BTC $66,449.38 +1.98%
ETH $1,933.25 +1.46%
BNB $573.35 +0.32%
XRP $1.12 +2.65%
SOL $78.28 +0.63%
TRX $0.3289 +0.97%
DOGE $0.0735 +1.96%
ADA $0.1743 +2.51%
BCH $224.66 +1.69%
LINK $8.69 +1.39%
HYPE $60.82 -2.35%
AAVE $96.85 +7.21%
SUI $0.7691 +0.78%
XLM $0.1928 +3.08%
ZEC $531.15 -1.72%
BTC $66,449.38 +1.98%
ETH $1,933.25 +1.46%
BNB $573.35 +0.32%
XRP $1.12 +2.65%
SOL $78.28 +0.63%
TRX $0.3289 +0.97%
DOGE $0.0735 +1.96%
ADA $0.1743 +2.51%
BCH $224.66 +1.69%
LINK $8.69 +1.39%
HYPE $60.82 -2.35%
AAVE $96.85 +7.21%
SUI $0.7691 +0.78%
XLM $0.1928 +3.08%
ZEC $531.15 -1.72%

fil

All
Article
Flash

Slow Fog Cosine: Claude Code exposes high-risk security vulnerabilities, malicious configuration files may silently execute commands

The founder of Slow Fog, Yu Xian, retweeted a tweet on the X platform regarding the potential poisoning attack risks of Claude Code and published an analysis of the poisoning attack details targeting Grok Build CLI and Claude Code CLI.It pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, creating gaps that serve as channels for attackers. Attackers may execute arbitrary commands through malicious project configuration files without the user's knowledge, thereby stealing API keys, cloud credentials, or controlling local devices.Researchers constructed a testing environment and found that on Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks.If the attack is successful, attackers may further steal API keys from AI services like Claude and OpenAI, resulting in account cost losses, gain access to servers and data by obtaining cloud service credentials from AWS, Alibaba Cloud, Tencent Cloud, modify code repositories to implant backdoors, and use local devices as jump points to attack corporate internal networks. It is reported that the related vulnerabilities have existed for a year.

Humanity Protocol has completed the preparation for the fulfillment of over 540 million tokens, and the "3:10" plan will be launched on June 25 for unlocking

According to on-chain data monitoring, the Humanity Protocol ($H) Foundation's related addresses have completed the planned token transfers, involving a "3:10" structured hedging profit-taking plan aimed at early investors, with a token scale exceeding 540 million. According to the previously announced schedule, the related tokens will officially enter the unlocking process on June 25, marking that the plan has completed the preparatory work for payment and has entered the formal performance stage.Previously, Humanity Protocol underwent a series of ecological recovery processes due to a hacking incident, including promoting a 1:1 exchange of new and old tokens for real holding users on exchanges, and implementing KYC and AML compliance verification for the abnormal on-chain issuance chips generated after the attack to reduce market circulation risks. The timely advancement of this unlocking plan is seen as an important progress node for the project in fulfilling commitments to investors and restoring ecological order after the security incident.Humanity Protocol mainly focuses on AI identity verification and Web3 identity infrastructure. As the demand for AI agents, real-person verification, anti-witch attacks, and on-chain identity applications continues to grow, this sector still has long-term development potential. If Humanity Protocol can continue to promote product and application implementation after completing token migration and ecological recovery, its subsequent performance will still attract market attention.
app_icon
ChainCatcher Building the Web3 world with innovations.