BTC $63,041.71 -0.26%
ETH $1,881.53 +0.27%
BNB $606.16 -0.29%
XRP $1.00 -0.39%
SOL $75.38 -0.48%
TRX $0.3323 -0.38%
DOGE $0.0699 +0.13%
ADA $0.1800 -0.89%
BCH $203.29 -1.36%
LINK $8.94 +2.01%
HYPE $55.85 -3.03%
AAVE $86.66 -0.88%
SUI $0.6794 -0.79%
XLM $0.1598 +0.39%
ZEC $490.55 +0.94%
BTC $63,041.71 -0.26%
ETH $1,881.53 +0.27%
BNB $606.16 -0.29%
XRP $1.00 -0.39%
SOL $75.38 -0.48%
TRX $0.3323 -0.38%
DOGE $0.0699 +0.13%
ADA $0.1800 -0.89%
BCH $203.29 -1.36%
LINK $8.94 +2.01%
HYPE $55.85 -3.03%
AAVE $86.66 -0.88%
SUI $0.6794 -0.79%
XLM $0.1598 +0.39%
ZEC $490.55 +0.94%

xpos

All
Article
Flash

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.

Slow Fog Cosine: Claude Code exposes high-risk security vulnerabilities, malicious configuration files may silently execute commands

The founder of Slow Fog, Yu Xian, retweeted a tweet on the X platform regarding the potential poisoning attack risks of Claude Code and published an analysis of the poisoning attack details targeting Grok Build CLI and Claude Code CLI.It pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, creating gaps that serve as channels for attackers. Attackers may execute arbitrary commands through malicious project configuration files without the user's knowledge, thereby stealing API keys, cloud credentials, or controlling local devices.Researchers constructed a testing environment and found that on Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks.If the attack is successful, attackers may further steal API keys from AI services like Claude and OpenAI, resulting in account cost losses, gain access to servers and data by obtaining cloud service credentials from AWS, Alibaba Cloud, Tencent Cloud, modify code repositories to implant backdoors, and use local devices as jump points to attack corporate internal networks. It is reported that the related vulnerabilities have existed for a year.

Myanmar's electric fraud AI industrialization exposed: Starlink becomes a key infrastructure, with encrypted payments and OpenAI/Google models included in the toolchain

According to a report from Hongxing News, an investigation report leaked from a scam park in Myanmar shows that global telecom fraud is accelerating towards an "AI industrialization + cross-border encrypted payment" system. The scam network completes fund circulation through cryptocurrency and uses automated tools based on large models for multi-language script generation, identity disguise, and emotional manipulation.According to the investigation analysis, these systems extensively utilize OpenAI's ChatGPT and Google's Gemini at the functional level to support "scaled social fraud." The funding side achieves rapid laundering and transfer through on-chain payments and cross-border channels, forming a dual structure of "AI customer acquisition + encrypted settlement," which gives the fraud industry a high degree of automation and transnational diffusion capability. In addition, Starlink, owned by Musk, has become the number one network service provider for the scam park in Myanmar, with American ISP providers carrying nearly one-fifth of the park's traffic.In response to the related accusations, OpenAI stated that the behavior of scammers using ChatGPT is highly similar to that of ordinary users, making identification difficult. However, they have banned about 100,000 suspicious accounts monthly through behavioral pattern recognition and risk control systems. Google stated that its AI models have safety barriers in place and emphasized its commitment to "responsible AI development" to limit the tools' use for fraud and other illegal purposes.

first_img Japan's large corporate pension funds plan to allocate about 1% to cryptocurrencies and reduce their exposure to the yen

According to CoinPost, Japan's national corporate pension fund plans to start investing in cryptocurrencies in the fiscal year 2026, with an allocation ratio of about 1% of its total operating assets (approximately 21.3 billion yen).The report states that the asset allocation ratio for the fiscal year 2025 is: 80% in yen, 15% in US dollars, and 5% in other currencies. However, in the fiscal year 2026, the yen allocation ratio will decrease to 70%, and a new 10% allocation will be made for currencies from developed countries. The remaining 5% will consist of emerging market currencies, gold, and cryptocurrencies.The main purpose is to diversify currency risk. The fund's executive director, Ai Yuki, stated that due to the potential weakening of the US dollar as a benchmark currency, they decided not to increase their holdings in US dollars and instead use cryptocurrencies like Bitcoin as a hedge against currency depreciation, as Bitcoin has a lower correlation with the US dollar index.After approximately six years of investigation, the fund has determined that the cryptocurrency market has matured as the investor base has expanded. In the future, the fund will continue to explore the possibility of expanding cryptocurrency investments, including funds for arbitrage trading of various cryptocurrencies.

