BTC $64,116.56 +0.03%
ETH $1,867.02 +0.34%
BNB $566.37 +0.94%
XRP $1.09 +0.72%
SOL $74.15 +0.23%
TRX $0.3297 -0.08%
DOGE $0.0713 +3.31%
ADA $0.1649 +0.43%
BCH $209.78 -0.10%
LINK $8.38 +0.36%
HYPE $57.76 -1.85%
AAVE $91.84 -3.01%
SUI $0.7108 -0.83%
XLM $0.1784 +0.40%
ZEC $480.51 -2.89%
BTC $64,116.56 +0.03%
ETH $1,867.02 +0.34%
BNB $566.37 +0.94%
XRP $1.09 +0.72%
SOL $74.15 +0.23%
TRX $0.3297 -0.08%
DOGE $0.0713 +3.31%
ADA $0.1649 +0.43%
BCH $209.78 -0.10%
LINK $8.38 +0.36%
HYPE $57.76 -1.85%
AAVE $91.84 -3.01%
SUI $0.7108 -0.83%
XLM $0.1784 +0.40%
ZEC $480.51 -2.89%

prevent

All
Article
Flash

CertiK: The losses from wrench attacks have surged nearly 12 times, making operational security the new core of prevention

Web3 security company CertiK released the "2026 First Half Wrench Attack Report." The report shows that in the first half of 2026, a total of 52 publicly verified wrench attack incidents were recorded globally, an increase of 33.3% year-on-year; related losses amounted to approximately $124 million, an increase of about 11.8 times compared to the same period last year.The report points out that attackers are shifting from exploiting technical vulnerabilities to targeting asset holders and their real-world relationship networks, with home invasion incidents rising from 1 in the first half of 2025 to 20, accounting for 41% of the total incidents during the same period. Europe has become a high-frequency attack region, with 33 incidents occurring in France, accounting for 63.5% of global cases.CertiK states that as real-world risks become a significant challenge for digital asset security, businesses and high-value individuals need to establish a more comprehensive protection system. CertiK has launched operational security services to help identify risks related to the exposure of information such as identity, home, residence, and travel trajectory; at the same time, through CertiK Security Workspace, it correlates off-chain intelligence, on-chain transactions, and AML risk signals to support institutions in tracking and analyzing cybercrime activities.In addition, CertiK is strengthening cooperation with international law enforcement agencies such as Interpol and Europol to provide technical support for cross-border attack investigations and security policy research.

hot_img The South Korean Financial Commission responds to the controversy over single-stock leveraged ETFs: there is indeed an effect in preventing capital outflow, but it is not the main cause of stock market volatility

The Financial Services Commission of South Korea responded positively to the recent controversies surrounding single-stock leveraged exchange-traded funds (ETFs) when it released supplementary regulatory measures. Byeon Je-ho, the Director of the Capital Markets Bureau of the Financial Services Commission, clearly stated that launching leveraged ETF products targeting single stocks such as Samsung Electronics and SK Hynix in the domestic market has indeed had a significant effect in locking in domestic investment demand and preventing capital outflow to overseas leveraged markets like Hong Kong or the United States.In response to external accusations that single-stock leveraged ETFs are the "main culprit" behind the recent increase in volatility in the South Korean stock market, the Financial Services Commission refuted this claim. Byeon Je-ho pointed out that the recent dramatic market fluctuations cannot be solely explained by leveraged ETFs, with the core reason being the alternating expectations of the global semiconductor industry cycle. Data shows that from May 26 to July 10, the annualized daily return volatility of U.S. SanDisk (131%), Micron (123%), and Japan's Kioxia (118%) was higher than that of South Korea's SK Hynix (113%) and Samsung Electronics (96%). Additionally, some investors' contrarian operations have played a role in stabilizing stock prices to some extent.Regarding the demands from some politicians and market participants to "forcefully delist single-stock leveraged ETFs," the Financial Services Commission clearly rejected this request. The official explanation stated that delisting must meet statutory termination criteria such as a sharp decline in market value or a lack of liquidity providers (LPs), and currently, the market is showing signs of heating up due to excessive demand, which does not meet the delisting conditions. The Financial Services Commission indicated that such calls should be understood as the market's urgent expectation for strengthened compliance and robust regulatory measures.

