Bitget confirms $351M security breach, suspends withdrawals
Related
Etherlink: EVM Bridge attempted to suspend transfers due to a security attack; no funds have been lost so far.
According to Foresight News , Etherlink has announced that its EVM Bridge has been targeted by a security attack. As a precaution, all transfers have been suspended to protect user funds while the issue is under investigation. No funds have been lost. The team is working closely with LayerZero, Asymmetric Research, and Zeeve to investigate the issue and ensure that the attack attempts are fully mitigated. A timeline for service restoration has not yet been determined.
Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw
Attackers reportedly registered Lenovo IDs using victims’ email addresses, allowing them to sign into existing Dropbox accounts without their passwords.
Core Lightning confirms multiple vulnerabilities, prepares security update
Core Lightning advised operators to use offline mode if they do not install the forthcoming update, keeping their nodes active but disconnected.
The Ministry of Industry and Information Technology issued a risk warning regarding the potential security backdoors in the AI programming tool Claude Code.
According to Odaily Odaily, the Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) of the Ministry of Industry and Information Technology recently discovered that the AI programming tool Claude Code has a security backdoor vulnerability, which poses a serious threat. Claude Code is an AI programming tool developed by Anthropic, an American company, which can autonomously complete code writing and repair tasks based on text requirements. Due to its built-in monitoring mechanism, it can send sensitive information such as user location and identity to remote servers without the user's consent. The affected Claude Code versions are 2.1.91 to 2.1.196. It is recommended that relevant units and users immediately conduct a comprehensive investigation. For development terminals that have installed the above-mentioned affected versions, they should immediately uninstall or upgrade to the latest secure version that has removed the relevant backdoor code. Strengthen the control of external access permissions and traffic monitoring of development tools within the core business network segment to prevent the unauthorized transmission of sensitive data.
Edel: The team will absorb the damage from the attack, and plans to restore functions such as withdrawals within 48 hours.
According to Foresight News , lending protocol Edel Finance has released an update on the attack, stating that it caused approximately $403,000 in bad debts. The Edel team immediately suspended all V1 contracts after detecting the anomaly. Edel V1 remains suspended, with plans to resume normal operations, including withdrawals, within approximately 48 hours. The Edel team stated that users will not suffer any losses as a result of this incident. The team will absorb the bad debts and restore the balances of affected depositors on a 1:1 basis. Meanwhile, the team has tracked the attacker's transaction records and is coordinating with exchanges and ecosystem partners. A formal white-hat settlement proposal has also been issued to the attacker, demanding the return of the remaining funds within a specified period in exchange for a security bounty. According to a previous report by Foresight News , CertiK monitoring revealed that the lending marketplace Edel Finance was attacked today. Attackers manipulated the system by exploiting the fact that the price of wGOOGLx collateral depends on the balance of its GOOGLx account, stealing approximately $204,000 through lending.
Taiko's mainnet will be restored in four steps; the vulnerability has been patched and a security audit has been completed.
ChainCatcher reports that Ethereum Layer 2 project Taiko has announced that its fix has passed independent security expert review. The mainnet will be restored in four steps: deploying the fix and confirming the final chain state is correct, ensuring there are no forged checkpoints or acceptable attacker commits; replenishing cross-chain bridge liquidity to ensure all L2 assets maintain a 1:1 reserve; restoring network operation and reopening L2 transfers, exchanges, and transactions; and having the security committee propose lifting the cross-chain bridge suspension to fully restore asset inflow and outflow. Taiko stated that initially, conservative withdrawal limits will be set as an additional security measure, but this is not expected to affect normal user asset operations.