Security
Security coverage from the StreamSage Security desk. Sources on every story. Page 3.
- Binance and Kraken restore NES trading after exploit
Recovery rules differ by venue, with Binance using two snapshots for swaps and Kraken supporting only Ethereum-based NES.
- Blockstream refuses ransom demand for remaining Liquid exploit bitcoin
Blockstream stated it will not pay for the return of 598.5 BTC and plans to work with law enforcement to trace the assets.
- Anthropic Reports Claude Misuse in Cyberattacks and Surveillance
The company identified two specific misuse patterns, including a Russian-speaking operator targeting over 20 organizations and a surveillance tool built in Mali.
- Trezor's third breach this year hits 347,000 wallets
The latest attack came via Brevo, a marketing platform. Trezor says it killed the phishing link in 20 minutes, but 2,500 people had already clicked.
- GoodDollar's $100K drain left one network unexplained
A Celo bug drained $107,445 from GoodDollar reserves, but Superfluid says the flaw was Celo-only, leaving a $20,857 XDC loss with no stated cause.
- Trezor Brevo email breach exposes 347,000 subscriber addresses
Hackers accessed the email domain of Trezor's partner Brevo, enabling phishing emails to 347,000 newsletter subscribers without exposing wallet data.
- Orionx Halts Withdrawals and Winds Down After Alleged $7M Asset Transfers
Orionx is shutting down, and the math in its legal filings does not quite match its public headline.
- Tether faces $91B exposure from dual-key vulnerability
Hacken's report identifies a gap in USDT's authorization process that could expose $91 billion in reserves.
- Liquid Network pauses after purported ‘white-hat’ hackers withdraw $320 million in bitcoin
Liquid halted operations after a SideSwap PAK withdrawal, yet the company has not identified the vulnerability that authorized the transfer.
- Solana v1 upgrade bug risks silent fee limit failures
Unpatched RPC readers and indexers face hard failures or non-binding fee caps when the Solana v1 transaction format activates on mainnet.
- Firo hard fork activates in hours to fix privacy coin inflation flaw
Firo requires operators to upgrade to v0.14.18.0 before block 1,371,000 to restore multi-input Spark spending after an August vulnerability.
- OpenAI Agents Posted 18,000 Messages on German Wiki
Researchers found AI agents sharing workarounds on DseWiki from May to June; OpenAI disputes the hacking claim.
- Trezor Discloses 67,000 Additional Customers in ShipMonk Breach
ShipMonk notified Trezor on Sept. 2 that the breach included order data from Nov. 2019 to Aug. 2021, expanding the Aug. 13 disclosure.
- Ledger faces $500 million class action over data breaches
Plaintiff Douglas Kim alleges thieves used data leaked in 2020 and 2023 to steal nearly $2 million of his crypto.
- TAC Chain Frozen 10 Days After 2.9 Billion Token Exploit
Foundation proposes treasury bailout for sold tokens while 1.66 billion attacker-held TAC remains unresolved on BNB Chain.
- The Cronos halt exposed the real DeFi vulnerability
A $75 million exploit forced Cronos to pause, but the argument over whether that was protection or control misses the protocol flaw that made the attack possible.
- Fogo halts mainnet after 400 million FOGO token theft
The network was paused about 15 hours after the Foundation reported an attacker took 400 million FOGO tokens, worth roughly $3 million.
- Radiant World leaves blue-chip firms counting losses
Several firms, including top banks and Glencore, are counting losses after lending money and reputations to the little-known iron ore trader Radiant World.
- Moonwell hit by $9M exploit, its fourth in a year
Attacker drained borrow liquidity by manipulating the price of collateral token MAMO, marking a fourth security incident in twelve months.
- Core Lightning confirms multiple vulnerabilities, prepares security update
According to CoinTelegraph, Core Lightning has confirmed the existence of multiple vulnerabilities in the software.