Binance Square
Crypto Pulse Media
1.4k 投稿

Crypto Pulse Media

Real-Time Crypto Market Intelligence Bitcoin • Altcoins • Web3 • Blockchain Global Coverage | Data-Driven Insights Crypto Pulse Media – Stay Ahead of the Market
2.5K+ フォロー
513 フォロワー
545 いいね
投稿
·
--
記事
翻訳参照
Crypto Hacks Surged to $763M in Q2 2026 as Operational Failures SpikeCrypto hacks stole $763,971,791 across 67 incidents in Q2 2026, with accessibility weaknesses the single biggest point of failure. According to a recent report by blockchain security and compliance firm Hacken, Q2 saw crypto hacks rise by 58.3% from Q1’s $482.7 million and netted the highest losses since Q2 2025. While smart contract bugs accounted for most incidents, their cumulative loss only mounted to just 11% of all losses. Operational and infrastructural failures, including compromised keys and signers, took the bigger pie at 88.3% of all losses. As for the perpetrators, 75.5% of the funds drained were attributed to Democratic People’s Republic of Korea (DPRK) actors. Note that Consensys, the company behind Ethereum’s wallet MetaMask, recently acknowledged hiring a software developer linked to North Korea. Realizing this a month later, the individual was fired and his system access revoked. The firm reported the incident to law enforcement while reassuring users that no funds were lost, no data was leaked, and no malicious code was deployed. The report also documents that Q2 witnessed the first case of AI malicious prompt injection causing an exfiltration of $174,000. Here, the firm notes that failure comes from “inadequate review, missing variants and weak testing.” In the European Union, the grace period for crypto players to pursue a full license expired on July 1. By this time, only about 215 Crypto-Asset Service Providers (CASPs) had acquired Markets in Crypto-Assets Regulation (MiCA) authorization despite 1,200 expressing interest. Binance, MEXC and HTX (formerly Huobi) are among the most prominent exchanges that were forced to shut down under this rule. Additionally, Circle’s USDC is so far the only MiCA-compliant stablecoin out of the top 10 in terms of market cap. Nonetheless, Hacken notes that the most trusted counterparties in the future will be the ones that prove safety first, regardless of their existence period, their audits, and total value locked. #TerraLabs #YiHeBinance #receita_federal #EconomicAlert

Crypto Hacks Surged to $763M in Q2 2026 as Operational Failures Spike

Crypto hacks stole $763,971,791 across 67 incidents in Q2 2026, with accessibility weaknesses the single biggest point of failure.
According to a recent report by blockchain security and compliance firm Hacken, Q2 saw crypto hacks rise by 58.3% from Q1’s $482.7 million and netted the highest losses since Q2 2025.
While smart contract bugs accounted for most incidents, their cumulative loss only mounted to just 11% of all losses. Operational and infrastructural failures, including compromised keys and signers, took the bigger pie at 88.3% of all losses.
As for the perpetrators, 75.5% of the funds drained were attributed to Democratic People’s Republic of Korea (DPRK) actors.
Note that Consensys, the company behind Ethereum’s wallet MetaMask, recently acknowledged hiring a software developer linked to North Korea. Realizing this a month later, the individual was fired and his system access revoked. The firm reported the incident to law enforcement while reassuring users that no funds were lost, no data was leaked, and no malicious code was deployed.
The report also documents that Q2 witnessed the first case of AI malicious prompt injection causing an exfiltration of $174,000. Here, the firm notes that failure comes from “inadequate review, missing variants and weak testing.”
In the European Union, the grace period for crypto players to pursue a full license expired on July 1. By this time, only about 215 Crypto-Asset Service Providers (CASPs) had acquired Markets in Crypto-Assets Regulation (MiCA) authorization despite 1,200 expressing interest.
Binance, MEXC and HTX (formerly Huobi) are among the most prominent exchanges that were forced to shut down under this rule. Additionally, Circle’s USDC is so far the only MiCA-compliant stablecoin out of the top 10 in terms of market cap.
Nonetheless, Hacken notes that the most trusted counterparties in the future will be the ones that prove safety first, regardless of their existence period, their audits, and total value locked.
#TerraLabs
#YiHeBinance
#receita_federal
#EconomicAlert
記事
翻訳参照
Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apartAt least three were drained in quick succession in a 6-hour period for a combined total exceeding $35 million, according to blockchain data assessed by CoinDesk and reported by security firms BlockAid and Peckshield. The run of attacks share a common thread. None broke the underlying cryptography — each was either a logic flaw, where the code ran as written but the rules still let money out, or a compromised key that handed an attacker control it should never have had. The most damning was blockchain network Verus. Blockaid detected an exploit on the Verus-Ethereum bridge early Thursday that drained about $7.54 million in ether, tokenized bitcoin and a spread of stablecoins. The firm flagged that the attack reused the same bridge contract and entry path as an earlier hack, exploiting an identical class of bug. CoinDesk reported that earlier incident, an $11.5 million loss, in May. A bridge is a blockchain-based tool that lets assets move between two networks that otherwise cannot interact with each other. It holds real tokens on one side and issues claims against them on the other, and its safety depends entirely on correctly verifying that every withdrawal is genuinely backed by assets locked on the other chain. The Verus flaw let an attacker trigger payouts on the Ethereum side that were never properly backed on the Verus side, so the bridge released real money against a claim worth almost nothing. The attacker returned most of the funds in exchange for a bounty after the May attack. Verus then redeposited the recovered money into the same bridge on July 8, according to onchain records compiled by security researchers, and the bridge was draineagain two weeks later. The cost of that trust is visible in the protocol's wn numbers. Verus held close to $100 millnvalue locked at the start of 2025, accordingo DefiLlama. #quickfarm #GamingCoins #kriptohaber24 #ZAIBOTIO #NOTCOİN

Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart

At least three were drained in quick succession in a 6-hour period for a combined total exceeding $35 million, according to blockchain data assessed by CoinDesk and reported by security firms BlockAid and Peckshield.
The run of attacks share a common thread. None broke the underlying cryptography — each was either a logic flaw, where the code ran as written but the rules still let money out, or a compromised key that handed an attacker control it should never have had.
The most damning was blockchain network Verus. Blockaid detected an exploit on the Verus-Ethereum bridge early Thursday that drained about $7.54 million in ether, tokenized bitcoin and a spread of stablecoins.
The firm flagged that the attack reused the same bridge contract and entry path as an earlier hack, exploiting an identical class of bug. CoinDesk reported that earlier incident, an $11.5 million loss, in May.
A bridge is a blockchain-based tool that lets assets move between two networks that otherwise cannot interact with each other. It holds real tokens on one side and issues claims against them on the other, and its safety depends entirely on correctly verifying that every withdrawal is genuinely backed by assets locked on the other chain.
The Verus flaw let an attacker trigger payouts on the Ethereum side that were never properly backed on the Verus side, so the bridge released real money against a claim worth almost nothing.
The attacker returned most of the funds in exchange for a bounty after the May attack. Verus then redeposited the recovered money into the same bridge on July 8, according to onchain records compiled by security researchers, and the bridge was draineagain two weeks later.
The cost of that trust is visible in the protocol's wn numbers. Verus held close to $100 millnvalue locked at the start of 2025, accordingo DefiLlama.
#quickfarm
#GamingCoins
#kriptohaber24
#ZAIBOTIO
#NOTCOİN
記事
米当局、スキャムセンター特別捜査チームによる暗号資産詐欺の事業から2,500万ドル超を回収すべての告発は、シークレットサービスのサイバー詐欺タスクフォースによる別々の捜査に結び付けられている。2,500万ドルは、同タスクフォースが回収した8億ドル超の一部だ。 スキャムセンター特別捜査チームは、米国の検事ジャンニーン・フェリス・ピロが2025年11月に、中国の越境型犯罪組織に関連した暗号資産(クリプト)投資詐欺を止めるために立ち上げた。 「この2,500万ドル規模の押収は、私が2025年11月に発足させたスキャムセンター特別捜査チームの直接の成果であり、こうした国際的な詐欺ネットワークを強力に狙い撃ちすることの力を示している」とピロ氏は声明で述べた。

米当局、スキャムセンター特別捜査チームによる暗号資産詐欺の事業から2,500万ドル超を回収

すべての告発は、シークレットサービスのサイバー詐欺タスクフォースによる別々の捜査に結び付けられている。2,500万ドルは、同タスクフォースが回収した8億ドル超の一部だ。
スキャムセンター特別捜査チームは、米国の検事ジャンニーン・フェリス・ピロが2025年11月に、中国の越境型犯罪組織に関連した暗号資産(クリプト)投資詐欺を止めるために立ち上げた。
「この2,500万ドル規模の押収は、私が2025年11月に発足させたスキャムセンター特別捜査チームの直接の成果であり、こうした国際的な詐欺ネットワークを強力に狙い撃ちすることの力を示している」とピロ氏は声明で述べた。
記事
翻訳参照
Glassnode flags possible data exposure, warns customers of phishing riskGlassnode, a prominent crypto market data and analytics provider, has notified customers of an ongoing security incident that may have resulted in the exposure of certain user information, including email addresses. The company said it is actively investigating the incident and has yet to determine the full extent of any affected data. Glassnode urged users to remain alert for phishing attempts and fraudulent communications impersonating the company. It advised customers to trust only emails sent from its official domain, noting that it does not operate a customer support phone line, and said it will provide further updates if additional action is required. Concerns about a potential Glassnode data breach first surfaced in a Reddit post, where a user warned that Glassnode’s email list may have been leaked or hacked after receiving a phishing email at an address created exclusively for the blockchain analytics platform. The user said the targeted nature of the message indicated that customer email data may have been exposed. #GamingCoins #YapayzekaAI #Robertkiyosaki

Glassnode flags possible data exposure, warns customers of phishing risk

Glassnode, a prominent crypto market data and analytics provider, has notified customers of an ongoing security incident that may have resulted in the exposure of certain user information, including email addresses.
The company said it is actively investigating the incident and has yet to determine the full extent of any affected data.
Glassnode urged users to remain alert for phishing attempts and fraudulent communications impersonating the company. It advised customers to trust only emails sent from its official domain, noting that it does not operate a customer support phone line, and said it will provide further updates if additional action is required.
Concerns about a potential Glassnode data breach first surfaced in a Reddit post, where a user warned that Glassnode’s email list may have been leaked or hacked after receiving a phishing email at an address created exclusively for the blockchain analytics platform. The user said the targeted nature of the message indicated that customer email data may have been exposed.
#GamingCoins
#YapayzekaAI
#Robertkiyosaki
記事
翻訳参照
Balance Coin crashes 99% after reported $915K exploitBalance Coin, an algorithmic stablecoin designed to maintain a peg to the US dollar, has fallen more than 99% following a reported exploit. The stablecoin, the native algorithmic stablecoin of Balance Protocol, is currently trading at $0.001358, down from $0.9954, according to CoinMarketCap. Blockchain security firm PeckShield on Wednesday said the depeg followed a $915,000 exploit of decentralized autonomous organization 42DAO, which governs the Balance Protocol and its BLC token. TenArmor said it had detected a suspicious attack involving GemJoin and 42DAO on the BNB Chain. #pepepumping #HotTrends #Yazdan #xmucanX #Dogecoin‬⁩

