BTC $77,230.23 -1.12%
ETH $2,467.48 -0.19%
BNB $713.86 -0.67%
XRP $1.35 -2.23%
SOL $99.83 -1.50%
TRX $0.3385 -0.27%
DOGE $0.0838 -1.87%
ADA $0.2076 -2.97%
BCH $226.74 -8.46%
LINK $11.47 -2.72%
HYPE $80.15 -3.87%
AAVE $122.88 -1.28%
SUI $0.7366 -3.60%
XLM $0.1761 -1.93%
ZEC $1,110.78 -9.00%
BTC $77,230.23 -1.12%
ETH $2,467.48 -0.19%
BNB $713.86 -0.67%
XRP $1.35 -2.23%
SOL $99.83 -1.50%
TRX $0.3385 -0.27%
DOGE $0.0838 -1.87%
ADA $0.2076 -2.97%
BCH $226.74 -8.46%
LINK $11.47 -2.72%
HYPE $80.15 -3.87%
AAVE $122.88 -1.28%
SUI $0.7366 -3.60%
XLM $0.1761 -1.93%
ZEC $1,110.78 -9.00%

fog

All
Article
Flash

first_img The Fogo mainnet has been down for 46 hours due to the theft of 400 million FOGO, with no scheduled restart time

According to The Defiant, the Fogo mainnet has stopped producing blocks for about 46 hours since Saturday afternoon due to an attack on the Fogo Foundation, resulting in 4 million FOGO tokens (approximately 10.3% of the circulating supply) being transferred to the attacker's address. The foundation initially stated that the chain itself was unaffected, but 15 hours later, the network was actively paused, and plans were made to restrict the related addresses through an upgrade. Currently, the Fogo official explorer shows the last block as 718,525,971, and the RPC endpoint returns a 502 error, while the on-chain TVL tracked by DefiLlama has been frozen at $987,000 for three consecutive days.This downtime is attributed to Fogo's validator design: the chain is managed by a council of 7 voting validators, with the foundation staking evenly among 7 operators, allowing for coordination to pause and implement a client-level address blacklist within minutes. On the exchange side, both KuCoin and Gate have disabled FOGO deposits and withdrawals but retained trading, with a 24-hour spot trading volume of approximately $2.3 million. Meanwhile, a Twitter account impersonating the Fogo Foundation, @FcgoFNDN, posted a false compensation voting link, and Fogo officials reminded users to rely only on information from official channels.Fogo is the second network to actively pause over the weekend, following Cronos, which rolled back its state due to an attack on the Tectonic lending protocol. Fogo raised approximately $7 million by selling 2% of its supply through Binance before launching its mainnet in January, with a valuation of $350 million. The foundation has not yet disclosed details of the attack, compensation plans, or a restart timeline.

Slow Fog Cosine: Claude Code exposes high-risk security vulnerabilities, malicious configuration files may silently execute commands

The founder of Slow Fog, Yu Xian, retweeted a tweet on the X platform regarding the potential poisoning attack risks of Claude Code and published an analysis of the poisoning attack details targeting Grok Build CLI and Claude Code CLI.It pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, creating gaps that serve as channels for attackers. Attackers may execute arbitrary commands through malicious project configuration files without the user's knowledge, thereby stealing API keys, cloud credentials, or controlling local devices.Researchers constructed a testing environment and found that on Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks.If the attack is successful, attackers may further steal API keys from AI services like Claude and OpenAI, resulting in account cost losses, gain access to servers and data by obtaining cloud service credentials from AWS, Alibaba Cloud, Tencent Cloud, modify code repositories to implant backdoors, and use local devices as jump points to attack corporate internal networks. It is reported that the related vulnerabilities have existed for a year.

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.
app_icon
ChainCatcher Building the Web3 world with innovations.