BTC $78,302.78 +0.18%
ETH $2,444.64 -0.60%
BNB $686.99 -0.82%
XRP $1.37 -1.57%
SOL $103.35 -1.66%
TRX $0.3343 -1.84%
DOGE $0.0826 -2.76%
ADA $0.1963 -2.30%
BCH $246.37 +0.00%
LINK $11.25 -1.46%
HYPE $81.72 -2.19%
AAVE $123.01 -2.95%
SUI $0.7248 -2.03%
XLM $0.1763 -1.79%
ZEC $837.39 -0.55%
BTC $78,302.78 +0.18%
ETH $2,444.64 -0.60%
BNB $686.99 -0.82%
XRP $1.37 -1.57%
SOL $103.35 -1.66%
TRX $0.3343 -1.84%
DOGE $0.0826 -2.76%
ADA $0.1963 -2.30%
BCH $246.37 +0.00%
LINK $11.25 -1.46%
HYPE $81.72 -2.19%
AAVE $123.01 -2.95%
SUI $0.7248 -2.03%
XLM $0.1763 -1.79%
ZEC $837.39 -0.55%

pda

All
Article
Flash

Ledger CTO responds to vulnerability FUD: The issue was fixed before it was disclosed, and users can safely use it by updating in a timely manner

Ledger's Chief Technology Officer Charles Guillemet stated that there has recently been "FUD" targeting Ledger in the market, as a smart contract security company claimed to have discovered vulnerabilities in the Ledger Ethereum application. Guillemet mentioned that there indeed were vulnerabilities related to certain Clear Signing processes in the Ledger Ethereum application, but these vulnerabilities were discovered by Ledger's security research team Donjon using AI-driven vulnerability research tools, and the fixes were completed and deployed two weeks ago. Users can obtain protection by timely updating their Ledger device firmware and applications.The relevant security company contacted Ledger's bug bounty program only after the fixes were completed, did not follow responsible disclosure processes, and did not communicate with the bug bounty team, yet implied in subsequent content that the issue had not been resolved. This approach is not true security research but rather a way to create panic for attention. AI is changing the cybersecurity landscape, and both attackers and defenders can enhance efficiency with AI, but AI-driven security research can only truly enhance the security of the entire ecosystem when basic security principles such as responsible disclosure and pre-release verification are followed.Guillemet finally reminded Ledger users to keep their device firmware, Ledger applications, and related software up to date to automatically receive the latest security fixes and research results. Users should not be influenced by the related "FUD" and should timely update their software and maintain safe habits.

SafePal updates on security incident progress: launching anti-phishing actions and will commission a third-party agency to review the order system

The cryptocurrency wallet project SafePal has released updates on the security incident, stating that it is continuously tracking phishing websites and impersonation accounts, and plans to introduce a professional anti-phishing security company to expedite the removal of malicious information to protect user asset security. SafePal mentioned that it is currently in the final selection process among four professional anti-phishing security companies, and once a partner is selected, it will further enhance the efficiency of handling threats such as counterfeit websites and scam accounts.The team is also continuously monitoring whether the affected data has been sold or made public, including channels such as dark web forums and trading markets. Once signs of data leakage are detected, affected users will receive risk alerts immediately. Regarding security audits, SafePal stated that it is in the final selection among three mature independent security institutions, which will conduct a comprehensive security review of the order system. Meanwhile, the team is reassessing the order and logistics processes to reduce the amount of data that needs to be stored in the initial phase of the system, thereby reducing potential risks from the source.For affected users, SafePal stated that it will continue to provide one-on-one assistance through official support channels and will keep updating the fraud protection page, providing updates on the incident, FAQs, and analysis of fraud cases. SafePal once again reminds users: the official will never ask users to provide their seed phrase. Users should not disclose their seed phrase to anyone, should not scan unknown QR codes or click on suspicious links, and should verify the source of information through official channels.

