Posts

Showing posts with the label cybersecurity

Explained: how crypto's 'largest supply chain attack' stole just $0.05

A widespread security supply chain attack led to panic across the crypto community yesterday with users warned to “refrain from making any on-chain transactions.” Researchers at security firm Aikido raised the alarm after discovering that 18 popular node package manager (npm) packages contained malicious code. After being notified, the developer who maintains the popular npm packages, alias Qix, confirmed the compromise. He’d been “pwned” via a phishing email which “looked very legitimate.” Despite the packages being widespread across the crypto industry, the attack led to almost no losses. Samczsun, the head of Security Alliance, a blockchain security collective, called the result a “generational fumble.” my sincerest condolences to the person responsible for this, this was a generational fumble, the likes of which we will probably never see again https://t.co/nfiTU5K0Ig — samczsun (@samczsun) September 8, 2025 Read more: ‘Decentralized’ apps suff...

Lazarus hackers have become excellent ETH traders

The North Korean hacker collective Lazarus Group is up over $40 million on the proceeds from last year’s Radiant Capital hack, and now it’s trading the ether (ETH) market like a pro. The group’s movements were picked up by EmberCN, a Chinese-language blockchain data Analysis account on X. It noted that the hackers sold “9,631 ETH at an average price of $4,562 for 43.937 million DAI just a week ago,” before buying the dip today for a total of 4487.8 ETH with an average price of $4,154. 啊,好家伙,这 Radiant Capital 黑客竟然玩起波段来了: 他不是在一周前以 $4,562 的均价卖出了 9,631 枚 ETH 换成 4393.7 万 DAI 嘛。 这几天 ETH 回调了,他在过去 1 小时里又用 $864 万 DAI 以 $4,096 的价格重新买回了 2109.5 枚 ETH… 现在 Radiant Capital 黑客持有 14,436 枚 ETH+3529 万… https://t.co/hO4MbNPrjd pic.twitter.com/ihLYhpmNAV — 余烬 (@EmberCN) August 20, 2025 Read more: The solution to crypto’s Lazarus problem could be simpler than expected After spending the first half of August surging from $3,400 to almost $4,800, close to its all...

Exploits, hacks and scams stole almost $1B in 2023: Report

Image
Cybersecurity firm CertiK reported that as of August, over $997 million was lost to flash loan attacks, exit scams and exploits in 2023. Malicious actors targeting the crypto space have taken more than $45 million in digital assets from their victims in the month of August alone and a total of $997 million year-to-date (YTD), according to a report shared by the blockchain security firm CertiK. In the report, CertiK highlighted that exit scams took around $26 million, flash loan attacks took $6.4 million and exploits took $13.5 million from their victims in August 2023. The cybersecurity firm confirmed that the total losses amounted to over $45 million. Major incidents that happened in August. Source: CertiK CertiK pointed out that some of the major incidents that contributed to the amount lost include the Zunami Protocol attack, which led to $2.2 million in losses; the Exactly Protocol exploit, which took $7.3 million; and the PEPE (PEPE) withdrawal incident, which led to $13.2 milli...

Jump Crypto finds double-voting vulnerability in Celer’s SGN

Image
The bug would have allowed malicious validators to compromise the network and applications that rely on it, including Celer’s cBridge. Web3 investor and developer Jump Crypto has identified a vulner ability in Celer’s State Guardian Network (SGN) that would allow malicious validators to compromise the network and applications dependent on it, including Celer’s cBridge. According to Jump Crypto’s postmortem report, validators were allowed to vote more than once on the same update due to a bug in the SGN EndBlocker code. By allowing validators to vote multiple times, malicious actors could multiply their voting power to approve harmful updates. The report explained: “The [EndBlocker] code is missing a check that prevents a validator from voting on the same update twice. A malicious validator could exploit this by voting multiple times on the same update, effectively multiplying their voting power and potentially tipping the vote in favor of an invalid or malicious update." Celer...