# Cybersecurity Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Cybersecurity", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

Going Undercover in Southeast Asia's Black and Gray Market Communities: Openly Priced Human Trafficking, Personal Information Inquiries, and Money Laundering in One Package

Investigation into Southeast Asia's crypto-facilitated black and gray industries reveals a highly organized criminal ecosystem, utilizing USDT as its core financial artery. The operation involves a complete industrialized chain: human trafficking sourced via Telegram groups with individuals priced in USDT; illegal data harvesting ("record checking") for targeted scams; and readily available technical services for creating sophisticated fake trading platforms and apps. The fraud process is equally systematic, employing "phone port" operations to mask international calls, targeted引流 (traffic acquisition) tactics, and "precise chat" phases using AI-generated personas and scripts to build trust. Finally, illicit proceeds are laundered through a "card-to-USDT" process, making funds difficult to trace. Central to this network are illegal cryptocurrency escrow platforms (e.g., Xindan, Dali), acting as hubs that connect service providers with criminal groups. These platforms facilitated over 3.4 billion USDT in inflows in the first half of 2026. Their promotional content has even infiltrated mainstream social media platforms. The article details real-world fraud cases, including fake exchange "arbitrage pools" and impersonation DApps that trap victims. It concludes with five key anti-fraud guidelines: avoid "side hustle" schemes involving bank/crypto transfers; protect personal data; recognize "pig-butchering" scam patterns (building rapport then pushing fake investments); use only reputable crypto platforms; and remain vigilant against too-good-to-be-true offers online.

marsbitYesterday 05:41

Going Undercover in Southeast Asia's Black and Gray Market Communities: Openly Priced Human Trafficking, Personal Information Inquiries, and Money Laundering in One Package

marsbitYesterday 05:41

AI Will Destroy Cryptocurrency? Vitalik: Don't Panic, 90% of My Net Worth Is My Bet

Ethereum co-founder Vitalik Buterin has publicly countered a prediction that AI will cause Bitcoin's price to crash by over 50% within two years. The debate originated from AI risk commentator Liron Shapiro, who argued that AI could erode trust in Bitcoin's network security, even without breaking its core cryptography. Buterin remains optimistic about long-term network security, stating that issues not requiring full social consensus for fixes—like attacks on clients, mining pools, or infrastructure—are manageable. He believes AI is highly unlikely to compromise Bitcoin's underlying proof-of-work or hash functions, noting his personal stake aligns with this view as roughly 90% of his wealth is in crypto. The discussion highlights a key market divergence on AI's impact. Shapiro's point is that exposing critical security weaknesses in surrounding ecosystem elements (wallets, bridges, exchanges, smart contracts) could severely damage market confidence, even if Bitcoin's core remains intact. Real-world incidents, like the AI-driven automated attacks that forced Boltz to halt operations, demonstrate such threats are already testing crypto defenses. Security experts warn AI-powered smart contract exploits could lead to billions in losses. The broader tech and crypto industries are now in an arms race to develop defensive AI tools that can keep pace with offensive capabilities. Initiatives like Anthropic's Glasswing project, involving major firms, aim to proactively find and patch vulnerabilities. Over 100 organizations, including tech giants and financial institutions, have signed an open letter warning of increasingly sophisticated AI-powered cyber attacks, urging enhanced protection for critical infrastructure. The core question is not whether AI can "destroy Bitcoin," but whether defensive measures, audits, and infrastructure upgrades can be implemented quickly enough to prevent attackers from gaining a decisive, confidence-shattering advantage in the crypto ecosystem.

