BTC $64,151.43 -0.92%
ETH $1,858.74 -0.99%
BNB $564.61 -0.27%
XRP $1.08 -1.58%
SOL $73.84 -2.31%
TRX $0.3301 +0.99%
DOGE $0.0691 -0.09%
ADA $0.1635 -3.22%
BCH $209.34 -0.46%
LINK $8.34 -1.41%
HYPE $58.50 -0.02%
AAVE $93.66 -1.96%
SUI $0.7090 -4.83%
XLM $0.1774 -2.56%
ZEC $495.45 -2.44%
BTC $64,151.43 -0.92%
ETH $1,858.74 -0.99%
BNB $564.61 -0.27%
XRP $1.08 -1.58%
SOL $73.84 -2.31%
TRX $0.3301 +0.99%
DOGE $0.0691 -0.09%
ADA $0.1635 -3.22%
BCH $209.34 -0.46%
LINK $8.34 -1.41%
HYPE $58.50 -0.02%
AAVE $93.66 -1.96%
SUI $0.7090 -4.83%
XLM $0.1774 -2.56%
ZEC $495.45 -2.44%

security

All
Article
Flash

OKX, in collaboration with Elliptic, SlowMist, and OttoSec, released the Web3 Security and Risk Control Report for the first half of 2026

According to official news, OKX, in collaboration with Elliptic, SlowMist, and OttoSec, has released the "Web3 Security and Risk Control Report for the First Half of 2026." The report points out that the focus of Web3 attacks is gradually shifting from smart contract code to more complex scenarios such as signature processes, user devices, operational infrastructure, and AI Agents.Data shows that in the first half of 2026, the OKX risk control system intercepted over 5.7 million high-risk transactions, including approximately 2.41 million transactions related to hacking and theft, about 1.48 million transactions related to phishing, and around 990,000 transactions related to fraud. The OKX Web3 on-chain intelligence label library currently has over 1 billion labels, covering more than 420 chains, and has integrated capabilities such as address screening, transaction monitoring, and sanction address control into infrastructures like DEX and Exchange OS.In addition, in terms of user protection, OKX has intercepted over 7 million visits to risky websites, completed over 200,000 device risk assessments, identified over 60,000 high-risk apps, and intercepted or alerted on over 4 million high-risk signature operations. The report also introduces the "risk control pre-positioning" design in scenarios such as Exchange OS, Outcomes, RWA, and Agentic Wallet.

BlackRock, Strategy, and others jointly established the Bitcoin Security Alliance, committing to provide $15 million in funding for core developers and quantum resistance research over the next three years

Nine financial institutions and Bitcoin companies announced the joint establishment of the Bitcoin Security Alliance, with founding members including Anchorage Digital, ARK Invest, BlackRock, Block, Blockstream, Coinbase, Fidelity, Galaxy, and Strategy, covering the entire chain of institutions such as custody, trading, infrastructure, payments, and asset management.The alliance commits to providing a total of $15 million in funding over the next three years to support developers and researchers in the field of Bitcoin security, including long-term work to prepare Bitcoin for the future era of quantum computing. Each member independently decides which developers, researchers, or organizations to direct their funding towards. The daily operations of the alliance are coordinated on a voluntary basis by Brink Executive Director Mike Schmidt, with Brink being a nonprofit organization that funds Bitcoin open-source developers.The alliance clearly states that it does not formulate or direct Bitcoin protocols, does not express opinions on specific protocol changes, and does not represent Bitcoin or its developers—Bitcoin development continues to be carried out by a globally decentralized community of contributors. Its positioning is to emulate the model of industry organizations that have long supported open-source software, providing resources and attention to developers without controlling the underlying work.Strategy CEO Phong Le stated, "As long-term holders, ensuring the security of Bitcoin for generations is our greatest incentive"; BlackRock's Global Head of Digital Assets Robert Mitchnick pointed out that the work of Bitcoin core developers is "extremely important," and this commitment will provide "significant additional funding" for Bitcoin's long-term security needs. The alliance will also serve as a reliable source of information for investors, the public, and the media in the field of Bitcoin security, with plans to publish and continuously update materials related to Bitcoin security in the coming months.