Balance Coin crashes 99% after reported $915K exploit

Balance Coin, an algorithmic stablecoin designed to maintain a peg to the US dollar, has fallen more than 99% following a reported exploit.
The stablecoin, the native algorithmic stablecoin of Balance Protocol, is currently trading at $0.001358, down from $0.9954, according to CoinMarketCap.
Blockchain security firm PeckShield on Wednesday said the depeg followed a $915,000 exploit of decentralized autonomous organization 42DAO, which governs the Balance Protocol and its BLC token.
TenArmor said it had detected a suspicious attack involving GemJoin and 42DAO on the BNB Chain.
#pepepumping
#HotTrends
#Yazdan
#xmucanX
#Dogecoin‬⁩
記事
翻訳参照
SecondFi to wind down after $2.6M ADA theft linked to wallet flawCardano-based wallet SecondFi is preparing to shut down after a security breach exposed issues around wallet security and left hundreds of users awaiting recovery options. SecondFi said it will wind down SecondFi and Yoroi wallet services after attackers stole about 16.1 million ADA, worth roughly $2.6 million, due to a cryptographic flaw in its wallet software, according to an update published on Wednesday. The platform said an independent investigation by blockchain intelligence provider Groom Lake identified a sophisticated external actor behind the attack and found indicators potentially linked to North Korea’s Lazarus Group, although no attribution has been confirmed. It added that the breach affected 374 wallets. The update came nearly a month after SecondFi first disclosed the exploit in late June, with affected users still waiting for recovery tools and migration options that the company says are now targeted for release in August. SecondFi’s latest update has drawn frustration from some users who say they are still waiting for a clear path to recover or migrate their assets after the exploit. Earlier guidance from the platform advised affected users not to restore recovery phrases into new Cardano wallets, saying that moving funds elsewhere “does not mitigate the risk” while SecondFi investigated the incident. On June 27, SecondFi said it had identified a recovery path and expected to begin the process within about two weeks after completing testing and security reviews. Nearly a month later, the company said the recovery tool is still under development and is now expected to launch in August. But many of us were told our funds could be recovered within two weeks. Now we’re being asked to wait even longer,” one user wrote in response to SecondFi’s Wednesday update. Cointelegraph contacted SecondFi for details on potential reimbursement plans but did not receive a response by publication time. EMURGO also did not respond to earlier requests for comment. #Kriptocutrader #jasmyustd #PEPEATH #ZeusInCrypto

SecondFi to wind down after $2.6M ADA theft linked to wallet flaw

Cardano-based wallet SecondFi is preparing to shut down after a security breach exposed issues around wallet security and left hundreds of users awaiting recovery options.
SecondFi said it will wind down SecondFi and Yoroi wallet services after attackers stole about 16.1 million ADA, worth roughly $2.6 million, due to a cryptographic flaw in its wallet software, according to an update published on Wednesday.
The platform said an independent investigation by blockchain intelligence provider Groom Lake identified a sophisticated external actor behind the attack and found indicators potentially linked to North Korea’s Lazarus Group, although no attribution has been confirmed. It added that the breach affected 374 wallets.
The update came nearly a month after SecondFi first disclosed the exploit in late June, with affected users still waiting for recovery tools and migration options that the company says are now targeted for release in August.
SecondFi’s latest update has drawn frustration from some users who say they are still waiting for a clear path to recover or migrate their assets after the exploit.
Earlier guidance from the platform advised affected users not to restore recovery phrases into new Cardano wallets, saying that moving funds elsewhere “does not mitigate the risk” while SecondFi investigated the incident.
On June 27, SecondFi said it had identified a recovery path and expected to begin the process within about two weeks after completing testing and security reviews. Nearly a month later, the company said the recovery tool is still under development and is now expected to launch in August.
But many of us were told our funds could be recovered within two weeks. Now we’re being asked to wait even longer,” one user wrote in response to SecondFi’s Wednesday update.
Cointelegraph contacted SecondFi for details on potential reimbursement plans but did not receive a response by publication time. EMURGO also did not respond to earlier requests for comment.
#Kriptocutrader
#jasmyustd
#PEPEATH
#ZeusInCrypto
記事
翻訳参照
U.S. DOJ Moves to Seize $25 Million in Cryptocurrency Linked to International Fraud RingThe U.S. Department of Justice has initiated forfeiture proceedings to seize more than $25 million in cryptocurrency tied to an international fraud investigation, according to a report by The Block. The action marks the latest effort by federal authorities to recover digital assets linked to cross-border financial crimes. Prosecutors are pursuing a formal forfeiture action to transfer the seized cryptocurrency to the state, the DOJ confirmed. The assets were secured during a broader investigation into an international fraud scheme, though officials have not disclosed specific details about the alleged perpetrators or the nature of the fraudulent activity. The case underscores the growing role of cryptocurrency in illicit financial networks and the government’s increasing capacity to trace and recover digital funds. This case highlights the dual nature of cryptocurrency: while it enables financial innovation, it also presents new avenues for fraud. For legitimate investors and businesses, the DOJ’s actions signal a maturing regulatory environment that prioritizes consumer protection and asset recovery. However, the seizure also raises questions about due process for asset owners and the challenges of proving ownership in decentralized systems. The outcome of this forfeiture could set a precedent for how U.S. authorities handle similar cases involving digital assets. #CrudeOilFuturesRiseOver4% #SuperMicroRisesNearly20% #SenateReleasesUpdatedCLARITYActText #GoogleDocsMagic #xmucan

U.S. DOJ Moves to Seize $25 Million in Cryptocurrency Linked to International Fraud Ring

The U.S. Department of Justice has initiated forfeiture proceedings to seize more than $25 million in cryptocurrency tied to an international fraud investigation, according to a report by The Block. The action marks the latest effort by federal authorities to recover digital assets linked to cross-border financial crimes.
Prosecutors are pursuing a formal forfeiture action to transfer the seized cryptocurrency to the state, the DOJ confirmed. The assets were secured during a broader investigation into an international fraud scheme, though officials have not disclosed specific details about the alleged perpetrators or the nature of the fraudulent activity. The case underscores the growing role of cryptocurrency in illicit financial networks and the government’s increasing capacity to trace and recover digital funds.
This case highlights the dual nature of cryptocurrency: while it enables financial innovation, it also presents new avenues for fraud. For legitimate investors and businesses, the DOJ’s actions signal a maturing regulatory environment that prioritizes consumer protection and asset recovery. However, the seizure also raises questions about due process for asset owners and the challenges of proving ownership in decentralized systems. The outcome of this forfeiture could set a precedent for how U.S. authorities handle similar cases involving digital assets.
#CrudeOilFuturesRiseOver4%
#SuperMicroRisesNearly20%
#SenateReleasesUpdatedCLARITYActText
#GoogleDocsMagic
#xmucan
記事
翻訳参照
Zilliqa Ledger app vulnerability lets attackers recover signer’s private keysLayer-1 blockchain network Zilliqa warned that a vulnerability in the Zilliqa Ledger app could allow attackers to recover users’ private keys using publicly available onchain data. The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key,” Zilliqa said in a Wednesday X post. Zilliqa said protective measures are in place to prevent further losses and that a coordinated remediation plan is being finalized. Users who signed at least five native Zilliqa transactions with a Ledger device are considered compromised and are advised to await further guidance before taking any action. The warning comes after Zilliqa on Monday asked exchanges to temporarily pause Zilliqa ($ZIL) deposits and withdrawals after identifying a security vulnerability that resulted in the theft of an undisclosed amount of $ZIL from a cold wallet. Zilliqa said it will publish a corrected version of the app in coordination with Ledger. It said that users transacting $ZIL through EVM-compatible tooling were not affected. The $ZIL token fell 1.5% in the past 24 hours and 17% over the past week, to trade above $0.0024 at publication, according to CoinMarketCap. #quickfarm #EconomicAlert #Robertkiyosaki #tobechukwu #Launchpool

