Scan to download
BTC $77,217.06 -0.01%
ETH $2,120.84 +0.27%
BNB $655.90 +1.21%
XRP $1.36 -0.63%
SOL $86.87 +1.26%
TRX $0.3647 +1.02%
DOGE $0.1056 +1.29%
ADA $0.2515 +1.97%
BCH $378.64 +1.31%
LINK $9.81 +2.76%
HYPE $59.23 +2.89%
AAVE $88.23 +0.27%
SUI $1.11 +1.82%
XLM $0.1476 +2.87%
ZEC $636.91 -3.32%
BTC $77,217.06 -0.01%
ETH $2,120.84 +0.27%
BNB $655.90 +1.21%
XRP $1.36 -0.63%
SOL $86.87 +1.26%
TRX $0.3647 +1.02%
DOGE $0.1056 +1.29%
ADA $0.2515 +1.97%
BCH $378.64 +1.31%
LINK $9.81 +2.76%
HYPE $59.23 +2.89%
AAVE $88.23 +0.27%
SUI $1.11 +1.82%
XLM $0.1476 +2.87%
ZEC $636.91 -3.32%

stems

Grafana: Investigation reveals that recent security incidents have not affected customer production systems and operations

The open-source data visualization tool Grafana has released the latest progress on the investigation of the security incident on May 16. The investigation found that this incident was limited to the GitHub environment of Grafana Labs, including both public and private source code as well as internal GitHub repositories, and did not affect customer production systems, operations, or the Grafana Cloud platform. The downloaded content, in addition to the source code, also included some repositories used by the team for collaboration and storage of internal operational information and business details, involving business contact names and email addresses, rather than data from production systems or the cloud platform.Grafana Labs has made it clear that the codebase was downloaded but not tampered with, and currently, customers and open-source users do not need to take any action. The incident originated from a TanStack npm supply chain attack conducted through the Mini Shai-Hulud campaign. Grafana Labs detected malicious activity on May 11 and initiated an emergency response, but a credential was overlooked, allowing the attacker to gain access. After receiving a ransom demand on May 16, the company decided not to pay the ransom and has rotated automated credentials, implemented enhanced monitoring, audited all commits since May 11, and significantly strengthened GitHub security configurations. The company has notified federal law enforcement, and the investigation is ongoing.

The Gate TradFi stock section has launched 52 CFD contract trading pairs including GIS (General Mills) and MPWR (Monolithic Power Systems) and has introduced the second phase of the new coin airdrop event, sharing 100,000 USDT

According to the official announcement, the Gate TradFi stock section has launched 52 contracts for difference trading pairs including GIS (General Mills), MPWR (Monolithic Power Systems), HSY (Hershey), COTY (Coty Inc.), CTSH (Cognizant), INFY (Infosys), SO (Southern Company), ALK (Alaska Airlines), BAP (Credicorp), CIB (Grupo Cibest), SYY (Sysco), DD (DuPont), DTE (DTE Energy), PSX (Phillips 66), AON (Aon), MCO (Moody's), CHT (Chunghwa Telecom), GT (Goodyear Tire & Rubber), GFS (GlobalFoundries), MAR (Marriott International), WYNN (Wynn Resorts), SYF (Synchrony Financial), EPD (Enterprise Products Partners), CBOE (Chicago Board Options Exchange Global Markets), IVZ (Invesco), MLM (Martin Marietta Materials), EXC (Exelon), PNC (PNC Financial Services Group), AMT (American Tower), BDX (Becton Dickinson), WMB (Williams), AIG (American International Group), CPRI (Capri Holdings), HBAN (Huntington Bancshares), SYK (Stryker), ZTS (Zoetis), BMRN (BioMarin Pharmaceutical), APD (Air Products and Chemicals), STT (State Street), XLE (State Street Energy Select SPDR ETF), IBIT (iShares Bitcoin Trust), ASTS (AST SpaceMobile), AUPH (Aurinia Pharmaceuticals), PTON (Peloton Interactive), CRON (Cronos Group), GPRO (GoPro), OPFI (OppFi), RIG (Transocean), XRX (Xerox), MANU (Manchester United), URA (Global X Uranium ETF), LIT (Global X Lithium Battery ETF), supporting 4x fixed leverage.In addition, the Gate TradFi stock section will launch the second phase of the new coin airdrop from April 29 at 16:00 to May 8 at 16:00 (UTC+8). During the event, users can register to receive 30 USDT and can share a prize pool of 100,000 USDT by participating in the trading of newly listed assets, with a maximum individual reward of 3,130 USDT.

Bitrefill disclosed that it was attacked by suspected North Korean hackers, resulting in a customer data breach, and has shut down relevant systems for isolation

Bitcoin payment service provider Bitrefill disclosed on platform X that it suffered a cyberattack on March 1, 2026, resulting in a customer data breach. The attack originated from a compromised employee's laptop and allowed the attackers to access certain databases and cryptocurrency wallets.Investigations revealed that the attack method was highly similar to past attacks on cryptocurrency companies by the North Korean DPRK Lazarus/Bluenoroff hacker group. Approximately 18,500 purchase records involved limited customer information (email, cryptocurrency payment addresses, and IP metadata), with about 1,000 records having customer name information stored in an encrypted format, but potentially accessible. Bitrefill stated that customers do not need to take special actions but are advised to be vigilant for unusual information.Bitrefill further added that it has currently shut down related systems for isolation and is collaborating with security experts, on-chain analysts, and law enforcement. Operations have nearly returned to normal. The company emphasized that it is long-term profitable and financially robust enough to absorb this loss and will continue to strengthen cybersecurity measures, including internal access controls, monitoring, and emergency response mechanisms.

US SEC Commissioner suggests cautiously advancing the innovation exemption for tokenized securities and raises key issues such as information disclosure systems

Hester M. Peirce, a commissioner of the U.S. Securities and Exchange Commission, stated that a research initiative for a "regulatory exemption" for tokenized securities has been launched, allowing limited trading and technical experimentation for certain tokenized securities. This exemption plan will be more cautious than the "comprehensive exemption" proposed by the industry.She believes it is worth exploring whether different types of tokenization models for securities can be tested under the innovation exemption framework and whether issuer consent is needed for third parties to issue tokenized versions of their stocks, in order to promote technological innovation while avoiding regulatory arbitrage and maintaining core investor protection mechanisms.Hester M. Peirce also emphasized that regulators should not overly interfere with private capital allocation. The SEC is currently assessing several key issues, including: whether the existing information disclosure system is sufficient to cover the ownership structure of tokenized securities, the disclosure obligations of brokers and clearing agencies in the issuance of tokenized securities, the compatibility of atomic settlement with the current T+1 settlement rules, and the applicability of regulatory authority in the absence of intermediaries or under new intermediary structures.
app_icon
ChainCatcher Building the Web3 world with innovations.