BTC $78,798.87 +0.59%
ETH $2,484.50 +0.46%
BNB $748.76 -0.57%
XRP $1.42 +1.71%
SOL $103.31 +0.37%
TRX $0.3387 +0.22%
DOGE $0.0902 +0.71%
ADA $0.2171 -0.26%
BCH $257.27 +0.67%
LINK $12.05 -3.84%
HYPE $85.79 +2.69%
AAVE $128.50 -1.30%
SUI $0.8033 -1.45%
XLM $0.1870 -1.28%
ZEC $1,246.76 +8.07%
BTC $78,798.87 +0.59%
ETH $2,484.50 +0.46%
BNB $748.76 -0.57%
XRP $1.42 +1.71%
SOL $103.31 +0.37%
TRX $0.3387 +0.22%
DOGE $0.0902 +0.71%
ADA $0.2171 -0.26%
BCH $257.27 +0.67%
LINK $12.05 -3.84%
HYPE $85.79 +2.69%
AAVE $128.50 -1.30%
SUI $0.8033 -1.45%
XLM $0.1870 -1.28%
ZEC $1,246.76 +8.07%

linke

All
Article
Flash

Maya Protocol Attacked: Six Linked Vulnerabilities Result in Approximately $1.7 Million Stolen, Liquidity Pool Shrinks by $11 Million

The cross-chain liquidity protocol Maya Protocol was attacked on August 18, with the attacker exploiting six interconnected software vulnerabilities to create false account balances, stealing approximately 20.83 BTC (about $1.34 million) and other assets, resulting in a total direct loss of about $1.65 million. The incident led to the suspension of trading on the MAYAChain network, with its token CACAO plummeting nearly 89% from $0.115 to $0.013, before recovering to around $0.03.Technical reviews show that the attack began when MAYAChain mistakenly judged a transaction to be lost and triggered a compensation mechanism, but the mechanism miscalculated, adding about 49 million CACAO to a small liquidity pool, while the protocol's reserves only held about 168,000 CACAO. After the transfer failed, the system incorrectly saved the new balance, and the attacker subsequently deposited a very small amount into the liquidity pool, acquiring over 99% of the pool's share and immediately withdrawing 48.87 million CACAO, which was then exchanged for Bitcoin, Ethereum, and other assets.The incident caused the total value of the Maya Protocol liquidity pool to decrease by about $10.9 million, of which approximately $6.4 million was due to the depreciation of CACAO, and about $2.9 million came from arbitrage trading. The team expressed hope that the attacker would return the funds in the form of a bug bounty; otherwise, they would seek to recover losses through investments in channels like Aztec Chain. Maya Protocol has not yet announced a specific time for resuming trading. This incident once again exposed the security risks within the complex logic of DeFi protocols.

Holding 28,600 BTC, worth 1.8 billion USD, the wallet cluster is suspected to be linked to the Zhimin Qian money laundering case

According to on-chain detective Specter, it has discovered a cluster of wallets holding 28,600 BTC, worth approximately $1.8 billion, suspected to be related to wallets previously attributed to the money laundering case of Zhimin Qian.A few weeks ago, a Bitcoin wallet that had been dormant since 2017 transferred 1,020 BTC, worth about $60 million, and began distributing funds to multiple addresses in a manner consistent with money laundering activities. After tracking these transactions, Specter found that the related wallet cluster was connected to publicly associated addresses investigated in the UK concerning Zhimin Qian. From 2014 to 2017, Zhimin Qian organized large-scale investment fraud in China, affecting over 128,000 victims. UK authorities later traced a significant amount of criminal proceeds flowing into Bitcoin, with the Met Police ultimately seizing 60,000 BTC, marking the largest cryptocurrency seizure in UK history at that time.In July 2021, UK authorities transferred the seized BTC, creating identifiable on-chain associations. Following the recent transfer of 1,020 BTC, Specter identified additional wallets, which currently hold a total of 28,600 BTC, worth approximately $1.8 billion. These wallets have largely been dormant since June 2021. Based on on-chain evidence, it remains unclear whether these wallets are still controlled by the same actor, other custodians, or have been identified by law enforcement.

The U.S. SEC has postponed the review of the first batch of prediction market ETFs, which are linked to real events such as election outcomes and economic recessions

According to Reuters, the U.S. Securities and Exchange Commission (SEC) has delayed the review of the first batch of predictive market ETFs, resulting in the postponement of more than 24 products originally scheduled for launch. Insiders revealed that the SEC is requesting issuers to provide further clarification on product mechanisms and information disclosure details, and this delay is expected to be temporary.Issuers such as Roundhill Investments, Bitwise Asset Management, and GraniteShares submitted applications in February this year to launch ETF products linked to real-world events such as election results, economic recessions, tech layoffs, and oil prices.According to SEC rules, ETF applications typically become effective automatically 75 days after submission unless the regulatory agency intervenes. Currently, Roundhill has set May 5 as the effective date, and Bitwise and GraniteShares' products are also expected to launch around the same time. The market is closely watching whether the SEC will ultimately approve these products that open up the "event contract" asset class.Bitwise Chief Investment Officer Matt Hougan stated, "This is a rapidly maturing field, and regulation is maturing in parallel," noting that innovative products like Bitcoin ETFs have also gone through a lengthy review process but ultimately launched successfully.

The Ethereum Foundation identified about 100 "national-level hackers" infiltrators, linked to North Korea

The Ethereum Foundation recently released a summary report on the ETH Rangers security project, revealing that during a 6-month security funding program, researchers identified approximately 100 suspected state-sponsored cyber operatives, including infiltrators from North Korea, who have been active in multiple Web3 projects.The report indicates that relevant investigations were advanced through projects like the "Ketman Project," where researchers issued warnings to about 53 blockchain projects, revealing that these individuals infiltrated development teams under false identities and participated in fund flows and technical positions. Meanwhile, some related funds have been frozen, amounting to hundreds of thousands of dollars. The security team also incorporated relevant intelligence into the threat analysis system for the Lazarus Group and disclosed it at security conferences such as DEF CON, showing that state-level cyber attacks are continuously infiltrating the infrastructure of the cryptocurrency industry.In terms of overall results, the program has frozen or recovered over $5.8 million in funds, reported or documented over 785 vulnerabilities, and handled 36 security incidents, indicating that the security threats currently faced by the Ethereum ecosystem have escalated from simple vulnerability attacks to systemic risks involving state-level actors. Additionally, the report points out that North Korean hackers have also infiltrated projects through methods such as "remote IT workers," involving various attack paths such as account takeovers, freelancing platform infiltrations, and fund transfers, making them a key target for industry prevention.The Ethereum Foundation emphasizes that the security of decentralized networks requires "decentralized defense" and will continue to support security research, threat intelligence, and talent development to address the escalating state-level cyber threats.
app_icon
ChainCatcher Building the Web3 world with innovations.