BTC $83,293.91 -1.63%
ETH $2,677.15 -0.28%
BNB $761.64 -2.11%
XRP $1.48 -2.48%
SOL $117.72 -4.17%
TRX $0.3355 +0.61%
DOGE $0.0931 -4.26%
ADA $0.2439 -4.69%
BCH $306.77 -7.85%
LINK $15.14 +7.94%
HYPE $86.85 -5.04%
AAVE $146.08 -5.51%
SUI $1.13 -10.12%
XLM $0.2248 +3.75%
ZEC $1,464.20 -8.51%
AAPL $338.59 -0.47%
AMZN $246.40 -1.52%
GOOGL $342.63 -0.39%
MSFT $509.78 -1.52%
META $717.46 -4.30%
NVDA $229.21 +1.82%
TSLA $357.98 -4.14%
SNDK $1,712.63 -3.96%
INTC $115.93 -7.28%
SPCX $145.94 -2.27%
MU $1,053.88 -3.75%
AMD $609.57 -4.12%
BTC $83,293.91 -1.63%
ETH $2,677.15 -0.28%
BNB $761.64 -2.11%
XRP $1.48 -2.48%
SOL $117.72 -4.17%
TRX $0.3355 +0.61%
DOGE $0.0931 -4.26%
ADA $0.2439 -4.69%
BCH $306.77 -7.85%
LINK $15.14 +7.94%
HYPE $86.85 -5.04%
AAVE $146.08 -5.51%
SUI $1.13 -10.12%
XLM $0.2248 +3.75%
ZEC $1,464.20 -8.51%
AAPL $338.59 -0.47%
AMZN $246.40 -1.52%
GOOGL $342.63 -0.39%
MSFT $509.78 -1.52%
META $717.46 -4.30%
NVDA $229.21 +1.82%
TSLA $357.98 -4.14%
SNDK $1,712.63 -3.96%
INTC $115.93 -7.28%
SPCX $145.94 -2.27%
MU $1,053.88 -3.75%
AMD $609.57 -4.12%

security

All
Article
Flash

first_img Chainlink released CCIP 2, allowing enterprises to customize cross-chain security verification

On Monday, the oracle network Chainlink released the cross-chain interoperability protocol CCIP 2, making significant upgrades to its communication and cross-chain bridge infrastructure. The new version allows enterprises to add their own security verification checks on top of Chainlink's default network of 16 independent node operators. Enterprises can run their own validators or hire external service providers such as Infosys and Nethermind. Chainlink stated that users should not be forced to become "cross-chain security infrastructure experts."This upgrade comes about five months after the Kelp DAO was hacked in April of this year. The attackers are reportedly linked to the North Korean Lazarus group, stealing approximately $292 million in rsETH by deceiving the single validator relied upon by the Kelp cross-chain bridge, which operates on LayerZero. LayerZero blamed Kelp for using only a single validator, while Kelp stated that LayerZero employees had reviewed its setup and raised no objections. Kelp subsequently announced that it would migrate rsETH to Chainlink.The upgrade also adjusts the security mechanism that Chainlink had previously heavily promoted; its risk management network will no longer operate as an independent review node, with such independent checks now provided by optional validators. This means that users who have not added any validators currently rely on a single validation network, whereas previously they relied on two. Existing Chainlink users have been automatically migrated to the new version, but the company has not disclosed which institutions are using the new validators, only stating that Aave and Maple have begun adopting other features of the upgrade.

Bitget CEO live-streamed a response to the platform's first security incident in eight years: the attack originated from a vulnerability in a third-party security product, and the losses will be covered by the user protection fund

In today's community live broadcast, Bitget CEO Gracy responded to recent security incidents and the platform's financial status. She candidly stated that this is the first security incident encountered since Bitget was established 8 years ago. After a complete trace, it was found that hackers exploited vulnerabilities in third-party security products to steal internal network access credentials, forged withdrawal commands to the wallet system, and deceived the wallet into executing abnormal transfers that bypassed risk checks. Gracy emphasized that no private keys were leaked, and cold wallets were unaffected; specific technical details will be disclosed in the formally released security report.Gracy pointed out that the verified losses from this incident are within the coverage of the protection fund, and user funds are not affected. The platform's own funds exceed $1.4 billion, which includes approximately $464 million in the user protection fund. The platform will continue to uphold the security commitments made when the protection fund was established in 2022, planning to replenish the fund to the baseline of $300 million within a week."The protection fund is not just a slogan, but an important mechanism that provides tangible security for users in the event of extreme security incidents," Gracy stated. In the face of sudden security challenges, the platform's comprehensive strength and its ability to take responsibility are important criteria for measuring its risk response capability and long-term credibility. Bitget will continue to uphold its long-term commitment to prioritize user interests.

