Hexens disclosed that it has patched a major vulnerability in Aptos, with a theoretical risk exposure of up to $70 billion.
Related
Aptos blockchain was found to have a critical vulnerability, with an attack cost of only a few hundred dollars; the team has promptly fixed it.
PANews reported on July 5th that, according to Coindesk, white-hat hackers at security firm Hexens discovered a vulnerability in the Aptos blockchain, which has since been patched. If maliciously exploited, this vulnerability could have put up to $70 billion in digital assets at systemic risk, including stablecoins and cross-chain bridges. In late February, Hexens researchers reported a critical vulnerability in the Move virtual machine (the execution environment for handling on-chain smart contracts) to the Aptos development team. They described it as an "expiration cache vulnerability" that could lead to type confusion, meaning the software could be tricked into mistaking one on-chain resource for another. Researchers simulated the attack in a real network environment with a success rate exceeding 90%.
Warning: A wallet generation vulnerability known as "Ill Bloom" leaves thousands of accounts at risk.
PANews reported on July 6th that, according to Coinspect Security, a wallet generation vulnerability called "Ill Bloom" is being exploited by attackers, allowing them to control affected wallets and steal funds. This vulnerability has affected wallets on multiple blockchains since 2018, and the affected wallets were still being generated weeks ago, indicating it did not originate from a single software wallet. Coinspect stated that hundreds of accounts had already lost approximately $3 million on May 27th, and another $2 million has been transferred from exposed wallets in the last few hours. Thousands of accounts remain at risk, covering Bitcoin, Ethereum and L2, Tron, and Solana. Coinspect has released an affected address checking tool and is urging wallet providers to integrate lightweight weak seed phrase detection functionality.
Security firm Coinspect reports that a wallet vulnerability dating back to 2018 resulted in the theft of $3.14 million last month, with Chinese users' assets at higher risk.
PANews reported on July 5th that security firm Coinspect Security published an article on the X platform stating that through analysis of crypto wallet seeds generated using insecure code since 2018, they discovered thousands of seeds that had been actually used. Last month alone, they found that these wallets had a total of $3.14 million stolen, most of which went unreported. Some funds were concentrated in a single address, exhibiting money laundering patterns. One affected address transferred $2 million out just hours after the alert was issued; it is unclear whether this was for theft. Coinspect warned that users who believe many of their assets remain at risk may be located in China.
A 25-year-old AI stock market guru's fund disclosed a new major holding in SHAZ, which rose 14.07% in overnight trading on the US stock market.
According to Mars Finance, on June 30th, a newly disclosed 13G filing by Situational Awareness LP, managed by 25-year-old Wall Street AI stock guru Leopold Aschenbrenner, revealed that the fund now holds a 19.9% stake in SharonAI Holdings (SHAZ). The filing shows that the filers include Leopold Aschenbrenner and Carl Shulman. SharonAI Holdings Inc. is a high-performance computing (HPC) company that deploys large-scale energy and computing infrastructure, manages US energy markets and infrastructure assets. According to market data, SHAZ's US stock rose 14.07% in overnight trading, currently trading at $92.4.
Bitunix Analyst: Canceling Iranian Oil Waivers and Deteriorating Hormuz Situation Increase Risk Asset Volatility
According to BlockBeats, on July 8th, global markets were focused on the renewed deterioration of the situation in the Middle East. The US not only expanded its military strikes against Iran but also revoked waivers for Iranian oil sales, further escalating security risks in the Strait of Hormuz. International oil prices surged by approximately 5%, reflecting the market's re-inflation of energy supply uncertainty. The situation is no longer just a simple military conflict; rather, it involves a simultaneous increase in risks to energy transportation and the global supply chain. Iran continues to strengthen its claims to control the Strait of Hormuz, while the US military has raised the local shipping threat level to "serious," indicating that global energy transportation remains highly volatile. On the other hand, Saudi Arabia's plan to expand its Red Sea oil pipeline shows that major oil-producing countries have already planned alternative transportation routes to reduce their dependence on the Strait of Hormuz. Regarding monetary policy, New York Federal Reserve President Williams stated that lower energy prices have helped improve short-term inflation, but policy remains in an appropriate position. He did not provide clear guidance on future interest rate direction, and the Fed will continue to adjust policy based on economic data. It is worth noting that the risks in the US technology sector have also increased simultaneously. Nasdaq 100 volatility has reached a two-decade high, with AI-related trading remaining highly concentrated. Some Wall Street institutions have begun using options for hedging and are gradually shifting funds towards defensive sectors such as healthcare and consumer staples, reflecting profit-taking pressure on highly valued tech stocks. In the crypto market, Bitcoin remains range-bound. Short-term market liquidity is mainly concentrated in four key liquidation zones: $62,500 and $60,000 on the downside, and $64,300 and $67,700 on the upside. With continued macroeconomic disruptions, prices may still see liquidity liquidation around highly leveraged positions, and short-term volatility is expected to remain high. The market will continue to monitor developments in the Middle East, oil prices, and global risk sentiment.
Bloomberg: Quantum computing puts approximately 34% of the existing Bitcoin supply at risk of being hacked.
PANews reported on July 7th, citing Bloomberg, that quantum computing is considered a new threat that could potentially crack the cryptographic algorithms of crypto assets such as Bitcoin. Quantum computers are expected to far surpass traditional computers in decrypting complex mathematical problems, and theoretically, could deduce private keys from public keys, thereby stealing on-chain assets. Wallets with early address formats and those that reuse addresses are at the highest risk. Galaxy Digital estimates that approximately 34% of circulating Bitcoin, worth about $470 billion, may become targets for future quantum attacks. Coinbase has established an advisory committee, and Strategy, where Michael Saylor works, has also launched a related risk project.