BTC $77,642.45 -2.74%
ETH $2,438.78 -2.08%
BNB $689.28 -2.94%
XRP $1.38 -3.65%
SOL $103.97 -2.87%
TRX $0.3407 +0.69%
DOGE $0.0850 -3.09%
ADA $0.2013 -4.07%
BCH $246.92 -6.61%
LINK $11.37 -2.91%
HYPE $81.81 -2.18%
AAVE $121.06 -3.87%
SUI $0.7389 -3.23%
XLM $0.1779 -3.41%
ZEC $806.38 +2.26%
BTC $77,642.45 -2.74%
ETH $2,438.78 -2.08%
BNB $689.28 -2.94%
XRP $1.38 -3.65%
SOL $103.97 -2.87%
TRX $0.3407 +0.69%
DOGE $0.0850 -3.09%
ADA $0.2013 -4.07%
BCH $246.92 -6.61%
LINK $11.37 -2.91%
HYPE $81.81 -2.18%
AAVE $121.06 -3.87%
SUI $0.7389 -3.23%
XLM $0.1779 -3.41%
ZEC $806.38 +2.26%

nsa

All
Article
Flash

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

Coinbase launches AiFi financial system: x402 has processed over 205 million transactions

Coinbase stated on the X platform that the financial layer surrounding AI agents is referred to as agent finance, or AiFi, which encompasses agent trading and agent commerce. AI agents can research information, make decisions, and execute operations on behalf of individuals and businesses, and they need to perform basic financial activities such as payments, receipts, value storage, and fund transfers. Coinbase claims that it is building tools for AI agents to continuously execute financial operations within predefined goals, permissions, limitations, and security boundaries.Coinbase indicated that Coinbase Advisor, Coinbase for Agents, x402, and Coinbase Business have formed the AiFi infrastructure. Coinbase Advisor is an SEC-registered investment advisor integrated into the app for Coinbase One users, providing portfolio analysis and guidance through a chat interface; Coinbase for Agents connects tools like Claude, ChatGPT, and Cursor to Coinbase accounts via MCP, allowing users to set operational conditions and security boundaries for agents, as well as create independent sandbox accounts for agent use.Coinbase stated that x402 is an open payment standard initiated by Coinbase and currently managed by an independent foundation, which supports AI agents in paying fees to other agents, applications, and services. As of now, x402 has processed over 205 million transactions, with a transaction volume of $53 million, covering 200,000 sellers, with Coinbase facilitating 67% of the activities. Single payments can be used for API calls, datasets, research materials, or computing resources.Coinbase indicated that Coinbase Business supports enterprises in natively receiving AI agent payments in USDC, and Coinbiz can help merchants sell services and content to software without relying on credit card credentials, manual invoicing, or payment processes designed with human customers in mind. Eligible businesses can earn a floating reward of 3.35% from idle USDC balances. USDC currently accounts for 99% of on-chain agent commerce transactions, while x402 represents 97% of agent finance protocol usage, with related activities operating on Base.

The Sandbox: Compensation will be carried out based on the on-chain snapshot before the attack, and the compensation application process is expected to open within two weeks

The Sandbox released an update on the security vulnerability attack incident involving the SAND cross-chain bridge, stating that the attacker modified the verification mechanism to forge cross-chain deposit messages and mint unbacked SAND. This incident resulted in approximately 14.7423 million SAND being withdrawn, valued at about $697,000. Additionally, some uncollateralized SAND was profited through market trading, leading to an overall economic impact of approximately $1.497 million, of which the attacker actually obtained about $987,000.The Sandbox stated that the attack did not affect the supply of SAND on Ethereum and Polygon, with the total amount of SAND on Ethereum remaining unchanged at 3 billion. There were also no super administrator privileges stolen, and the attack stemmed from a vulnerability caused by the combination of the general call function in the token contract and the design of bridge permissions. Currently, the related addresses have been marked, and collaboration has begun with exchanges, security agencies, and the LayerZero team.For affected users, The Sandbox promises to compensate wallets holding legitimate bridged SAND with a 1:1 ratio of SAND on the Ethereum chain based on an on-chain snapshot taken before the attack. The compensation application process is expected to open within two weeks and will last for two weeks.
app_icon
ChainCatcher Building the Web3 world with innovations.