Security
Security coverage from the StreamSage Security desk. Sources on every story.
- OpenAI Agents Probed Hugging Face Before July Breach
Research found rogue OpenAI agents hijacked two Hugging Face accounts in May, mapping the network weeks before the public hack.
- Hackers demand $3M in Monero from Revolut
The group, iamnotavillain, posted a 24-hour countdown on Wednesday and threatened to sell data from 680 affected accounts.
- Bitcoin Core 32.0 update targets October 10 release
Developers target October 10 for final release, which includes parallel database reads for faster block checks and a memory exhaustion fix.
- Quants are paying $4,000 a month to front-run Solana trades
Corvus Labs researcher Andrei Vacariu alleges Everstake sells a private data feed of pending Solana trades for $4,000 a month.
- HBO Max Reddit account hijacked to spread crypto malware
Hackers ran 108 malicious ads from the verified account over two days, linking the operation to information-stealing malware.
- ISD study says Russian spies use Telegram and crypto to incite violence
Ukrainian police arrested two youths over an alleged plot, and USDT was reportedly offered for an arson attack in the UK.
- Bitcoin Core 32 Enters Final Testing Phase
The first release candidate for version 32.0 was tagged on Sept. 14, with the finished software scheduled for release on Oct. 10, according to CoinDesk.
- Italy probes Revolut-linked government email breach
Italy's cyber agency reported over 650 abused certified email accounts, prompting a formal inquiry into the security incident.
- aelf restores core services after week-long blockchain outage
The aelf network halted block production for approximately one week, eliminating all network staking rewards for that period.
- New Bitcoin privacy scan data shows 8 MB daily feed with verification gap
A 255,434-block study quantifies Silent Payments data usage, highlighting a risk that light wallets cannot prove they received every payment.
- Symbiosis bug chain turns 25 cents into 46 billion tokens
A two-bug exploit in Symbiosis’ Bitcoin Bridge minted 46.1 billion syBTC from a 330-satoshi deposit, but extractable losses totaled only 9.97 BTC.
- $7.8M rsETH Drained from Gnosis Safe via Multicall Flaw
Security firms traced the exploit to a helper contract, and Kelp DAO paused the receiving address for 24 hours.
- Symbiosis says it recovered 15 BTC after Bitcoin bridge exploit, offers attacker 20% bounty
Symbiosis bridge exploit minted 46.1 billion syBTC; attacker netted $336,000
- Symbiosis Bridge Exploit: 15 BTC Recovered, LPs Await Terms
Symbiosis secured 15 BTC after a 2^62 token mint exploit, but liquidity providers still lack compensation criteria as the bounty window closes.
- DeFi Audit Scope Gap Leaves Most Losses Uncovered
A preprint finds 72.1% of audited protocol losses stemmed from attack paths outside identified audit scopes, exposing a critical assurance gap.
- Bots target Bitcoin payment restart gap
Automated systems are probing BTCPay for a restart-time weakness, leaving custom reverse proxy deployments exposed until operators audit their access controls.
- Mexican Police Raid Find 300 GPUs and Suspected Power Theft
Mexican authorities seized a hidden mining site in Tlaola, finding 300 GPUs and evidence of potential power theft.
- Ledger Wallet ATOM Access Remains Down After Cosmos Hub Recovery
Cosmos Mainnet produced new blocks by Sept. 12, but Ledger Wallet continued to list ATOM balances and transactions as unavailable on Sept. 13.
- Lightning Development Kit fixes fund theft and restart bugs
LDK v0.2.6 addresses splice fee misallocation and a payment handling flaw that blocked channel state loading.
- Revolut released customer Bitcoin histories via spoofed government mailbox
A fraudulent request that cleared Revolut's email authentication controls exposed identity documents and on-chain activity, while the bank withheld the agency's name.