Zilliqa Ledger app vulnerability lets attackers recover signer’s private keys

Layer-1 blockchain network Zilliqa warned that a vulnerability in the Zilliqa Ledger app could allow attackers to recover users’ private keys using publicly available onchain data.
The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key,” Zilliqa said in a Wednesday X post.
Zilliqa said protective measures are in place to prevent further losses and that a coordinated remediation plan is being finalized. Users who signed at least five native Zilliqa transactions with a Ledger device are considered compromised and are advised to await further guidance before taking any action.
The warning comes after Zilliqa on Monday asked exchanges to temporarily pause Zilliqa ($ZIL) deposits and withdrawals after identifying a security vulnerability that resulted in the theft of an undisclosed amount of $ZIL from a cold wallet.
Zilliqa said it will publish a corrected version of the app in coordination with Ledger. It said that users transacting $ZIL through EVM-compatible tooling were not affected.
The $ZIL token fell 1.5% in the past 24 hours and 17% over the past week, to trade above $0.0024 at publication, according to CoinMarketCap.
#quickfarm
#EconomicAlert
#Robertkiyosaki
#tobechukwu
#Launchpool
記事
翻訳参照
Altcoin Investors Beware! Security Crisis Deepens: Two Major Exchanges Added Them to Their Warning LZilliqa ($ZIL), one of the popular altcoins of the 2021 bull season, announced that it is facing a significant security crisis due to a critical vulnerability discovered in its Ledger hardware wallet application. Zilliqa, in a statement made from the X account, stated that the attack stemmed from a security vulnerability in the Ledger application. At this point, Zilliqa states that a critical vulnerability in the Ledger application makes the private keys used for $ZIL transactions vulnerable to recovery attacks. The team stated that the problem affects all versions released from 2019 to 2026, and that active exploitation was observed on July 19th. Following this active vulnerability, the team stated that $ZIL transactions were suspended, but EVM transactions were not affected by this security flaw. Following these developments, South Korea-based cryptocurrency exchanges Upbit and Bithumb classified $ZIL as a “warning asset” in their trading markets. Exchanges have announced that they are suspending deposits and withdrawals for $ZIL, citing user security concerns. Upbit and Bithumb made similar statements, warning that trading support for $ZIL could be completely terminated if the security issue is not resolved within a reasonable timeframe or if adequate measures to protect investors are not taken. This development has led to a review of security measures within the Zilliqa ecosystem, and users who conduct $ZIL transactions via Ledger are advised to change their addresses and discontinue using their compromised wallets. As you may recall, Zilliqa previously announced that $ZIL held in a cold wallet had been stolen in a security incident at one of its partner exchanges. #ONDO‬⁩ #LISTAAirdrop #FlokiCoin #ZE_TRAD🐂 #YiHeBinance

Altcoin Investors Beware! Security Crisis Deepens: Two Major Exchanges Added Them to Their Warning L

Zilliqa ($ZIL), one of the popular altcoins of the 2021 bull season, announced that it is facing a significant security crisis due to a critical vulnerability discovered in its Ledger hardware wallet application.
Zilliqa, in a statement made from the X account, stated that the attack stemmed from a security vulnerability in the Ledger application.
At this point, Zilliqa states that a critical vulnerability in the Ledger application makes the private keys used for $ZIL transactions vulnerable to recovery attacks.
The team stated that the problem affects all versions released from 2019 to 2026, and that active exploitation was observed on July 19th.
Following this active vulnerability, the team stated that $ZIL transactions were suspended, but EVM transactions were not affected by this security flaw.
Following these developments, South Korea-based cryptocurrency exchanges Upbit and Bithumb classified $ZIL as a “warning asset” in their trading markets.
Exchanges have announced that they are suspending deposits and withdrawals for $ZIL, citing user security concerns.
Upbit and Bithumb made similar statements, warning that trading support for $ZIL could be completely terminated if the security issue is not resolved within a reasonable timeframe or if adequate measures to protect investors are not taken.
This development has led to a review of security measures within the Zilliqa ecosystem, and users who conduct $ZIL transactions via Ledger are advised to change their addresses and discontinue using their compromised wallets.
As you may recall, Zilliqa previously announced that $ZIL held in a cold wallet had been stolen in a security incident at one of its partner exchanges.
#ONDO‬⁩
#LISTAAirdrop
#FlokiCoin
#ZE_TRAD🐂
#YiHeBinance
記事
翻訳参照
AI Startup ORO Loses $630K in ALPHA Tokens After North Korean Hackers Exploit Telegram Video CallAI shopping agent developer ORO has confirmed a significant security breach, losing approximately $630,000 worth of ALPHA tokens in an attack attributed to a North Korean state-backed hacking group. The incident, detailed in ORO’s internal incident report and first reported by Protos, highlights the increasingly sophisticated social engineering tactics used by cybercriminals to target cryptocurrency projects. According to ORO’s findings, the attack began when an employee received a message on Telegram from an acquaintance met at a previous offline conference. The hacker, impersonating a trusted contact, convinced the employee to join a video call. During this call, malware was deployed onto the employee’s device, granting the attackers access to internal systems and ultimately the company’s ALPHA token reserves. ORO stated that the method aligns with known patterns of the Lazarus Group, a notorious North Korean hacking collective responsible for numerous high-profile crypto thefts. The use of social engineering—building trust through fake identities and leveraging real-world connections—marks a dangerous evolution in crypto-related cybercrime. This incident serves as a stark reminder that even early-stage AI projects with valuable token treasuries are prime targets. The attack exploited human trust rather than technical vulnerabilities, underscoring that security awareness training is as critical as software safeguards. For the broader crypto ecosystem, it reinforces the need for robust multi-signature wallets, hardware security modules, and strict verification protocols for any communication involving fund transfers. ORO has since engaged with blockchain security firms and law enforcement to trace the stolen funds, though recovering tokens from state-sponsored actors is notoriously difficult. The company is also reviewing its internal security policies and employee communication guidelines.The attackers used a social engineering tactic: they contacted an ORO employee on Telegram, impersonating a known acquaintance, and convinced the employee to join a video call that installed malware on the employee’s device, allowing theft of ALPHA tokens. ORO attributes the attack to a North Korean state-backed hacking group, likely the Lazarus Group, which has a long history of targeting cryptocurrency exchanges and projects. Projects should implement strict verification for any communication involving fund transfers, use multi-signature wallets, provide regular security awareness training, and avoid relying solely on messaging apps for sensitive operational conversations. #BitcoinDominanceRisesTo59% #SenateReleasesUpdatedCLARITYActText #DellRises11%MarketCapNears$290B #HongKongStorageStocksStrengthen #Nasdaq100RisesOnChipRebound

