BTC $79,198.69 -0.47%
ETH $2,490.19 +0.39%
BNB $743.83 +0.15%
XRP $1.40 -0.86%
SOL $104.69 -1.12%
TRX $0.3348 -0.04%
DOGE $0.0905 +2.13%
ADA $0.2218 +2.01%
BCH $262.23 +2.57%
LINK $13.06 +7.16%
HYPE $86.82 -2.58%
AAVE $133.16 -0.69%
SUI $0.8270 +4.31%
XLM $0.1922 +4.47%
ZEC $1,175.26 +0.81%
BTC $79,198.69 -0.47%
ETH $2,490.19 +0.39%
BNB $743.83 +0.15%
XRP $1.40 -0.86%
SOL $104.69 -1.12%
TRX $0.3348 -0.04%
DOGE $0.0905 +2.13%
ADA $0.2218 +2.01%
BCH $262.23 +2.57%
LINK $13.06 +7.16%
HYPE $86.82 -2.58%
AAVE $133.16 -0.69%
SUI $0.8270 +4.31%
XLM $0.1922 +4.47%
ZEC $1,175.26 +0.81%

slowmist

Tất cả
Bài viết
Tin nhanh

OKX hợp tác với Elliptic, SlowMist, OttoSec phát hành báo cáo an ninh và quản lý rủi ro Web3 nửa đầu năm 2026

Theo thông tin từ ChainCatcher, theo thông báo chính thức, OKX đã hợp tác với Elliptic, SlowMist, OttoSec để phát hành "Báo cáo An ninh và Quản lý rủi ro Web3 nửa đầu năm 2026". Báo cáo chỉ ra rằng, trọng tâm tấn công Web3 đang dần chuyển từ mã hợp đồng thông minh sang các quy trình ký, thiết bị người dùng, cơ sở hạ tầng vận hành và các tình huống phức tạp hơn như AI Agent.Dữ liệu cho thấy, trong nửa đầu năm 2026, hệ thống quản lý rủi ro của OKX đã chặn tổng cộng hơn 5,7 triệu giao dịch có rủi ro cao, trong đó có khoảng 2,41 triệu giao dịch liên quan đến hacker và trộm cắp, khoảng 1,48 triệu giao dịch liên quan đến lừa đảo, và khoảng 990.000 giao dịch liên quan đến lừa đảo. Thư viện nhãn thông tin trên chuỗi Web3 của OKX hiện đã sở hữu hơn 1 tỷ nhãn, bao phủ hơn 420 chuỗi, và đã tích hợp khả năng kiểm tra địa chỉ, giám sát giao dịch và kiểm soát địa chỉ bị trừng phạt vào các cơ sở hạ tầng như DEX, Exchange OS.Ngoài ra, trong lĩnh vực bảo vệ người dùng, OKX đã chặn hơn 7 triệu lượt truy cập vào các trang web có rủi ro, hoàn thành hơn 200.000 lượt kiểm tra rủi ro thiết bị, nhận diện hơn 60.000 ứng dụng có rủi ro cao, và đã chặn hoặc cảnh báo hơn 4 triệu thao tác ký có rủi ro cao. Báo cáo cũng giới thiệu thiết kế "quản lý rủi ro trước" trong các tình huống như Exchange OS, Outcomes, RWA và Agentic Wallet.

Cảnh báo an toàn: 30 gói npm độc hại giả mạo kho giao dịch robot, nhắm mục tiêu đánh cắp khóa và cụm từ ghi nhớ của nhà phát triển

Tin tức từ ChainCatcher, SlowMist đã phát hành cảnh báo an ninh, phát hiện một cuộc tấn công chuỗi cung ứng npm độc hại phối hợp, kẻ tấn công đã lợi dụng kho lưu trữ bot giao dịch giả mạo và các gói npm chủ đề DeFi để phát tán trình thu thập thông tin JavaScript, mục tiêu nhắm vào người dùng npm, nhà phát triển DeFi và người dùng bot giao dịch.Cuộc tấn công này liên quan đến 30 gói npm độc hại, trong đó stake-math@3.5.4 xuất hiện như một phụ thuộc khóa trong kho lưu trữ donoaccestag/forex-mt5-trading-bot, kho này trình bày khoảng 2300 nhánh được tạo ra hàng loạt có độ đồng nhất cao, phần lớn tập trung dưới tài khoản poly-stocks, tín hiệu rất rõ ràng. Phạm vi dữ liệu nhạy cảm mà kẻ tấn công có thể đánh cắp rất rộng, bao gồm thư viện ví tiền điện tử, Cookie trình duyệt và mật khẩu đã lưu, lịch sử duyệt web, thông tin xác thực của nhà phát triển, lịch sử Shell, thư viện trình quản lý mật khẩu, khóa riêng, cụm từ ghi nhớ và mã thông báo API được lộ trong mã nguồn.SlowMist khuyến nghị các nhà phát triển ngay lập tức gỡ bỏ các gói npm bị ảnh hưởng, kiểm tra package.json và package-lock.json cũng như nhật ký CI xem có chứa bất kỳ gói độc hại nào trong số 30 gói đó hay không; coi các hệ thống đã thực hiện npm install là có thể đã bị xâm nhập, thay đổi tất cả ví, khóa riêng, mã thông báo npm, thông tin xác thực đám mây, khóa SSH và mã thông báo API đã lộ, và xây dựng lại môi trường bị ảnh hưởng từ hình ảnh sạch.

