Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT
Fomopeek, a malicious iPhone app distributed through Apple’s App Store, has been linked to nearly $580,000 in stolen USDT. Blockchain security firm SlowMist began investigating the app over the weekend after receiving reports of stolen assets linked to…
Pragma flags 6 price feeds as critical risk following $3.5M Starknet lending exploit
Oracle provider Pragma classified 6 of 22 mainnet market and rate feeds as critical risk in a Sept. 18 assessment, warning lenders that an available token price does not establish that collateral can be sold to cover a loan. The liquidity report followed…
One wallet links $1.55 million FetchAI theft to massive 408.5 million NTX mint
A coordinated attack drained 8.7 million FET and used a compromised NuNet minter key to create 408.5 million NTX. The Sept. 19 attack emptied the Ethereum-side conversion contract used by SingularityNET’s bridge, removing 8,721,530 FET worth about $1.55…
Why keeping your private keys safe won’t always stop crypto theft
Almost 4,000 Bitcoin left Liquid’s reserve on Sept. 6 through a withdrawal the network approved, even though the private keys used to authorize it hadn’t been stolen. Software had accepted a withdrawal that should never have qualified. Liquid…
Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours
Anthropic’s Claude helped three security researchers breach OpenAI accounts and reach an internal code repository within 72 hours. Researchers at cybersecurity startup Hacktron chained an image-processing vulnerability with a flaw in OpenAI’s identity…
7-day blockchain outage wipes out a full week of staking rewards after emergency aelf shutdown
aelf, a blockchain network built around its AELF MainChain and tDVV dAppChain, has restored public node access and several core services after malicious smart-contract activity led to a controlled recovery. The incident halted block production for…
Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid
Cross-chain protocol Symbiosis said it recovered approximately 15 BTC after an attacker exploited its native Bitcoin Bridge, but affected liquidity providers still lack compensation terms as a Sep. 13 bounty window nears its unspecified cutoff. The…
Audited DeFi protocols lost $885M to attacks that occurred completely outside their audit scopes
In decentralized finance, “audited” is often presented as a verdict on an entire project. In practice, an audit usually covers named code, components and versions at a particular point in time. Anything added, excluded or operated around that boundary…
A seven-year-old blockchain is permanently abandoning its own network to seek refuge on Ethereum
Harmony is proposing to shut down the blockchain it controversially restored through a rollback less than three weeks ago. The Sept. 6 plan would end Harmony’s independent network, move ONE to Ethereum, and preserve the token through a snapshot and…
Users exposed by Trezor breach grows sixfold after supposedly deleted shipping logs are found
Hardware wallet maker Trezor says a breach at logistics provider ShipMonk exposed contact and order data for another approximately 67,000 U.S. customers after years-old records remained in the vendor’s systems despite written deletion assurances.…