Crypto News
Written and ranked by the community. A manipulation-resistant algorithm surfaces what matters.
Atomic Wallet Disputes $479K Monero Loss Claim, Cites Lack of Evidence
Atomic Wallet has publicly refuted a viral allegation of a user losing approximately $479,000 worth of Monero (XMR). The wallet provider stated it cannot verify the claim due to a lack of direct user support contact and insufficient verifiable evidence, raising questions about the credibility of the accusation. Key Takeaways Atomic Wallet cannot verify a claim of a 633 XMR ($479k) loss due to no direct user support contact and lack of verifiable evidence. The allegation originated from a newly created X account, which Atomic Wallet flagged for unusual activity and credibility concerns. The dispute occurs amidst a recent surge in Monero's price, followed by a minor market correction. Viral Allegation Surfaces The controversy began when an X user, identifying as Nicolas van Saberhagen, claimed their Monero balance dropped to zero immediately after opening the Atomic Wallet application. The user alleged that 633 XMR, valued at around $479,000 at the time, were transferred to the same address through multiple transactions. The user also noted that the app displayed a banner indicating their funds were safe during the incident. Atomic Wallet Questions Claim's Credibility In response, Atomic Wallet stated that an internal review of the allegation could not confirm any loss. The company highlighted that over 20 hours had passed since the claim was made public, yet no support request had been filed through official channels. Atomic Wallet emphasized that Monero's inherent privacy features mean screenshots alone cannot verify a loss, as transaction details are not publicly visible. Without access to transaction data or wallet logs, the company asserted it cannot independently confirm if funds were moved or compromised. Unusual Account Activity Flagged Further raising concerns, Atomic Wallet pointed to unusual behavior associated with the account making the claim. The company noted that the same account announced a 30 XMR giveaway shortly after reporting the alleged loss. Atomic Wallet also mentioned that the account appeared to be newly created, exhibited irregular follower growth, and had been linked to past impersonation reports, suggesting potential credibility issues. Non-Custodial Nature and Open Investigation Atomic Wallet reiterated its operation as a non-custodial wallet, meaning it does not control or store user funds. Users are responsible for managing their assets directly via private keys stored on their personal devices. The company expressed willingness to investigate the matter further if the user contacts their support team directly. Broader Implications for Crypto Users The incident has also sparked discussions about the risks associated with closed-source wallet software. The complainant suggested that while the Monero network itself functioned correctly, trusting closed-source applications with private keys carries inherent risks. This situation arises as Monero has seen increased market activity, with its price surging over 50% in the past week due to renewed interest in privacy-focused cryptocurrencies, before experiencing a slight pullback. The difficulty in authenticating claims related to privacy coins like Monero, where transactions are private by default, is underscored by this event. It also highlights the importance of direct communication with wallet providers in resolving user disputes. As of now, there is no independent evidence to corroborate the alleged loss, and the issue remains unresolved pending contact from the user. Sources Atomic Wallet Denies Verifying Viral $479K Monero Loss Allegation · Cardano Feed, Cardano Feed. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
SecurityStarknet Addresses Network Outage: Post-Mortem Reveals State Discrepancy
Starknet, an Ethereum layer-2 scaling network, has published a post-mortem report detailing the cause of a recent temporary mainnet outage. The disruption, which lasted approximately 18 minutes, was attributed to a state discrepancy between the blockifier execution layer and the proving layer. While the network has since resumed normal operations, the incident has prompted a commitment to enhanced testing and code audits to prevent future occurrences. Key Takeaways A state discrepancy between the blockifier and proving layers caused the outage. The proving layer successfully prevented faulty transactions from reaching L1 finality. Approximately 18 minutes of network activity were reverted, requiring users to resubmit transactions. Starknet is enhancing testing and audits to prevent similar issues. Root Cause of the Outage The core issue stemmed from an edge case involving cross-function calls, variable writes, and reverts. In this specific scenario, the blockifier incorrectly remembered a state write that occurred within a reverted function, leading to an erroneous transaction execution. However, Starknet's proving layer, designed to verify the correctness of execution, detected this inconsistency. This safeguard prevented the faulty transactions from being finalized on the Ethereum mainnet, triggering a block