BTC $79,198.69 -0.47%
ETH $2,490.19 +0.39%
BNB $743.83 +0.15%
XRP $1.40 -0.86%
SOL $104.69 -1.12%
TRX $0.3348 -0.04%
DOGE $0.0905 +2.13%
ADA $0.2218 +2.01%
BCH $262.23 +2.57%
LINK $13.06 +7.16%
HYPE $86.82 -2.58%
AAVE $133.16 -0.69%
SUI $0.8270 +4.31%
XLM $0.1922 +4.47%
ZEC $1,175.26 +0.81%
BTC $79,198.69 -0.47%
ETH $2,490.19 +0.39%
BNB $743.83 +0.15%
XRP $1.40 -0.86%
SOL $104.69 -1.12%
TRX $0.3348 -0.04%
DOGE $0.0905 +2.13%
ADA $0.2218 +2.01%
BCH $262.23 +2.57%
LINK $13.06 +7.16%
HYPE $86.82 -2.58%
AAVE $133.16 -0.69%
SUI $0.8270 +4.31%
XLM $0.1922 +4.47%
ZEC $1,175.26 +0.81%

incident

Tất cả
Bài viết
Tin nhanh

Coinbase reviews the May outage incident: AWS cascading failure exposes architectural risks

Coinbase released a retrospective report on the large-scale service interruption event on May 7, 2026.The outage lasted approximately 8 hours, with full recovery taking about 12 hours. During this time, trading, deposits, withdrawals, and most core services were unavailable or severely degraded. Coinbase stated that the outage was caused by multiple cooling units failing simultaneously in the cooling system of a data center in one availability zone (use1-az4) in the AWS us-east-1 region, triggering cabinet thermal protection shutdowns, which led to EC2 instances and EBS volumes going offline, affecting multiple internet services.During the recovery process, the Coinbase trading matching engine lost quorum due to the cluster architecture deployed in a single AWS data center losing most nodes. It required urgent code adjustments and the reconstruction of a new node group to restore operation, gradually restarting market trading during the recovery.Additionally, the AWS-managed Kafka (MSK) service experienced control plane failures, preventing the automatic re-election of partition leaders, further blocking quotes, fees, and some settlement and data flow systems, which expanded the overall impact.After manual partition migration in collaboration with the AWS engineering team, the system gradually returned to normal. Coinbase stated that this incident exposed its shortcomings in cross-availability zone automatic switching capabilities and disaster recovery for managed middleware. The company will upgrade its cross-region hot backup architecture, strengthen regular failure drills, and migrate the Kafka system from dual availability zones to a three availability zone deployment, while also working with AWS to advance root cause fixes and improvements.

THORChain has released a recovery plan for the attack incident, and voting for node operators has begun

THORChain has released its fourth update regarding the attack incident on May 15, and the proposal ADR028 has been announced, with voting for node operators now open.According to the recovery plan, the protocol will first absorb losses through its own liquidity, with the remaining portion to be shared by synthetic asset holders; the specific distribution ratio of the two is still under evaluation. The protocol's own liquidity will be reduced to zero, and will be gradually replenished through system revenue. This plan will not issue or sell RUNE, nor will it dilute any holders.On the technical side, GG20 will be temporarily retained and has completed patch upgrades. Trading will resume after the vulnerabilities are fixed and node rotation is successfully conducted, with a future release pace that is slower and more security-conscious. Innocent nodes located in the same vault as the attacker will be protected, while the attacker nodes will be fully confiscated. The recovered RUNE will be paired with the recovered assets, and any excess will be destroyed.The protocol also offers a white hat bounty to the attacker to recover funds; if some are returned, the recovery plan will be adjusted proportionally. THORChain remains neutral and permissionless, and there will be no review of the attacker's Swap transactions after trading resumes. Node operators are currently voting on the proposal direction, and the numbers in the ADR are only indicative, with adjustments to be made through Mimir later.

The security incidents at GitHub and Grafana are likely related to a large-scale "mini sandworm" supply chain attack

According to the threat intelligence released by Slow Fog, several high-frequency npm packages including AntV and Echarts-for-react, as well as the Python SDK durabletask, have recently been targeted by the Mini Shai-Hulud "mini sandworm" supply chain attack. The npm account atool was compromised, and the attacker automatically published 637 malicious versions within 22 minutes, affecting 317 packages. The attacker continuously uploaded durabletask versions 1.4.1, 1.4.2, and 1.4.3 within 35 minutes, bypassing normal release controls and impersonating an official Microsoft release.The large-scale leak of GitHub tokens and the ransomware attack on Grafana Labs are likely related to this supply chain attack. Affected components include high-frequency components such as AntV and Echarts-for-react in the npm ecosystem, as well as Python packages durabletask 1.4.1, 1.4.2, and 1.4.3. Attackers can steal cloud and local credentials, gain unauthorized access to internal repositories and sensitive cloud infrastructure, move laterally to developer machines and CI/CD pipelines, sell and exploit leaked GitHub tokens, and implement ransom and data leak threats.Slow Fog recommends immediately rotating all exposed credentials, replacing affected packages, isolating potentially infected systems, and implementing strict dependency review policies. Previously, it was reported that the "mini sandworm" worm had recently completed widespread infection in open-source code repositories, and developers should be vigilant in checking for issues.

GitHub updates security incident investigation: An employee's device was compromised, involving a contaminated VS Code extension

GitHub has updated the details of the investigation into the unauthorized access incident of its internal repositories: GitHub detected and contained an incident yesterday involving an employee's device being compromised, which involved a maliciously implanted VS Code extension. GitHub removed the malicious extension, isolated the affected terminals, and immediately initiated an incident response. Current assessments show that only GitHub's internal repositories experienced data exfiltration, and the approximately 3,800 repositories claimed by the attackers are roughly consistent with the investigation results. GitHub has prioritized rotating critical credentials, is analyzing logs, verifying credential rotations, and monitoring subsequent activities, with a complete report to be released after the investigation is concluded.Additionally, Slow Mist's Chief Information Security Officer 23pds commented on this incident, stating: "By analyzing leaks from cybercrime forums, hackers may have used Anthropic's Mythos security AI to precisely breach GitHub's defenses and steal information from about 4,000 core internal repositories: including the source code for Copilot, the algorithms for CodeQL, the Actions runtime, and the entire billing system. Further analysis of this code could lead to subsequent attacks, having a profound security impact on the integration of the open-source community."
app_icon
ChainCatcher Building the Web3 world with innovations.