Scan to download
BTC $59,533.42 -0.77%
ETH $1,590.66 +0.77%
BNB $552.48 -0.11%
XRP $1.04 -0.13%
SOL $74.01 +2.29%
TRX $0.3192 -1.14%
DOGE $0.0723 -1.23%
ADA $0.1452 +0.16%
BCH $199.18 +1.53%
LINK $7.30 -0.23%
HYPE $65.54 +4.39%
AAVE $91.26 -1.22%
SUI $0.6959 +0.61%
XLM $0.1855 +6.50%
ZEC $399.40 +3.93%
BTC $59,533.42 -0.77%
ETH $1,590.66 +0.77%
BNB $552.48 -0.11%
XRP $1.04 -0.13%
SOL $74.01 +2.29%
TRX $0.3192 -1.14%
DOGE $0.0723 -1.23%
ADA $0.1452 +0.16%
BCH $199.18 +1.53%
LINK $7.30 -0.23%
HYPE $65.54 +4.39%
AAVE $91.26 -1.22%
SUI $0.6959 +0.61%
XLM $0.1855 +6.50%
ZEC $399.40 +3.93%

stolen

All
Article
Flash

Axelar Network was hacked, and approximately 4.67 million dollars worth of tokens were stolen

Axelar Network stated on platform X that an event affecting assets bridged from the Axelar chain to the Secret Network via IBC has been discovered, with approximately $4.67 million worth of tokens stolen.According to the information currently available, the issue is limited to the ICS-20 smart contract on the Secret side, which is part of the Cosmos IBC connection between Secret and Axelar, used to bridge assets from Axelar to Secret. The Axelar Emergency Committee immediately disabled the Secret and Secret-SNIP connections upon discovering the incident. The team is contacting relevant exchanges and law enforcement agencies. The incident is limited to assets bridged from Axelar to Secret via IBC. Other IBC connections or Secret tokens do not appear to be affected. Other Axelar integrations are unaffected. The core protocol of Axelar is not impacted.Additionally, according to Common Prefix's analysis of the Secret Network incident, an attacker exploited an infinite minting vulnerability in a modified CW20-ICS20 token contract on Secret, stealing approximately $4.67 million. The attacker minted arbitrary Secret-wrapped Axelar assets on Secret by launching a new Cosmos chain (with only one validator) and self-relaying IBC packets to it. The contract did not verify which IBC channel the inbound tokens came from. The attacker exited through the Axelar bridge. The Axelar protocol was not compromised and prevented the spread of contagion to other chains.

Raydium core contributors: will fully compensate for stolen assets, the current mainnet program has not been affected

Raydium core contributor InfraRAY posted on platform X, stating that the team has confirmed that the old version of the AMM V3 program, which was previously discontinued in 2021, has been attacked. The attacker unauthorizedly removed part of the liquidity, but this incident does not affect current Raydium users, and the related liquidity pools have been unable to interact through the official Raydium UI since being disabled. The Raydium SDK and DApp also do not support operations on the mainnet old version AMM V3 liquidity pools.The five affected liquidity pools include: Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, and RAY-SOL. Preliminary statistics show that the stolen assets include approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC, with a total value of about $1.34 million. The related losses will be fully compensated by the treasury.Investigations reveal that the vulnerability originated from insufficient verification of the LP token minting address. The attacker created new LP tokens and impersonated legitimate LP tokens, bypassing the protocol's ratio verification mechanism to extract funds. However, this incident is classified as an independent logical vulnerability and is not due to private key leakage or permission intrusion, and there is no risk of spread. Currently, all existing Raydium mainnet programs have not been affected.

Humility: The stolen funds amount to 36 million dollars, and we will cooperate with the police to investigate and recover the funds

Humility Protocol released a security incident update on the X platform, indicating that yesterday the H token suffered a coordinated attack on the Ethereum and BSC chains, with over $36 million in assets confirmed to have been stolen and sold off.Preliminary investigations show that the incident originated from an employee's computer being compromised, leading to the leakage of the multi-signature wallet keys controlling the Hyperlane Bridge ProxyAdmin. Among them, the attacker obtained 3 out of 6 private keys from Gnosis Safe holders on the Ethereum chain, transferred ownership of ProxyAdmin to their controlled wallet, and upgraded the bridging contract to a malicious implementation, subsequently transferring approximately 141.2 million H tokens in a single transaction.Meanwhile, the attacker also controlled 3 out of 5 private keys from Safe wallet holders on the BSC chain, taking over ProxyAdmin in the same manner and deploying a malicious contract with unlimited minting capabilities, minting 200 million H tokens to their wallet in two transactions.Humility stated that it has suspended all deposit and withdrawal operations for the affected bridging services and is collaborating with exchanges and other relevant partners to mitigate losses, while also cooperating with law enforcement to investigate and attempt to recover some of the stolen funds.

The second trial of the 660,000 yuan virtual currency theft case in Wuhan, China, has been revised: the main culprit was sentenced to ten years and six months in prison, and the amount stolen was determined based on the actual payment cost incurred by the victim

According to the "Procuratorial Daily," Lin, Zeng, and Dai conspired to use virtual currency trading as a pretext. During the trading process, they secretly filmed the victim's digital wallet private key and, after the virtual currency was credited, secretly logged into the victim's wallet to reverse the transaction, transferring the related virtual currency back to their controlled accounts. The three committed the crime three times, causing the victim a total economic loss of 660,000 yuan.The first-instance court held that in the absence of a clear judicial interpretation regarding the valuation method of virtual currency and sentencing standards, it was inappropriate to directly determine the amount involved as particularly huge based on the victim's purchase amount of 660,000 yuan. Therefore, they sentenced the three based on "other serious circumstances," imposing prison terms ranging from eight years to five years and six months, along with fines. The Hanyang District Procuratorate of Wuhan City in Hubei Province subsequently filed an appeal, which was supported by the Wuhan City Procuratorate.The prosecution argued that the first-instance court applied the law incorrectly and imposed an excessively light sentence. Prosecutor Dai Wentao of the Wuhan City Procuratorate stated that in the case where the victim had a clear loss amount to refer to, it was contradictory and legally erroneous to claim that the value of virtual currency could not be determined. In judicial practice, using the resale price and transaction price as the basis for determining the amount of theft has become mainstream, and determining the value of virtual currency based on the actual cost paid by the victim has factual, legal, and practical basis.The Intermediate Court of Wuhan accepted the prosecution's opinion in the second instance, revoked the corresponding content of the original judgment, and changed the determination of the theft amount to particularly huge. It sentenced the principal offender Lin to ten years and six months in prison for theft, and sentenced the accomplices Zeng and Dai to eight years in prison each, along with fines.

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.
app_icon
ChainCatcher Building the Web3 world with innovations.