reorganization instead. Network Recovery and User Impact As a result of the detected error, Starknet initiated a block reorganization, rolling back about 18 minutes of network activity. While this prevented permanent damage and ensured user funds remained secure, affected users had to resubmit their transactions. The team confirmed that the network has returned to full functionality. Lessons Learned and Future Prevention This incident underscores the complexities of developing advanced layer-2 solutions with multi-layered technology stacks. The Starknet team has committed to strengthening its testing procedures and conducting more rigorous code audits, particularly focusing on the interactions between execution logic and rollback mechanisms. This proactive approach aims to minimize the likelihood of future disruptions. Previous Incidents This is not the first disruption Starknet has experienced in 2025. A more significant outage occurred in September following a protocol upgrade named Grinta, which lasted over five hours and was caused by a sequencer bug. That incident also required chain reorganizations and transaction resubmissions, highlighting the ongoing challenges in ensuring consistent uptime for next-generation blockchain networks. Sources Starknet publishes post-mortem report after temporary network outage — TradingView News, TradingView — Track All Markets. Starknet Explains What Went Wrong Behind Monday’s Mainnet Outage, FinanceFeeds. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
0 0.0 0by dAppConNewcomer
SecurityWeb3 Suffers Record Losses: North Korean Hackers and Weak Key Security Blamed
Web3 platforms experienced a staggering $3.95 billion in losses in 2025, a significant increase from the previous year. A new report from Hacken highlights that over half of these losses are directly linked to North Korean threat actors, with poor key management and operational security failures being the primary drivers, rather than simple coding errors. Key Takeaways Total Web3 losses reached approximately $3.95 billion in 2025, an increase of $1.1 billion from 2024. North Korean-linked threat actors are responsible for over half of the total stolen funds. Access control failures and operational security breakdowns accounted for $2.12 billion, significantly more than smart contract vulnerabilities. The Bybit breach, a single theft of nearly $1.5 billion, is the largest on record and a major contributor to the overall losses. Access Control Over Code The Hacken 2025 Yearly Security Report reveals a concerning trend: access control failures and broader operational security breakdowns were responsible for approximately $2.12 billion, or nearly 54% of all losses. This starkly contrasts with the $512 million attributed to smart contract vulnerabilities. The report emphasizes that systemic operational risks, such as weak keys, compromised signers, and inadequate off-boarding procedures, are the leading causes of the most significant and unrecoverable losses. Regulatory Lag and Industry Practices Despite regulators in major jurisdictions outlining clear security requirements like role-based access control, secure onboarding, and institutional-grade custody solutions, many Web3 companies continue to employ insecure practices. Yehor Rudystia, Head of Forensic at Hacken Extractor, noted that common issues include failing to revoke developer access upon off-boarding, using single private keys for protocol management, and lacking robust Endpoint Detection and Response systems. Rudystia stressed the importance of regular penetration tests, incident simulations, custody control reviews, and independent audits, especially for large exchanges and custodians. Moving Towards Hard Requirements Hacken anticipates a further tightening of security standards as supervisors transition from soft guidance to mandatory requirements. Yevheniia Broshevan, Hacken's Co-founder and CEO, highlighted the opportunity for the industry to elevate its security baseline by adopting clear protocols for dedicated signing hardware and implementing essential monitoring tools. The report also calls for regulators and law enforcement to treat North Korean threat actor playbooks as a specific supervisory concern, advocating for real-time threat intelligence sharing and threat-specific risk assessments focused on phishing-led access attacks. Sources North Korea-linked theft and poor key security dominate Web3 losses: Hacken — TradingView News, TradingView — Track All Markets. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
0 0.0 0by dAppConNewcomer
SecurityBinance Coin Faces Potential Downturn