AI Startup ORO Loses $630K in ALPHA Tokens After North Korean Hackers Exploit Telegram Video Call

AI shopping agent developer ORO has confirmed a significant security breach, losing approximately $630,000 worth of ALPHA tokens in an attack attributed to a North Korean state-backed hacking group. The incident, detailed in ORO’s internal incident report and first reported by Protos, highlights the increasingly sophisticated social engineering tactics used by cybercriminals to target cryptocurrency projects.
According to ORO’s findings, the attack began when an employee received a message on Telegram from an acquaintance met at a previous offline conference. The hacker, impersonating a trusted contact, convinced the employee to join a video call. During this call, malware was deployed onto the employee’s device, granting the attackers access to internal systems and ultimately the company’s ALPHA token reserves.
ORO stated that the method aligns with known patterns of the Lazarus Group, a notorious North Korean hacking collective responsible for numerous high-profile crypto thefts. The use of social engineering—building trust through fake identities and leveraging real-world connections—marks a dangerous evolution in crypto-related cybercrime.
This incident serves as a stark reminder that even early-stage AI projects with valuable token treasuries are prime targets. The attack exploited human trust rather than technical vulnerabilities, underscoring that security awareness training is as critical as software safeguards. For the broader crypto ecosystem, it reinforces the need for robust multi-signature wallets, hardware security modules, and strict verification protocols for any communication involving fund transfers.
ORO has since engaged with blockchain security firms and law enforcement to trace the stolen funds, though recovering tokens from state-sponsored actors is notoriously difficult.
The company is also reviewing its internal security policies and employee communication guidelines.The attackers used a social engineering tactic: they contacted an ORO employee on Telegram, impersonating a known acquaintance, and convinced the employee to join a video call that installed malware on the employee’s device, allowing theft of ALPHA tokens.
ORO attributes the attack to a North Korean state-backed hacking group, likely the Lazarus Group, which has a long history of targeting cryptocurrency exchanges and projects.
Projects should implement strict verification for any communication involving fund transfers, use multi-signature wallets, provide regular security awareness training, and avoid relying solely on messaging apps for sensitive operational conversations.
#BitcoinDominanceRisesTo59%
#SenateReleasesUpdatedCLARITYActText
#DellRises11%MarketCapNears$290B
#HongKongStorageStocksStrengthen
#Nasdaq100RisesOnChipRebound
記事
翻訳参照
80% of Malicious Code Passed AI Review in CI/CD Pipeline Security TestWhen an AI agent says it has reviewed the code, that might mean almost nothing. A new research paper by Yohann Sidot, published on arXiv, lays out a sobering finding: in a sophisticated multi-agent system built specifically to enforce CI/CD pipeline security, a single cleverly worded external request was enough to push malicious code all the way to deployment — bypassing every automated check in its path. The research examined a pipeline composed of five distinct production LLMs sourced from three different providers. The architecture followed a realistic CI/CD flow: triage, developer, security scan, review, and approve/deploy. The whole system ran in shadow mode behind an LLM firewall, designed to simulate a genuinely hardened agentic environment. The entry agent performed well on one narrow metric. Across 40 attempts, it never leaked its system prompt — a result suggesting that surface-level prompt confidentiality can hold. But that turned out to be the least interesting finding of the study. All data in this research was entirely synthetic. The attack simulations used a mocked exfiltration sink, and no real external URLs were contacted at any point. This is methodologically sound for a controlled study, but it also means the prevalence of these specific attack patterns in live production pipelines remains an open question. The gap between a clean experimental setup and the messier reality of deployed systems is real. Production pipelines differ in architecture, LLM configuration, organizational policy layers, and human-in-the-loop intervention points. What the paper establishes is a proof-of-concept vulnerability class — not a confirmed attack in the wild. Still, the core insight holds regardless of deployment context: if AI agents can be made to defer to fabricated authority signals, and if the code they approve is clean enough to evade pattern-based detection, then the verification layer of an agentic CI/CD pipeline is only as strong as the agents’ capacity to reason about intent — and that capacity, the paper shows, is neither guaranteed nor easy to operationalize at scale. Only LLM reasoning about the intent of the code — rather than its syntax or pattern-based properties — provided any partial defense. All other controls, including distributed verification and prompt secrecy, were insufficient on their own. #GoogleDocsMagic #Robert #LISTAAirdrop #Kriptocutrader

