditional brokerage accounts or KYC checks. According to DefiLlama data, its cumulative perpetual contract trading volume has exceeded $5 trillion, with current open contracts of approximately $13.3 billion.

first_img Solana crypto card hacked, Avici token plummets 49%

The Solana-based crypto debit card infrastructure Rain was hacked due to vulnerabilities in outdated contracts, resulting in approximately $1.1 million in funds being stolen. The affected crypto bank Avici's token AVICI dropped from a 24-hour high of $0.43 to a historical low of $0.217, a decline of 49%, before recovering to around $0.378.Avici confirmed that the attack only affected the card funds contract used for recharge consumption, and its self-custody wallets were not impacted, promising to fully refund the affected balances. In this incident, 1,685 Avici users lost approximately $500,800; another crypto bank, Tria, also had 636 users affected, with losses exceeding $430,000. The discrepancy between the approximately $1.1 million tracked on-chain and the losses reported by Avici indicates that other protocols supported by Rain were also attacked.Transaction data shows that the attacker repeatedly submitted signature authorizations, adding themselves as administrators of the card collateral account and withdrawing balances. The stolen stablecoins were exchanged for SOL, cross-chain to Ethereum, and ultimately flowed into the mixer Tornado Cash. Avici has filed a report with the FBI's Internet Crime Complaint Center. This incident also exposed issues with the custody transfer behind some self-custody crypto cards: although users control their wallets, the funds used for consumption are transferred to third-party contracts.
app_icon
ChainCatcher Building the Web3 world with innovations.