BTC $83,494.50 -1.31%
ETH $2,679.57 -0.32%
BNB $764.61 -1.64%
XRP $1.49 -2.45%
SOL $118.78 -3.32%
TRX $0.3358 +0.63%
DOGE $0.0940 -2.91%
ADA $0.2457 -3.50%
BCH $308.43 -7.65%
LINK $15.31 +8.92%
HYPE $88.06 -3.97%
AAVE $148.12 -4.27%
SUI $1.14 -9.02%
XLM $0.2289 +5.94%
ZEC $1,471.70 -8.38%
AAPL $338.46 -0.55%
AMZN $246.58 -1.44%
GOOGL $342.77 -0.39%
MSFT $509.94 -1.44%
META $715.18 -4.72%
NVDA $228.70 +1.47%
TSLA $357.44 -4.30%
SNDK $1,710.69 -4.11%
INTC $115.99 -7.79%
SPCX $145.66 -2.13%
MU $1,053.43 -3.79%
AMD $608.39 -4.12%
BTC $83,494.50 -1.31%
ETH $2,679.57 -0.32%
BNB $764.61 -1.64%
XRP $1.49 -2.45%
SOL $118.78 -3.32%
TRX $0.3358 +0.63%
DOGE $0.0940 -2.91%
ADA $0.2457 -3.50%
BCH $308.43 -7.65%
LINK $15.31 +8.92%
HYPE $88.06 -3.97%
AAVE $148.12 -4.27%
SUI $1.14 -9.02%
XLM $0.2289 +5.94%
ZEC $1,471.70 -8.38%
AAPL $338.46 -0.55%
AMZN $246.58 -1.44%
GOOGL $342.77 -0.39%
MSFT $509.94 -1.44%
META $715.18 -4.72%
NVDA $228.70 +1.47%
TSLA $357.44 -4.30%
SNDK $1,710.69 -4.11%
INTC $115.99 -7.79%
SPCX $145.66 -2.13%
MU $1,053.43 -3.79%
AMD $608.39 -4.12%

users

All
Article
Flash

DyorSwap: The previously identified "GIWA Mainnet" is actually a fake chain built by scammers, and compensation for affected users will be provided through treasury funds

DyorSwap officially announced that the so-called "GIWA Mainnet" identified by the team earlier is actually a fake chain set up by scammers. This fake network used the correct GIWA chain ID (9134), making it appear legitimate during the initial verification phase. The team also identified several suspicious messages and individuals within the related community that may be connected to this incident. The announcement stated that significant losses have occurred due to this fraudulent cross-chain bridge.DyorSwap stated that it is taking three immediate actions: first, contacting a professional security team to conduct further on-chain tracking and investigate the involved addresses, transactions, and fund flows; second, preserving all relevant evidence, including chat records, RPC information, cross-chain bridge addresses, and on-chain transactions; third, preparing to use treasury funds to compensate affected users, with eligibility criteria, loss verification processes, compensation scope, and detailed plans to be announced after the investigation and verification processes are completed.DyorSwap emphasized that until further notice, users should not use any unofficial GIWA mainnet RPCs, cross-chain bridges, or contracts, and should not send funds to any related addresses. The official team deeply apologizes to every affected user in this incident and states that subsequent updates will be released as soon as possible.

DyorSwap: The previously identified "GIWA Mainnet" is actually a fake chain built by scammers, and compensation for affected users will be provided through national treasury funds

DyorSwap officially announced that the so-called "GIWA mainnet" previously identified by the team is actually a fake chain set up by scammers. This fake network used the correct GIWA chain ID (9134), making it appear legitimate during the initial verification phase. The team also identified several suspicious messages and individuals within the related community that may be connected to this incident. The announcement stated that significant losses have occurred due to this fraudulent cross-chain bridge.DyorSwap stated that it is taking three immediate actions: first, contacting a professional security team to conduct further on-chain tracking and investigate the involved addresses, transactions, and fund flows; second, preserving all relevant evidence, including chat records, RPC information, cross-chain bridge addresses, and on-chain transactions; third, preparing to use treasury funds to compensate affected users, with eligibility criteria, loss verification processes, compensation scope, and detailed plans to be announced after the investigation and verification processes are completed.DyorSwap emphasized that until further notice, users should not use any unofficial GIWA mainnet RPCs, cross-chain bridges, or contracts, and should not send funds to any related addresses. The official team deeply apologizes to every affected user in this incident and states that subsequent updates will be released as soon as possible.

