BTC $64,815.14 +1.45%
ETH $1,924.98 +1.11%
BNB $591.05 +3.67%
XRP $1.08 +0.94%
SOL $74.48 +1.68%
TRX $0.3287 +0.92%
DOGE $0.0704 +0.80%
ADA $0.1699 +4.08%
BCH $216.21 +3.88%
LINK $8.46 +2.50%
HYPE $55.61 +3.87%
AAVE $98.79 +3.18%
SUI $0.6955 +1.53%
XLM $0.1721 +0.59%
ZEC $472.60 +1.88%
BTC $64,815.14 +1.45%
ETH $1,924.98 +1.11%
BNB $591.05 +3.67%
XRP $1.08 +0.94%
SOL $74.48 +1.68%
TRX $0.3287 +0.92%
DOGE $0.0704 +0.80%
ADA $0.1699 +4.08%
BCH $216.21 +3.88%
LINK $8.46 +2.50%
HYPE $55.61 +3.87%
AAVE $98.79 +3.18%
SUI $0.6955 +1.53%
XLM $0.1721 +0.59%
ZEC $472.60 +1.88%

slow

All
Article
Flash

OKX, in collaboration with Elliptic, SlowMist, and OttoSec, released the Web3 Security and Risk Control Report for the first half of 2026

According to official news, OKX, in collaboration with Elliptic, SlowMist, and OttoSec, has released the "Web3 Security and Risk Control Report for the First Half of 2026." The report points out that the focus of Web3 attacks is gradually shifting from smart contract code to more complex scenarios such as signature processes, user devices, operational infrastructure, and AI Agents.Data shows that in the first half of 2026, the OKX risk control system intercepted over 5.7 million high-risk transactions, including approximately 2.41 million transactions related to hacking and theft, about 1.48 million transactions related to phishing, and around 990,000 transactions related to fraud. The OKX Web3 on-chain intelligence label library currently has over 1 billion labels, covering more than 420 chains, and has integrated capabilities such as address screening, transaction monitoring, and sanction address control into infrastructures like DEX and Exchange OS.In addition, in terms of user protection, OKX has intercepted over 7 million visits to risky websites, completed over 200,000 device risk assessments, identified over 60,000 high-risk apps, and intercepted or alerted on over 4 million high-risk signature operations. The report also introduces the "risk control pre-positioning" design in scenarios such as Exchange OS, Outcomes, RWA, and Agentic Wallet.

Slow Fog Cosine: Claude Code exposes high-risk security vulnerabilities, malicious configuration files may silently execute commands

The founder of Slow Fog, Yu Xian, retweeted a tweet on the X platform regarding the potential poisoning attack risks of Claude Code and published an analysis of the poisoning attack details targeting Grok Build CLI and Claude Code CLI.It pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, creating gaps that serve as channels for attackers. Attackers may execute arbitrary commands through malicious project configuration files without the user's knowledge, thereby stealing API keys, cloud credentials, or controlling local devices.Researchers constructed a testing environment and found that on Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks.If the attack is successful, attackers may further steal API keys from AI services like Claude and OpenAI, resulting in account cost losses, gain access to servers and data by obtaining cloud service credentials from AWS, Alibaba Cloud, Tencent Cloud, modify code repositories to implant backdoors, and use local devices as jump points to attack corporate internal networks. It is reported that the related vulnerabilities have existed for a year.

Vitalik: Maintain an open attitude towards slowing down or pausing AI, and agree to initiate a pause if extreme situations arise

Vitalik posted on the X platform, stating that AI 2040 and its critics have incompatible worldviews regarding the speed and significance of AI progress. AI 2040 believes that unless strong measures are taken to completely prevent it, some form of superintelligence will emerge in various scenarios by 2040; critics argue that AI 2040 underestimates human coordination capabilities and threatens freedom, but do not view ASI itself as a risk of power concentration.He believes that if he were convinced that the current form of AI is just an ordinary technology, he would be closer to the critics' camp; if he were convinced that superintelligence would inevitably arrive by 2030, he would be closer to the AI 2040 camp. At the same time, due to significant uncertainty, he remains open to the idea of slowing down or pausing, and feels uncomfortable with the stance proposed by some large AI companies and intellectuals that "open source is detrimental, and the ideal outcome is to maintain global control dominance."Vitalik stated that an important reason he supports the d/acc platform is that directions such as formal verification, cryptography, secure and open hardware, pandemic resilience, defensive biotechnology, food and basic resource security, public cognitive systems, and non-concentrated power physical security are worth promoting under both worldviews. He also mentioned that the 2040 plan has increasingly supported open source and incorporated the idea of "mutual assured destruction of computational power," which is an improvement compared to allowing a few participants to selectively deprive their identified subjects of rights.There is no way to avoid trade-offs regarding whether to slow down or pause, and Vitalik believes that trigger conditions can be preset, allowing for a more open attitude towards slowing down or pausing when sufficient conditions are met within a specific timeframe.He also stated that if he were Elon Musk or Zuck, he would significantly transform Twitter into a platform that helps identify and facilitate such large win-win agreements, encouraging more people to participate in discussions, but he thinks this might also be naive. Currently, he does not see any non-naive ASI transition response plans, so he tends to show some tolerance towards those who are trying.
2026-07-11
app_icon
ChainCatcher Building the Web3 world with innovations.