BTC $78,580.52 -0.66%
ETH $2,489.79 +0.10%
BNB $752.57 +1.71%
XRP $1.43 +2.07%
SOL $103.86 -0.11%
TRX $0.3388 +1.48%
DOGE $0.0900 -0.11%
ADA $0.2246 +1.73%
BCH $257.81 -1.48%
LINK $12.69 -1.63%
HYPE $84.01 -1.73%
AAVE $129.44 -2.06%
SUI $0.8231 +0.50%
XLM $0.1904 -0.53%
ZEC $1,179.80 +0.88%
BTC $78,580.52 -0.66%
ETH $2,489.79 +0.10%
BNB $752.57 +1.71%
XRP $1.43 +2.07%
SOL $103.86 -0.11%
TRX $0.3388 +1.48%
DOGE $0.0900 -0.11%
ADA $0.2246 +1.73%
BCH $257.81 -1.48%
LINK $12.69 -1.63%
HYPE $84.01 -1.73%
AAVE $129.44 -2.06%
SUI $0.8231 +0.50%
XLM $0.1904 -0.53%
ZEC $1,179.80 +0.88%

oh

All
Article
Flash

Researchers disclose Solana PoH clock attack vulnerability: Transition risks remain unresolved before Alpenglow upgrade

According to CryptoSlate, researchers from USENIX Security have publicly disclosed a clock attack vulnerability targeting Solana's Proof of History (PoH) mechanism, which was privately reported to the Solana development team back in December 2025. The research shows that a malicious scheduler leader can manipulate the PoH logical clock by "re-anchoring," slowing down the advancement of logical time, thus gaining a longer transaction selection window in physical time, and isolating honest leader blocks using the TowerBFT fork choice mechanism, with the required staking ratio for the attacker being less than 33%.The Alpenglow security competition with a reward of 50,000 SOL under Anza concluded on August 19, but the vulnerability was excluded from the review scope due to the competition rules that state "actions that can only be triggered when Alpenglow is not activated." The Solana development team stated that they are aware of the related behavior, believe that the probability of the most severe scenario occurring under current conditions is low, and expect that the Alpenglow upgrade will fundamentally eliminate the prerequisites for the attack. Currently, the Alpenglow code has been included in the Agave 4.2 client but has not yet been activated on the mainnet, and is expected to go live with Agave 4.3. Until then, the transitional risk of this vulnerability has not been publicly analyzed or addressed at the implementation level.

first_img Winbond Electronics has initiated the expansion of its Kaohsiung Luzhu plant, with Module B expected to start construction in 2027

According to the Industrial and Commercial Times, driven by the long-term growth in demand for memory and advanced packaging due to AI, Winbond Electronics has proactively initiated expansion plans for its Kaohsiung Luzhu plant, merging the originally planned phases two and three into Module B for simultaneous development. Construction of the cleanroom is expected to start in 2027, with equipment installation beginning as early as the beginning of 2029, and equipment will be phased in according to customer demand forecasts and LTA. Currently, there are already customers negotiating for capacity in 2029 and 2030.Industry sources indicate that Winbond's niche DRAM and SLC NAND are in short supply in the third quarter, with a quarterly price increase estimated at about 50%; NOR Flash benefits from large cloud service provider customers stocking up, with a quarterly price increase estimated at about 30%. The price increase for memory in the fourth quarter is expected to converge to 2% to 5%, but thanks to increased DRAM capacity and growing shipment volumes, revenue and profits can still maintain a quarterly increase. Winbond's consolidated revenue in the second quarter was NT$59.843 billion, a quarterly increase of 56.4% and a year-on-year increase of 184.7%. DRAM prices increased by about 100% quarter-on-quarter, while Flash rose by about 43%, with consolidated gross margin rising to 66.2% and after-tax earnings per share of NT$5.40.The Module B product plan includes Standard DRAM, CUBE DRAM, Wafer-on-Wafer (WoW), and silicon capacitors (Si-Cap), which will support 14-nanometer and future 12-nanometer DRAM processes, with plans to introduce EUV equipment in the future.