Magic Eden: Current open orders are not affected by this vulnerability; users in the EVM market from February to October 2024 need to revoke related contract authorizations

Magic Eden announced that the vulnerability occurred in the NFT trading protocol Payment Processor V2 maintained by Limit Break. Magic Eden adopted this protocol for EVM network transaction settlements in 2024 but stopped using V2 in October 2024 and will completely shut down the EVM market in the first quarter of 2026. Therefore, NFTs currently listed on Magic Eden are not affected by this vulnerability.NFTs listed through its EVM market between February and October 2024 may be affected, while listings after October 2024 are generally not impacted. The platform is contacting the protocol owner and maintainer Limit Break to explore other risk mitigation measures, including pausing protocol transfers, and will continue to investigate the actual scope of the impact.Magic Eden reminds users who have listed or traded NFTs on its EVM market to revoke relevant contract authorizations on the Ethereum, Polygon, and Base networks. Users can filter the address through revoke.cash and revoke all authorizations marked as "approved for all" for NFTs. Magic Eden emphasizes that revoking authorization cannot recover assets that have already been transferred.Yuga Labs' Vice President of Blockchain Quit stated today that at 9 AM Eastern Time, attackers exploited the Payment Processor V2 vulnerability to steal a large number of NFTs. After contacting the LimitBreak team, the latter quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain is also temporarily unable to be paused. Therefore, the team implemented a white-hat operation, successfully transferring and protecting 23,155 NFTs valued at over 5.7 million dollars.

first_img Meta's Muse AI assistant reads users' private information and falsely reports the method of access

Meta's personal AI assistant Muse has been accused of reading users' private iMessages without permission and providing false explanations about how it accesses this information. Technology columnist Jason Aten installed the assistant on his iPhone and Mac when Muse launched on September 8 and explicitly refused to grant it access to personal data such as information and calendars.A few days later, Muse sent Aten a notification suggesting he write a column about the new iPhone that he had just discussed with his podcast partner, also mentioning a deadline reminder from the editor. Aten asked Muse how it knew this, and it replied that the Mac application only forwards notification previews and does not involve the content of messages. In reality, Muse had synchronized over 187,000 records from the local private information database on the Mac, an operation that requires full disk access permissions on macOS.David Singleton, head of Meta's superintelligent lab, responded on Threads that this feature requires users to actively choose to opt-in. Aten denied ever turning on that switch and stated that Meta had not answered related questions. Amazon has banned Muse from shopping on its site, stating that the assistant did not indicate its AI identity while browsing and seemed capable of capturing and storing user credentials. Since its launch, Muse has been downloaded over 2.5 million times, with its promotion emphasizing user control over access.

first_img X sued two British users, accusing them of defrauding $277,000 in creator revenue

The social media platform X has filed a lawsuit in London against two British residents, accusing them of defrauding the company through the Creator Revenue Sharing program. X Internet Unlimited Company and X Corp. stated in the lawsuit that Vivek Kumar Sen, Zamyang Sherpa, and unidentified accomplices operated multiple X accounts in collaboration, using likes, retweets, and replies to create a false impression of genuine interaction to increase their share of revenue from the program. X was acquired last year by Elon Musk's artificial intelligence company xAI for $33 billion.The plaintiffs named a total of 9 accounts, including @Vivek4real_, @Bitcoin_Teddy, @saylordocs, @TrendingBitcoin, @Kalshibacktest, and @PolyBackTest. X accused several accounts of posting identical or highly similar cryptocurrency-related content within minutes of each other, with one post interval being only 11 seconds; at the same time, these accounts had overlapping financial and identity information, such as the Stripe account associated with @Bitcoin_Teddy being registered under the name "Stefan Mann," while the associated bank account and email both belonged to Sen.X claimed it suffered a loss of £207,384 (approximately $277,000) due to program expenditures and is seeking at least £75,000 (approximately $100,000) for investigation, analysis, remediation, and prevention of further violations.
app_icon
ChainCatcher Building the Web3 world with innovations.