Crypto M - Crypto News
2.08K subscribers
15.9K photos
194 links
Your #1 destination for the latest and most unbiased market news on Bitcoin, Ethereum, NFT, Fintech, Web3, DeFi, and Blockchain.
Download Telegram
🚀 Clipper Faces Security Breach Due To API Vulnerability

According to PANews, blockchain analytics firm Fuzzland's co-founder, Chaofan Shou, issued a warning regarding a security breach on the decentralized exchange platform Clipper. The breach, attributed to an API vulnerability potentially involving private key exposure, has resulted in losses exceeding $500,000. Additionally, there is a risk of $6.5 million being compromised.

Shou has advised users to withdraw their funds immediately to prevent further losses. The incident highlights the ongoing security challenges faced by decentralized platforms, emphasizing the need for robust security measures to protect user assets. As the situation unfolds, users are urged to remain vigilant and take necessary precautions to safeguard their investments.


#Clipper #SecurityBreach #APIVulnerability #Blockchain #Fuzzland #DecentralizedExchange #CryptoSecurity #PrivateKeyExposure #UserFunds #Investments #SecurityChallenges
🚀 DEXX Apologizes And Commits To Compensation After Security Breach

According to Odaily, DEXX has issued a public apology following a security breach that resulted in the loss of user funds. The platform expressed its deepest regrets to all affected users, acknowledging that negligence in security measures led to the incident. DEXX has committed to taking full responsibility for the adverse outcomes and is determined to compensate all users who suffered losses due to the breach.

The statement from DEXX emphasized the importance of unity between the platform and its users during this challenging time. The team urged both parties to cease any further harm or attacks, highlighting that mutual support is crucial for overcoming the crisis. DEXX reassured users that it has no intention of abandoning the platform or its community. Instead, the team is dedicated to safeguarding the platform and ensuring that affected users receive the compensation they deserve.


#DEXX #SecurityBreach #UserFunds #Apology #Compensation #CommunitySupport #PlatformUnity #Negligence #CrisisManagement
🚀 1inch Addresses Security Breach and Enhances Safety Measures

According to PANews, 1inch has disclosed a security breach that occurred on December 9. The official blog of 1inch revealed that attackers fraudulently gained access to the private key of the 1inch Labs Resolver smart contract owner. This unauthorized access allowed the attackers to alter contract settings and transfer funds from the 1inch Resolver.

The 1inch team responded swiftly to address the issue, successfully revoking the compromised access. In response to the incident, 1inch has strengthened its security measures to prevent similar occurrences in the future. The company emphasized that since their protocol is non-custodial, user funds remain secure. Additionally, 1inch assured that its application and infrastructure were not affected by the breach and continue to be fully secure.


#1inch #SecurityBreach #SmartContract #Cybersecurity #Blockchain #CryptoSafety #UserFunds #NonCustodial #SafetyMeasures #1INCH
🚀 Phantom Addresses Security Concerns Amid Criticism

According to Odaily, the cryptocurrency wallet Phantom has addressed recent security concerns, stating that a reported vulnerability does not pose a risk to user funds. This statement comes after security researcher @CloakdDev criticized the platform. Phantom apologized for communication delays and reiterated its commitment to security, asserting that user funds are not threatened. However, the company did not provide further technical details or a timeline for any potential actions. Similarly, Cloakd did not offer technical specifics about the alleged vulnerability.

On January 21, Cloakd expressed disappointment with Phantom's response and initiated a discussion on social media platform X. The researcher remarked, "This has become a joke—I can't even get updates from their security team." Cloakd highlighted concerns over the delay, considering Phantom's scale and reach. Following Phantom's response, Cloakd countered the wallet's claims, asserting that the vulnerability "directly puts user funds at risk." The researcher advised Phantom users to take precautions, such as backing up their seed phrases and considering alternative wallets.


#Phantom #cryptocurrency #security #vulnerability #userfunds #CloakdDev #acknowledgment #backup #seedphrases #alternativewallets
🚀 Infini Takes Legal Action Following $50 Million Fund Loss

According to Odaily, Infini has issued a statement regarding the recent loss of $50 million, announcing that it has filed a lawsuit with the Hong Kong High Court and served court documents to the relevant blockchain addresses. The company has requested several legal measures: 1) an asset freeze order to prevent the involved parties from transferring or disposing of the funds; 2) a demand for the wallet controllers to disclose their identities to further trace the asset flow; 3) permission for service outside the jurisdiction to support legal actions across different jurisdictions.