CertiK: The losses from wrench attacks have surged nearly 12 times, making operational security the new core of prevention

Web3 security company CertiK released the "2026 First Half Wrench Attack Report." The report shows that in the first half of 2026, a total of 52 publicly verified wrench attack incidents were recorded globally, an increase of 33.3% year-on-year; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report points out that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world relationship networks, with home invasion incidents rising from 1 in the first half of 2025 to 20, accounting for 41% of the total incidents during the same period. Europe has become a high-frequency attack region, with 33 incidents occurring in France, accounting for 63.5% of global cases.CertiK states that as real-world risks become a significant challenge for digital asset security, businesses and high-value individuals need to establish a more comprehensive protection system. CertiK has launched operational security services to help identify risks related to the exposure of information such as identity, home, residence, and travel trajectory; at the same time, through CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities.In addition, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol to provide technical support for cross-border attack investigations and security policy research.

Slow Fog Cosine: Claude Code exposes high-risk security vulnerabilities, malicious configuration files may silently execute commands

The founder of Slow Fog, Yu Xian, retweeted a tweet on the X platform regarding the potential poisoning attack risks of Claude Code and published an analysis of the poisoning attack details targeting Grok Build CLI and Claude Code CLI.It pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, creating gaps that serve as channels for attackers. Attackers may execute arbitrary commands through malicious project configuration files without the user's knowledge, thereby stealing API keys, cloud credentials, or controlling local devices.Researchers constructed a testing environment and found that on Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks.If the attack is successful, attackers may further steal API keys from AI services like Claude and OpenAI, resulting in account cost losses, gain access to servers and data by obtaining cloud service credentials from AWS, Alibaba Cloud, Tencent Cloud, modify code repositories to implant backdoors, and use local devices as jump points to attack corporate internal networks. It is reported that the related vulnerabilities have existed for a year.

a16z invests in AI agent security company Runta

Venture capital firm Andreessen Horowitz (a16z) announced an investment in AI Agent security startup Runta, which aims to help businesses manage and constrain AI agents like "raising children." The specific investment amount has not been disclosed.Runta founder Guanlan Dai previously worked on the technical team at Cloudflare and was a founding engineer at API connection startup Kong. He stated that AI agents share similarities with growing children: they have the ability to perform tasks autonomously but also require boundaries, supervision, and permission management. Dai believes that just as parents provide home safety protection for children and limit their access to credit cards, businesses also need to restrict the important documents that AI agents can access, the range of operations they are allowed to perform, and the amount of disposable funds available at one time.Runta is developing a set of "AI Agent guardianship" infrastructure to help businesses manage AI agents' permissions, security risks, and behavioral boundaries, preventing autonomous AI systems from causing data leaks, erroneous operations, or financial losses during task execution. As businesses increasingly deploy AI agents with autonomous decision-making capabilities, establishing a trustworthy and secure agent management system is becoming a new infrastructure requirement. Runta aims to become the "parental control layer" of the AI Agent era, providing capabilities such as agent identity management, permission control, risk limitation, and operational supervision for businesses. Industry insiders believe that as AI agents evolve from simple assistants to autonomous entities capable of operating business systems, handling transactions, and executing complex tasks, the infrastructure market surrounding agent security, governance, and compliance may experience rapid growth.

Japan's largest security token platform Progmat has completed its migration to Avalanche, officially bringing over $2.7 billion in assets on-chain

Japan's largest securities token issuance and management platform, Progmat, has completed its migration to the Avalanche blockchain, transferring all managed tokenized assets worth over 452 billion yen (approximately 2.7 billion USD) from a Corda 5-based permissioned chain to a dedicated Avalanche Layer 1. This migration was announced in February this year and was completed as scheduled, without affecting the normal operations of financial institutions.Progmat stated that the new architecture no longer relies on a single blockchain and can support future multi-chain expansion. All smart contracts have been migrated to the EVM environment, and while maintaining the original functionality, the speed of asset rights transfer processing has increased by 3 to 5 times, with the final confirmation time for transactions reduced to under 2 seconds. Progmat was initially incubated by Japan's largest bank, Mitsubishi UFJ Trust and Banking Corporation (MUFG), and became an independent operation in 2023. It currently has the support of major Japanese financial institutions such as Mizuho Bank, Tokyo Stock Exchange, and SBI, holding a 53% market share in Japan's securities token market and accounting for 64.6% of the total issuance scale of securities tokens, covering most tokenized real estate and corporate bond projects.In addition, Progmat established a working group for the tokenization of Japanese government bonds and on-chain repurchase (Repo) in May this year, collaborating with asset management institutions, banks, and securities companies to research the tokenization of Japanese government bonds and explore application scenarios such as 24/7 trading and T+0 real-time settlement.
app_icon
ChainCatcher Building the Web3 world with innovations.