South Korea promotes new regulations for telecom financial fraud prevention, with encrypted assets included in the scope of victim compensation

According to Etoday, the Financial Services Commission of South Korea has announced a draft amendment to the "Special Law on Preventing Telecom Financial Fraud and Returning Victim Funds," planning to include funds from phone scams that are transferred to crypto assets within the scope of victim compensation, and to clarify the standards for the return and valuation of crypto assets. The relevant regulations are expected to officially take effect on October 1.According to the new regulations, if the frozen assets are cryptocurrencies, victims will generally be compensated based on the type and quantity of assets; if the defrauded assets differ in form from the frozen assets, compensation will be made in the form of assets that existed at the time the account was frozen. In cases where cash and crypto assets are mixed, the regulatory authorities will value the crypto assets based on the market price at the time of freezing to determine the final compensation amount.The Financial Services Commission of South Korea stated that clarifying the form of returned assets and the timing of valuation will help achieve faster and fairer compensation in complex cases involving mixed funds from multiple victims. It is reported that the public consultation for the draft amendment will continue until August 24.

Monad Co-founders: If a rate limit is set on collateral supply, today's rsETH event could prevent a loss of about 200 million dollars

Keone Hon from Monad Lianchuang stated: "I feel that the lending protocol for the liquidity pool should set rate limits on the supply of assets deposited as collateral. For example, if the current supply is 100 million and the supply cap is 300 million, then in the next 10 minutes, the maximum allowed increase should be to 110 million, rather than allowing a one-time deposit of the full 200 million. In reality, no one needs to complete such a large deposit all at once.This is important because when certain exotic assets are attacked, the impact depends on the scale of the exit channels for that asset. Especially in many cases where attacks belong to infinite issuance vulnerabilities, the scale of the exit that can be made essentially determines the upper limit of the attack losses. Lending protocols are often the largest exit channels. If a smart cap is introduced, where the initial cap is slightly above the current supply and is gradually adjusted to the real cap over several hours, it would have a huge effect. With such a mechanism, rsETH depositors could have avoided about 200 million dollars in losses.This also raises a point: the asset issuers themselves should support such mechanisms. If you are issuing redeemable tokens with redemption delays, you are not worried about hackers redeeming directly from you, but you need to compress the scale of external exit paths as much as possible without affecting normal users. Therefore, a high supply cap should be seen as a risk rather than a symbol of strength. For example, the Hyperbridge DOT attack did not result in a 100 million dollar loss because there were very few exit paths; the Resolv attack loss was 24 million dollars instead of 200 million dollars because the scale of the exit path limited the loss cap. This is an obvious principle, but there are still immediately actionable measures: audit the supply caps of all assets and lower the caps when unnecessary."

The Ministry of Industry and Information Technology of China issued a risk alert regarding the timely update of specific iOS versions to prevent the exploitation of vulnerabilities

The Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) of the Ministry of Industry and Information Technology of China has monitored and found that attackers are using exploit tools targeting Apple Inc.'s terminal products to carry out cyber attack activities, which can lead to serious harms such as information theft and system control. The affected range includes Apple terminal products such as iPhone and iPad running iOS 13 to 17.2.1.Attackers induce users to use the Safari browser to visit web pages containing malicious code through methods such as SMS, email, or web poisoning, comprehensively utilizing security vulnerabilities present in the terminal devices to implant remote control Trojans into the victim's terminal products, stealing sensitive user information, gaining maximum privileges, and taking control.It is recommended that users of Apple terminal products conduct risk assessments, and promptly fix vulnerabilities through version upgrades and patch installations (refer to the Apple Security Updates). Pay attention to system update notifications and the latest security update announcements released by Apple, upgrade to the latest secure version in a timely manner, strengthen security awareness, avoid clicking on unknown links, and prevent the risk of cyber attacks.
app_icon
ChainCatcher Building the Web3 world with innovations.