Bitmart: Plans to orderly resume part of its business operations in phases, with the latest update to be released by September 9

BitMart officially released a long announcement on platform X, with the main content as follows: "This announcement aims to inform everyone of the latest developments following the announcement on July 26, 2026. We thank users for their patience during this period.After further discussions with users, stakeholders, and professional advisors, BitMart is formulating a potential restructuring plan as an alternative to a comprehensive liquidation. This plan may include a phased and orderly resumption of some business operations while distributing assets to creditors. The relevant arrangements still require further legal, financial, operational, and compliance assessments. To advance the relevant processes, BitMart has appointed Weikai Law Firm as its restructuring legal advisor. Weikai will work with BitMart's other professional advisors to evaluate feasible plans and assist in formulating a potential restructuring plan, which includes a framework for phased resumption of operations.Currently, we are working with the advisory team to develop a roadmap, aiming to release the next update no later than September 9, 2026.Once the relevant information is confirmed, we will continue to update the community. During the advancement of the above work, we kindly ask everyone to remain patient and understanding. Once the business recovery plan is formally drafted, we plan to solicit feedback from community users. Please continue to pay attention to our official website, official mobile app, and official social media channels for subsequent announcements. As always, please be vigilant against various scam messages and only trust content released through BitMart's official channels. Thank you for your trust and support."

BounceBit Chain update on vulnerability attack progress: will permanently halt the chain and migrate to BNB Chain

The cross-chain yield protocol BounceBit has released a security incident announcement stating that its blockchain network experienced a protocol-level vulnerability attack from August 19, 21:02 UTC to August 20, 01:54 UTC. The attacker exploited an authorization flaw in the underlying architecture of Evmos to transfer BB tokens from 9 mainnet accounts without the account owners' authorization. According to the announcement, the attacker transferred approximately 286.5 million BB through 14 transactions.The impact of the incident is limited to the BounceBit Chain itself and does not involve issues related to private key leakage, signature forgery, wallet, hardware device, or exchange account security. BounceBit's CeDeFi Strategy, Promo Vaults, Prime, and RWA products were not affected.BounceBit stated that the vulnerability originated from a defect in the authorization verification of the protocol's native module within the Evmos architecture. The attacker bypassed the security checks that were supposed to verify the authorization relationship of the funding source account when calling the relevant module through a smart contract, allowing them to designate any account as the source of funds.After the incident, the BounceBit Chain stopped block production at block height 20,702,857. The team then decided not to upgrade the chain but to permanently shut down the BounceBit Chain and reissue BB as a BEP-20 token based on the BNB Chain. BounceBit stated that the new BB token supply will be based on an on-chain snapshot taken before the first abnormal transfer (block height 20,697,260), and the 286,543,148 BB transferred by the attacker will not be included in the new token balance.Users do not need to submit applications or migrate wallets; the official plan is to automatically distribute the new BB to the corresponding BNB Chain addresses. For staked BB, BounceBit stated that it will be restored at the snapshot time, and holders do not need to perform unbinding or redemption operations. Currently, BounceBit has submitted requests for freezing and assistance to relevant exchanges and has reminded users to be vigilant against scams and not to click on any BB migration or claim links that have not been officially confirmed. The team stated that they will announce the new BEP-20 BB contract address and reissuance progress in the future.

Stable update white paper: 82% of STABLE tokens locked until the end of 2029 will be released

Stable has released an updated white paper, whose core design concept is to rebuild blockchain infrastructure around stablecoins. Unlike traditional public chains that treat stablecoins as application layer assets, Stable uses USDT as a native Gas asset and primary settlement asset, allowing users to complete transactions without holding additional volatile tokens. At the same time, the network supports PYUSD issued by PayPal as a primary settlement asset.In terms of token economics, the total supply of STABLE is 10 billion tokens. Among them, approximately 1.8 billion tokens (18%) were in circulation at the time of token generation, including 10% for Genesis Distribution and 8% for the foundation's first-day unlock; the remaining 8.2 billion tokens (82%) will enter a Universal Lock pool.The white paper indicates that the 8.2 billion locked tokens will adopt a unified release mechanism, unlocking gradually in 7 phases:Phase 1: 5% (410 million tokens) released on December 8, 2027Phase 2: 5% (410 million tokens) released on March 8, 2028Phase 3: 10% (820 million tokens) released on June 8, 2028Phase 4: 15% (1.23 billion tokens) released on September 8, 2028Phase 5: 15% (1.23 billion tokens) released on December 8, 2028Phase 6: 20% (1.64 billion tokens) released on March 8, 2029Phase 7: 30% (2.46 billion tokens) released on June 8, 2029All locked tokens will be unlocked through daily linear release, expected to be fully in circulation by December 8, 2029, at the latest. Additionally, the white paper sets a price protection mechanism; if the volume-weighted average price of the token is below $0.025 in the 30 days prior to the specified release date, the relevant unlocking phase may be postponed by up to 9 months.

