BTC $84,297.72 +1.07%
ETH $2,736.93 +2.01%
BNB $765.76 -0.30%
XRP $1.55 +2.47%
SOL $120.68 +0.79%
TRX $0.3353 +0.20%
DOGE $0.0960 +1.93%
ADA $0.2526 +0.26%
BCH $312.63 -0.36%
LINK $15.30 +4.77%
HYPE $88.38 -1.94%
AAVE $172.96 +15.37%
SUI $1.17 -1.23%
XLM $0.2327 +1.79%
ZEC $1,443.97 -8.99%
AAPL $337.17 -0.87%
AMZN $246.92 -0.32%
GOOGL $342.73 +0.43%
MSFT $508.71 -0.47%
META $724.08 -2.99%
NVDA $230.46 +0.59%
TSLA $359.18 -3.19%
SNDK $1,724.73 -0.68%
INTC $116.72 -3.32%
SPCX $146.93 -1.76%
MU $1,067.81 -0.36%
AMD $614.29 -1.77%
BTC $84,297.72 +1.07%
ETH $2,736.93 +2.01%
BNB $765.76 -0.30%
XRP $1.55 +2.47%
SOL $120.68 +0.79%
TRX $0.3353 +0.20%
DOGE $0.0960 +1.93%
ADA $0.2526 +0.26%
BCH $312.63 -0.36%
LINK $15.30 +4.77%
HYPE $88.38 -1.94%
AAVE $172.96 +15.37%
SUI $1.17 -1.23%
XLM $0.2327 +1.79%
ZEC $1,443.97 -8.99%
AAPL $337.17 -0.87%
AMZN $246.92 -0.32%
GOOGL $342.73 +0.43%
MSFT $508.71 -0.47%
META $724.08 -2.99%
NVDA $230.46 +0.59%
TSLA $359.18 -3.19%
SNDK $1,724.73 -0.68%
INTC $116.72 -3.32%
SPCX $146.93 -1.76%
MU $1,067.81 -0.36%
AMD $614.29 -1.77%

dent

All
Article
Flash

Bitget CEO live-streamed a response to the platform's first security incident in eight years: the attack originated from a vulnerability in a third-party security product, and the losses will be covered by the user protection fund

In today's community live broadcast, Bitget CEO Gracy responded to recent security incidents and the platform's financial status. She candidly stated that this is the first security incident encountered since Bitget was established 8 years ago. After a complete trace, it was found that hackers exploited vulnerabilities in third-party security products to steal internal network access credentials, forged withdrawal commands to the wallet system, and deceived the wallet into executing abnormal transfers that bypassed risk checks. Gracy emphasized that no private keys were leaked, and cold wallets were unaffected; specific technical details will be disclosed in the formally released security report.Gracy pointed out that the verified losses from this incident are within the coverage of the protection fund, and user funds are not affected. The platform's own funds exceed $1.4 billion, which includes approximately $464 million in the user protection fund. The platform will continue to uphold the security commitments made when the protection fund was established in 2022, planning to replenish the fund to the baseline of $300 million within a week."The protection fund is not just a slogan, but an important mechanism that provides tangible security for users in the event of extreme security incidents," Gracy stated. In the face of sudden security challenges, the platform's comprehensive strength and its ability to take responsibility are important criteria for measuring its risk response capability and long-term credibility. Bitget will continue to uphold its long-term commitment to prioritize user interests.

DyorSwap: The previously identified "GIWA Mainnet" is actually a fake chain built by scammers, and compensation for affected users will be provided through treasury funds

DyorSwap officially announced that the so-called "GIWA Mainnet" identified by the team earlier is actually a fake chain set up by scammers. This fake network used the correct GIWA chain ID (9134), making it appear legitimate during the initial verification phase. The team also identified several suspicious messages and individuals within the related community that may be connected to this incident. The announcement stated that significant losses have occurred due to this fraudulent cross-chain bridge.DyorSwap stated that it is taking three immediate actions: first, contacting a professional security team to conduct further on-chain tracking and investigate the involved addresses, transactions, and fund flows; second, preserving all relevant evidence, including chat records, RPC information, cross-chain bridge addresses, and on-chain transactions; third, preparing to use treasury funds to compensate affected users, with eligibility criteria, loss verification processes, compensation scope, and detailed plans to be announced after the investigation and verification processes are completed.DyorSwap emphasized that until further notice, users should not use any unofficial GIWA mainnet RPCs, cross-chain bridges, or contracts, and should not send funds to any related addresses. The official team deeply apologizes to every affected user in this incident and states that subsequent updates will be released as soon as possible.