80% of Malicious Code Passed AI Review in CI/CD Pipeline Security Test

When an AI agent says it has reviewed the code, that might mean almost nothing. A new research paper by Yohann Sidot, published on arXiv, lays out a sobering finding: in a sophisticated multi-agent system built specifically to enforce CI/CD pipeline security, a single cleverly worded external request was enough to push malicious code all the way to deployment — bypassing every automated check in its path.
The research examined a pipeline composed of five distinct production LLMs sourced from three different providers. The architecture followed a realistic CI/CD flow: triage, developer, security scan, review, and approve/deploy. The whole system ran in shadow mode behind an LLM firewall, designed to simulate a genuinely hardened agentic environment.
The entry agent performed well on one narrow metric. Across 40 attempts, it never leaked its system prompt — a result suggesting that surface-level prompt confidentiality can hold. But that turned out to be the least interesting finding of the study.
All data in this research was entirely synthetic. The attack simulations used a mocked exfiltration sink, and no real external URLs were contacted at any point. This is methodologically sound for a controlled study, but it also means the prevalence of these specific attack patterns in live production pipelines remains an open question.
The gap between a clean experimental setup and the messier reality of deployed systems is real. Production pipelines differ in architecture, LLM configuration, organizational policy layers, and human-in-the-loop intervention points. What the paper establishes is a proof-of-concept vulnerability class — not a confirmed attack in the wild.
Still, the core insight holds regardless of deployment context: if AI agents can be made to defer to fabricated authority signals, and if the code they approve is clean enough to evade pattern-based detection, then the verification layer of an agentic CI/CD pipeline is only as strong as the agents’ capacity to reason about intent — and that capacity, the paper shows, is neither guaranteed nor easy to operationalize at scale.
Only LLM reasoning about the intent of the code — rather than its syntax or pattern-based properties — provided any partial defense. All other controls, including distributed verification and prompt secrecy, were insufficient on their own.
#GoogleDocsMagic
#Robert
#LISTAAirdrop
#Kriptocutrader
記事
ロシア議会、暗号資産市場を規制する法律を可決ロシアの国家ドゥーマは、暗号資産市場のためのルールを定める法案を承認した。同法案は、国内における暗号資産の取引のための条件や、越境貿易の条件を設定している。 議会は、デジタル通貨とデジタル権利に関する『Digital Currency and Digital Rights』という題名の法案第1194918-8号を、火曜日に行われた第2読会および第3読会で可決した。法案に関する最終採決を議員らが予定していたことから、公式な議会記録によれば、その事前の見通しどおりだった。 本法は、暗号資産市場の参加者(暗号資産取引所、ブローカー、資産運用会社、カストディアンを含む)に対する規制された枠組みを作り、同分野で事業を行う企業に求められる要件を定めている。

ロシア議会、暗号資産市場を規制する法律を可決

ロシアの国家ドゥーマは、暗号資産市場のためのルールを定める法案を承認した。同法案は、国内における暗号資産の取引のための条件や、越境貿易の条件を設定している。
議会は、デジタル通貨とデジタル権利に関する『Digital Currency and Digital Rights』という題名の法案第1194918-8号を、火曜日に行われた第2読会および第3読会で可決した。法案に関する最終採決を議員らが予定していたことから、公式な議会記録によれば、その事前の見通しどおりだった。
本法は、暗号資産市場の参加者(暗号資産取引所、ブローカー、資産運用会社、カストディアンを含む)に対する規制された枠組みを作り、同分野で事業を行う企業に求められる要件を定めている。
記事
「クリプトに対抗せよ」:社会主義者のサンダース、テックの億万長者に対して集会を呼びかけミネアポリスで行われた、ミネソタ州副知事ペギー・フラナガンの上院選出馬を支援する選挙イベントでの登場時、サンダースは「彼らは強力な産業に挑む」と述べた。 「私たちは共に、クリプト、AI業界、AIPAC、そしてその他の億万長者のスーパーPACに立ち向かい、ペギーをアメリカ合衆国上院へ送る」——サンダースはXにこう書いた。 サンダースのコメントは、議会内のいわゆる「反・暗号資産(クリプト)軍」のリーダーである、進歩派の民主党員エリザベス・ウォーレンの最近の発言を呼び起こすものだ。彼女は自身の最近のSNS投稿でも、政治における暗号資産の資金の役割を批判した。

「クリプトに対抗せよ」:社会主義者のサンダース、テックの億万長者に対して集会を呼びかけ

ミネアポリスで行われた、ミネソタ州副知事ペギー・フラナガンの上院選出馬を支援する選挙イベントでの登場時、サンダースは「彼らは強力な産業に挑む」と述べた。
「私たちは共に、クリプト、AI業界、AIPAC、そしてその他の億万長者のスーパーPACに立ち向かい、ペギーをアメリカ合衆国上院へ送る」——サンダースはXにこう書いた。
サンダースのコメントは、議会内のいわゆる「反・暗号資産(クリプト)軍」のリーダーである、進歩派の民主党員エリザベス・ウォーレンの最近の発言を呼び起こすものだ。彼女は自身の最近のSNS投稿でも、政治における暗号資産の資金の役割を批判した。
記事
パキスタン、マネーロンダリング対策のため暗号捜査ユニットを立ち上げパキスタンの最高位の連邦捜査機関は、暗号資産に関連した犯罪を取り締まるための専用ユニットを設置し、デジタル資産を受け入れるための国家的取り組みのうち、執行面を強化している。 連邦捜査局(FIA)は、新たに稼働を開始した国家指揮統制センター(NC3)内に暗号資産の捜査ユニットを設置し、仮想通貨を通じて行われるマネーロンダリングおよびテロ資金供与を対象にすると、同局の対テロ責任者が述べた。 FIA対テロ部門の局長であるムハンマド・アタール・ワヒード博士は、現地メディア『ドーン』に対し、このユニットは暗号の犯罪利用を捜査すると説明した。一方で、最近設立されたパキスタン仮想資産規制当局(PVARA)は、デジタル資産を規制する責任を負う機関であり続けるという。さらに同氏は、他の2つの機関である国家サイバー犯罪捜査局および反麻薬部隊に対し、サイバー犯罪や薬物取引での暗号の利用に対抗するために同様のユニットを設置するよう促し、捜査を一定の期間内に終えるための新たな規則が起草中であると述べた。

