# Security Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Security", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

ZEUS shuts down its infrastructure following a hacker attack; this is the third Lightning network outage within a week

On August 5, the ZEUS wallet disabled its Lightning services following a cybersecurity incident, becoming the third major Lightning service provider (after Boltz and AQUA) to halt operations within roughly 72 hours. ZEUS confirmed the attack was contained and no user funds were lost. These sequential outages raised user concerns about the security of Lightning infrastructure providers, though not about the underlying Bitcoin Lightning Network itself. Broader crypto markets showed little reaction, with Bitcoin trading around $64,600. ZEUS founder Evan Kaloudis stated the company disabled its infrastructure for a comprehensive security audit. While customer channels were affected, ZEUS assured that funds were safe and promised replacement liquidity service provider (LSP) channels upon restoration. Despite the disruptions, analytics from Lightning Amboss indicated the overall Lightning Network remained healthy. Public network capacity and channel count actually saw slight increases during the week of the incidents. The events are seen as highlighting risks associated with centralized dependencies within the Lightning ecosystem, reinforcing the value of self-custody and decentralized node operation. ZEUS stated the incident will strengthen its security measures, referencing its prior SOC 2 audit and plans to implement technologies like Validating Lightning Signer (VLS) to enhance long-term security.

cryptonews.ru08/06 11:20

ZEUS shuts down its infrastructure following a hacker attack; this is the third Lightning network outage within a week

cryptonews.ru08/06 11:20

Ethereum Team Explains How AI Is Changing the Approach to Smart Contract Security

The Ethereum team published a guest post series by a leading Vyper developer under the pseudonym "big_tech_sux," focusing on the role of formal verification in the era of rapidly advancing AI. The author argues that progress in Large Language Models (LLMs) is making the mathematical proof of program correctness more accessible. For smart contracts managing billions of dollars, formal verification is gradually becoming a necessity. Formal verification is a mathematical method that proves a program works correctly for all possible execution scenarios, not just those covered by tests. It can find extremely rare bugs that are practically impossible to detect through conventional testing. While previously requiring large teams of experts, modern LLMs significantly simplify this process as they approach Artificial General Intelligence (AGI). However, the author notes that formal verification remains complex and resource-intensive, even with AI assistance. The development of AI simultaneously increases the effectiveness of both defenders and attackers. Formal verification can shift the advantage toward defenders, as they can use it to prove a system's resilience to *all* possible inputs, whereas an attacker only needs to find one exploitable sequence. Therefore, for critical software like high-value smart contracts, formal verification is becoming "not an option, but a necessary prerequisite." This continues a discussion previously initiated by Ethereum co-founder Vitalik Buterin on using AI for formal code verification.

cryptonews.ru08/06 11:20

Ethereum Team Explains How AI Is Changing the Approach to Smart Contract Security

cryptonews.ru08/06 11:20

Dice vs. Hackers: Why South Korean Bitcoiners Escaped the Coldcard Hack Unscathed

South Korea's Bitcoin community suffered minimal direct losses from the recent Coldcard hardware wallet hack, despite the device's popularity among its most experienced users. An error in random number generation in certain Coldcard models allowed attackers to access vulnerable seed phrases, leading to the theft of over 1,596 BTC (approx. $130M) from thousands of addresses globally. Analyst Koji Higashi attributes Korea's resilience not to luck, but to a long-standing community culture of self-custody and caution. Local leaders have long promoted generating seed phrases independently from any device, relying on offline, analog methods like dice rolls or coin flips to create true randomness, followed by offline BIP39 phrase creation and verification. In contrast, English-speaking self-custody communities, despite high technical literacy, experienced more significant losses. Higashi links this to greater reliance on influencers, some with ties to the manufacturer (Coinkite), creating an echo chamber of trust in the device's security without independent verification. Korean leaders, lacking commercial ties, provided more neutral risk assessments that their followers heeded. The incident underscores applying Bitcoin's "don't trust, verify" principle not just to code, but to information sources. The key takeaway is to create seed phrases using independent physical methods where possible and to default to distrusting any device's built-in random number generator.

cryptonews.ru08/06 10:51

Dice vs. Hackers: Why South Korean Bitcoiners Escaped the Coldcard Hack Unscathed

cryptonews.ru08/06 10:51

Ethereum Community in Uproar! Whose Cake is EIP-8363 Cutting Into?

