BTC $79,487.88 +0.09%
ETH $2,499.28 -0.07%
BNB $705.49 -0.20%
XRP $1.42 -0.89%
SOL $104.89 +0.59%
TRX $0.3410 +0.91%
DOGE $0.0867 -1.71%
ADA $0.2079 -1.60%
BCH $264.35 -1.86%
LINK $11.76 +0.18%
HYPE $83.07 +0.84%
AAVE $125.28 -0.51%
SUI $0.7580 -0.93%
XLM $0.1828 -1.27%
ZEC $799.82 +2.31%
BTC $79,487.88 +0.09%
ETH $2,499.28 -0.07%
BNB $705.49 -0.20%
XRP $1.42 -0.89%
SOL $104.89 +0.59%
TRX $0.3410 +0.91%
DOGE $0.0867 -1.71%
ADA $0.2079 -1.60%
BCH $264.35 -1.86%
LINK $11.76 +0.18%
HYPE $83.07 +0.84%
AAVE $125.28 -0.51%
SUI $0.7580 -0.93%
XLM $0.1828 -1.27%
ZEC $799.82 +2.31%

ln

All
Article
Flash

MANTRA announces the review of the attack incident: A down-scaling vulnerability led to the transfer of over 720 million tokens, with approximately 37.96 million tokens frozen

On August 20, MANTRA Chain released a complete review report of the security incident, confirming that the attacker exploited an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency cosmos/evm, unauthorizedly transferring a total of 720,923,967.99 MANTRA from two addresses, valued at approximately 3.6 million dollars based on the price before the attack. Among them, the attacker transferred 600,000,035.56 MANTRA from the on-chain burn address and 120,923,932.44 MANTRA from a genesis-era multi-signature address related to an early incentive program.MANTRA stated that this incident did not involve the leakage of validator keys, administrator privileges, governance control, or multi-signature signers; the attacker did not require privileged access and could complete the attack solely through unauthorized contract deployment and self-funded wallets. The first abnormal transfer occurred at 19:06 UTC on August 20, when the attacker transferred approximately 600 million MANTRA from the burn address; subsequently, at 22:59 UTC, another transfer of approximately 120.9 million MANTRA was made. The chain subsequently stopped operating at 23:13 UTC and resumed after upgrading to v8.4.0. The entire network interruption lasted for 30 hours and 13 minutes.This vulnerability was not an issue with MANTRA's self-developed code but originated from the cosmos/evm module, which is responsible for providing EVM functionality on the Cosmos SDK. The vulnerability allowed the attacker to execute unsigned balance deductions without checking if the balance was sufficient, causing an overflow of values and bypassing normal account authorization logic. MANTRA stated that as of today, no funds have been recovered, with approximately 37.96 million MANTRA (accounting for 5.27% of the total transferred) still remaining in the attacker's address, which has been frozen due to the chain's suspension and v8.4.0 restrictions. The remaining funds have flowed to related trading platforms, and the recovery efforts have entered the law enforcement investigation stage. In the future, monitoring of accounts that cannot normally authorize transfers, burn addresses, and other historically "non-transferable" addresses will be strengthened, and efforts will be made to promote improvements in the security vulnerability disclosure process within the Cosmos ecosystem.

Core Lightning, the Bitcoin Lightning Network software, issued an emergency warning due to the discovery of multiple real vulnerabilities in an AI report

According to CoinDesk, the developers of the Bitcoin Lightning Network payment software Core Lightning (CLN) issued an urgent warning to node operators after the team received a large number of AI-generated security reports, revealing several real vulnerabilities. The development team advised operators not to directly shut down the machine power but to restart the software in "--offline" mode, which stops communication with other Lightning Network nodes while still keeping it operational to continuously monitor the Bitcoin blockchain and protect the funds in the payment channels.The Core Lightning team began receiving a large number of AI-generated vulnerability reports since early August, some of which have been confirmed to be valid. Developers will keep the details confidential for two weeks to complete the patch development and plan to release a signed patch version for operators to verify the source. The source code and vulnerability details will be made public after the confidentiality period ends.This is the second AI-related security incident in the Lightning Network this month. Earlier in early August, BTCPay Server experienced a vulnerability that led to the leakage of credentials for some Lightning Network nodes and theft of funds. Additionally, the "Bitcoin Red Team," composed of 16 developers, used AI models to scan 390 Bitcoin code repositories at the end of July, discovering nearly 5,000 issues, 85 of which were rated as critical.

Ledger CTO responds to vulnerability FUD: The issue was fixed before it was disclosed, and users can safely use it by updating in a timely manner

Ledger's Chief Technology Officer Charles Guillemet stated that there has recently been "FUD" targeting Ledger in the market, as a smart contract security company claimed to have discovered vulnerabilities in the Ledger Ethereum application. Guillemet mentioned that there indeed were vulnerabilities related to certain Clear Signing processes in the Ledger Ethereum application, but these vulnerabilities were discovered by Ledger's security research team Donjon using AI-driven vulnerability research tools, and the fixes were completed and deployed two weeks ago. Users can obtain protection by timely updating their Ledger device firmware and applications.The relevant security company contacted Ledger's bug bounty program only after the fixes were completed, did not follow responsible disclosure processes, and did not communicate with the bug bounty team, yet implied in subsequent content that the issue had not been resolved. This approach is not true security research but rather a way to create panic for attention. AI is changing the cybersecurity landscape, and both attackers and defenders can enhance efficiency with AI, but AI-driven security research can only truly enhance the security of the entire ecosystem when basic security principles such as responsible disclosure and pre-release verification are followed.Guillemet finally reminded Ledger users to keep their device firmware, Ledger applications, and related software up to date to automatically receive the latest security fixes and research results. Users should not be influenced by the related "FUD" and should timely update their software and maintain safe habits.

first_img Linera opens pre-registration for the LNRA community round, subscription from September 1 to 8

The real-time market application underlying protocol Linera announces the opening of pre-registration for the $LNRA community round, aimed at traders, badge recipients, community members, and external participants, allowing for token purchases before Season 1 and TGE. Pre-registration is open from now until September 1 UTC, with the subscription period from September 1 to 8 UTC. Participants can join at a fixed price / FDV using USDC on Base through sale.linera.net, with round pricing and scale to be announced on August 28.This round is divided into a reserved pool for badge holders and an open pool for all registered users. Badges can be earned daily through trading and social activities on app.linera.xyz and claimed at portal.linera.net. Higher levels and points determine the priority order for the reserved pool; the open pool is allocated proportionally, with a single wallet limit of $100,000. For every $1 committed, 1 Commitment Credit is earned, which can be used for fee-free trading volume in Season 1 on app.linera.xyz, with refunds also counted.It is reported that 65% of the total supply belongs to the community (including reserves and this pre-sale), while investors and early contributors hold a total of 25%, with a three-year vesting period from distribution. Linera claims there are currently about 50,000 traders, over 80 million predictions, and over 2 billion test trades, nearing the launch of the mainnet.
app_icon
ChainCatcher Building the Web3 world with innovations.