marsbit2 days ago 03:21

AI Will Destroy Cryptocurrency? Vitalik: Don't Panic, 90% of My Net Worth Is My Bet

marsbit2 days ago 03:21

Ledger and Trezor call for standardization of vulnerability disclosure

Ledger's CTO, Charles Guillemet, and Trezor have called for the standardization of coordinated vulnerability disclosure as an industry norm. Guillemet's open letter proposes a standardized four-step process: confidential reporting, reproduction, confirmation, and an agreed-upon fix timeline, with 90 days as a baseline. The initiative, supported by Trezor, Foundation, and others, highlights the urgency of responsible practices as AI tools make finding bugs easier and cheaper, potentially leading to premature public disclosures that harm users. Guillemet outlined three problematic scenarios: repackaging patched bugs as active threats, full disclosure before a fix, and teasing vulnerabilities for social media attention. He issued three calls: for users to update software promptly, for new AI-assisted researchers to report through official channels, and for companies to reward responsible disclosure and avoid amplifying irresponsible reports. Trezor's head of security, Jan Komarek, echoed the sentiment, emphasizing security as a continuous cycle and warning that premature disclosure can cause secondary damage like phishing scams. He cited a recent Liquid Network incident, where funds were withdrawn to highlight a bug, as a violation of responsible disclosure principles. The call follows a recent dispute between Ledger and security firm TestMachine over the disclosure timeline of an Ethereum app vulnerability, which Ledger claims was patched prior to public reporting. In summary, industry leaders are advocating for a unified, responsible approach to vulnerability disclosure to protect users in the cryptocurrency ecosystem, especially as AI lowers the barrier to finding exploits.

cryptonews.ru09/07 18:51

Ledger and Trezor call for standardization of vulnerability disclosure

cryptonews.ru09/07 18:51

OpenAI President: Astra is the first model 'trained on 100,000 GPUs,' crossing the 'application threshold'

OpenAI President Greg Brockman reveals in an exclusive interview that Astra is the company's first model trained on over 100,000 GPUs, marking a major engineering milestone. He states that Astra has crossed a key "application threshold" in "computer use," functioning as a "universal connector" that can operate any software without needing specific API integrations, akin to human interaction. Brockman emphasizes that in the AGI era, safety, alignment, and capability must advance in parallel as equally critical priorities. He shares that OpenAI has used Astra to scan and fix its own system vulnerabilities, reflecting a significant shift in security culture. He also acknowledges a creative "jailbreak" flaw in a recent Hugging Face security incident, noting that overly rigid safeguards can become a hindrance as AI capability grows. Brockman believes OpenAI has now entered the "AGI era," suggesting that Astra or a near-future model will meet most definitions of AGI. On strategy, he stresses that OpenAI's massive consumer base (e.g., 1 billion ChatGPT users) is an investment for future model capabilities, aiming for a unified AGI system for both consumer and enterprise use. Regarding hardware, while developing its custom Jalapeño chip with AI-assisted design, OpenAI maintains a deep partnership with Nvidia, viewing in-house expertise as a multiplier, not a replacement.

marsbit09/07 02:17

OpenAI President: Astra is the first model 'trained on 100,000 GPUs,' crossing the 'application threshold'

marsbit09/07 02:17

G7 Warning on Quantum Attacks Accelerates Transition to New Cryptographic Security System

The G7 cybersecurity working group urges countries and businesses to immediately begin transitioning to post-quantum cryptography, a warning directly relevant to crypto networks, exchanges, and custodians who must undertake costly system upgrades before quantum computers threaten modern encryption. Their report, while not mentioning cryptocurrencies specifically, highlights the risk quantum computing poses to public-key cryptography, which underpins crypto transactions. A key concern is the "harvest now, decrypt later" strategy, where encrypted data is collected for future decryption, a threat also applicable to blockchain's publicly visible keys. Europe has set concrete deadlines, mandating that all EU member states begin their transition by the end of 2026, with high-risk systems completing it by 2030. This shifts quantum readiness from a technical issue to a regulatory and competitive necessity. Bitcoin and Ethereum are pursuing different upgrade paths. Bitcoin's BIP-360 proposal aims to mitigate long-term quantum vulnerabilities, while Ethereum's broader roadmap targets upgrades to validator signatures, commitments, and zero-knowledge proofs by 2029. A major challenge is the increased data size of post-quantum signatures, which could raise storage, bandwidth, and transaction costs. The immediate market risk is not a quantum attack itself, but the complex preparation for it: governance debates, protocol development, infrastructure changes, and the vulnerability of old wallets with exposed keys. With entities like Google accelerating their migration timelines and NIST proposing phase-out dates for current standards, having a migration plan is becoming a competitive advantage.