DyorSwap: The previously identified "GIWA Mainnet" is actually a fake chain built by scammers, and compensation for affected users will be provided through national treasury funds

DyorSwap officially announced that the so-called "GIWA mainnet" previously identified by the team is actually a fake chain set up by scammers. This fake network used the correct GIWA chain ID (9134), making it appear legitimate during the initial verification phase. The team also identified several suspicious messages and individuals within the related community that may be connected to this incident. The announcement stated that significant losses have occurred due to this fraudulent cross-chain bridge.DyorSwap stated that it is taking three immediate actions: first, contacting a professional security team to conduct further on-chain tracking and investigate the involved addresses, transactions, and fund flows; second, preserving all relevant evidence, including chat records, RPC information, cross-chain bridge addresses, and on-chain transactions; third, preparing to use treasury funds to compensate affected users, with eligibility criteria, loss verification processes, compensation scope, and detailed plans to be announced after the investigation and verification processes are completed.DyorSwap emphasized that until further notice, users should not use any unofficial GIWA mainnet RPCs, cross-chain bridges, or contracts, and should not send funds to any related addresses. The official team deeply apologizes to every affected user in this incident and states that subsequent updates will be released as soon as possible.

Zhao Changpeng: There is no ability to influence the price of the cryptocurrency market; posting and the timing of positive news are purely coincidental

Binance founder Zhao Changpeng stated during the podcast "When Shift Happens" that he remains bullish on Bitcoin but denies having the ability to influence the price of the entire crypto market. Previously, on August 19, when Bitcoin was around the $60,000 range, Zhao Changpeng posted that if one wants their future self to thank today's decisions in two years, immediate action is needed. This post was interpreted by the market as a hint to buy Bitcoin, and in the following days, the crypto market rose by about 20%.Zhao Changpeng responded that he does not have the ability to drive the entire market price. He stated that he has always been bullish on the crypto industry, and almost all of his posts have a bullish tendency, posting 5 to 10 times a day, so it is not surprising that one of his posts coincidentally appeared before positive news.Zhao Changpeng mentioned that about 5 hours after the post was published, Trump gave a relatively positive speech about the crypto industry, mentioning the push for Hyperliquid to enter the U.S. market, but he did not know the content of the speech in advance. He emphasized that if he had any information that could affect the market, he would not post about it. Therefore, the post and the subsequent market rise were merely a coincidence in timing.Regarding the Bitcoin cycle, Zhao Changpeng stated that the crypto market has roughly followed a four-year cycle to date. At that time, some speculated that Bitcoin might bottom out in October, but he believes there is no need to wait until October to express a bullish view.

first_img Google disclosed the AI security agent PageBreak, which has identified over 500 vulnerabilities

The Google Product Security Team has disclosed an internal AI agent called PageBreak, used to test the security of its first-party web applications. This agent is built on Google's Gemini model and began a pilot program in November 2025, transitioning to a formal project in January 2026, with the goal of autonomously scaling vulnerability discovery and reducing manual input.Unlike common AI scanning tools, PageBreak hands over hypotheses to specialized validators after discovering suspicious defects, attempting actual exploitation in a real-time running copy of the application, and only reports once confirmed exploitable, with a false positive rate close to zero. Google claims that PageBreak has identified over 500 XSS vulnerabilities in its first-party web applications, which can be used to hijack login sessions, steal data, or impersonate users.Google stated that the security team has been overwhelmed in recent years by a large number of AI-generated vulnerability reports that appear reasonable but are not valid, making it a major challenge to distinguish real defects from hallucinations. When testing applications built using the next-generation high-assurance framework, PageBreak found only two vulnerabilities. The next step for Google is to integrate PageBreak with the automated remediation agent CodeMender, providing confirmed vulnerabilities with accompanying fixes.

first_img Bitget updates on the security incident progress: the stolen amount is revised to 387.5 million USD, and the withdrawal recovery time will be announced before 12 PM tomorrow

Bitget TradFi Chief Growth Officer Xie Jiayin issued an update on the platform's security incident, stating that the withdrawal time will be announced before noon tomorrow. The security team has identified the hacker's attack path and methods, and has grasped the details of how the attacker bypassed security measures, coming very close to tracing the source of the attack. The incident investigation by third-party security teams Mandiant and SlowMist is still ongoing, with a detailed report pending from the security team.On-chain tracking confirms that approximately $387.5 million has been transferred to the hacker's address, previously estimated at $351.6 million. This revision includes ZEC and TRX, and no other unauthorized transfers have been found. Xie Jiayin stated that the stolen funds at the platform level will be fully covered by the Bitget User Protection Fund, ensuring that user assets are not subject to any losses.Bitget has officially launched a fund recovery bounty program, offering a 5% bounty for voluntarily freezing the attacker’s funds and a 5% bounty for voluntarily recovering funds. The bounty also applies to assistance already provided. The platform has published the attacker's address, a real-time tracking dashboard, and a submission portal, with relevant information also available for submission through Bybit's Lazarus bounty platform.
app_icon
ChainCatcher Building the Web3 world with innovations.