Scan to download
BTC $71,090.61 -3.42%
ETH $1,959.72 -2.52%
BNB $679.28 -5.72%
XRP $1.28 -3.95%
SOL $79.28 -3.37%
TRX $0.3459 -0.62%
DOGE $0.0980 -2.01%
ADA $0.2259 -3.52%
BCH $283.33 -5.37%
LINK $8.86 -2.89%
HYPE $71.50 +3.70%
AAVE $79.48 -2.91%
SUI $0.8624 -1.85%
XLM $0.2451 -2.28%
ZEC $528.54 -4.34%
BTC $71,090.61 -3.42%
ETH $1,959.72 -2.52%
BNB $679.28 -5.72%
XRP $1.28 -3.95%
SOL $79.28 -3.37%
TRX $0.3459 -0.62%
DOGE $0.0980 -2.01%
ADA $0.2259 -3.52%
BCH $283.33 -5.37%
LINK $8.86 -2.89%
HYPE $71.50 +3.70%
AAVE $79.48 -2.91%
SUI $0.8624 -1.85%
XLM $0.2451 -2.28%
ZEC $528.54 -4.34%

sand

The security incidents at GitHub and Grafana are likely related to a large-scale "mini sandworm" supply chain attack

According to the threat intelligence released by Slow Fog, several high-frequency npm packages including AntV and Echarts-for-react, as well as the Python SDK durabletask, have recently been targeted by the Mini Shai-Hulud "mini sandworm" supply chain attack. The npm account atool was compromised, and the attacker automatically published 637 malicious versions within 22 minutes, affecting 317 packages. The attacker continuously uploaded durabletask versions 1.4.1, 1.4.2, and 1.4.3 within 35 minutes, bypassing normal release controls and impersonating an official Microsoft release.The large-scale leak of GitHub tokens and the ransomware attack on Grafana Labs are likely related to this supply chain attack. Affected components include high-frequency components such as AntV and Echarts-for-react in the npm ecosystem, as well as Python packages durabletask 1.4.1, 1.4.2, and 1.4.3. Attackers can steal cloud and local credentials, gain unauthorized access to internal repositories and sensitive cloud infrastructure, move laterally to developer machines and CI/CD pipelines, sell and exploit leaked GitHub tokens, and implement ransom and data leak threats.Slow Fog recommends immediately rotating all exposed credentials, replacing affected packages, isolating potentially infected systems, and implementing strict dependency review policies. Previously, it was reported that the "mini sandworm" worm had recently completed widespread infection in open-source code repositories, and developers should be vigilant in checking for issues.

On the first day of the Victoria Harbour special exhibition, the number of visitors exceeded ten thousand, and the on-site viewing enthusiasm surged

Gate's outdoor crossover exhibition "Racing the Future" officially opened at the K11 MUSEA waterfront promenade in Victoria Harbour, Hong Kong. On the opening day, the event attracted a large number of citizens and tourists, with attendance exceeding ten thousand, and the waterfront area remained crowded, creating a lively atmosphere.As the official sponsor of the F1 Red Bull Racing team, Gate showcased the team's brand new 2026 racing car and related equipment at this exhibition, and set up an interactive experience area to attract visitors to closely experience the combination of racing engineering and speed culture. Many visitors stopped to take photos and engage with the interactive content. The racing suits, equipment, and gloves of champion driver Max Verstappen and driver Isack Hadjar were also on display, along with a giant driver helmet installation of Max Verstappen, drawing many fans to the event.In addition, Gate will hold the "Gate 13 Blue Carpet Ceremony" on April 20, where the unveiling of the F1 Red Bull Racing team's display car and brand collaboration will take place; that evening, Gate will also host a high-end anniversary dinner at the Rosewood Hong Kong, with platform founder and CEO Dr. Han in attendance, and over 300 representatives from top industry institutions and partners expected to participate in the exchange.

Ernst & Young launches Blockchain Privacy Sandbox, supporting the development of privacy smart contracts on EVM chains

EY announced the launch of the Blockchain Privacy Sandbox, a web-based development environment designed to help businesses and developers experiment with privacy-preserving smart contracts on public chains compatible with the Ethereum Virtual Machine. It is reported that this sandbox environment is based on the open-source technology Starlight, allowing developers to convert standard Solidity smart contracts into applications with privacy protection features while retaining the original contract logic, and providing exploratory, replicable, and modifiable sample projects to accelerate proof of concept development.Currently, the Blockchain Privacy Sandbox is mainly used for experimentation and validation, supporting businesses in assessing the feasibility of privacy smart contracts, testing functionalities, and validating application scenarios before officially integrating Starlight. EY stated that this tool lowers the technical barrier for conducting privacy experiments on public chains by providing an easy-to-use web environment. Starlight, as the underlying ZKP compiler, has been open-sourced, allowing developers to integrate privacy features through its GitHub repository. As businesses' demand for data privacy protection on public chains increases, the attention on zero-knowledge proof technology continues to rise. Relevant reports indicate that the global ZKP market is expected to reach approximately $7.6 billion by 2033.
app_icon
ChainCatcher Building the Web3 world with innovations.