Ministry of State Security: The so-called anonymity of virtual currency is a false proposition

The Ministry of State Security's WeChat public account published an article titled "Is Virtual Currency Crime Untraceable? Think Again!" stating that virtual currency has become an important tool for criminals engaging in illegal activities. The associated risks include being a "hotbed" for money laundering crimes, a "shelter" for cyber attacks, and an "accomplice" for espionage and theft. The article argues that the so-called "anonymity" of virtual currency is fundamentally a false proposition.The article states that blockchain is open and transparent, on-chain data is immutable, and complete transaction records are preserved, which can provide a basis for full-chain traceability. Address anonymity is merely a temporary separation of wallet addresses from real identities, and fiat currency exchanges leave traces such as device codes and network IPs. The article summarizes this as examining the ledger, checking the chain, and discussing the private key: the entire transaction leaves traces, making it difficult to hide real identities; if the private key is kept by the individual, it cannot be recovered if lost, while if it is entrusted to a platform, there is a risk of platform bankruptcy or disappearance.The article also mentions that in February 2026, the People's Bank of China and several departments reiterated that Bitcoin, Ethereum, Tether, and others should not and cannot be used as circulating currency, and related activities are classified as illegal financial activities, which are strictly prohibited. The article warns to be cautious of high-paying part-time jobs that settle in virtual currency and states that reports can be made through 12339, www.12339.gov.cn, the Ministry of State Security's WeChat public account, or local national security agencies.

first_img Google disclosed the AI security agent PageBreak, which has identified over 500 vulnerabilities

The Google Product Security Team has disclosed an internal AI agent called PageBreak, used to test the security of its first-party web applications. This agent is built on Google's Gemini model and began a pilot program in November 2025, transitioning to a formal project in January 2026, with the goal of autonomously scaling vulnerability discovery and reducing manual input.Unlike common AI scanning tools, PageBreak hands over hypotheses to specialized validators after discovering suspicious defects, attempting actual exploitation in a real-time running copy of the application, and only reports once confirmed exploitable, with a false positive rate close to zero. Google claims that PageBreak has identified over 500 XSS vulnerabilities in its first-party web applications, which can be used to hijack login sessions, steal data, or impersonate users.Google stated that the security team has been overwhelmed in recent years by a large number of AI-generated vulnerability reports that appear reasonable but are not valid, making it a major challenge to distinguish real defects from hallucinations. When testing applications built using the next-generation high-assurance framework, PageBreak found only two vulnerabilities. The next step for Google is to integrate PageBreak with the automated remediation agent CodeMender, providing confirmed vulnerabilities with accompanying fixes.

first_img Bitget updates on the security incident progress: the stolen amount is revised to 387.5 million USD, and the withdrawal recovery time will be announced before 12 PM tomorrow

Bitget TradFi Chief Growth Officer Xie Jiayin issued an update on the platform's security incident, stating that the withdrawal time will be announced before noon tomorrow. The security team has identified the hacker's attack path and methods, and has grasped the details of how the attacker bypassed security measures, coming very close to tracing the source of the attack. The incident investigation by third-party security teams Mandiant and SlowMist is still ongoing, with a detailed report pending from the security team.On-chain tracking confirms that approximately $387.5 million has been transferred to the hacker's address, previously estimated at $351.6 million. This revision includes ZEC and TRX, and no other unauthorized transfers have been found. Xie Jiayin stated that the stolen funds at the platform level will be fully covered by the Bitget User Protection Fund, ensuring that user assets are not subject to any losses.Bitget has officially launched a fund recovery bounty program, offering a 5% bounty for voluntarily freezing the attacker’s funds and a 5% bounty for voluntarily recovering funds. The bounty also applies to assistance already provided. The platform has published the attacker's address, a real-time tracking dashboard, and a submission portal, with relevant information also available for submission through Bybit's Lazarus bounty platform.
app_icon
ChainCatcher Building the Web3 world with innovations.