Echo Protocol has initiated a campaign to collect information on affected users of eBTC and is urging them to submit Discord support tickets.
Related
SlowMist: Detected malicious supply chain attack campaign targeting npm users and DeFi developers.
According to Foresight News , SlowMist has detected a coordinated malicious npm supply chain campaign that uses fake trading bot codebases and DeFi-themed npm packages to deliver JavaScript information-stealing tools to npm users, DeFi developers, and trading bot users. This campaign involved 30 malicious npm packages, including stake-math@3.5.4, which was identified as a locked dependency in donoaccestag/forex-mt5-trading-bot. The codebase exhibited clear anomalies: it relied on a malicious npm package that had already been reported for security violations, and contained approximately 2300 highly homogeneous, possibly batch-generated forks, primarily concentrated under the poly-stocks account. Potential attackers may steal sensitive local data such as encrypted wallets, browser cookies, saved passwords, browsing history, developer credentials, shell history, password manager vaults, private keys, seed phrase, and API tokens found in the source code. Developers should immediately remove the affected npm packages, audit the CI logs (e.g., _2024111120230_| / _2024111120231_|) to locate these 30 malicious packages, consider systems that have run `npm install` as potential victims, promptly replace exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens, and rebuild the affected environment from a clean image.
Hinkal's privacy protocol has suspended affected smart contracts due to abnormal USDC transactions on the Ethereum blockchain.
Odaily Odaily reports that decentralized privacy protocol Hinkal Protocol has announced it has noticed unusual activity involving USDC on the Ethereum network within its system. Currently, this only affects the Ethereum blockchain; other chains are unaffected. As a precaution, affected smart contracts have been suspended, and a comprehensive investigation and analysis of related on-chain transactions and activities is underway. The investigation is ongoing, and updates will be released as information becomes available. Previously, it was reported that Hinkal suffered a loss of $800,000 due to a suspicious USDC transaction.
Community users have reported a bug in the Alkanes protocol that allows for unlimited token issuance; one address has reportedly minted 100 million DIESEL tokens.
According to community user @ Odaily, a serious bug has been detected in the Alkanes protocol, causing an unlimited increase in token issuance. One address recently exploited the bug, resulting in an additional 100 million tokens ($DIESEL). The assets are not displayed on the official Espoo streaming browser or the Subfrost interface. Users holding these assets should be aware of the risk. It is reported that the administrator of the official Alkanes Telegram group has temporarily stated that the funds are safe.
Binance co-CEO responds to MiCA's new rules taking effect: Transition support will be provided to affected users.
Odaily Odaily reports that Binance Co-CEO Richard Teng responded to the EU's MiCA regulations taking effect, stating that Binance will continue to provide transition support to affected users, including providing follow-up procedures and alternative solutions to ensure asset security and service continuity. He also advised users to seek account support and assistance through official customer service channels. Richard Teng acknowledged that regulatory changes may bring some uncertainty and user inconvenience, and that Binance is currently maintaining close communication with regulators to ensure a responsible compliance transition.
SecondFi has launched an asset recovery wallet check tool, allowing users to initially check if their wallets have been affected.
According to Foresight News , Cardano wallet service provider SecondFi has launched an asset recovery wallet check tool, allowing users to initially check if their wallets have been affected. The official statement indicates that the addresses currently displayed are based on SecondFi's preliminary review data of the security incident (not final data) and may not be a complete or final list.
Richard Teng posted an article regarding the MiCA transition: Affected users' assets are safe, and withdrawals can still be made after July 1st.
According to Foresight News , Binance Co-CEO Richard Teng stated that Binance is facilitating the MiCA compliance transition. Affected users' assets are safe, and they can still use previously announced options such as withdrawals after July 1st. He said the platform is directly communicating with affected users regarding subsequent steps and reminded users with account issues to contact customer service through official channels.