cryptonews.ru09/05 16:18

G7 Warning on Quantum Attacks Accelerates Transition to New Cryptographic Security System

cryptonews.ru09/05 16:18

OpenAI Unveils GPT-6 Astra: The Era of Human-Level AI Begins

OpenAI officially unveiled GPT-6 Astra on September 3, hailing it as the world's most intelligent flagship model. It integrates the company's research in pre-training, reinforcement learning, and human alignment. OpenAI claims Astra achieves state-of-the-art results in computer tasks, web search, software development, cybersecurity, science, and professional benchmarks. The model scored 98% on FrontierMath Tier 4, 99.9% on ARC-AGI-3, and 100% on ExploitBench for vulnerability-to-exploit conversion. President Greg Brockman stated this launch marks the beginning of the era of Artificial General Intelligence (AGI). OpenAI emphasized major safety improvements, noting Astra shows 0% unauthorized goal overreach in complex request scenarios, a significant reduction from the 48% rate of GPT-5.6 Sol. Internally, Astra has reached a "Critical" cybersecurity level under OpenAI's Preparedness Framework. The model was initially released to a limited group but will soon roll out to ChatGPT Plus, Pro, Business, Enterprise users, and via APIs. Enterprise administrators must manually enable access. Notably, the analysis points out a rapid shift from OpenAI's August 7th pause in development due to potential "Critical" cybersecurity risks to the public release with that status confirmed less than a month later. This raises questions about whether Astra's safety guardrails, validated in controlled benchmarks, will hold under real-world, unpredictable user conditions.

cryptonews.ru09/04 08:31

OpenAI Unveils GPT-6 Astra: The Era of Human-Level AI Begins

cryptonews.ru09/04 08:31

US and Europe Disrupt Sality Botnet Used for Cryptocurrency Theft

The U.S. Department of Justice announced an international operation to disrupt the Sality botnet, used for spreading malware, cyberattacks, and cryptocurrency theft. The operation, conducted on August 31, 2026, involved U.S., Bulgarian, Hungarian, and Romanian authorities with support from Europol and Eurojust, along with CrowdStrike and Shadowserver Foundation. Law enforcement seized Sality-related domains, while CrowdStrike executed a sinkhole operation to isolate infected devices from the botnet operators. Europol data indicates the infrastructure was linked to over 11 million unique IP addresses, with up to 1 million devices controlled at its peak. At the time of disruption, it could still spread malware to over 15,000 machines globally. First appearing in 2003, Sality evolved from a file virus into a decentralized P2P botnet, allowing infected devices to communicate directly, making it resilient. It distributed credential-stealing tools, proxy software, and DDoS malware. For the past eight years, a key component was EggJagger, a clipper that hijacked copied Bitcoin and Ethereum wallet addresses, redirecting funds to the attacker. CrowdStrike estimates at least $150,000 in cryptocurrency was stolen via EggJagger alone. The takedown exploited the network's architecture by removing active Sality nodes and replacing them with controlled sinkhole servers, cutting off command flow. Shadowserver is working with ISPs to identify remaining infected devices. CrowdStrike links Sality to the Russian-speaking cybercriminal group SALTY SPIDER. Overall, since the start of 2025, cyber incidents involving crypto platforms have caused $3.63 billion in losses.

cryptonews.ru09/03 11:29

US and Europe Disrupt Sality Botnet Used for Cryptocurrency Theft

cryptonews.ru09/03 11:29

活动图片