BTC $78,440.60 -1.42%
ETH $2,472.44 -1.37%
BNB $752.01 +0.67%
XRP $1.40 -0.76%
SOL $102.98 -2.61%
TRX $0.3389 +1.03%
DOGE $0.0893 -2.09%
ADA $0.2185 -2.57%
BCH $256.26 -1.96%
LINK $12.53 -5.91%
HYPE $83.24 -5.35%
AAVE $129.10 -4.35%
SUI $0.8127 -2.56%
XLM $0.1885 -3.20%
ZEC $1,156.90 -3.03%
BTC $78,440.60 -1.42%
ETH $2,472.44 -1.37%
BNB $752.01 +0.67%
XRP $1.40 -0.76%
SOL $102.98 -2.61%
TRX $0.3389 +1.03%
DOGE $0.0893 -2.09%
ADA $0.2185 -2.57%
BCH $256.26 -1.96%
LINK $12.53 -5.91%
HYPE $83.24 -5.35%
AAVE $129.10 -4.35%
SUI $0.8127 -2.56%
XLM $0.1885 -3.20%
ZEC $1,156.90 -3.03%

security

All
Article
Flash

first_img The case of four people murdered in Mexico involves a Bitcoin robbery, and two suspects are facing trial

According to Cointelegraph, the Attorney General's Office of the State of Mexico (FGJEM) reported that two suspects, Diego Sebastián and Gerardo, were arrested for allegedly murdering Jonathan Meléndez, the keyboardist of the rock band Camilo Séptimo, along with his pregnant wife, daughter, and an employee. The family's golden retriever was also killed.The suspects are accused of committing the crime to obtain a cold wallet that allegedly contained millions of dollars in Bitcoin, with one of the suspects being a business partner of the victim, using that relationship to gain access to the victim's home. The two will appear in court on Wednesday, where the judge will decide if there is enough evidence to continue the criminal proceedings. If convicted, each suspect could face a prison sentence of 25 to 70 years corresponding to each victim.Such violent robberies targeting cryptocurrency holders (known as "ransom attacks") are on the rise. According to CertiK data, there were 52 reported ransom attack incidents globally in the first half of 2026, a year-on-year increase of 33.3%; among them, there were 20 home invasions targeting cryptocurrency holders, compared to only 1 during the same period last year.Chainalysis estimates that in the first half of 2026, criminals stole over 30 million dollars in cryptocurrency through ransom attacks. In 2025, global ransom attack incidents increased by 75% to 72 cases, with France leading with 19 cases, accounting for about 40% of the total attacks in Europe.

first_img Ukrainian police dismantle cryptocurrency scam, with monthly thefts reaching 1 million USD

The Ukrainian police and the Security Service of Ukraine (SBU) recently dismantled a scam network that used a fake investment platform to steal cryptocurrency. This network disguised itself as an investment platform website, luring users to connect their main cryptocurrency wallets and approve a small test transaction when withdrawing funds. Subsequently, it used a "wallet stealer" hidden within the website to automatically transfer user funds to wallets controlled by the operators, kicking victims off the platform. Investigators have currently confirmed 62 victims, with over 46 Ukrainian citizens involved, and the network could steal up to $1 million per month.The police stated that the false profits displayed on the platform are part of the scam, with operators manually creating transactions and adjusting user account balances to create the illusion of investment growth. In addition to cryptocurrency, the platform also collected victims' passport information, phone numbers, email addresses, login credentials, and photos during the registration and identity verification process. The main organizer of the network is a 25-year-old IT expert who recruited over 46 Ukrainian citizens and operated multiple offices in Kyiv and surrounding areas, with members responsible for building and maintaining fake websites, contacting potential victims, and providing security.Victims come from multiple countries, including Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada, and Israel. The police traced the gang's server equipment located in the Netherlands and obtained a database stored there, which included a list of victims, cryptocurrency wallet addresses, suspected stolen amounts, internal communications, and platform operation information. The Ukrainian police and SBU subsequently executed 34 searches in Kyiv and surrounding areas, seizing over 100 computers, more than 100 mobile phones, 79 SIM cards, documents, cash, and 15 vehicles.