パキスタン、マネーロンダリング対策のため暗号捜査ユニットを立ち上げ

パキスタンの最高位の連邦捜査機関は、暗号資産に関連した犯罪を取り締まるための専用ユニットを設置し、デジタル資産を受け入れるための国家的取り組みのうち、執行面を強化している。
連邦捜査局(FIA)は、新たに稼働を開始した国家指揮統制センター(NC3)内に暗号資産の捜査ユニットを設置し、仮想通貨を通じて行われるマネーロンダリングおよびテロ資金供与を対象にすると、同局の対テロ責任者が述べた。
FIA対テロ部門の局長であるムハンマド・アタール・ワヒード博士は、現地メディア『ドーン』に対し、このユニットは暗号の犯罪利用を捜査すると説明した。一方で、最近設立されたパキスタン仮想資産規制当局(PVARA)は、デジタル資産を規制する責任を負う機関であり続けるという。さらに同氏は、他の2つの機関である国家サイバー犯罪捜査局および反麻薬部隊に対し、サイバー犯罪や薬物取引での暗号の利用に対抗するために同様のユニットを設置するよう促し、捜査を一定の期間内に終えるための新たな規則が起草中であると述べた。
記事
バーニー・サンダース、2026年の選挙前に暗号に挑むと誓う米上院議員バーニー・サンダースは、暗号(クリプト)業界への批判を新たにし、ミネソタ州副知事ペギー・フラナガンの上院選出馬を支援する選挙イベントの中で、デジタル資産の団体を他の資金力のある政治勢力と並べて位置付けた。 7月21日のX投稿で、サンダースは「共に、暗号(クリプト)、AI業界、AIPAC、そしてその他の億万長者のスーパーPACに立ち向かう」と書いた。さらに、このキャンペーンの目的はフラナガンを米上院へ送ることだと付け加えた。コメントは、暗号資産の価格やブロックチェーン技術というよりも、政治的な支出や産業の影響力に焦点が当たっていた。

バーニー・サンダース、2026年の選挙前に暗号に挑むと誓う

米上院議員バーニー・サンダースは、暗号(クリプト)業界への批判を新たにし、ミネソタ州副知事ペギー・フラナガンの上院選出馬を支援する選挙イベントの中で、デジタル資産の団体を他の資金力のある政治勢力と並べて位置付けた。
7月21日のX投稿で、サンダースは「共に、暗号(クリプト)、AI業界、AIPAC、そしてその他の億万長者のスーパーPACに立ち向かう」と書いた。さらに、このキャンペーンの目的はフラナガンを米上院へ送ることだと付け加えた。コメントは、暗号資産の価格やブロックチェーン技術というよりも、政治的な支出や産業の影響力に焦点が当たっていた。
記事
インドのITR期限が迫る:知っておくべき暗号資産の税制ルールインドの所得税申告(ITR)提出期限が近づいており、投資家にはミスの余地がほとんどありません。ITRを提出する前に、デジタル資産の取引をどのように申告するかに特に注意する必要があります。インドには現在、包括的な暗号資産の税制がありますが、多くの投資家はこれらのルールをまだ把握していません。ビットコインを取引した場合でも、エアドロップに参加した場合でも、$NFTを購入した場合でも、インドの暗号資産に関する税制を遵守し続けなければなりません。 2022年にインド政府は、暗号資産の税制ルールを導入し、暗号資産およびその他の仮想資産(VDA)を別の課税制度の下に含めました。法律によれば、暗号資産を売却または譲渡して利益を得た投資家は30%の課税対象となります。さらに、定められた基準額を超えるすべての暗号資産取引には、源泉徴収(TDS)として1%が適用されます。

インドのITR期限が迫る:知っておくべき暗号資産の税制ルール

インドの所得税申告(ITR)提出期限が近づいており、投資家にはミスの余地がほとんどありません。ITRを提出する前に、デジタル資産の取引をどのように申告するかに特に注意する必要があります。インドには現在、包括的な暗号資産の税制がありますが、多くの投資家はこれらのルールをまだ把握していません。ビットコインを取引した場合でも、エアドロップに参加した場合でも、$NFTを購入した場合でも、インドの暗号資産に関する税制を遵守し続けなければなりません。
2022年にインド政府は、暗号資産の税制ルールを導入し、暗号資産およびその他の仮想資産(VDA)を別の課税制度の下に含めました。法律によれば、暗号資産を売却または譲渡して利益を得た投資家は30%の課税対象となります。さらに、定められた基準額を超えるすべての暗号資産取引には、源泉徴収(TDS)として1%が適用されます。
記事
インド初の不動産トークン化の枠組みとして、マハラシュトラがDELTA法を提案マハラシュトラ州は、不動産をトークン化するためのブロックチェーンを基盤とした法的枠組みについて、先進的な計画を進めている。デヴェンドラ・ファダナヴィス州首相が、州がインドで最初にこのような法律を導入できる可能性を見据え、当局に対して法案の草案作成を指示した。 Xでマハラシュトラ州首相デヴェンドラ・ファダナヴィスが共有した声明によると、州政府は、提案されているマハラシュトラ・デジタル化および土地トークン資産の交換法(DELTA法)に関する作業を開始した。同法は、ブロックチェーン技術を通じて、不動産に紐づくトークン化された権益をデジタル化し、交換するための法的枠組みを構築することを目的としている。