**Ethereum Community Debates Controversial Staking Proposal EIP-8363** A new Ethereum proposal, EIP-8363, dubbed "Tapered Issuance Burn," has ignited heated debate within the community. The core idea is to reduce and eventually eliminate new issuance rewards for validators as the total amount of staked ETH approaches 50% of the total supply (around 60.25 million ETH). The authors, including EthCC founder Jérôme de Tychey and Ethereum Foundation researcher Justin Drake, argue the current system perpetually incentivizes more staking, potentially leading to centralization as stake flows to large custodians and liquid staking tokens (LSTs). They also aim to reduce dilution pressure on non-staking ETH holders. Under the proposal, validator rewards from consensus-layer issuance would be partially burned based on a formula tied to the total staked amount. Net rewards would gradually approach zero as staking nears the 50% threshold. Notably, execution-layer rewards (tips, MEV) are unaffected. A proposed 18-month transition period would soften the initial impact. The community reaction has been predominantly critical. Key concerns include: * **Centralization Risk:** Critics like Obol's Oisín Kyne argue very low rewards could drive out solo stakers and smaller operators, leaving only large, cost-insensitive institutions, thus increasing validator centralization. * **Ecosystem Impact:** Aave's Stani Kulechov warns it could hurt ETH's predictable yield appeal for institutions and compress yields for LST-based DeFi strategies (e.g., recursive lending). * **Process & Timing:** Some, like ether.fi's Mike Silagadze, criticize the proposal's late submission ahead of a key upgrade deadline, limiting discussion time. Supporters believe the change is necessary to maintain ETH as a neutral reserve asset and avoid excessive security costs and holder dilution. If implemented, solo stakers would face higher relative operational costs and longer recovery times from penalties. LST yields would converge with native ETH, challenging their value proposition. The entire DeFi interest rate ecosystem, built around staking yield, could be pressured. While all ETH holders would benefit from reduced dilution, the net effect on ETH's price and adoption remains uncertain due to potential demand-side impacts from lower yields. The proposal is currently an early-stage draft and has not been officially slated for inclusion in any upcoming network upgrade.

marsbit08/06 05:22

Ethereum Community in Uproar! Whose Cake is EIP-8363 Cutting Into?

marsbit08/06 05:22

Bitcoin Price Fluctuates Around $64,000 as Coldcard Losses Exceed $116 Million

Bitcoin's price is holding around $64,000 despite significant negative pressure. Losses from a vulnerability in Coldcard hardware wallets have surpassed $116 million, with thefts continuing in waves. Michael Saylor's MicroStrategy sold another 1,638 BTC (its third sale this year), and wallets linked to the firm moved a further 1,030 BTC, raising fears of a fourth sale. In Washington, the "Clarity Act" bill faces likely failure after Democratic senators blocked negotiations. The Coldcard flaw, stemming from a March 2021 firmware bug, caused some devices to generate seeds with only ~40 bits of entropy instead of 128, exposing long-term holders to brute-force attacks. Developer James O'Beirn launched a public dashboard tracking the ongoing thefts in real-time; a test wallet with no added entropy was drained within an hour. Coinkite has halted shipments and urged affected users to move funds immediately, as firmware updates alone cannot eliminate the risk. For bulls, a potential floor is seen around Bitcoin's production cost, currently estimated at $54,000 (with an energy cost component of ~$40k). Historically, prices have bottomed below this cost in previous cycles. Meanwhile, exchange inflows have spiked as worried Coldcard users transfer coins, and with MicroStrategy still holding $5 billion in approved sales, alongside the potential collapse of the Clarity Act, further downward pressure looms.

cryptonews.ru08/05 19:02

Bitcoin Price Fluctuates Around $64,000 as Coldcard Losses Exceed $116 Million

cryptonews.ru08/05 19:02

Coldcard Urges Users to Move Bitcoin as Vulnerability Remains Exploited

Coldcard has urgently warned users to move their Bitcoin holdings, confirming on Tuesday that a vulnerability—which has already led to the theft of up to $114 million from self-custody wallets—remains actively exploited. The company stressed this is not a precautionary alert, citing a fourth wave of fraudulent transactions on Monday that drained approximately 449 BTC from 709 addresses. The flaw, dormant since 2021, involves firmware in cases where funds are controlled by a single key without a second confirmation. Users of Mk3 models (with firmware 4.0.1 or later) must transfer funds immediately. Owners of Mk4, Mk5, and Q models with firmware below 5.6.0 or 1.5.0Q should update firmware, generate a new wallet, then move coins. The vulnerability is tied to insufficient entropy during seed phrase generation, potentially allowing attackers to guess the key and drain wallets remotely. An exception is made for users who employed the device’s “dice roll” feature for key generation, as those wallets never touched the compromised code. Vincent Buzon, a cybersecurity expert at rival hardware wallet maker Ledger, noted the incident stemmed from an implementation failure, emphasizing that secure entropy generation must be hardware-based. He warned that software wallets on unprotected devices are riskier, and holding funds on centralized exchanges represents “not ownership, but an IOU.” Bitcoin traded around $63,800 in the U.S. on Tuesday, largely unaffected by the wallet warning.

cryptonews.ru08/05 18:05

Coldcard Urges Users to Move Bitcoin as Vulnerability Remains Exploited

cryptonews.ru08/05 18:05

活动图片