# Сопутствующие статьи по теме Security

Новостной центр HTX предлагает последние статьи и углубленный анализ по "Security", охватывающие рыночные тренды, новости проектов, развитие технологий и политику регулирования в криптоиндустрии.

IOSG: DeFi at Its Most Critical Moment, The Real Vulnerability Lies Not in the Code

In April 2026, a series of major DeFi exploits—targeting Drift Protocol ($285M), KelpDAO ($292M via bridge), and Wasabi Protocol ($4.5M)—revealed a fundamental security crisis. None involved smart contract code vulnerabilities. Instead, losses stemmed from compromised operational foundations: social engineering of multi-signature signers, a single-point-of-failure bridge validator, and stolen admin private keys. This month, where over $625M was stolen across ~30 incidents, marked the collapse of DeFi's core security premise: that rigorous code audits alone ensure safety. The real vulnerabilities lay in trusted operational components—admin keys, governance councils, and bridge configurations—areas audits typically ignore. The KelpDAO incident triggered an asymmetric domino effect: its $2.92B unsupported token mint caused ~$8.5B in outflows from Aave and a $13.2B total DeFi TVL drop in 48 hours, showcasing how one protocol's operational failure can cascade through composable systems. The article argues that most so-called "DeFi" is actually "OpenFi": permissionless and transparent on-chain, but critically reliant on trusted third parties for key operations. This inherent trade-off between decentralization and operational feasibility is often obscured by marketing. The industry's path forward requires honest disclosure of trust assumptions (like L2Beat's framework), treating operational security as a first-class discipline alongside code audits, and designing systems whose risks can be clearly assessed and insured. The April events were not a code security failure but a breakdown in the mental model surrounding it.

marsbit05/26 03:08

IOSG: DeFi at Its Most Critical Moment, The Real Vulnerability Lies Not in the Code

marsbit05/26 03:08

Vitalik is Personally 'Dismantling' the Ethereum Foundation

Vitalik Buterin recently published an extensive article addressing core concerns about Ethereum's future direction and the role of the Ethereum Foundation (EF). He clarifies that the EF is not his personal domain nor the central authority of Ethereum; it operates as just one node within the broader ecosystem. The board makes collective decisions, with significant operational work led by Aya Miyaguchi, allowing Vitalik to focus on technical matters. The article critiques the perception that the EF should act like a conventional, fast-moving tech company. Buterin warns that merely chasing higher TPS, lower latency, or better marketing—like other chains—risks diluting Ethereum's foundational values. He draws a parallel to Google's evolution away from its "Don't be evil" ethos. Instead, the EF's renewed mandate is to focus on preserving and strengthening Ethereum's core principles, summarized as CROPS: **C**ensorship-resistance, **R**esistance to capture, **O**pen source, **P**rivacy, and **S**ecurity. The foundation will concentrate its limited resources (holding only ~0.16% of ETH) on these long-term, non-commercializable fundamentals, while ecosystem growth, applications, and market-facing activities should be driven by external teams and capital. Buterin outlines key technical priorities aligned with this vision: 1) Advancing formal verification to mathematically prove the absence of bugs; 2) Enhancing consensus security to maintain operation without reliance on social coordination during outages; and 3) Reducing dependency on intermediaries (like RPCs) to strengthen user sovereignty and privacy. He acknowledges ETH as Ethereum's most valuable asset, crucial for security, but stresses that promoting its value is a task for the wider ecosystem, not the EF. Ultimately, Buterin's message is a strategic refocus: the EF will become a smaller, more focused entity guarding Ethereum's essential, harder-to-achieve properties, ensuring it remains distinct not just in performance but in its commitment to decentralization, resistance, and security.

marsbit05/26 01:48

Vitalik is Personally 'Dismantling' the Ethereum Foundation

marsbit05/26 01:48

Luffa Secures Strategic Investment from Hong Kong Listed Company Guofu Quantum, Post-Money Valuation Reaches $220 Million

On May 26, innovative tech company Luffa AI announced a strategic investment from Hong Kong-listed Guofu Quantum Innovation Ltd. (Stock Code: 00290.HK). Post-investment, Luffa AI's valuation reached $220 million. The two parties will engage in deep strategic collaboration across AI, quantum security, blockchain, and compliant finance to jointly explore the new frontier of AI+Quantum+Blockchain+FinTech. Luffa addresses internet fragmentation—where identities, value, and AI agents are locked within siloed platforms—by building a super-connector across three core dimensions. It leverages decentralized identity (DID), empowers AI agents, and uses on-chain governance for communities. Its content system transforms channels into programmable, tradable value containers for creators. An aggregation layer with its SuperBox mini-program platform, multi-chain wallet, LuffaPay, and multi-agent commercial protocols completes the ecosystem, connecting users, identities, assets, and value. As of February 2026, Luffa's ecosystem has seen rapid growth, surpassing 3 million global downloads, 2 million registered users, and 150,000 daily active users. Its core wallet and SuperBox platform are live, with validated use cases in prediction markets, AI games, RWA, and creator economies. In 2026, Luffa will focus on building an AI-driven Web3 ecosystem. This investment marks a key milestone for Luffa in privacy protection, smart interaction, and Web3 infrastructure. Guofu Quantum, with its expertise in quantum encryption and institutional finance, will provide technological backing to accelerate Luffa's global commercialization. Planned collaborations include joint R&D in AI-driven financial solutions, digital asset exploration, compliant RegTech development, and applying quantum security to blockchain. Luffa CEO Michael Liu stated the partnership will help "create a better network" where users truly own their data and privacy. Guofu Quantum CEO Yuan Tianfu highlighted this as a crucial step in merging quantum tech with AI and Web3.