Peter Thiel's Mystical Society Dark Rating Exposed: Big Shots are Divided into Three, Six, and Nine Grades, with C Grade at the Top and A Grade at the Bottom, Prices Discounted Based on Fame

According to an analysis of the latest leaked data by WIRED, the secretive society Dialog, co-founded by Peter Thiel, has an extremely ruthless and biased "grading and elimination" mechanism.Dialog implements a secret rule of "rating upon entry." Although the club has thousands of members, only 192 personal profiles (including 130 formal members and some candidates) were leaked and reviewed by WIRED. They reveal the club's counterintuitive hierarchy of disdain: C-level is the highest VIP, B-level is the overwhelming majority of ordinary members, while the A-level, usually regarded as the best, is actually the least known bottom tier.This rating is directly tied to members' wallets. Only about 25% of VIP "C" level big shots are required to pay the full attendance fee, while among the bottom "A" level members, the proportion paying the full attendance fee of tens of thousands of dollars is as high as 70%.Ironically, the AI screening mechanism introduced by Dialog is extremely superstitious about so-called "national recognition." For example, actor Josh Brolin, who played "Thanos," has never attended but wins VIP "C" level status due to box office success and millions of fans; meanwhile, academic giant Tyler Cowen was deemed "not famous enough among ordinary people" by the AI and nearly classified into the ordinary tier, only barely promoted to C-level through human intervention.The "value-added points" serve as a scythe for eliminating "useless people," specifically measuring members' resource connections and intellectual contributions to other club giants. After each gathering, staff review members' performances like "code review," and those with too low value-added points, cultural mismatches, or declining visibility will be ruthlessly removed from the invitation list.Additionally, the leaked database also exposed its built-in social and dating matching system (10% of members join the singles pool), which has a "no-match list" while recommending pairings.This so-called objective assessment system is also filled with biases: women make up one-third of the members but only receive 18% of VIP seats; politically, it is even harder to escape differential treatment. Although more than half of the members identify as "left-leaning," the probability of "right-leaning" members obtaining VIP status is more than twice that of left-leaning members, and even the "left-leaning" label of an environmental leader was forcibly rewritten to "right-leaning" by staff in the background.

India's cryptocurrency tax review exposes approximately $930 million in undeclared income, with a comprehensive strengthening of itemized reporting and cross-platform verification for the 2026 tax season

As India's tax enforcement intensifies, cryptocurrency investors face stricter reporting and compliance requirements in the 2026 tax season, with incorrect declarations potentially triggering fines and audits. Reports indicate that under current rules, cryptocurrency gains are still subject to a 30% uniform capital gains tax, and a 1% Tax Deducted at Source (TDS) is levied on transactions exceeding a certain amount, while losses cannot be offset across assets. The new Income Tax Act (2025) came into effect on April 1, 2026, but the core tax framework remains largely unchanged.In terms of reporting, investors must fill out a dedicated Schedule VDA section in the ITR-2 or ITR-3 forms and are required to record each transaction individually, including all operations such as trading, exchanging, transferring, and clearing, rather than just summarizing gains. The report emphasizes that regulatory focus has clearly escalated. The Indian tax authorities will directly obtain user-level transaction data through trading platforms, custodians, and wallet service providers, and will automatically cross-check this with reported information; discrepancies will trigger system flags and audits.Data shows that the Indian tax authorities have issued over 44,000 notices and discovered approximately 88.8 billion rupees (about 930 million USD) in unreported virtual asset income. Meanwhile, the tax department is enhancing its tracking capabilities by combining on-chain analysis tools with international data-sharing mechanisms. Additionally, starting in 2027, India will align with the OECD cryptocurrency reporting framework to achieve automatic exchange of cross-border transaction data, and overseas exchange holdings will gradually come under regulatory scrutiny.Analysis points out that common errors include misuse of reporting forms, omission of airdrop and staking income, and failure to correctly match 1% TDS records, among others. The report emphasizes that cryptocurrency tax compliance is shifting from "post-reporting" to "real-time traceability," and investors need to strengthen year-round record management.
app_icon
ChainCatcher Building the Web3 world with innovations.