# Security Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Security", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

BSC Confirms Pasteur Hard Fork Release Date at the End of August

BNB Chain has confirmed that the Pasteur hard fork for the BNB Smart Chain (BSC) mainnet will activate at 02:30 UTC on August 25, 2026. Node operators must upgrade to client version 1.7.7 by that time to avoid network disconnection. The hard fork, packaged under the BEP-673 meta-proposal, consolidates three other proposals: BEP-682, BEP-695, and BEP-675. BEP-682 aims to secure cross-chain bridges by fixing a vulnerability where validator signatures in asset transfers could be counted multiple times, allowing a threshold to be met with fewer genuine signatures. The update ensures duplicate signatures are removed before counting. BEP-695 addresses a flaw in staking and governance systems where a validator's old consensus key, after being rotated for maintenance, could retain its administrative privileges. The fix ensures retired keys immediately lose their authority and prevents validators from avoiding slashing through key rotation. BEP-675 aims to increase network throughput. It allows a block proposer to submit a pre-executed block, reducing the time validators spend re-executing transactions. Testnet results showed validator execution time dropped from 125ms to 15ms, and throughput increased by nearly 88% to 2,324 TPS, with average block gas usage rising significantly. Node operators must follow detailed upgrade procedures. Developers using the BEP-675 scheme may need to run a full node instead of a light client, as they are now responsible for creating fully executed blocks.

cryptonews.ru08/14 19:26

BSC Confirms Pasteur Hard Fork Release Date at the End of August

cryptonews.ru08/14 19:26

To Counter Quantum Threat, Ethereum Abandons Poseidon and Switches to Traditional Hashes

On August 13th, Ethereum researcher Justin Drake announced a strategic pivot in the face of the quantum computing threat: the Ethereum Foundation will abandon the SNARK-friendly hash function Poseidon at the L1 level in favor of traditional hash functions like SHA2 or BLAKE2. This decision, informed by eight years of research, represents a major shift in Ethereum's post-quantum cryptography roadmap. Poseidon, introduced in 2019, has been favored for zkRollups and zkVMs due to its efficiency within SNARK circuits. However, its shorter cryptographic history and analysis timeline became liabilities when post-quantum security became a critical requirement. The change is enabled by breakthroughs in SNARK design, particularly the adoption of "binary field" arithmetic. This allows traditional hash functions (which rely heavily on bitwise operations) to be verified efficiently in SNARKs, with recent benchmarks achieving millions of hashes per second on a laptop. Another key driver is the accelerating timeline of the quantum threat. Reports warn that "Cryptographically Relevant Quantum Computers" (CRQCs) could break current public-key cryptography (like ECDSA) as early as the 2030s, risking trillions in on-chain assets. The enhanced cryptanalysis capabilities of AI have also weakened some post-quantum candidates, pushing Ethereum towards hash-based schemes, deemed more quantum-resistant. Ethereum's post-quantum deployment plan aims for a production-ready leanVM by 2027, followed by full deployment across the consensus, execution, and data availability layers by 2028. This leanVM will aggregate numerous large post-quantum signatures into a single compact proof per block. Other major blockchains are also preparing. Solana's core developers have independently chosen the NIST-standardized Falcon signature scheme for their post-quantum roadmap. Starknet has outlined a multi-phase plan, starting with replacing its Pedersen hash with BLAKE2. By moving from the specialized Poseidon to the battle-tested SHA2/BLAKE2, Ethereum is opting for mature, widely analyzed cryptographic primitives, prioritizing long-term security assurance in the quantum era.

marsbit08/14 06:38

To Counter Quantum Threat, Ethereum Abandons Poseidon and Switches to Traditional Hashes

marsbit08/14 06:38

Trezor Customer Data Leak: Coins Are Safe, But Phishing Is Inevitable

Trezor, a hardware cryptocurrency wallet manufacturer, reported a data breach at its logistics partner, ShipMonk, affecting around 13,689 customers. The incident, confirmed on August 13, 2026, involved unauthorized access to ShipMonk's systems, which stored order information from May 10 to August 8, 2026. Trezor's own systems and user crypto assets were not compromised. The leaked data varies: for 11,742 customers, full names, email addresses, phone numbers, and delivery addresses were exposed. For 1,947 others, only name, city, and email were leaked. The breach was limited to customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor warns affected users of an increased risk of phishing attacks, where malicious actors may use the stolen contact details to impersonate Trezor, banks, or exchanges to steal wallet recovery phrases. All impacted customers have been notified via email. In response, Trezor announced a planned "Anonymous Delivery" feature for the EU (September 2026) and the US (end of 2026), aiming to anonymize logistics data. ShipMonk has not yet issued a public statement on its official website. The analysis highlights this as a recurring industry pattern where third-party logistics vendors become weak links in the supply chain, storing data longer than necessary. Similar incidents, like the 2020 Ledger breach, led to prolonged phishing campaigns. A key question remains whether hardware wallets can ever fully decouple from external logistics risks.

cryptonews.ru08/13 21:26

Trezor Customer Data Leak: Coins Are Safe, But Phishing Is Inevitable

cryptonews.ru08/13 21:26

Cryptomarket Loses $14 Billion Due to Hacks. What Was Special About 2026?

The cryptocurrency market lost over $14 billion due to hacks and code exploits from 2016 to 2026, according to a CoinGecko report. The year 2026 has seen a significant spike, with 164 separate incidents recorded as of August—a 70% increase from all of 2025. Although the total financial loss for 2026 currently stands at about $1.2 billion, still below the peak of $2.77 billion in 2022, the number of attacks is unprecedented. Analysts attribute this rise to improved tracking methods and increased malicious activity, possibly fueled by advancements in artificial intelligence. Notable 2026 breaches include the April hacks of Drift and Kelp protocols, resulting in losses of $295 million and $293 million, respectively. The Kelp exploit, linked to North Korean hackers, involved minting unbacked tokens via a LayerZero bridge vulnerability, which were then used as collateral on Aave. This triggered a massive withdrawal of liquidity from Aave and the broader DeFi sector, leading to over $20 billion in sector-wide outflows by August, despite the eventual recovery of the stolen Kelp funds. The report also highlights that market reactions to hacks often inflict greater financial damage than the exploits themselves. For instance, following the BonkDAO hack, the token's market cap fell by nearly $140 million, far exceeding the $21 million direct loss. Other examples include the DRIFT token dropping 80% and Step Finance's token losing over 99% of its value, leading to the protocol's bankruptcy. The analysis notes that the real total damage is likely higher, as it excludes individual wallet breaches and broader ecosystem losses.

cryptonews.ru08/13 20:31

Cryptomarket Loses $14 Billion Due to Hacks. What Was Special About 2026?

cryptonews.ru08/13 20:31

活动图片