marsbit05/26 01:44

Luffa Secures Strategic Investment from Hong Kong Listed Company Guofu Quantum, Post-Money Valuation Reaches $220 Million

marsbit05/26 01:44

Research on Commercialization Infrastructure for Crypto Agents: In-depth Analysis of Stablecoin as the Core "Native Currency Layer" and Settlement Network

This article explores the commercialization of AI Agents and the critical "payment gap" they face within traditional financial systems. It argues that stablecoins (like USDC, USDT) provide a superior, native "monetary layer" for AI, enabling programmable, permissionless, 24/7, and transparent value transfer essential for autonomous agents. The piece details infrastructure initiatives from key players: Coinbase's AgentKit and Agentic Wallets for on-chain payments; Circle's CCTP for cross-chain USDC transfers and AgentStack for micro-payments; and Stripe's stablecoin APIs bridging traditional commerce. Collaborations like AWS-Stripe-Coinbase and Google-Coinbase are also highlighted. Key application scenarios are analyzed: 1) DeFi yield optimization, where agents autonomously manage capital across protocols; 2) Ultra-micro-payments (e.g., per API call) enabled by low-fee stablecoin protocols like x402 and Gateway; 3) Automated yield generation through yield-bearing stablecoins, transforming agents into self-sustaining economic units. Major challenges to scaling are identified: private key security and risks like prompt injection; regulatory grey areas regarding agent identity (KYA) and liability; and technical risks including smart contract vulnerabilities and ensuring AI intent alignment during financial operations. In conclusion, the fusion of AI Agents and stablecoins is fundamentally reshaping digital commerce settlement. While security and regulation are immediate hurdles, the infrastructure being built paves the way for a self-operating, agent-driven on-chain economy, shifting humans from transaction approvers to system designers.

marsbit05/26 01:04

Research on Commercialization Infrastructure for Crypto Agents: In-depth Analysis of Stablecoin as the Core "Native Currency Layer" and Settlement Network

marsbit05/26 01:04

DeFi Has Reached Its Most Dangerous Moment: The Real Vulnerabilities Are Not in the Code

DeFi in Peril: The Real Vulnerability Isn't in the Code April 2026 marked a paradigm shift in DeFi security, with over $625 million lost across 30 incidents—the worst month in crypto history by event count. Crucially, none of the major exploits (Drift Protocol: $285M, KelpDAO: $292M, Wasabi Protocol: $4.5M) resulted from smart contract vulnerabilities. Instead, failures occurred in the operational "plumbing": social engineering to compromise multi-signature councils, a single-point-of-failure 1-of-1 bridge validator, and stolen admin private keys. These events expose a fundamental misalignment: the industry's security model has long focused on code audits, while the actual attack surface has shifted to privileged access points and off-chain infrastructure. The article introduces the term "OpenFi" to describe this reality: permissionless, on-chain, yet operationally dependent on trusted third parties (admins, validators, oracles) at key junctures. The KelpDAO exploit vividly demonstrated asymmetric "contagion risk." A configuration error in a smaller protocol triggered a panic, causing approximately $13.2 billion in outflows from larger, unaffected protocols like Aave within 48 hours, as users fled uncertain collateral. The core dilemma is the double-edged sword of centralization. Operational levers like emergency councils (e.g., Arbitrum freezing stolen funds post-KelpDAO) enable crisis response but also create catastrophic attack surfaces if compromised (e.g., Drift). The path forward demands radical honesty: protocols must clearly disclose their trust assumptions, operational levers, and failure modes. The industry must treat operational security (key management, configurations, incident response) with the same rigor as code security. Survival depends on building systems whose risks can be understood, priced, and insured, moving beyond the outdated "code is law" mantra to a mature model of disclosed and managed trust.