Infini explained that the fund outflow was due to an unauthorized transfer that bypassed multi-signature approval, caused by a vulnerability in permission management. In response, the company has restructured its contract permission framework, introduced third-party audits, and implemented an on-chain monitoring system to strengthen governance mechanisms and ensure the security of user assets. The platform emphasized that user funds remain unaffected, with all deposit, withdrawal, and payment card services operating normally.


#Infini #LegalAction #Lawsuit #HongKongHighCourt #AssetFreeze #Blockchain #UnauthorizedTransfer #Security #UserFunds #GovernanceMechanisms
🚀 Morpho Labs Resolves Front-End Update Issue, Ensures User Funds Are Safe

According to PANews, Morpho Labs announced on the X platform that the team has identified and resolved an issue that arose during a recent front-end update of the Morpho App. The changes have been rolled back, and the application is now functioning normally. Morpho Labs confirmed that all user funds within the protocol remain secure and unaffected. The team plans to release a detailed explanation shortly.

#MorphoLabs #FrontEndUpdate #UserFunds #Security #TechUpdate
🚀 KiloEx Reports Progress on April Hack Investigation

According to BlockBeats, KiloEx has reported progress in the investigation of the hacking incident that occurred on April 15. The company has filed a report with the Hong Kong police, who have opened a case and are collaborating with the criminal and cybersecurity departments. Some information related to the hackers has been obtained. KiloEx is also working with the security firm SlowMist to compile a detailed incident report, which will be released when appropriate.

The security vulnerability has been addressed, and there is currently no risk of position liquidation. All positions will be settled at the snapshot prices before the incident. KiloEx is developing a compensation plan and raising funds, with the Vault function set to gradually resume once the plan is implemented, ensuring the safety of user funds.

The stolen funds have not been moved by the hackers. KiloEx has repeatedly communicated on-chain, requesting the return of 90% of the funds, but has yet to receive a response. The relevant addresses have been blocked in collaboration with multiple DeFi protocols and centralized exchanges (CEX).

In response to rumors of internal involvement, KiloEx has clarified that the police and SlowMist have fully engaged in the investigation and have accessed all internal data. If there were any internal issues, the case would not have been filed.


#KiloEx #hack #investigation #HongKong #cybersecurity #SlowMist #incidentreport #userfunds #compensationplan #DeFi #CEX #internalinvestigation
🚀 FlowX Finance Resumes Services After Security Incident

According to PANews, Sui ecosystem decentralized exchange (DEX) FlowX Finance announced on the X platform that its aggregator services have been restored. Users can now continue to use the aggregator, and issues related to losses due to low liquidity have been addressed.

FlowX Finance had previously suspended services temporarily following a security incident involving Cetus. During the suspension, the platform collaborated with Sui ecosystem partners to conduct a code review, aiming to ensure secure operations and protect user funds acting as liquidity providers.


#FlowXFinance #SuiEcosystem #DEX #AggregatorServices #SecurityIncident #UserFunds #LiquidityProviders #CodeReview #SUI
🚀 Berachain Foundation Pauses Contract Due to Potential Vulnerability

According to Foresight News, the Berachain Foundation announced via a tweet that a potential vulnerability was discovered today in the PoL incentive claim contract. As a result, the contract has been paused, and funds have been withdrawn from it. These funds will soon be transferred to a new contract. The foundation assured that user funds have not been affected or lost.

#Berachain #Foundation #ContractPause #Vulnerability #PoLIncentive #UserFunds #CryptoSecurity #BERA
🚀 Lido Addresses Security Vulnerability in Dual Governance System

According to PANews, Lido has disclosed a security vulnerability affecting its Dual Governance (DG) system's RageQuit mechanism. The issue was reported through the Immunefi platform, but user funds remain unaffected. Although the vulnerability has not been exploited, Lido has implemented several mitigation measures. The initial 'training wheels' phase of the Dual Governance system and the readiness of the emergency committee to intervene if necessary have equipped Lido contributors to eliminate any potential abuse risks.

Future steps include the emergency committee being on standby for intervention, proposing, testing, and reviewing fixes, conducting a bug bounty program on the Dual Governance testnet, and holding on-chain votes to deploy the fixes. Comprehensive implementation of the corrective measures is underway.


