# Vulnerability Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Vulnerability", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

CertiK's Director Lau Believes Artificial Intelligence Brings Net Benefits Despite Risks

In an interview with Bitcoin.com News, Kaijern Lau, senior director of engineering at blockchain security firm CertiK, discussed the dual role of artificial intelligence (AI) in both cyberattacks and defensive security measures. He acknowledged that while AI accelerates vulnerability discovery and enables sophisticated, machine-speed attacks—as demonstrated by the recent autonomous AI agent breach of Hugging Face—it simultaneously offers substantial defensive benefits. Lau emphasized that human oversight remains essential for verifying AI-generated findings and mitigating false positives. He cited research into hardware wallet vulnerabilities as an example where AI aids in pattern recognition, but expert validation is still crucial. Regarding the Hugging Face incident, he noted it was a controlled test case and not proof of uncontrollable AI, though it highlighted AI's evolving capabilities in chaining together vulnerabilities for coordinated attacks. Lau asserted that AI-powered security is becoming the norm for code-based industries like Web3 and blockchain. Companies must invest in AI-driven defenses to counter adversaries who are also leveraging AI for more advanced attacks. CertiK is actively developing AI tools such as the AI Skill Scanner to assess AI agent risks and the AI Auditor for automated blockchain project analysis, employing a multi-model, multi-agent approach to enhance security accuracy. Overall, Lau believes AI will be a net positive for Web3 security, but it requires a continuous balancing act, as it lowers the barrier for attacks while significantly boosting defensive efficiency and threat detection scale for organizations like CertiK.

cryptonews.ru2 days ago 13:47

CertiK's Director Lau Believes Artificial Intelligence Brings Net Benefits Despite Risks

cryptonews.ru2 days ago 13:47

Bitcoin 'Red Team' Uncovers 4,962 Vulnerabilities Following Coldcard Hack

A security vulnerability in the Coldcard hardware wallet led to the theft of over 1,800 BTC (worth more than $116 million at the time) from long-term holders, stemming from a firmware bug first identified in March 2021. This incident prompted the formation of the volunteer 'Bitcoin Red Team,' led by developer Calle and Rob Hamilton, CEO of custody insurance firm Anchorwatch. The team conducted an emergency audit of the broader open-source Bitcoin ecosystem. Sixteen security researchers spent 27.5 hours analyzing 390 Bitcoin-related open-source repositories, combining AI-assisted analysis with manual review. They documented a total of 4,962 vulnerabilities, including 85 classified as critical and 635 as high severity. Funding was provided by the non-profit OpenSats. The team described the ecosystem's security state as "extremely poor," though only about one-fifth of the findings have been independently reproduced so far. The highest concentration of critical issues was found in privacy and coinjoin tools, accounting for 24% of critical finds. Cryptographic libraries had the highest absolute number of issues (1,101) but a lower proportion of high-severity ones. Most analyzed projects had few or no critical problems, with the real danger concentrated in a small group of tools handling private key generation, signing, and privacy-preserving transactions—the same category responsible for the original Coldcard failure. The audit is the first phase of an ongoing effort. The next steps involve verifying which vulnerabilities are actually exploitable and coordinating responsible disclosure with affected projects. For the self-custody community, the audit shows white-hat researchers are now scaling their efforts to match the pace of potential attackers.

cryptonews.ru2 days ago 13:40

Bitcoin 'Red Team' Uncovers 4,962 Vulnerabilities Following Coldcard Hack

cryptonews.ru2 days ago 13:40

Security Analyst Points Out Vulnerability in Tether's Blockchain Transaction Freezing Process

A blockchain security analyst has pointed out a vulnerability in Tether's transaction freezing process. Darcy, co-founder of FlashRescue, revealed that targeted funds were drained from a wallet while Tether was in the process of freezing it. This criticism highlights a significant time gap between the freeze request and its final blockchain confirmation, which is managed by a multi-signature wallet mechanism. An analysis of 2,955 Tether freeze events on Ethereum and TRON showed an average delay of 2 hours, 16 minutes, and 15 seconds. During this window, at least 60 addresses managed to completely empty their assets, transferring a total of $20.4 million in USDT, often starting just 14 minutes after the freeze proposal. Another 113 addresses transferred part of their assets, totaling approximately $35.5 million, before the freeze took effect. A notable public example was Tether's action against Iran's central bank in July. Following OFAC sanctions on four TRON wallets holding over $165 million in stablecoins, Tether froze $131 million, but around $34 million had already been moved by the time of the freeze. While Tether is often praised for its speed compared to competitor Circle, which faces criticism for inaction and only freezes wallets based on law enforcement or court orders, this execution gap presents a risk. Tether stated it coordinates directly with investigators during active cases and has collaborated with over 340 agencies across 65 countries, helping freeze assets worth over $4.4 billion. However, analysts warn that once stolen funds are mixed with unrelated money on certain addresses, recovery becomes nearly hopeless as Tether rarely freezes pools with unverifiable origins.

cryptonews.ru08/06 20:10

Security Analyst Points Out Vulnerability in Tether's Blockchain Transaction Freezing Process

cryptonews.ru08/06 20:10

Hackers Breached a Popular Library for JS Developers: Why the npm Vulnerability is Dangerous for Crypto

Hackers have compromised the popular JavaScript utility 'keyv' through a developer account, triggering a major supply-chain attack. Starting August 4, 2026, they injected malicious code into new versions. The code auto-executes during the routine `npm install` command, stealthily downloading malware onto developers' machines. The malware hunts for highly sensitive data: npm and GitHub credentials, AWS cloud keys, SSH access, KeePass files, IDE configurations, and—critically—cryptocurrency wallet files, seed phrases, and private keys for networks like Solana and Monero. Stolen data is encrypted and exfiltrated via public GitHub repositories and servers contacted through an Ethereum smart contract. The worm self-propagates by using stolen credentials to publish infected updates to other popular npm packages, deepening its persistence. Current estimates indicate between 444 and 868 packages (over 1,300 versions) are affected. This incident is particularly dangerous for the crypto industry. A breach on a developer's machine can grant attackers access to project code, servers, and ultimately lead to major fund thefts. Analysis suggests this is the third wave of the 'Shai-Hulud' campaign, highlighting systemic trust issues within the npm ecosystem rather than a one-off event. It underscores that even routine actions can pose severe risks, urging crypto teams to exercise extreme caution with their tooling.

cryptonews.ru08/06 15:51

Hackers Breached a Popular Library for JS Developers: Why the npm Vulnerability is Dangerous for Crypto

cryptonews.ru08/06 15:51

活动图片