インド初の不動産トークン化の枠組みとして、マハラシュトラがDELTA法を提案

マハラシュトラ州は、不動産をトークン化するためのブロックチェーンを基盤とした法的枠組みについて、先進的な計画を進めている。デヴェンドラ・ファダナヴィス州首相が、州がインドで最初にこのような法律を導入できる可能性を見据え、当局に対して法案の草案作成を指示した。
Xでマハラシュトラ州首相デヴェンドラ・ファダナヴィスが共有した声明によると、州政府は、提案されているマハラシュトラ・デジタル化および土地トークン資産の交換法(DELTA法)に関する作業を開始した。同法は、ブロックチェーン技術を通じて、不動産に紐づくトークン化された権益をデジタル化し、交換するための法的枠組みを構築することを目的としている。
記事
ヘスター・ピアース氏、SEC投資家向け諮問委員会の開催を発表ヘスター・ピアース氏は本日開催されるSEC投資家向け諮問委員会(Investor Advisory Committee)会合について発表し、コーポレート・ガバナンスとトークン化に関する議論が行われる予定だ。今回の会合は、重大な規制上の論点に取り組むものであり、暗号資産(クリプト)分野のステークホルダーにとって重要だ。詳細は公式情報源こちらを参照。 暗号資産市場全体は引き続きさまざまなシグナルが混在しており、規制枠組みに対する不確実性を反映している。ピアース氏の発表は、トークン化やコーポレート・ガバナンスをめぐる議論がますます重要になっている時期にあたる。SEC投資家向け諮問委員会は、伝統的な市場とデジタル・アセット市場の双方に影響を与え得る今後の政策を形作る可能性のある見通しを示すことが期待されている。投資家は、規制のあり方が変わるかもしれないという状況に備えながら、これらの動向を熱心に注視している。

ヘスター・ピアース氏、SEC投資家向け諮問委員会の開催を発表

ヘスター・ピアース氏は本日開催されるSEC投資家向け諮問委員会(Investor Advisory Committee)会合について発表し、コーポレート・ガバナンスとトークン化に関する議論が行われる予定だ。今回の会合は、重大な規制上の論点に取り組むものであり、暗号資産(クリプト)分野のステークホルダーにとって重要だ。詳細は公式情報源こちらを参照。
暗号資産市場全体は引き続きさまざまなシグナルが混在しており、規制枠組みに対する不確実性を反映している。ピアース氏の発表は、トークン化やコーポレート・ガバナンスをめぐる議論がますます重要になっている時期にあたる。SEC投資家向け諮問委員会は、伝統的な市場とデジタル・アセット市場の双方に影響を与え得る今後の政策を形作る可能性のある見通しを示すことが期待されている。投資家は、規制のあり方が変わるかもしれないという状況に備えながら、これらの動向を熱心に注視している。
記事
米政府、中国のAIモデルによるIP(知的財産)盗用をめぐり制裁をちらつかせる米財務長官スコット・ベッセントは、ワシントンは、中国のAI企業が米国のモデル開発者から知的財産を盗んだ証拠が見つかれば制裁する可能性があると述べた。 火曜に米Fox Businessで語った際、ベッセントはトランプ政権がオープンソースのAIを支持しているものの、外国企業が米国の技術をコピーすることは容認しないと語った。 警告は、中国のモデルが進歩し、Moonshot AIのKimi K3を含む中国勢が、OpenAIやAnthropicが優勢だったコーディング、エージェント型のタスク、その他の分野で地歩を固めていることによって生じている。 Axiosは月曜に、トランプ政権が中国のオープンソース・モデルに対するより広範な制限を検討していると報じたが、この主張は争われている。

米政府、中国のAIモデルによるIP(知的財産)盗用をめぐり制裁をちらつかせる

米財務長官スコット・ベッセントは、ワシントンは、中国のAI企業が米国のモデル開発者から知的財産を盗んだ証拠が見つかれば制裁する可能性があると述べた。
火曜に米Fox Businessで語った際、ベッセントはトランプ政権がオープンソースのAIを支持しているものの、外国企業が米国の技術をコピーすることは容認しないと語った。
警告は、中国のモデルが進歩し、Moonshot AIのKimi K3を含む中国勢が、OpenAIやAnthropicが優勢だったコーディング、エージェント型のタスク、その他の分野で地歩を固めていることによって生じている。
Axiosは月曜に、トランプ政権が中国のオープンソース・モデルに対するより広範な制限を検討していると報じたが、この主張は争われている。
記事
CLARITY法アップデート:ホワイトハウスの協議は順調だったとルミス事務所が発言CLARITY法の倫理条項をめぐる超党派の協議が火曜日、連邦議会議事堂で再開された。交渉担当者たちは、同法案の最終局面であり、最も頑固な障害となってきた文言の整理に取り組んでいる。 記者のエレノア・タレットによれば、議員らは並行してDeFiの条項についても協議しているが、倫理がなお立法を止めている最大の引っかかりだという。2つの流れは同時に進んでいるものの、内情を知る関係者によれば、何よりも先に倫理の問題が決着する必要があるとしている。 シンシア・ルミス上院議員のスポークスマンは、決議が近づいているかもしれないことを最も明確に示す兆候だとしている。交渉の状況について聞かれると、そのスポークスマンは先週、ルミス氏の事務所とホワイトハウスの間で行われた会話がうまくいったと述べ、今後数日で公表される見込みの倫理に関する文言が、その有意義な協議内容を反映することになるだろうとした。

CLARITY法アップデート:ホワイトハウスの協議は順調だったとルミス事務所が発言

CLARITY法の倫理条項をめぐる超党派の協議が火曜日、連邦議会議事堂で再開された。交渉担当者たちは、同法案の最終局面であり、最も頑固な障害となってきた文言の整理に取り組んでいる。
記者のエレノア・タレットによれば、議員らは並行してDeFiの条項についても協議しているが、倫理がなお立法を止めている最大の引っかかりだという。2つの流れは同時に進んでいるものの、内情を知る関係者によれば、何よりも先に倫理の問題が決着する必要があるとしている。
シンシア・ルミス上院議員のスポークスマンは、決議が近づいているかもしれないことを最も明確に示す兆候だとしている。交渉の状況について聞かれると、そのスポークスマンは先週、ルミス氏の事務所とホワイトハウスの間で行われた会話がうまくいったと述べ、今後数日で公表される見込みの倫理に関する文言が、その有意義な協議内容を反映することになるだろうとした。
ログインして、さらにコンテンツを読む
厳選トピックで世界の暗号資産トレーダーの仲間入り
⚡️ 暗号資産に関する最新かつ有益な情報が見つかります。
💬 世界最大の暗号資産取引所から信頼されています。
👍 認証を受けたクリエイターから、有益なインサイトを得られます。
メール / 電話番号
サイトマップ
Cookieの設定
プラットフォーム利用規約