#Lido #Security #Vulnerability #DualGovernance #RageQuit #Immunefi #Mitigation #UserFunds #EmergencyCommittee #BugBounty #OnChainVotes #Fixes #CryptoSecurity #LDO
🚀 Harvest Suspends Vaults Amid Balancer Ecosystem Exposure

According to PANews, DeFi platform Harvest announced on the X platform that approximately $47,000 of user funds in its vaults are exposed to the Balancer ecosystem, primarily involving euro (EUR) and BAL-related products. As a precautionary measure, these vaults have been suspended, allowing users to withdraw at any time. The incident has not impacted Harvest's vault infrastructure, and the platform continues to operate normally.

#Harvest #VaultsSuspended #DeFi #Balancer #Exposure #EUR #BAL #UserFunds #Crypto #Security #PANews
🚀 Lido Ensures User Funds Remain Secure Amid Balancer V2 Pool Attack

According to Foresight News, Lido has announced that certain Balancer V2 pools have been attacked. However, the Lido protocol remains unaffected, and all user funds are secure. As a precautionary measure, Lido GGV's management team, Veda, has withdrawn its unaffected Balancer positions. All Lido Earn funds continue to be safe.

#Lido #BalancerV2 #Security #Crypto #UserFunds #Veda #Protocol #Attack #FundsSecure #LidoEarn
🚀 0G Foundation Targeted in Attack Exploiting Vulnerability

According to ChainCatcher, the 0G Foundation reported a targeted attack on its reward contract via the X platform. The attacker exploited the emergency withdrawal function of the 0G reward contract, stealing 520,010 $0G tokens, which were subsequently bridged and dispersed through Tornado Cash.

The attacker accessed a leaked private key from an Alibaba Cloud instance responsible for managing NFT status and reward updates, storing the key locally. This breach was facilitated by a critical vulnerability in Next.js (CVE-2025-66478) exploited on December 5, leading to multiple Alibaba Cloud instances being compromised. The attacker moved laterally through internal IP addresses, affecting calibration services, validator nodes, Gravity NFT services, node sales services, computing, Aiverse, Perpdex, Ascend, and others.

The confirmed losses include 520,010 $0G tokens, 9.93 ETH, and $4,200 USDT. Despite the breach, the core chain infrastructure and user funds remain unaffected, aside from the reward distribution contract.


#0GFoundation #Attack #VulnerabilityExploitation #EmergencyWithdrawal #TornadoCash #PrivateKeyLeak #AlibabaCloud #NextjsVulnerability #CVE2025 #NFT #RewardContract #BlockchainSecurity #DeFi #Ethereum #CryptoTheft #UserFunds #CyberSecurity #ETH
🚀 Biconomy Loses Access to HyperSignals_ai Account on X Platform

Biconomy has announced that it has lost access to its HyperSignals_ai account on the X platform. According to Odaily, efforts are underway to restore access, and the account will remain locked until recovery is complete. The issue is limited to the X platform account, with user funds remaining secure and the platform operating normally with all strategies online.

#Biconomy #HyperSignals_ai #Xplatform #AccountAccess #Odaily #UserFunds #PlatformSecurity #BICO
🚀 Holdstation Faces Supply Chain Attack Resulting in Significant Losses

Holdstation, a provider of account abstraction solutions, has experienced a supply chain attack, according to ChainCatcher. The attack involved the theft of developer session tokens, allowing the attacker to bypass two-factor authentication and inject malicious code into an application update, leading to the theft of user funds.

The attack resulted in a loss of 462,000 USDT, with the attacker's address identified as 0xcbfA60B39cfAeaE475f649fB6705bD477219bF8d. In response, the Holdstation team has suspended services and pledged to fully compensate affected users. They are collaborating with security teams to investigate the incident and have issued a message on the blockchain, hoping to encourage the attacker to return the funds through a bug bounty program.


#supplychainattack #cybersecurity #userfunds #usdt #accountabstraction #maliciouscode #securitybreach #blockchain #bugbounty
🚀 Sonic Restores Sonicscan After Temporary Disruption

Sonic announced that Sonicscan has been restored and fully resynchronized approximately 45 minutes ago. According to NS3.AI, the network functioned normally throughout the incident, ensuring that transaction processing and user funds remained unaffected. The team is currently investigating the cause of the disruption.

#Sonic #Sonicscan #Disruption #NS3AI #TransactionProcessing #NetworkRestoration #UserFunds #Investigation