BTC $83,544.37 -1.02%
ETH $2,689.98 +0.14%
BNB $761.82 -1.99%
XRP $1.50 -1.25%
SOL $118.90 -2.55%
TRX $0.3357 +0.69%
DOGE $0.0937 -2.70%
ADA $0.2471 -2.74%
BCH $310.30 -6.68%
LINK $15.37 +9.89%
HYPE $87.51 -4.56%
AAVE $148.72 -3.89%
SUI $1.15 -7.52%
XLM $0.2284 +6.09%
ZEC $1,487.10 -6.65%
AAPL $338.79 -0.28%
AMZN $246.57 -0.99%
GOOGL $342.65 -0.20%
MSFT $509.74 -1.31%
META $718.87 -4.10%
NVDA $229.64 +2.38%
TSLA $358.54 -3.77%
SNDK $1,716.95 -3.15%
INTC $116.32 -5.58%
SPCX $146.28 -2.13%
MU $1,057.56 -2.97%
AMD $611.78 -2.97%
BTC $83,544.37 -1.02%
ETH $2,689.98 +0.14%
BNB $761.82 -1.99%
XRP $1.50 -1.25%
SOL $118.90 -2.55%
TRX $0.3357 +0.69%
DOGE $0.0937 -2.70%
ADA $0.2471 -2.74%
BCH $310.30 -6.68%
LINK $15.37 +9.89%
HYPE $87.51 -4.56%
AAVE $148.72 -3.89%
SUI $1.15 -7.52%
XLM $0.2284 +6.09%
ZEC $1,487.10 -6.65%
AAPL $338.79 -0.28%
AMZN $246.57 -0.99%
GOOGL $342.65 -0.20%
MSFT $509.74 -1.31%
META $718.87 -4.10%
NVDA $229.64 +2.38%
TSLA $358.54 -3.77%
SNDK $1,716.95 -3.15%
INTC $116.32 -5.58%
SPCX $146.28 -2.13%
MU $1,057.56 -2.97%
AMD $611.78 -2.97%

rev

All
Article
Flash

first_img MEXC user: API not revoked after account was hacked, approximately 340,000 USD was transferred away

A MEXC user posted on X that their account was compromised after someone reset the security items. MEXC has confirmed the account was hacked, frozen the account, and assisted in recovery, but did not revoke the API left by the attacker. From 04:12 to 04:25 on September 27, 2026 (Beijing time), the account transferred out 322,110 USDT and 9,133,999 ONE, totaling approximately $340,000, about 27 minutes after the 24-hour transfer limit was lifted.The user stated that at 03:10 on September 25, they received a reset security item email that was not submitted by them, and about 10 minutes later, the request was approved. Subsequently, the account was logged in from an IP in Jakarta, Indonesia, bound to Google verification, and at 05:05, an API was created, approximately 83 seconds after logging in. At 10:55 that day, MEXC froze the account after a risk review and reverted to the original email. Customer service responded in writing that the review materials met the requirements, so the binding change was approved, and after the risk review, the account was urgently frozen and reverted to the initial email. The user changed their password and Google verification on September 26 but stated that the API was not revoked, and there were no related records in the security operation history.The user also claimed that there were no new login records in the login history when the assets were transferred out. They have submitted a formal claim to MEXC and attempted to report to the police, with the ticket number M2026092712031, requesting the platform to preserve logs, provide a written explanation of the review and API situation, and return the aforementioned assets. MEXC customer service stated that it is currently unable to confirm whether these transfers were initiated via APP, WEB, or API, and the issue has been forwarded to the relevant department.