Binance Coin (BNB) is showing signs of a potential price decline, currently trading significantly below its yearly high. This downturn is closely linked to a noticeable slump in key performance indicators for the BNB Smart Chain (BSC), raising concerns among investors about the token's future trajectory. Key Takeaways Binance Coin (BNB) price has fallen nearly 40% from its yearly peak. The BNB Smart Chain (BSC) is experiencing a significant drop in transaction volume and fees. Technical indicators suggest a bearish outlook for BNB, with a descending triangle pattern and an impending death cross. Deteriorating BNB Smart Chain Activity Recent data reveals a concerning trend in the activity on the BNB Smart Chain. Over the past month, the network has seen an 83% decrease in transactions, handling just over 402 million. This decline in network activity has also impacted fees, which have dropped by 17% in the last 30 days, amounting to over $14.3 million. While still the second-highest fee earner after Tron, this reduction is a notable shift. Declining Total Value Locked and DEX Volume Further metrics underscore the weakening state of the BSC ecosystem. The total value locked (TVL) within the network has fallen from a year-to-date high of $12.2 billion to $8.9 billion, reaching its lowest point since July. Similarly, Decentralized Exchange (DEX) volume has experienced a sharp decline, dropping to $55 billion this month from a yearly high of $118 billion. The futures open interest for BNB has also decreased, falling from $2.7 billion to over $1.3 billion. Technical Analysis Points to Bearish Trend From a technical standpoint, the Binance Coin price chart presents a bearish outlook. The BNB token has experienced a substantial drop from its peak of $1,373 to its current trading price of $855. The formation of a descending triangle pattern, a recognized bearish continuation signal, coupled with an impending death cross (where the 50-day moving average crosses below the 200-day moving average), suggests further downside potential. A confirmed bearish breakout below the triangle's lower boundary at $817 could lead to a further decline, potentially targeting the 78.6% Fibonacci retracement level at $695. Sources Binance Coin price risks a deeper dive as key BSC metrics slump, crypto.news. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
0 0.0 0by BishopNewcomer
SecurityTrust Wallet Pledges Full Compensation After $7 Million Browser Extension Hack
Trust Wallet has initiated a formal compensation process for users affected by a recent security breach involving its Chrome browser extension. The incident, which saw approximately $7 million in digital assets stolen, was caused by malicious code embedded in version 2.68 of the extension. The company has pledged to reimburse all impacted users and is working diligently to verify claims. Key Takeaways Trust Wallet is compensating victims of a $7 million browser extension hack. The breach affected version 2.68 of the Chrome extension due to malicious code. Approximately $7 million in Bitcoin, Ether, and Solana assets were stolen. Binance founder Changpeng Zhao confirmed that Trust Wallet will cover all losses. Mobile app users and other browser extension versions were not impacted. The Security Incident Unveiled The security vulnerability came to light on Christmas Day when users reported funds being drained shortly after updating the Trust Wallet Chrome extension on December 24th. An investigation by Trust Wallet revealed that a leaked Chrome Web Store API key was used to publish the compromised version, bypassing the usual internal release checks. The malicious code, designed to harvest wallet seed phrases, was embedded within a modified analytics library. Compensation Process Underway Trust Wallet has established an official support form on its portal for affected users to submit claims. The process requires victims to provide details such as their email address, country of residence, compromised wallet addresses, the attacker's receiving addresses, and relevant transaction hashes. The company is working around the clock to verify each case meticulously to ensure accuracy and security in the compensation process. Financial Impact and Binance's Assurance An estimated $7 million in digital assets, including Bitcoin, Ether, and Solana, were stolen across multiple blockchains. Blockchain security firms noted that a significant portion of the stolen funds was moved through centralized exchanges, complicating tracing efforts. However, Changpeng Zhao, founder of Binance (which acquired Trust Wallet in 2018), publicly assured that the company would cover all affected losses, stating that user funds are "SAFU" (Secure Asset Fund for Users). Scope of the Breach It is important to note that the security incident was limited to version 2.68 of the Trust Wallet Chrome browser extension. Users of the mobile application and those running other versions of the browser extension were not affected. Trust Wallet has since released version 2.69 with a fix for the vulnerability. Sources Trust Wallet launches compensation process for $7 million browser extension hack victims, The Block. Hack: Trust Wallet Begins Compensation Process After Hack, Live Bitcoin News. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
0 0.0 0by dAppConNewcomer
SecurityX's New Terms: AI Prompts and Outputs Now 'Content,' Sparking Privacy Alarms