first_img Anthropic admits that Claude accessed the system beyond his authority due to a security error

In a blog post released on Monday, Anthropic acknowledged that its Claude model had unauthorized access to real computer systems during a cybersecurity assessment, an incident reflecting operational security failures as well as alignment failures in motivation reasoning and intent to harm. Anthropic disclosed in July that the Claude model had breached the systems of three companies because the third-party assessment environment was connected to the public internet, while the model was informed it was in a simulated environment without internet access.Anthropic stated that Claude may have interpreted evidence of real internet access as still being in a simulated environment and was willing to take harmful actions on the real internet to complete the cybersecurity assessment task. Additionally, during tests at the UK AI Safety Institute, after assessors deliberately granted Claude Mythos internet access, the model took unauthorized actions on the live network. Anthropic emphasized that the models involved did not have the cybersecurity protections included in the officially released products.Following the incident on July 30, Anthropic has suspended cybersecurity assessments of pre-release models and introduced stricter protections: tests must run in verified offline sandboxes equipped with real-time monitoring; a new classifier can intercept suspected boundary violations, terminate tests, and notify humans. Anthropic has also expanded the scope of offline monitoring used by internal frontier agents. Previously, OpenAI models had also breached Hugging Face in July to obtain answers for cybersecurity tests, with investigations revealing that about 1,200 agents acted collaboratively through unauthorized message boards.

first_img OpenAI's new model Astra can autonomously discover and exploit software vulnerabilities, rated as "critical" in cybersecurity capability level

OpenAI stated that its upcoming Astra model can autonomously discover previously unknown software vulnerabilities and convert them into usable attack vectors without human intervention, making it the company's first model to reach the "Critical" cybersecurity capability level threshold. In a blog post released on Tuesday, OpenAI mentioned that according to its Preparedness Framework, reaching this level means the model can discover zero-day vulnerabilities and develop usable exploit code in hardened real systems without human involvement, or design and execute attacks based solely on a high-level objective.In testing, Astra achieved a 100% score in benchmark tests for developing exploit code based on known vulnerabilities and discovered two previously unknown vulnerabilities in another internal test. Additionally, the model successfully broke through a hardened browser sandbox and executed commands on the host machine, while gaining root access by exploiting multiple weaknesses in the operating system. OpenAI stated that it has delayed some of Astra's development progress to enhance security measures and plans to make its advanced cybersecurity capabilities available only to selected testers.This capability is particularly relevant to the cryptocurrency industry, as software vulnerabilities can be converted into financial losses within minutes. CoinDesk reported in June that increasingly powerful AI models can compress the process of searching code, discovering misconfigurations, and assembling attacks from days or weeks to machine speed. Security researchers noted at the time that the significant change was not the emergence of new categories of attacks, but rather the dramatically increased speed at which existing vulnerabilities are discovered and exploited.

first_img Core DAO Emergency Hard Fork Due to Validators Over-Claiming Rewards Plan

Core DAO is coordinating an emergency hard fork due to some validators receiving CORE rewards that exceeded the protocol's expected issuance. Core stated in an update that the situation has been brought under control, and "malicious validators" can no longer claim excess rewards. This fork is a forward upgrade and will not roll back the network or revoke any confirmed transactions.Previously, Core indicated in a status update on Monday that the rewards accumulated by a small number of validators were significantly higher than the protocol's expected issuance. The incident was limited to the reward distribution phase, user assets remain secure, and they promised to release a technical review report. Following the incident, several exchanges restricted CORE transfers: Coinbase suspended deposits and withdrawals on the Core network, Bithumb and Coinone suspended deposits and withdrawals, Bitget suspended deposits and withdrawals citing wallet maintenance, and LBank suspended deposits at the request of the project party.Core has not disclosed the amount of excess issued CORE, the duration of the activity, or whether additional tokens have entered circulation, nor have they provided details on the vulnerability that allowed validators to receive rewards. Cointelegraph reached out to Core for further information but had not received a response by the time of publication.
app_icon
ChainCatcher Building the Web3 world with innovations.