BTC $79,220.03 -0.85%
ETH $2,494.50 -0.16%
BNB $739.87 -1.53%
XRP $1.40 -1.63%
SOL $104.07 -1.60%
TRX $0.3343 -0.49%
DOGE $0.0905 +0.33%
ADA $0.2208 +0.05%
BCH $260.95 +1.22%
LINK $12.78 -2.46%
HYPE $85.29 -3.27%
AAVE $132.47 -0.90%
SUI $0.8299 +2.49%
XLM $0.1925 +3.90%
ZEC $1,155.23 -5.68%
BTC $79,220.03 -0.85%
ETH $2,494.50 -0.16%
BNB $739.87 -1.53%
XRP $1.40 -1.63%
SOL $104.07 -1.60%
TRX $0.3343 -0.49%
DOGE $0.0905 +0.33%
ADA $0.2208 +0.05%
BCH $260.95 +1.22%
LINK $12.78 -2.46%
HYPE $85.29 -3.27%
AAVE $132.47 -0.90%
SUI $0.8299 +2.49%
XLM $0.1925 +3.90%
ZEC $1,155.23 -5.68%

atta

Tất cả
Bài viết
Tin nhanh

Công ty khởi nghiệp tính toán không gian Starcloud đã hoàn thành vòng gọi vốn mới với 250 triệu USD, Manhattan West Ventures dẫn đầu

ChainCatcher tin tức, theo báo cáo của TechCrunch, công ty khởi nghiệp về sức mạnh tính toán không gian Starcloud đã thông báo hoàn thành vòng gọi vốn mới trị giá 250 triệu USD, do Manhattan West Ventures dẫn đầu, cùng với sự tham gia của các tổ chức như Nvidia, Cisco, Benchmark, EQT, trong đó Nvidia đã đầu tư khoảng 25 triệu USD trong vòng gọi vốn này.Nguồn vốn mới sẽ được sử dụng để mở rộng cơ sở sản xuất vệ tinh và thúc đẩy nghiên cứu và phát triển vệ tinh trung tâm dữ liệu quỹ đạo thế hệ tiếp theo Starcloud-3. Starcloud tiết lộ rằng công ty đã đưa vào hoạt động GPU trung tâm dữ liệu H100 của Nvidia và đã hoàn thành việc huấn luyện mô hình dựa trên GPU đó. Hiện tại, hầu hết các dự án tính toán không gian đang sử dụng chip tính toán biên, trong khi Starcloud đang hợp tác với Nvidia để cung cấp dữ liệu thử nghiệm cho GPU Vera Rubin Space-1 được thiết kế đặc biệt cho môi trường không gian trong tương lai. Giám đốc điều hành của Starcloud, Philip Johnston, trước đó cũng đã cho biết kế hoạch khai thác bitcoin trong không gian.

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

Aave releases post-attack investigation on Kelp rsETH bridge

Regarding the attack on the Kelp rsETH LayerZero V2 bridge that occurred on April 18, Aave released a post-incident investigation on the X platform, emphasizing that the exposure was primarily due to third-party bridge infrastructure rather than the protocol itself. The attacker executed an RPC poisoning attack targeting a single validator of LayerZero, forging a cross-chain message. This led to the release of 116,500 rsETH on the Ethereum side without actual destruction on Unichain. The attacker subsequently deposited the stolen rsETH into Aave V3 (Ethereum Core and Arbitrum), borrowing approximately 82,650 WETH and 821 wstETH.The Aave Protocol Guardian and Risk Steward immediately implemented protective measures for the rsETH and WETH reserves. Currently, the WETH and rsETH markets in the affected V3 deployments are operating normally. The rsETH held by the attacker on Arbitrum has been destroyed, the LayerZero OFT adapter has been fully recharged in five batches, rsETH support has been fully restored, and Kelp has reopened the withdrawal, bridging, and claims functions for rsETH. The WETH LTV in the affected markets has been reset to pre-attack values, and Aave V3 is fully operational across all markets except for rsETH.The Arbitrum DAO has voted to authorize the transfer of frozen ETH to Aave LLC, and it is currently awaiting on-chain execution. The court is still reviewing the substantive content of the injunction, and Aave LLC will continue to comply with the injunction during the court's deliberation. Ongoing projects include: the Aave risk framework from Llama Risk, the bridging assessment framework, the release of evaluation reports for currently live assets, on-chain execution of Arbitrum DAO votes, and the court's review of the injunction.

Superfortune: The leakage of the attacker's private key rather than address poisoning is not the work of an insider

Superfortune, incubated by Manta, recently released an update on the X platform regarding a security incident, stating that the attack was not carried out by internal personnel and that no team members were involved. The claim about the team secretly selling tokens is incorrect. The team has also not had any contact with Web3Port.The investigation confirmed that the attack was not due to address poisoning, but rather a leak of the signer's private key. The attacker independently held the private key and submitted a transaction with a forged address 43 minutes after the correct transaction. The forged address shares the first and last four characters with the correct address (starting with 0x70AE and ending with 5C15) to disguise itself in the Safe interface preview. The stolen funds are fully traceable and are currently stored in three cold wallets on Ethereum, containing approximately 2784 ETH, along with about 170,000 USDT that were cross-chain transferred out.The attacker also created a large number of counterfeit addresses and sent false transfer events to these addresses using Unicode-forged token symbols in an attempt to confuse tracking. This counterfeit address construction technique is the same as the method used when attacking this project. The attacker had pre-built a large-scale infrastructure, indicating that this was an industrialized operation rather than an opportunistic attack.
app_icon
ChainCatcher Building the Web3 world with innovations.