Social media platform X is set to implement significant changes to its Terms of Service effective January 15, 2026. The updated terms broaden the definition of "Content" to explicitly include AI prompts and outputs, granting X extensive rights to use this data for any purpose, including AI training. This move has ignited privacy concerns among users and watchdog groups. Key Takeaways AI prompts and outputs will be classified as "Content" under X's new terms. X gains broad, royalty-free, worldwide license to use this "Content" for AI training and other purposes. New clauses target AI "jailbreaking" and prompt injection. Stricter dispute resolution clauses and liability caps remain. Redefining Content and AI Training Rights The revised terms redefine "Content" to encompass "inputs, prompts, outputs," and any data "obtained or created through the Services." This expanded definition means that interactions with AI features on X, such as its Grok chatbot, will now fall under the platform's broad licensing agreement. Users grant X a worldwide, royalty-free, sublicensable license to use, copy, reproduce, process, adapt, modify, publish, transmit, display, and distribute this "Content" for "any purpose," explicitly including the training of machine learning and AI models. X asserts that access to its services constitutes sufficient compensation for these uses, a point that has drawn criticism. New Rules for AI Misuse and Enforcement In addition to the expanded definition of content, X's updated terms introduce specific clauses targeting AI circumvention. The term "misuse" will now include attempts to bypass platform controls through methods like "jailbreaking" and "prompt injection." This provides X with a contractual basis to enforce against such actions. The terms also include Europe-specific provisions addressing content enforcement under EU and UK law, detailing how "harmful" or "unsafe" content, such as bullying or content related to self-harm, will be handled, and outlining user challenge processes under the UK Online Safety Act 2023. Data Scraping, Dispute Resolution, and Liability X is maintaining its strict stance against automated access and data collection, with penalties for scraping remaining at $15,000 per 1,000,000 posts scraped within a 24-hour period. The updated wording clarifies that these penalties apply when a user "induces or knowingly facilitates" violations. Dispute resolution remains anchored in Tarrant County, Texas, with updated timelines for claims: one year for federal claims and two years for state claims. The platform also continues to enforce class-action waivers and caps its liability at $100 per covered dispute. Critics argue these provisions, along with the venue requirement, could "chill research" and make it difficult for users to pursue legal recourse. Sources X expands ‘Content’ to AI prompts, outputs in 2026 terms update, crypto.news. X claims the right to share your private AI chats with everyone under new rules – no opt out, Bitget. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
0 0.0 0by dAppConNewcomer
SecuritySEC Concludes Two-Year Probe into Ondo Finance Without Charges, Paving Way for Tokenized Treasury Expansion
The U.S. Securities and Exchange Commission (SEC) has officially closed its two-year investigation into Ondo Finance, a prominent player in the tokenization of financial assets. The probe, which examined the legality of Ondo's tokenized U.S. Treasury products and the classification of its ONDO tokens, concluded without any charges being filed. This resolution removes regulatory uncertainty and is expected to significantly boost Ondo Finance's expansion plans within the United States. Key Takeaways The SEC has ended a two-year investigation into Ondo Finance, allowing it to expand its tokenized asset operations in the US. Ondo Finance specializes in tokenized securities and enables global investors to access US stocks and ETFs via blockchain. Investigation Details and Resolution The investigation, which began in October 2023, focused on whether Ondo Finance's practices complied with U.S. securities laws, particularly concerning the tokenization of Treasury products and the ONDO token itself. Ondo Finance was formally notified of the investigation's termination in late November. This outcome marks a significant development in the ongoing U.S. discourse surrounding the regulation of tokenized assets. Ondo Finance's Role in Tokenization Ondo Finance is a platform dedicated to making U.S. stocks and Exchange Traded Funds (ETFs) accessible to global investors through blockchain technology. The company has been an advocate for clear regulatory frameworks for digital asset securities, submitting guidance to the SEC that emphasizes the need for clarity on tokenized treasuries and support for both permissioned and permissionless blockchains. Shifting Regulatory Landscape The conclusion of the Ondo Finance probe aligns with a broader trend observed under SEC Chair Paul Atkins, where a number of crypto-related investigations initiated during the previous administration have been closed. This includes reversals or dismissals of enforcement actions against other major digital asset firms. The SEC has also been increasing its focus on tokenization as a potential revolution for conventional finance, with recent discussions highlighting its impact on the issuance, trading, and settlement of public equities while maintaining investor protections. Future Expansion and New Offerings With the regulatory cloud lifted, Ondo Finance is poised for significant expansion in the U.S. market. The company has already taken steps to facilitate this, including registering as an investment advisor and acquiring Oasis Pro Markets, an SEC-registered broker-dealer, alternative trading system operator, and transfer agent. Ondo Finance plans to unveil new services for tokenizing physical assets at its upcoming Ondo Summit scheduled for February 3 in New York. Sources SEC drops two-year probe into Ondo Finance with no charges, Crypto Briefing. SEC Ends Ondo Probe With No Charges as Tokenization in Focus, CoinGape. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