A French woman has been detained on suspicion of manipulating the price of Verasity tokens and had previously purchased real estate worth over 50 million euros in Dubai

According to the French newspaper Le Monde, a 45-year-old woman born in Russia and naturalized in France in 2017, Svetlana A., has recently been placed under investigation and detained by a Paris investigating judge on charges of organized fraud, serious money laundering, and participation in a criminal gang. The French National Financial Prosecutor's Office stated that she and her British partner Robert H. are suspected of committing organized fraud by manipulating cryptocurrency prices, with the related funds suspected to be used for purchasing properties in Dubai.Reports indicate that Svetlana A. invested over 50 million euros in 2022 alone, acquiring about 100 apartments and 3 luxury villas in Dubai, with total rental income from 2022 to 2025 expected to be at least 4 million euros; she also purchased an entire building containing 73 apartments for 68 million dirhams (approximately 17.4 million euros). The cryptocurrency mentioned in the report is Verasity (VRA), launched by her partner in 2018. The price of VRA surged 65 times over a two-and-a-half-month period in the spring of 2021, followed by a significant decline, currently down approximately 99.98% from its historical peak. The lawyer for the parties involved stated that the sources of the related wealth are documented and legal, and they deny any wrongdoing. The case is still under investigation.

DyorSwap: The previously identified "GIWA Mainnet" is actually a fake chain built by scammers, and compensation for affected users will be provided through treasury funds

DyorSwap officially announced that the so-called "GIWA Mainnet" identified by the team earlier is actually a fake chain set up by scammers. This fake network used the correct GIWA chain ID (9134), making it appear legitimate during the initial verification phase. The team also identified several suspicious messages and individuals within the related community that may be connected to this incident. The announcement stated that significant losses have occurred due to this fraudulent cross-chain bridge.DyorSwap stated that it is taking three immediate actions: first, contacting a professional security team to conduct further on-chain tracking and investigate the involved addresses, transactions, and fund flows; second, preserving all relevant evidence, including chat records, RPC information, cross-chain bridge addresses, and on-chain transactions; third, preparing to use treasury funds to compensate affected users, with eligibility criteria, loss verification processes, compensation scope, and detailed plans to be announced after the investigation and verification processes are completed.DyorSwap emphasized that until further notice, users should not use any unofficial GIWA mainnet RPCs, cross-chain bridges, or contracts, and should not send funds to any related addresses. The official team deeply apologizes to every affected user in this incident and states that subsequent updates will be released as soon as possible.

DyorSwap: The previously identified "GIWA Mainnet" is actually a fake chain built by scammers, and compensation for affected users will be provided through national treasury funds

DyorSwap officially announced that the so-called "GIWA mainnet" previously identified by the team is actually a fake chain set up by scammers. This fake network used the correct GIWA chain ID (9134), making it appear legitimate during the initial verification phase. The team also identified several suspicious messages and individuals within the related community that may be connected to this incident. The announcement stated that significant losses have occurred due to this fraudulent cross-chain bridge.DyorSwap stated that it is taking three immediate actions: first, contacting a professional security team to conduct further on-chain tracking and investigate the involved addresses, transactions, and fund flows; second, preserving all relevant evidence, including chat records, RPC information, cross-chain bridge addresses, and on-chain transactions; third, preparing to use treasury funds to compensate affected users, with eligibility criteria, loss verification processes, compensation scope, and detailed plans to be announced after the investigation and verification processes are completed.DyorSwap emphasized that until further notice, users should not use any unofficial GIWA mainnet RPCs, cross-chain bridges, or contracts, and should not send funds to any related addresses. The official team deeply apologizes to every affected user in this incident and states that subsequent updates will be released as soon as possible.

first_img Bitget updates on the security incident progress: the stolen amount is revised to 387.5 million USD, and the withdrawal recovery time will be announced before 12 PM tomorrow

