BTC $64,058.16 -0.49%
ETH $1,860.67 +0.05%
BNB $566.70 +0.93%
XRP $1.09 -0.45%
SOL $73.91 -0.74%
TRX $0.3297 -0.20%
DOGE $0.0698 +1.82%
ADA $0.1633 -0.77%
BCH $210.55 +1.01%
LINK $8.36 -0.04%
HYPE $57.59 -0.73%
AAVE $90.83 -3.30%
SUI $0.7068 -2.10%
XLM $0.1778 -1.31%
ZEC $478.61 -3.82%
BTC $64,058.16 -0.49%
ETH $1,860.67 +0.05%
BNB $566.70 +0.93%
XRP $1.09 -0.45%
SOL $73.91 -0.74%
TRX $0.3297 -0.20%
DOGE $0.0698 +1.82%
ADA $0.1633 -0.77%
BCH $210.55 +1.01%
LINK $8.36 -0.04%
HYPE $57.59 -0.73%
AAVE $90.83 -3.30%
SUI $0.7068 -2.10%
XLM $0.1778 -1.31%
ZEC $478.61 -3.82%

nera

All
Article
Flash

Bitwise releases Q3 2026 staking report: Activity on various main chains rises but revenue generally declines, institutional entry becomes a core theme

According to the Bitwise "Q3 2026 Staking Report," Q2 2026 presents a divergent pattern of "increased on-chain activity and decreased fee revenue," with the core driving factor being various protocols actively reducing block space costs.In terms of core data across chains, Ethereum's active staking volume reached a historic high of 40.2 million ETH (accounting for 33% of the total supply), while network revenue decreased by 51% year-on-year to $64 million, although it rebounded in ETH terms quarter-on-quarter; Solana's Q2 Real Economic Value (REV) dropped to $51 million, significantly down from the peak of $812 million in Q1 2025, but non-voting transaction volume reached 9.8 billion, maintaining resilience in on-chain activity; Hyperliquid's Q2 total protocol revenue was $174.8 million, with perpetual contract trading volume reaching $65.2 billion, and the proportion of non-crypto assets (commodities, stock indices, etc.) rose to 32%; Avalanche C chain's transaction volume grew approximately fourfold year-on-year to 236 million transactions, but network revenue plummeted due to a significant drop in fees, leaving only $330,000; NEAR saw a dramatic 75% drop in on-chain transaction volume to 77.7 million transactions due to the collapse of Kai-Ching application activity, but the Intents execution layer generated fees approximately 68 times that of the base chain.In terms of institutional adoption, BlackRock launched an Ethereum staking ETF (ETHB), Coinbase and Circle each staked 500,000 HYPE, and Bitwise, 21Shares, and Grayscale successively launched HYPE spot ETFs. Additionally, the stablecoin payment chain Tempo, incubated by Stripe and Paradigm, processed $386 million in transfers in its first quarter, while the global payroll platform Deel distributed approximately $30 million to 7,200 contractors through this chain.

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.

Slow Fog Cosine: Claude Code exposes high-risk security vulnerabilities, malicious configuration files may silently execute commands

The founder of Slow Fog, Yu Xian, retweeted a tweet on the X platform regarding the potential poisoning attack risks of Claude Code and published an analysis of the poisoning attack details targeting Grok Build CLI and Claude Code CLI.It pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, creating gaps that serve as channels for attackers. Attackers may execute arbitrary commands through malicious project configuration files without the user's knowledge, thereby stealing API keys, cloud credentials, or controlling local devices.Researchers constructed a testing environment and found that on Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks.If the attack is successful, attackers may further steal API keys from AI services like Claude and OpenAI, resulting in account cost losses, gain access to servers and data by obtaining cloud service credentials from AWS, Alibaba Cloud, Tencent Cloud, modify code repositories to implant backdoors, and use local devices as jump points to attack corporate internal networks. It is reported that the related vulnerabilities have existed for a year.
app_icon
ChainCatcher Building the Web3 world with innovations.