链捕手05/25 15:17

DeFi Has Reached Its Most Dangerous Moment: The Real Vulnerabilities Are Not in the Code

链捕手05/25 15:17

Vitalik's Article Emphasizes Ethereum Must Be 'Amazing', But Foundation Is Not the Center

Vitalik Buterin has published a lengthy response to recent community criticism directed at the Ethereum Foundation (EF). Acknowledging a sense of "unease," he addresses concerns about the EF's strategic direction, its perceived disconnect from ETH's price performance, and calls for its reduced central role. Vitalik rejects the notion that the EF should be the central governing body of Ethereum, framing it instead as one "node with a clear mandate" among many within the ecosystem. He highlights the EF's limited ETH holdings (≈0.16% of supply) compared to other blockchain foundations and states it will no longer sell significant amounts of ETH. Its future focus will be on long-term, critical projects that align with Ethereum's core values of censorship-resistance and decentralization, which might not otherwise happen. A core argument is that Ethereum must be "amazing," but not by merely chasing higher transaction speeds at the cost of decentralization. He proposes focusing on the "CROPS" dimensions: creating a Cryptographically provable, Reliable, Open, Private, and Secure network. This includes pursuing goals like a formally verifiable, bug-free Ethereum client and minimizing protocol-level reliance on intermediaries. The article concludes by noting that while Vitalik clarifies the EF's refocused role, he does not directly address community suggestions for creating a new organization explicitly aligned with ETH's economic interests. This "alignment gap" is presented as a key challenge for Ethereum's future.

链捕手05/25 15:07

Vitalik's Article Emphasizes Ethereum Must Be 'Amazing', But Foundation Is Not the Center

链捕手05/25 15:07

Vitalik on the Future of the Ethereum Foundation: A Smaller, More Distinct, but Longer-Lasting Ship

Vitalik discusses the future direction of the Ethereum Foundation (EF), emphasizing a shift towards a smaller, more focused, and longer-lasting organization. He clarifies this is his personal view and that his own influence within EF is diminishing, which he welcomes. The key driver is aligning EF's actions with its stated values of decentralization, privacy, and being a "sanctuary technology," addressing criticism that its operations haven't fully reflected these ideals. He argues that EF should not be the "center" of Ethereum but one node among many with a specific mandate. With limited resources (holding only ~0.16% of all ETH), EF must focus its remaining efforts on long-term, mission-critical activities that wouldn't happen without its push, particularly those reinforcing Ethereum's core CROPS values (Censorship-Resistance, Resilience, Openness, Privacy, Security). This means making hard choices, potentially spinning out even respected projects to attract external capital, and cultivating a distinct cultural stance. The core technical vision is for Ethereum to be "amazing" not by chasing maximal throughput, but by excelling in the CROPS dimension. Key goals include: a provably bug-free Ethereum via AI-assisted formal verification; high-availability chain consensus combining the best of BFT and Bitcoin-style security; and minimization of intermediaries in transaction sending and user experience. These "unreasonable" ambitions aim to make Ethereum profoundly impressive in its core values, which also support ETH as a robust asset. The future EF will be a smaller, more opinionated ship built for longevity and meaningful impact.

链捕手05/25 06:44

Vitalik on the Future of the Ethereum Foundation: A Smaller, More Distinct, but Longer-Lasting Ship

链捕手05/25 06:44

Mythos Report Released: Billions of Devices Worldwide Exposed, 10,000 Critical Vulnerabilities Uncovered in 30 Days

The first report from Anthropic's "Project Glasswing" reveals staggering results from its secret initiative using the next-generation AI model, Claude Mythos Preview. In just 30 days, collaborating with roughly 50 global tech giants and critical infrastructure developers, Mythos identified over 10,000 high or critical-severity software vulnerabilities. It demonstrated an extremely low false-positive rate, even outperforming human experts, and successfully intercepted a $1.5 million bank fraud in progress. Key findings include uncovering 2,000 bugs in Cloudflare's core systems, fixing 271 critical vulnerabilities in Firefox 150 (ten times more than previous methods), and discovering a 27-year-old hidden bug in OpenBSD's codebase. The AI even autonomously constructed full attack chains for some exploits. Mythos also scanned over 1,000 essential open-source projects, identifying 23,019 total vulnerabilities, with 6,202 rated high/critical by the AI. Independent verification confirmed a 90.6% true-positive rate, validating 1,094 severe vulnerabilities. A critical case involved wolfSSL, a cryptography library used by billions of devices, where Mythos found a flaw allowing perfect digital certificate forgery. This unprecedented discovery speed has created a new crisis: human developers are overwhelmed and cannot patch vulnerabilities fast enough. In response, Anthropic is rolling out defensive tools like "Claude Security" to auto-generate patches and releasing frameworks to help security teams automate code review and threat modeling. Due to its immense power and potential for weaponization if misused, Anthropic is delaying Mythos's public release until robust safety measures are established. The company urges the industry to shorten patch cycles, enforce updates, and strengthen security fundamentals. The project signals a paradigm shift where AI could eventually make critical code vastly more secure, though the transition period poses significant challenges for human defenders.

marsbit05/25 00:09

Mythos Report Released: Billions of Devices Worldwide Exposed, 10,000 Critical Vulnerabilities Uncovered in 30 Days

marsbit05/25 00:09

活动图片