0 0.0 0by dAppConNewcomer
SecuritySolana Presale Botched: Sybil Attackers Hijack WET Token Launch, HumidiFi Resets
A Solana-based presale for the Wet (WET) token was abruptly halted and reset after a sophisticated Sybil attack, involving over 1,000 wallets, allegedly sniped nearly the entire token sale within seconds. The event, hosted on the decentralized exchange aggregator Jupiter, saw genuine participants locked out due to the coordinated bot activity. Key Takeaways A Sybil attack using over 1,000 wallets compromised the Solana WET token presale. HumidiFi, the project behind the presale, has scrapped the launch and will issue a new token with an airdrop for legitimate participants. Blockchain analytics firm Bubblemaps identified the alleged attacker, linking the coordinated wallets to a single entity. The incident highlights the growing threat of Sybil attacks in token presales and airdrops. The Attack Unfolds HumidiFi, the Solana automated market maker responsible for the presale, confirmed the attack and announced the cancellation of the initial launch. The team stated their intention to create a new token and conduct a pro-rata airdrop for all "Wetlist" and JUP staker buyers, explicitly excluding the identified sniper. A new public sale is planned for Monday. Identifying the Attacker Blockchain analytics platform Bubblemaps reported identifying the entity behind the presale manipulation. Their analysis revealed that a significant portion of the participating wallets, at least 1,100 out of 1,530, exhibited identical funding and activity patterns. These wallets, many new with no prior on-chain history, were funded by a small number of sources within a tight timeframe and with similar amounts of USDC. Bubblemaps CEO Nick Vaiman noted that despite some clusters not being directly linked on-chain, the behavioral similarities strongly indicated a single actor. Sybil Attacks: A Growing Threat This incident is not isolated. November saw similar Sybil attack patterns, including one where a single entity claimed 60% of aPriori's APR token airdrop and another where Edel Finance-linked wallets allegedly acquired 30% of their own EDEL tokens. Vaiman emphasized that Sybil attacks are a critical security threat to token launches. He recommended that projects implement Know Your Customer (KYC) measures, utilize algorithms for Sybil detection, or conduct manual reviews of participants to mitigate such risks. Sources Solana WET presale hijacked by Sybil wallets as HumidiFi resets launch — TradingView News, TradingView. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
0 0.0 0by dAppConNewcomer
SecurityHackers used Australian cyber police tools
Hackers have devised a sophisticated new scheme, leveraging Australia's official cybercrime reporting service to trick citizens into revealing sensitive information and stealing their cryptocurrency. By impersonating law enforcement and exploiting data breaches, criminals are creating a facade of legitimacy to defraud unsuspecting individuals. Key Takeaways Hackers used the Australian cyber police's public communication channel to target citizens. They exploited leaked personal data (emails, phone numbers) to create convincing scams. The criminals posed as police officers and exchange support staff to gain trust. The scams aimed to trick victims into transferring cryptocurrency to "secure" wallets. The Scam Unveiled Cybercriminals have been using the Australian Federal Police's (AFP) public channel for reporting cybercrime to their advantage. By intercepting personal data such as email addresses and phone numbers, likely through previous data breaches, they were able to initiate fraudulent activities. This information allowed them to send fake requests and impersonate authorities through the national online crime reporting system, ReportCyber. ReportCyber How the Fraud Worked One reported incident involved a victim receiving a call from someone claiming to be a police officer. The scammer informed the victim that their name was linked to a cryptocurrency wallet data breach and provided a seemingly official incident reference code from ReportCyber. The victim verified that their email was indeed part of a data leak, which the criminals had obtained. Subsequently, the fraudsters, posing as exchange support staff, urged the victim to transfer their funds to a "secure wallet." Fortunately, the victim became suspicious and ended the communication before any funds were lost. Sophisticated Tactics Employed Detective Superintendent of the AFP, Mari Anderson, highlighted the alarming legitimacy these scams now possess. "Cybercriminals are conducting a verification process of the victim's personal details that can align with generally