hot_img Xiaohongshu has created an "AI Shopping Guide" feature that directly pushes product cards and order links in conversation scenarios

According to an exclusive report from "Du Jia," Xiaohongshu is developing a brand new "AI Shopping Guide" feature, which relies on a conversational interaction model to directly push product cards and attach order jump links in Q&A scenarios. This project is led by Daoxuan (Pan Boyuan). As of the time of publication, Xiaohongshu has not responded.Previously, Xiaohongshu launched an AI summary feature in store reputation, and this AI shopping guide is a further extension of its intelligent transaction chain. According to public data, Xiaohongshu has approximately 400 million global MAU, with 39 million users engaging in explicit purchasing behavior daily, resulting in 140 million active purchase requests, over 47 million users entering merchant live streams, and more than 170,000 merchant group chats remaining active. During the 618 period, the GMV of store broadcasts increased by 265% year-on-year, and note content drove transaction growth of over 210%.Xiaohongshu currently adopts a dual transaction model of "internal marketplace closed loop plus external traffic diversion," and there is still room for improvement in the direct order conversion rate within the platform. The launch of the AI shopping guide feature is expected to further enhance its internal e-commerce GMV and revenue.

Telegram claims to have suffered from "de-listing extortion" attacks: the temporary removal of the app from the Apple App Store was caused by a user embedding prohibited content

Telegram founder and CEO Pavel Durov stated that Telegram was briefly removed from the App Store by Apple recently due to a user embedding illegal pornographic content in a public group. The app was restored within hours.Durov mentioned that the attackers exploited a technical vulnerability to insert AI-modified illegal content into old messages in active groups, hiding the content by editing historical messages, making it difficult for regular group members to discover and report it in a timely manner. Such attacks are classified as "takedown extortion," where attackers use automated accounts to embed violations in public groups and report them to platforms like Apple, attempting to force group administrators to pay a ransom, or else the community would be banned due to platform rules.Durov further explained that Telegram continuously combats illegal content through user reports, AI filtering, content hashing, and other mechanisms. This incident is not a systemic issue of the platform but rather a targeted attack exploiting rule loopholes by the attackers.He also warned that Apple's direct removal of the app without prior contact with Telegram could pose risks to all mobile applications that provide user-generated content (UGC), and platform developers need to enhance their defenses against malicious reporting and "takedown attacks."

The EU expands cryptocurrency restrictions on Belarus, prohibiting its citizens from controlling all cryptocurrency service providers under MiCA regulation

The European Union has further tightened restrictions on cryptocurrency assets related to Belarus, prohibiting Belarusian citizens and residents from owning, controlling, or managing cryptocurrency service providers regulated by the Markets in Crypto-Assets Regulation (MiCA). According to the Council Decision (CFSP) 2026/1847 passed by the EU Council, this measure is an extension of the EU's sanctions framework against Belarus's involvement in the Russia-Ukraine conflict.The new regulations will officially take effect on July 24, with the expanded restrictions on the cryptocurrency industry set to be implemented from August 25. According to MiCA, the affected services include operating cryptocurrency trading platforms, cryptocurrency exchanges, executing and transmitting customer orders, cryptocurrency issuance services, asset transfer services, investment consulting, and portfolio management.This restriction comes as the MiCA transition period ends on July 1. The EU had previously required unauthorized cryptocurrency businesses to cease related operations, or face regulatory enforcement. The EU stated that this expansion of restrictions is part of its efforts to combat the use of cryptocurrency platforms to evade sanctions against Russia. Previously, in the 21st round of sanctions against Russia, the EU had expanded the trading ban to 14 cryptocurrency-related service platforms outside the EU and established a mechanism to prohibit future transactions with any foreign cryptocurrency service providers identified as helping Russia evade sanctions. Market participants noted that as the MiCA regulatory framework is fully implemented, the EU is further strengthening its regulatory control over the cryptocurrency industry through licensing systems and sanction mechanisms.
app_icon
ChainCatcher Building the Web3 world with innovations.