BTC $63,964.81 -1.97%
ETH $1,855.77 -1.21%
BNB $564.50 -0.46%
XRP $1.09 -1.72%
SOL $73.90 -2.43%
TRX $0.3297 +0.08%
DOGE $0.0692 +0.15%
ADA $0.1628 -2.45%
BCH $210.48 -0.39%
LINK $8.31 -1.48%
HYPE $57.27 -1.86%
AAVE $91.47 -4.40%
SUI $0.7108 -4.25%
XLM $0.1775 -3.68%
ZEC $478.21 -5.91%
BTC $63,964.81 -1.97%
ETH $1,855.77 -1.21%
BNB $564.50 -0.46%
XRP $1.09 -1.72%
SOL $73.90 -2.43%
TRX $0.3297 +0.08%
DOGE $0.0692 +0.15%
ADA $0.1628 -2.45%
BCH $210.48 -0.39%
LINK $8.31 -1.48%
HYPE $57.27 -1.86%
AAVE $91.47 -4.40%
SUI $0.7108 -4.25%
XLM $0.1775 -3.68%
ZEC $478.21 -5.91%

native

All
Article
Flash

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.

X-Agent has joined the OKX Agent Marketplace, launching the first batch of MCP tools to create a machine-native economic closed loop

The AI Agent no-code operating platform X-Agent based on Web3 social networks has officially become a merchant in the OKX Agent Marketplace, launching three production-level risk analysis MCP (Model Context Protocol) tools, and deeply integrating with OKX Onchain OS and OKX Agentic Wallet, promoting the evolution of AI Agents from mere software logic to entities with autonomous economic behavior capabilities.The first batch of three pay-per-use MCP tools:X-Agent encapsulates the underlying risk assessment capabilities verified by the platform into standard MCP services for other Agents within the ecosystem to automatically discover and call:Token Security Scan: Identifies Rug Pull, Pi Xiu schemes, and contract restriction risks (0.03 USDT / use).Wallet Reputation: Evaluates the historical behavior of counterparties and "smart money" (0.01 USDT / use).Portfolio Health: Analyzes position concentration and volatility risks (0.01 USDT / use).Deep integration with the OKX ecosystem architecture, enabling machine micropayments:x402 machine-native settlement: Combines gas-free USDC settlement based on EIP-3009 with the Coinbase x402 protocol, achieving minimal per-use payments as low as 0.01 USDT on OKX X Layer, without the need for pre-deposit or manual approval.OKX TEE hardware-level custody: Integrates with OKX Agentic Wallet, storing private keys within OKX TEE (Trusted Execution Environment), with X-Agent authorized only through short-term session signatures, ensuring asset security from the source.Idempotent automated execution: Introduces Pre-Broadcast protection and idempotent state machines to prevent duplicate charges or state conflicts in on-chain autonomous tasks.Building a "two-way cycle" Agent economy:This collaboration marks the realization of a full-path connection in the X-Agent architecture from "identity - payment - execution - monetization - distribution." Agents can autonomously procure external services through OKX Agentic Wallet and package their capabilities into paid MCP tools to earn revenue, truly achieving a value closed loop for a decentralized Agent economy.

USDT will return to the Bitcoin network, and UTEXO will natively issue Bitcoin version USDT through the RGB protocol

Tether is preparing to natively issue USDT on the Bitcoin network based on the RGB v0.11.1 protocol, with commercialization and distribution handled by UTEXO. This will mark the return of USDT to the Bitcoin main chain after many years since it first landed on Bitcoin via the Omni protocol in 2014. Viktor Ihnatiuk, co-founder of UTEXO, stated that the company has received support from Tether to promote the implementation of native Bitcoin USDT.The RGB protocol employs client-side validation and integrates with the Lightning Network, enabling instant, low-cost, and private transactions of USDT while inheriting the security model of Bitcoin UTXO. In the future, users will be able to hold USDT directly through native Bitcoin addresses and complete transactions using Lightning Network wallets that support RGB, without relying on other public chains or intermediaries. Compared to the account model networks where USDT is primarily circulated, such as TRON and Ethereum, RGB naturally supports one-time addresses using the UTXO model and facilitates off-chain payments through the Lightning Network, effectively enhancing transaction privacy. Additionally, UTEXO is deeply integrated with Tether, reducing intermediary fees and data collection, and users can also convert USDT between different public chains at low cost through its already launched cross-chain bridge.

YZi Labs' incubation project Cournot has become the official AI-native oracle of 42

The AI native oracle Cournot Protocol, invested by YZi Labs, has officially integrated with 42, an event market backed by institutions such as Dragonfly and Coinbase Ventures, becoming its official AI native oracle. Cournot will provide continuous monitoring, evidence endorsement assessment, and a transparent analysis workflow driven by Cournot's "reasoning proof" framework.As the event trading platform expands into sectors such as sports, politics, creator economy, and crypto-native events, building a market adjudication mechanism is becoming a core challenge in the infrastructure domain. Unlike traditional data feed oracles, Cournot continuously tracks external dynamics, aggregates multi-source evidence for cross-examination, and analyzes the settlement conditions of various markets, generating an auditable reasoning chain while outputting adjudication results.The recent integration of the prediction market Myriad Markets by Cournot reflects the macro trend of the industry migrating towards "AI-assisted settlement" infrastructure. Cournot's core capabilities will gradually expand from empowering prediction markets to areas such as Agentic Commerce, complex RWA, card games, and parametric insurance. More and more platforms are realizing that complex real-world outcomes are often not adjudicated by a single API or a price feed, which is precisely why they are beginning to seek new types of oracles.
app_icon
ChainCatcher Building the Web3 world with innovations.