S&P Global Agrees To Acquire Smart Contract Security Firm OpenZeppelin
TL;DR S&P Global has agreed to acquire OpenZeppelin. OpenZeppelin is one of the best-known smart contract security and auditing firms in crypto. Financial terms were not disclosed, and the deal has not yet closed. One of traditional finance’s biggest risk-data companies is buying one of crypto’s best-known security firms. S&P Global has entered into a…
Chainalysis Warns Malware Operators Are Turning Blockchains Into Dead Drops
TL;DR Chainalysis says cyber attackers are increasingly storing malware instructions on public blockchains. It calls the technique “Blockchain Dead Drops.” The blockchain itself is not compromised; attackers are using its public, persistent data layer. Cybercriminals have found a new use for public blockchains, and it has nothing to do with moving money. Chainalysis says a…
EU Cyber Resilience Act Brings 24-Hour Vulnerability Reporting Into Force
TL;DR Parts of the EU Cyber Resilience Act’s vulnerability-reporting regime are now applicable. Manufacturers must issue early warnings for actively exploited vulnerabilities within 24 hours. Commercial crypto wallets can fall within the broader category of products with digital elements. One of the more practical pieces of Europe’s Cyber Resilience Act is starting to matter for…
Crypto Losses Hit $136M Across 50 Security Incidents In August
Crypto security losses reached $136 million across 50 incidents in August, according to PeckShieldAlert data, keeping exploits, phishing, and incident response firmly in view as the market enters September. The figure is another reminder that market recoveries do not erase infrastructure risk. Even when prices rise and liquidity improves, attackers continue to target smart contracts,…
Switchboard Halts Oracle Operations On SUI And Aptos After Potential Compromise
Switchboard has halted oracle operations on several networks, including SUI and Aptos, after detecting a potential security compromise. The precautionary halt also affects IOTA and Movement, according to the validated incident materials. The key detail is scope: Switchboard’s oracle services were halted on affected chains, not the chains themselves. That distinction matters. This should not…
EIP-7702 Wallet Delegation Faces Scrutiny After Phishing Research
Ethereum’s EIP-7702 wallet delegation feature is facing renewed scrutiny after security research presented at the USENIX Security Symposium linked a large share of analyzed authorization transactions to attacker-controlled contracts. The research found that 63% of EIP-7702 authorization transactions in the analyzed sample were connected to malicious contracts, with automated wallet-draining activity contributing to more than…
BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain
BTCPay Server has released version 2.4.2 to patch a critical vulnerability that allowed unauthenticated remote access to LND credential files, after attackers used the issue to drain merchant Lightning wallets. The project’s release notes describe a serious bug involving .macaroon files, which are used by LND to manage access permissions. In plain English, those files…
Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus
A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affected seed generation on some older device versions. According to the validated incident notes, the issue relates to Coldcard Mk3 firmware versions 4.0.1 through 5.0.3, along with Mk4 and Mk5 devices before firmware 5.6.0, and Q…
Ostium Halts Trading After $18M Oracle Key Breach
Ostium Halts Trading After $18M Oracle Key Breach Arbitrum-based perpetuals exchange Ostium has suspended trading after an $18.4 million exploit tied to a compromised off-chain oracle key, highlighting again how vulnerable trading venues can be when price infrastructure fails. The attack did not appear to stem from a direct breach of Ostium’s smart contract code.…
Bitcoin BIP-361 Draft Puts Quantum Security Back On The Agenda
Reference: GitHub Bitcoin BIP-361 Draft Puts Quantum Security Back On The Agenda Bitcoin developers have introduced BIP-361, a draft proposal designed to prepare the network for a future migration away from legacy signature schemes that could become vulnerable in a post-quantum environment. The proposal, titled “Post Quantum Migration and Legacy Signature Sunset,” was authored by…