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

Nano Labs, SlowMist, and Aquarius announced the establishment of the Fortress Foundation and launched its first initiative, the Fortress Initiative

ChainCatcher news, Nano Labs, SlowMist, and Aquarius announced the establishment of the Fortress Foundation and launched its first initiative—the Fortress Initiative. This is a framework for liquidity management security design and process audit standards, aimed at setting a new benchmark for security and transparency in the cryptocurrency liquidity management field. The initiative provides detailed security guidelines for liquidity management protocols and establishes practices for auditing liquidity management processes, supplemented by practical case studies to ensure operability.The core vision of the Fortress Initiative is to establish global standards for liquidity management security and process auditing, thereby building trust across the entire cryptocurrency ecosystem. Its mission is to provide cutting-edge security frameworks and rigorous audit standards, enabling organizations to effectively protect digital assets while optimizing liquidity management operations.The initiative follows a comprehensive one-year roadmap aimed at achieving a seamless transition from concept to full industry integration. The initial phase focuses on foundational development work, including defining concepts, establishing brand identity, assembling core contributors and partner organizations, and drafting frameworks through collaboration with key stakeholders. During this phase, the team developed risk assessment protocols, audit methodologies, and penetration testing plans, which were validated through pilot case studies. Subsequently, the launch phase will collect feedback and drive participation through formal releases, interactive panel discussions, live demonstrations, and community workshops at major industry events. The final phase will optimize and expand the framework based on early audit results, incorporate regulatory compliance measures, establish a trained network of auditors, and culminate in a security summit to showcase progress and plan future strategies.The Fortress team stated that in the early stages of the project, they will focus on inviting asset management protocols and ecosystem partners with BTC staking needs to participate in the construction.The initiative has received strong support from industry-leading organizations. Nano Labs (Nasdaq: NA) is a publicly listed company on Nasdaq and a leading chip design company in Asia, at the forefront of technological innovation and recognized as a major and steadfast holder of Bitcoin. SlowMist is a globally renowned blockchain security company with over a decade of professional experience, bringing unparalleled expertise to the field of cybersecurity. Aquarius is a research-driven asset management company managing over $600 million in assets, providing rich expertise in liquidity management and liquidity management strategies. Additionally, the Sei native lending protocol Takara Lend, supported by Sei Blockchain, joined as one of the first donating members, highlighting their commitment to collaboratively establish standards and processes that will shape the future of liquidity management security.The technical framework of the Fortress Initiative is equally robust, with security standards covering the entire liquidity management lifecycle—from pre-liquidity management assessments, continuous monitoring, to post-management issue response systems—integrating comprehensive testing, monitoring, coordination, and tracking systems comparable to ISO 9001 standards. This framework includes detailed smart contract code audits, comprehensively checking for issues such as permission vulnerabilities, security design, design logic, variable coverage, variable declarations and scopes, arithmetic accuracy, uninitialized storage pointers, and denial-of-service attacks. Additionally, the framework encompasses rigorous security awareness testing conducted through red team testing and phishing simulations, comprehensive multi-chain asset security monitoring, and thorough assessments of internal management processes, including recruitment, code deployment, incident response, and multi-signature wallet management.The Fortress Foundation is a non-profit organization dedicated to promoting blockchain security, with the goal of establishing standards for security and transparency in the liquidity management ecosystem.
Nano Labs, SlowMist, and Aquarius announced the establishment of the Fortress Foundation and launched its first initiative, the Fortress Initiative
app_icon
ChainCatcher Building the Web3 world with innovations.