# Theft Articoli collegati

Il Centro Notizie HTX fornisce gli articoli più recenti e le analisi più approfondite su "Theft", coprendo tendenze di mercato, aggiornamenti sui progetti, sviluppi tecnologici e politiche normative nel settore crypto.

Unbelievable! Cosmos Publishes High-Risk Patch Without Prior Notice, Hackers 'Empty' Project Treasuries First

A series of preventable security attacks recently struck multiple Cosmos ecosystem blockchains—including MANTRA, TAC, KiiChain, and Nesa—all built using the Cosmos EVM module. Attackers drained protocol treasury wallets and dumped the stolen tokens, causing assets like KII, TAC, and NES to plunge over 90% within hours. The root cause was a critical security vulnerability. On August 19, Cosmos Labs publicly released version v0.7.2 on GitHub, containing an urgent security patch. However, they failed to privately notify or coordinate with the dependent project teams beforehand, leaving the exploit details openly accessible. This allowed malicious actors to study and execute attacks before most teams could respond. Affected projects like KiiChain criticized Cosmos Labs for bundling the critical fix with unrelated updates and not treating it with the necessary urgency, such as recommending chains to pause operations. The exploit combined three upstream flaws in the Cosmos EVM module, affecting any chain with vesting accounts enabled. Despite some teams, like MANTRA, identifying the issue early, attacks continued for days. Nesa’s token crashed 94% before the team halted its chain. Cosmos Labs eventually issued a belated response, advising chains to pause, but widespread criticism highlighted a severe failure in vulnerability disclosure, patch coordination, and ecosystem communication. This incident underscores deep flaws in Cosmos's security auditing, cross-chain coordination, and emergency response systems, further damaging confidence in an ecosystem already facing significant project departures and declining traction.

marsbit10 h fa

Unbelievable! Cosmos Publishes High-Risk Patch Without Prior Notice, Hackers 'Empty' Project Treasuries First

marsbit10 h fa

Coldcard Theft Reflection: Source Code Visibility Does Not Equal Security

The article examines the open-source vs. closed-source debate in crypto, prompted by a theft of over $100M in Bitcoin from Coldcard hardware wallets. It clarifies key terminology: true "Free and Open Source Software" (FOSS) grants four essential freedoms (use, study, share, modify), while "source available" code, like Coldcard's firmware, may have usage restrictions. The piece argues that visible source code alone does not guarantee security; actual safety depends on the economic incentives for thorough, ongoing review by skilled individuals. Using Bitcoin Core as a model, the article describes a successful, transparent open-source development culture built on public review and consensus. It contrasts this with the Coldcard case, where a critical bug in a lightly-reviewed, source-available library went undetected for years, highlighting a "tragedy of the commons" scenario where assumed but absent scrutiny creates vulnerability. The economics of licensing are crucial: restrictive licenses can limit the pool of motivated commercial reviewers. Finally, the article explores AI's impact. It cites the Bitcoin Red Team's use of AI to rapidly audit codebases and find vulnerabilities at scale, demonstrating a powerful new tool for security. However, AI also floods projects with low-quality code, straining maintainers. The piece concludes that in high-stakes crypto, only well-audited projects—whether open or closed-source—can withstand evolving threats, with AI both challenging and aiding security practices.

marsbit2 giorni fa 07:10

Coldcard Theft Reflection: Source Code Visibility Does Not Equal Security

marsbit2 giorni fa 07:10

Russian Suspected of Stealing Cryptocurrency from Cold Wallet Worth Almost 10 Million Rubles

Russian authorities are investigating a suspect accused of stealing nearly 10 million rubles worth of cryptocurrency from a cold wallet. According to investigators, the wallet belonged to an unnamed commercial company executive's assistant. In March, the suspect allegedly gained access to the victim's wallet by "an unidentified method" and transferred the digital assets to another address. During a search of the suspect's home, police seized three computers and three mobile phones for forensic examination, as they may contain important digital evidence. The case is being investigated as grand larceny under the Russian Criminal Code, carrying a potential sentence of up to ten years in prison. Police are also checking the suspect's possible involvement in other cryptocurrency thefts and identifying potential accomplices. The article notes that while cold wallets (hardware wallets storing private keys offline) are considered more secure against remote hacking, they remain vulnerable if a perpetrator gains physical or direct access to the keys. In a related case earlier in June, a court in Tomsk sentenced two men to 8 and 9.5 years in a strict-regime colony for a robbery and cryptocurrency theft. They forced an acquaintance at knifepoint to log into a crypto exchange account and transfer over 85 bitcoins, valued at approximately $5.1 million at the time.

cryptonews.ru08/19 22:17

Russian Suspected of Stealing Cryptocurrency from Cold Wallet Worth Almost 10 Million Rubles

cryptonews.ru08/19 22:17

活动图片