BTC $77,830.28 -3.03%
ETH $2,442.61 -2.70%
BNB $691.11 -2.96%
XRP $1.38 -4.83%
SOL $104.08 -4.74%
TRX $0.3412 +1.06%
DOGE $0.0851 -4.48%
ADA $0.2030 -5.07%
BCH $247.94 -8.07%
LINK $11.43 -4.36%
HYPE $80.86 -4.54%
AAVE $122.14 -4.59%
SUI $0.7430 -4.79%
XLM $0.1792 -4.39%
ZEC $801.65 -1.34%
BTC $77,830.28 -3.03%
ETH $2,442.61 -2.70%
BNB $691.11 -2.96%
XRP $1.38 -4.83%
SOL $104.08 -4.74%
TRX $0.3412 +1.06%
DOGE $0.0851 -4.48%
ADA $0.2030 -5.07%
BCH $247.94 -8.07%
LINK $11.43 -4.36%
HYPE $80.86 -4.54%
AAVE $122.14 -4.59%
SUI $0.7430 -4.79%
XLM $0.1792 -4.39%
ZEC $801.65 -1.34%

review

All
Article
Flash

MANTRA announces the review of the attack incident: A down-scaling vulnerability led to the transfer of over 720 million tokens, with approximately 37.96 million tokens frozen

On August 20, MANTRA Chain released a complete review report of the security incident, confirming that the attacker exploited an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency cosmos/evm, unauthorizedly transferring a total of 720,923,967.99 MANTRA from two addresses, valued at approximately 3.6 million dollars based on the price before the attack. Among them, the attacker transferred 600,000,035.56 MANTRA from the on-chain burn address and 120,923,932.44 MANTRA from a genesis-era multi-signature address related to an early incentive program.MANTRA stated that this incident did not involve the leakage of validator keys, administrator privileges, governance control, or multi-signature signers; the attacker did not require privileged access and could complete the attack solely through unauthorized contract deployment and self-funded wallets. The first abnormal transfer occurred at 19:06 UTC on August 20, when the attacker transferred approximately 600 million MANTRA from the burn address; subsequently, at 22:59 UTC, another transfer of approximately 120.9 million MANTRA was made. The chain subsequently stopped operating at 23:13 UTC and resumed after upgrading to v8.4.0. The entire network interruption lasted for 30 hours and 13 minutes.This vulnerability was not an issue with MANTRA's self-developed code but originated from the cosmos/evm module, which is responsible for providing EVM functionality on the Cosmos SDK. The vulnerability allowed the attacker to execute unsigned balance deductions without checking if the balance was sufficient, causing an overflow of values and bypassing normal account authorization logic. MANTRA stated that as of today, no funds have been recovered, with approximately 37.96 million MANTRA (accounting for 5.27% of the total transferred) still remaining in the attacker's address, which has been frozen due to the chain's suspension and v8.4.0 restrictions. The remaining funds have flowed to related trading platforms, and the recovery efforts have entered the law enforcement investigation stage. In the future, monitoring of accounts that cannot normally authorize transfers, burn addresses, and other historically "non-transferable" addresses will be strengthened, and efforts will be made to promote improvements in the security vulnerability disclosure process within the Cosmos ecosystem.

first_img Tencent Hunyuan releases and open-sources Hy4 preview, with a total of 770B parameters and 49B activated

Tencent Hunyuan has released and open-sourced the next-generation large language model Hy4 preview. This model has a total of 770B parameters and 49B active parameters, with a context length exceeding 1M. It demonstrates strong capabilities in real productivity tasks such as coding, office work, and science, firmly placing it in the top tier of open-source models. Hy4 preview significantly expands in model size, context length, and data scale, and enhances real-world performance through high-quality data co-built with Tencent experts in software engineering, gaming, finance, security, and deep collaboration with products like WorkBuddy.In software engineering, the model enhances understanding, planning, debugging, and verification capabilities for long-range development tasks, enabling the construction of complex front-end projects like a Three.js miniature town from scratch. In game development, it supports generating playable prototypes from a single sentence and can complete a full demo in Unity. In smart office applications, it can handle complex financial audits, filtering, analyzing, and delivering from multiple documents. In scientific research, it achieves acceleration in tasks such as molecular dynamics simulations and has initially formed a recursive self-improvement feedback loop.Hy4 preview can be experienced in Tencent products such as WorkBuddy/CodeBuddy domestic and international versions, Yuanbao, ima, and can also be accessed via API calls through Tencent Cloud Tokenhub and OpenRouter. WorkBuddy/CodeBuddy will launch a limited-time free activity for two weeks. Since the reconstruction of the infrastructure, the Hunyuan large model has iterated a major version approximately every two months, continuously optimizing through a preview-first and formal version-following approach.