accepted expectations," she stated. "Moreover, they quickly move from messaging to a phone call, creating a sense of urgency." This incident underscores the increasingly elaborate and calculated methods criminals are using to exploit the trust of Australians. The AFP warns that these tactics are becoming more refined, making it harder for individuals to distinguish between genuine law enforcement and malicious actors. This case follows a trend of social engineering attacks targeting cryptocurrency users, with previous incidents involving impersonation of crypto exchanges and hardware wallet support. Preventing Future Attacks Authorities urge the public to remain vigilant against unsolicited communications, especially those requesting personal information or demanding immediate fund transfers. Always verify the identity of callers or senders through official channels, and be wary of any requests that seem too urgent or too good to be true. Reporting suspicious activity to the relevant authorities is crucial in combating these evolving cyber threats. Sources Hackers used an Australian cyber police service to steal cryptocurrency, ForkLog. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
0 0.0 0by ToTo BugelmanNewcomer
SecurityBybit Report Reveals Fund-Freezing Features in 16 Blockchains, Sparking Decentralization Debate
A recent report from Bybit's Lazarus Security Lab has revealed that 16 major blockchains possess built-in mechanisms to freeze user funds. This discovery has reignited discussions about the true nature of decentralization in the cryptocurrency space, as these capabilities allow for intervention in user transactions. Key Takeaways 16 major blockchains have active fund-freezing functions, with 19 more capable of implementing them via minor protocol changes. Three primary freezing mechanisms exist: hardcoded, configuration-based, and on-chain contract freezing. Notable blockchains like BNB Chain, Sui, Aptos, and VeChain have utilized these functions to mitigate hacks and recover stolen assets. The report emphasizes the need for greater transparency regarding these emergency controls. Understanding Fund Freezing Fund freezing occurs when a blockchain's foundation or governance group can lock a user's assets without their explicit consent. Once an address is blacklisted, tokens within it become inaccessible until removed by the controlling entity. Bybit's study analyzed 166 blockchains, employing AI-assisted scanning and manual validation to identify these functionalities. Mechanisms of Fund Freezing The report identifies three distinct methods for freezing funds: Hardcoded Freezing: Embedded directly into the blockchain's core code, allowing swift blocking of malicious addresses. Examples include CHILIZ, VIC, XDC, BNB Chain, and VeChain. Configuration-Based Freezing: Managed through configuration files or settings controlled by developers and validators. This method allows for private blacklisting without public disclosure. At least ten blockchains, including One, Vic, Aptos, Supra, EOS, Rose, Waxp, Sui, Linea, and Waves, utilize this approach. On-Chain Smart Contract Freezing: This method blocks malicious addresses directly through a smart contract, eliminating the need to restart nodes. It is the rarest method, identified only on HECO Chain (Huobi Eco Chain). Real-World Applications and Implications These fund-freezing tools have been employed in several high-profile incidents. Sui froze $162 million in stolen assets after the Cetus DEX hack, and Aptos later introduced similar blacklisting functions. BNB Chain used its hardcoded blacklists to limit the impact of a $570 million bridge exploit, while VeChain first used this capability in 2019 following a $6.6 million hack. While these interventions serve as emergency safeguards to protect users and limit fallout from major hacks, they also raise concerns about centralization. The ability for a small group to control funds challenges the foundational principle of decentralization. Bybit's Head of Group Risk Control and Security, David Zong, stated, "Blockchain was built on the principle of decentralization — yet our research shows that many networks are developing pragmatic safety mechanisms to respond quickly to threats." He stressed that transparency in these mechanisms is crucial for building trust within the industry. The report also identified 19 additional blockchains that could potentially support fund-freezing capabilities, including ATOM, DYDX, KAVA, LUNA, MANTRA, and SEI. Bybit advocates for clear and transparent safety mechanisms, urging projects to publicly disclose their intervention capabilities and establish robust governance standards for their use. Sources 16 Major Blockchains Can Freeze User Funds: Bybit Report, DailyCoin. Bybit’s Lazarus Security Lab Reveals Hidden Fund-Freezing Functions Across 16 Major Blockchains — TradingView News, TradingView. Lazarus Security Lab uncovers top blockchains with freeze backdoors, Cryptopolitan. Blockchain Freeze Functions Revealed in New Bybit Security Report, CoinLaw. Bybit Report Reveals Blockchains That Can Freeze Your Crypto — TradingView News, TradingView. This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
0 0.0 0by dAppConNewcomer