Bitget TradFi Chief Growth Officer Xie Jiayin issued an update on the platform's security incident, stating that the withdrawal time will be announced before noon tomorrow. The security team has identified the hacker's attack path and methods, and has grasped the details of how the attacker bypassed security measures, coming very close to tracing the source of the attack. The incident investigation by third-party security teams Mandiant and SlowMist is still ongoing, with a detailed report pending from the security team.On-chain tracking confirms that approximately $387.5 million has been transferred to the hacker's address, previously estimated at $351.6 million. This revision includes ZEC and TRX, and no other unauthorized transfers have been found. Xie Jiayin stated that the stolen funds at the platform level will be fully covered by the Bitget User Protection Fund, ensuring that user assets are not subject to any losses.Bitget has officially launched a fund recovery bounty program, offering a 5% bounty for voluntarily freezing the attacker’s funds and a 5% bounty for voluntarily recovering funds. The bounty also applies to assistance already provided. The platform has published the attacker's address, a real-time tracking dashboard, and a submission portal, with relevant information also available for submission through Bybit's Lazarus bounty platform.

Magic Eden: Current open orders are not affected by this vulnerability; users in the EVM market from February to October 2024 need to revoke related contract authorizations

Magic Eden announced that the vulnerability occurred in the NFT trading protocol Payment Processor V2 maintained by Limit Break. Magic Eden adopted this protocol for EVM network transaction settlements in 2024 but stopped using V2 in October 2024 and will completely shut down the EVM market in the first quarter of 2026. Therefore, NFTs currently listed on Magic Eden are not affected by this vulnerability.NFTs listed through its EVM market between February and October 2024 may be affected, while listings after October 2024 are generally not impacted. The platform is contacting the protocol owner and maintainer Limit Break to explore other risk mitigation measures, including pausing protocol transfers, and will continue to investigate the actual scope of the impact.Magic Eden reminds users who have listed or traded NFTs on its EVM market to revoke relevant contract authorizations on the Ethereum, Polygon, and Base networks. Users can filter the address through revoke.cash and revoke all authorizations marked as "approved for all" for NFTs. Magic Eden emphasizes that revoking authorization cannot recover assets that have already been transferred.Yuga Labs' Vice President of Blockchain Quit stated today that at 9 AM Eastern Time, attackers exploited the Payment Processor V2 vulnerability to steal a large number of NFTs. After contacting the LimitBreak team, the latter quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain is also temporarily unable to be paused. Therefore, the team implemented a white-hat operation, successfully transferring and protecting 23,155 NFTs valued at over 5.7 million dollars.

Robinhood Chain Research Report: In August, on-chain Gas revenue reached 6.6 million USD, and DEX trading volume rose to 1.5 billion USD

According to a report released by Spartan Capital, Robinhood Chain will launch its mainnet on July 1, 2026. By the end of August, the on-chain DEX trading volume had risen to $1.5 billion, with a TVL increasing to $711 million, and on-chain gas revenue in August reached $6.6 million.The report shows that most of the trading volume in August came from Uniswap, with a single-day on-chain fee reaching $2.1 million on August 31. Robinhood is responsible for running the sequencer and receives about 90% of the on-chain fees. After deducting Ethereum settlement costs and the 10% licensing fee paid to Arbitrum DAO, the net income for August was approximately $6 million. Regarding Robinhood Earn, users deposit USDG and borrow through Morpho, with the deposit scale increasing from $9.5 million on July 1 to $456 million on August 31, accounting for 68% of Robinhood Chain's TVL at the end of the month. Users can earn an estimated annualized yield of about 7%, while the yield on the loan side was approximately 3.7% at the end of August, with the difference subsidized by reward funds provided by Morpho and its lending partners.Meanwhile, the Meme ecosystem of Robinhood Chain is growing rapidly. By the end of August, over 340,000 tokens had been issued on-chain, with application layer transaction fees reaching $114 million in August. The report states that the trading volume of Meme and tokenized stock trading pairs is also growing rapidly, with the trading volume of Meme tokens paired with Robinhood Stock Tokens reaching $518 million in August. The report points out that the current trading activity on Robinhood Chain is still mainly driven by crypto-native users, and Robinhood's own 27 million funded accounts have not yet been migrated to the chain on a large scale. The gas subsidies in the Robinhood wallet will continue until September 29, and the Earn yield is also planned to be gradually reduced.
app_icon
ChainCatcher Building the Web3 world with innovations.