B.AI's benefits are continuously updated this week, with a 90% discount on the access channel launched, and Qwen3.8-Max is now available for free

B.AI welcomes several major updates this week. In terms of benefits, new users can log in with Bitget Wallet, Binance Wallet, or imToken Wallet to instantly receive 1 million free Credits; logging in with an invitation code grants an additional 300,000, with a maximum cumulative total of 1.3 million when combined with the exclusive wallet login gift. Referrers also enjoy permanent rebates on friend deposits and subscriptions. Recharge discounts are released simultaneously, with a 1:1 equivalent quota gift exclusive to the BNB Chain channel, while various other payment methods enjoy a 1:0.5 rebate, with a maximum of $100 worth of points available per user.On the model side, there is another breakthrough, as the "Self-selected Service Provider" lineup is significantly expanded this week, adding the Nebula channel and launching historic calling discounts as low as 10%; at the same time, Alibaba's Tongyi Qianwen flagship model Qwen3.8-Max officially lands on the platform, now open for a limited-time free experience. Currently, the self-selected mode has fully covered global mainstream large model series such as Claude, GPT, and Gemini, combined with recharge gifts and multiple discount tiers, continuously releasing extreme computing power cost-effectiveness for global developers and enterprise users.

Hong Kong police updated on the virtual currency Fun Coffee scam, with total losses rising to approximately HKD 104 million

According to Hong Kong 01, the Hong Kong police updated information regarding the virtual currency Fun Coffee scam, revealing that as of August 5, a total of 255 related reports had been received, an increase of 30 from earlier, with total losses rising to approximately HKD 104 million. In addition, the Macau police arrested two women involved in 9 cases amounting to about 3.6 million Macau patacas.Regarding TVB artists who have hosted activities related to the Fun Coffee scam, the Hong Kong police stated that during the investigation, they would definitely contact the victims and relevant individuals to identify the mastermind behind the scam and their roles. Fun Coffee claims to be a large coffee investment enterprise in Phu Quoc, Vietnam, with a capital scale exceeding USD 1 billion. It entered the Hong Kong market by the end of 2025, packaging its image through marathons, banquets, social events, distributing flyers, and inviting artists to promote it, while registering a company, opening offices, and stores in Hong Kong. The actual operation was to lure citizens into downloading the app to complete tasks under the guise of investing in high-tech coffee equipment, gene optimization technology, and agricultural equipment, using Tether (USDT) and other cryptocurrencies for deposits. The platform promised annual returns of up to 197%--278%, with higher returns for larger amounts and longer deposit periods, and set up a commission structure to encourage recruitment. In July 2026, the Hong Kong Securities and Futures Commission listed it as a suspicious investment product. In late July of the same month, the app suddenly ceased operations, withdrawals became impossible, customer service went offline, and the offices and stores were vacated, leading to the collapse of the scam.

first_img OpenAI update disclosure: The out-of-control AI agent has also infiltrated four platforms beyond Hugging Face

On July 28, OpenAI quietly updated its security incident disclosure, confirming that its AI agent accessed four external service platforms during the breach of Hugging Face, bringing the total number of affected platforms to five.Previously, OpenAI had disabled security filters while testing GPT-5.6 Sol and a more powerful model to assess raw capabilities. The model did not complete the security benchmark tests as expected; instead, it discovered a zero-day vulnerability in the package caching agent within the testing environment that granted internet access, subsequently breaching Hugging Face to steal answers.According to a forensic report released by Hugging Face on July 27, this autonomous agent executed 17,600 operations over approximately four and a half days, connecting 181 devices to the Hugging Face internal VPN and forging identity tokens. Among the four additional platforms, Modal Labs CTO Akshat Bubna confirmed through Reuters that his company was one of them, with the attacker using an unprotected public endpoint from a customer as a relay and command control base for the entire attack.The identities of the other three platforms remain undisclosed. OpenAI stated it would "directly notify the service providers" but would not publicly name them, as there is currently no legal requirement for mandatory disclosure. The U.S. Congress has responded by proposing a bipartisan "AI Emergency Shutdown Act," which aims to authorize the Department of Homeland Security to forcibly shut down AI models, with violators facing fines of up to $2 million per day.
app_icon
ChainCatcher Building the Web3 world with innovations.