SafePal updates on security incident progress: launching anti-phishing actions and will commission a third-party agency to review the order system

The cryptocurrency wallet project SafePal has released updates on the security incident, stating that it is continuously tracking phishing websites and impersonation accounts, and plans to introduce a professional anti-phishing security company to expedite the removal of malicious information to protect user asset security. SafePal mentioned that it is currently in the final selection process among four professional anti-phishing security companies, and once a partner is selected, it will further enhance the efficiency of handling threats such as counterfeit websites and scam accounts.The team is also continuously monitoring whether the affected data has been sold or made public, including channels such as dark web forums and trading markets. Once signs of data leakage are detected, affected users will receive risk alerts immediately. Regarding security audits, SafePal stated that it is in the final selection among three mature independent security institutions, which will conduct a comprehensive security review of the order system. Meanwhile, the team is reassessing the order and logistics processes to reduce the amount of data that needs to be stored in the initial phase of the system, thereby reducing potential risks from the source.For affected users, SafePal stated that it will continue to provide one-on-one assistance through official support channels and will keep updating the fraud protection page, providing updates on the incident, FAQs, and analysis of fraud cases. SafePal once again reminds users: the official will never ask users to provide their seed phrase. Users should not disclose their seed phrase to anyone, should not scan unknown QR codes or click on suspicious links, and should verify the source of information through official channels.

China Merchants Yonglong Bank reviews mainland investors' zero balance non-active investment accounts, which have not submitted declarations or face suspension and closure

On August 21, China Merchants Yonglong Bank issued a notice to customers, stating that it is cooperating with the latest risk management and account compliance guidelines from the Hong Kong Monetary Authority and the Securities and Futures Commission to conduct a comprehensive optimization and review of investment accounts for mainland investors. Upon verification, all investment accounts held by relevant customers (including wealth management, securities, and/or paper gold passbook accounts) as of May 22, 2026, have no asset balance, and there have been no investment transaction records in the past 12 months, which have been classified as "zero balance non-active investment accounts."To maintain normal account operations, the bank requires customers to submit the "Non-Active Investment Account Declaration" as soon as possible. Customers can complete the submission through the pop-up in the personal account section of the China Merchants Yonglong Bank mobile app; joint account holders or those who have not registered for the mobile app can call the customer service hotline for guidance, and each joint account holder must submit separately. The main content of the declaration includes confirming the accuracy of personal information, the legality of the source of funds, that the account has not been closed or suspended due to suspicious documents, and timely notification of any changes in information.The bank reminds that if customers fail to complete the submission in a timely manner, new investment transactions (including buying stocks, subscribing to wealth management products, etc.) will be suspended accordingly; if the submission continues to be delayed, it is expected that starting from November 2026, relevant "non-active investment accounts" may be closed. Once an account is suspended or closed, no new securities or wealth management product investment transactions can be conducted.

Ireland releases its first anti-money laundering strategy, which will strengthen the review of transfers to private crypto wallets

According to Decrypt, the Irish government has released its first national anti-money laundering (AML) strategy, which plans to strengthen the review of digital asset transfers involving self-hosted wallets and increase due diligence requirements for crypto companies when cooperating with overseas institutions.According to the announcement from the Irish Department of Finance, this strategy implements the remaining requirements of the EU's Transfer of Funds Regulation, which will require crypto asset service providers (CASP) to perform "enhanced checks" on transfers involving private wallets, while implementing stricter customer due diligence when conducting business with overseas crypto companies.The related measures are based on the Financial Action Task Force (FATF) Travel Rule, which requires the inclusion of sender and receiver information in digital asset transactions to enhance the transparency of fund flows. Ireland stated that the new regulations will be advanced in parallel with the EU's Markets in Crypto-Assets Regulation (MiCA).MiCA establishes a unified regulatory framework for crypto asset service providers, while Ireland previously granted a 12-month transition period for its domestic crypto companies, which is shorter than the maximum 18 months allowed by the EU. The transition period is set to end at the end of December 2025, so the new requirements will directly apply to companies that have obtained formal authorization.
app_icon
ChainCatcher Building the Web3 world with innovations.