# Exploit Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Exploit", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

Aztec Hacker Transfers 500 ETH to Tornado Cash Amid Record Year of Hacking Attacks

A hacker exploited the deprecated Aztec Connect bridge in June, stealing approximately 2.19 million dollars in crypto. According to blockchain security firm PeckShield, the attacker has now sent an additional 300 ETH (worth about $572,100 at the time) to the Tornado Cash mixer on August 8th, bringing the total amount laundered through the service to 500 ETH. The stolen funds, which originally included 909 ETH, are being transferred in irregular, smaller batches over time, contrasting with the rapid laundering patterns seen in other major crypto hacks. This slow, methodical approach does not fully conceal the funds. While Tornado Cash aims to break the on-chain link between deposits and withdrawals, transaction timing and behavioral analysis can still reveal patterns. Security analyses by firms like Blockaid indicate the exploit did not breach Aztec's core cryptography but rather exploited a flaw in proof verification and settlement boundaries within the obsolete system. The current Aztec Network and its AZTEC token were unaffected. The incident occurs amidst a record number of crypto hacks in the first half of 2026 (207 incidents), though total losses have decreased. Tornado Cash remains a significant tool for laundering illicit funds in the ecosystem. The case highlights the persistent risks associated with deprecated smart contracts and funds within legacy systems long after a protocol is sunset.

cryptonews.ru15h ago

Aztec Hacker Transfers 500 ETH to Tornado Cash Amid Record Year of Hacking Attacks

cryptonews.ru15h ago

Canadian Users Account for 25% of Losses Related to Coldcard Vulnerability

Canadian Bitcoin users suffered the highest losses, accounting for 25% of the total, from a vulnerability affecting the Coldcard hardware wallet, a situation analysts link to the strong local presence of its parent company Coinkite headquartered in Toronto. Australia followed with 15-20% of losses, while the US and Thailand accounted for 10-15%. Though the exploit hit English-speaking and early Bitcoin-adopting regions hardest, global impact was seen across Western Europe, Latin America, and key African crypto hubs. The total stolen assets reached $116 million. Galaxy Research identified a March 2021 firmware update—specifically the faulty implementation of a new random number generator (RNG)—as the single point of failure. A configuration error rendered the hardware RNG inactive, silently defaulting to a weaker software-based one, which generated private keys with low entropy for over five years before an attacker stole $70 million from 1,200 wallets in 41 minutes. In response, security experts urged manufacturers to eliminate backup RNG mechanisms in production and strictly adhere to validation standards like NIST FIPS 140-3. For incident response, immediate user communication and clear mitigation steps were prioritized alongside rigorous patch testing. For users with compromised seed phrases, a strict protocol was recommended: purchase a new reputable hardware wallet, generate a new seed offline, verify it with a test transaction, transfer all funds to the new setup, *then* attempt to update the original device's firmware. Experts also advised diversifying risk by using hardware wallets from different manufacturers to avoid a single point of failure. The incident sparked a fundamental debate about self-custody security models. Critics argue that offline storage alone isn't foolproof, highlighting that trust is always delegated to third parties, like wallet manufacturers. The consensus is shifting towards multi-vendor setups and mandatory baseline standards like multi-signature or Multi-Party Computation (MPC) wallets. The goal is to move from "trusting one device" to ensuring no single compromised component or entity can move funds, distributing trust across independent organizational and technological failure domains.

cryptonews.ru2 days ago 13:51

Canadian Users Account for 25% of Losses Related to Coldcard Vulnerability

cryptonews.ru2 days ago 13:51

活动图片