BTC $78,422.77 +0.29%
ETH $2,470.08 +0.72%
BNB $693.79 +0.13%
XRP $1.38 -0.76%
SOL $103.69 -1.60%
TRX $0.3383 -0.73%
DOGE $0.0835 -1.77%
ADA $0.1981 -1.57%
BCH $249.19 +0.97%
LINK $11.44 +0.05%
HYPE $80.84 -3.04%
AAVE $124.81 -0.63%
SUI $0.7359 -0.99%
XLM $0.1782 -0.58%
ZEC $862.81 +2.68%
BTC $78,422.77 +0.29%
ETH $2,470.08 +0.72%
BNB $693.79 +0.13%
XRP $1.38 -0.76%
SOL $103.69 -1.60%
TRX $0.3383 -0.73%
DOGE $0.0835 -1.77%
ADA $0.1981 -1.57%
BCH $249.19 +0.97%
LINK $11.44 +0.05%
HYPE $80.84 -3.04%
AAVE $124.81 -0.63%
SUI $0.7359 -0.99%
XLM $0.1782 -0.58%
ZEC $862.81 +2.68%

security

All
Article
Flash

first_img Polygon has fixed security vulnerabilities through two hard forks, which were previously deployed privately

Polygon Labs disclosed that it has fixed a batch of security vulnerabilities in its proof-of-stake network through two hard forks, with the related fixes privately deployed before public disclosure. According to a forum post released on Wednesday, the team packaged the fixes into the Austin hard fork of the Bor client and the Kyoto hard fork of the Heimdall client, both of which followed the standard process for fixing issues that affect consensus: first validated on the Amoy testnet, and then publicly disclosed once the mainnet was activated and the network was secure.The Austin fork fixed two denial-of-service paths in block processing, including a vulnerability where malicious block producers could crash peer nodes by filling them with oversized field data. The Kyoto fork addressed a broader range of consensus hardening issues, with the most severe vulnerability allowing an attacker to force the entire validator set to perform costly and coordinated work with just one crafted transaction—the cost of constructing the transaction is low, but the network processing cost is high. Polygon emphasized that none of the vulnerabilities were observed to be exploited on the mainnet and have been proactively addressed. The two upgrades are now mandatory for node operators and have taken effect without the need for state migration or resynchronization.This disclosure comes at a critical transformation period for Polygon, which has completed the migration of the traditional MATIC token to POL as part of a comprehensive overhaul of its network architecture. The news did not boost the price of POL; according to CoinGecko data, POL traded at approximately $0.09983 on Sunday, down 2.3% in 24 hours, down about 6.8% over the past week, and down about 60.8% over the past year, with a market capitalization of approximately $1.07 billion.

first_img The Cronos network has suspended operations due to an attack on Tectonic, with estimated losses of around 75 million dollars

The Cronos network associated with Crypto.com has suspended operations after detecting an attack on the lending protocol Tectonic. The Cronos Network announced on the X platform that it has identified vulnerabilities on Tectonic and has paused the network. Tectonic also confirmed that it is investigating the related incident and advised users not to interact with the protocol until safety is confirmed. According to DefiLlama data, Tectonic had a total locked value of approximately $121.7 million before the incident, with active loans of about $82.7 million.On-chain researcher Weilin Li attributed the attack to price manipulation of the TONIC token. The attacker bought enough TONIC within 20 minutes to inflate its price by about 100 times, then used the inflated tokens as collateral to borrow other assets from Tectonic, a method similar to the 2022 Mango Markets oracle manipulation attack. Li initially estimated that the attacker profited about $66 million, later discovering that another address controlled by a different attacker contained about $8 million, bringing the total estimate to around $75 million. Li also stated that the attacker only successfully bridged about $6 million to Ethereum, as the suspension of the Cronos network prevented most of the affected assets from flowing out.Crypto.com CEO Kris Marsalek stated that the company's app and exchange were not attacked, and its security team is assisting Tectonic with the investigation.

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.

first_img Solana crypto card hacked, Avici token plummets 49%

The Solana-based crypto debit card infrastructure Rain was hacked due to vulnerabilities in outdated contracts, resulting in approximately $1.1 million in funds being stolen. The affected crypto bank Avici's token AVICI dropped from a 24-hour high of $0.43 to a historical low of $0.217, a decline of 49%, before recovering to around $0.378.Avici confirmed that the attack only affected the card funds contract used for recharge consumption, and its self-custody wallets were not impacted, promising to fully refund the affected balances. In this incident, 1,685 Avici users lost approximately $500,800; another crypto bank, Tria, also had 636 users affected, with losses exceeding $430,000. The discrepancy between the approximately $1.1 million tracked on-chain and the losses reported by Avici indicates that other protocols supported by Rain were also attacked.Transaction data shows that the attacker repeatedly submitted signature authorizations, adding themselves as administrators of the card collateral account and withdrawing balances. The stolen stablecoins were exchanged for SOL, cross-chain to Ethereum, and ultimately flowed into the mixer Tornado Cash. Avici has filed a report with the FBI's Internet Crime Complaint Center. This incident also exposed issues with the custody transfer behind some self-custody crypto cards: although users control their wallets, the funds used for consumption are transferred to third-party contracts.

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

first_img Term Finance permanently closes Meta Vaults after governance attack, resulting in a loss of approximately 8.5 million USD

The development team of Term Finance, Term Labs, announced that after the governance attack incident, all Term Meta Vaults have been permanently closed, DAO governance rights have been revoked, but the withdrawal channel remains open. In an update on August 23, Term stated that this closure is irreversible and permanently prevents subsequent deposits, but did not disclose the scale of the remaining assets in the vault, only indicating that it will "explore pathways" to address any gaps, and the amount that depositors can recover remains undecided.Blockchain security company PeckShield estimates that the attacker stole approximately 2,843 ETH (worth about $6.87 million at the time) and 1.68 million USDC (which was later exchanged for about 1.68 million DAI), with total losses estimated at around $8.5 million. On-chain records confirm the related transfers: one transaction transferred 2,841.74 WETH to an address labeled "Term Finance Exploiter 1" by Etherscan, while another transaction transferred 1.68 million USDC to an address labeled "Term Finance Exploiter 2".Yearn stated that Term's vault contract uses its V3 architecture, but the attack occurred on Term's custom governance wrapper, which is not applicable to standard Yearn vaults. Term indicated that, according to the current investigation, its underlying protocol and direct lending market were not affected and is working with external security teams for remediation and recovery, but did not provide any compensation commitments or timelines.
app_icon
ChainCatcher Building the Web3 world with innovations.