BTC $76,975.78 -0.38%
ETH $2,483.46 -1.67%
BNB $716.27 -1.52%
XRP $1.35 -1.45%
SOL $99.64 -2.07%
TRX $0.3379 -0.60%
DOGE $0.0826 -2.58%
ADA $0.2044 -1.64%
BCH $221.49 -2.16%
LINK $11.26 -2.13%
HYPE $77.62 -2.39%
AAVE $125.05 -0.66%
SUI $0.7030 -3.03%
XLM $0.1782 -1.02%
ZEC $1,066.10 -5.44%
AAPL $330.44 -0.77%
AMZN $254.61 -0.90%
GOOGL $337.02 -1.02%
MSFT $493.25 -0.51%
META $642.23 -0.98%
NVDA $215.17 -1.55%
TSLA $361.11 -1.73%
SNDK $1,559.73 -4.34%
INTC $99.16 -2.69%
SPCX $148.88 -0.85%
MU $941.48 -2.73%
AMD $503.13 -2.32%
BTC $76,975.78 -0.38%
ETH $2,483.46 -1.67%
BNB $716.27 -1.52%
XRP $1.35 -1.45%
SOL $99.64 -2.07%
TRX $0.3379 -0.60%
DOGE $0.0826 -2.58%
ADA $0.2044 -1.64%
BCH $221.49 -2.16%
LINK $11.26 -2.13%
HYPE $77.62 -2.39%
AAVE $125.05 -0.66%
SUI $0.7030 -3.03%
XLM $0.1782 -1.02%
ZEC $1,066.10 -5.44%
AAPL $330.44 -0.77%
AMZN $254.61 -0.90%
GOOGL $337.02 -1.02%
MSFT $493.25 -0.51%
META $642.23 -0.98%
NVDA $215.17 -1.55%
TSLA $361.11 -1.73%
SNDK $1,559.73 -4.34%
INTC $99.16 -2.69%
SPCX $148.88 -0.85%
MU $941.48 -2.73%
AMD $503.13 -2.32%

exploit

All
Article
Flash

first_img OpenAI's new model Astra can autonomously discover and exploit software vulnerabilities, rated as "critical" in cybersecurity capability level

OpenAI stated that its upcoming Astra model can autonomously discover previously unknown software vulnerabilities and convert them into usable attack vectors without human intervention, making it the company's first model to reach the "Critical" cybersecurity capability level threshold. In a blog post released on Tuesday, OpenAI mentioned that according to its Preparedness Framework, reaching this level means the model can discover zero-day vulnerabilities and develop usable exploit code in hardened real systems without human involvement, or design and execute attacks based solely on a high-level objective.In testing, Astra achieved a 100% score in benchmark tests for developing exploit code based on known vulnerabilities and discovered two previously unknown vulnerabilities in another internal test. Additionally, the model successfully broke through a hardened browser sandbox and executed commands on the host machine, while gaining root access by exploiting multiple weaknesses in the operating system. OpenAI stated that it has delayed some of Astra's development progress to enhance security measures and plans to make its advanced cybersecurity capabilities available only to selected testers.This capability is particularly relevant to the cryptocurrency industry, as software vulnerabilities can be converted into financial losses within minutes. CoinDesk reported in June that increasingly powerful AI models can compress the process of searching code, discovering misconfigurations, and assembling attacks from days or weeks to machine speed. Security researchers noted at the time that the significant change was not the emergence of new categories of attacks, but rather the dramatically increased speed at which existing vulnerabilities are discovered and exploited.

Summer.fi Lazy Summer attack is not a contract vulnerability, but rather an exploitation of the NAV mechanism

Summer.fi released an analysis report on the Lazy Summer Protocol USDC treasury attack incident. The attacker manipulated the prices of two USDC treasury shares in a single atomic transaction, extracting approximately $6.04 million of depositor funds. The core of the attack lies in the calculation method of the treasury's net asset value (NAV).The attacker donated tokens that still retained the old valuation to a Silo Ark that had been suspended after the incident in November 2025 but had not yet been completely removed, resulting in an inflated total asset value of approximately 9.5%, raising the share price, which was then redeemed at an inflated price and withdrawn from the treasury's actual liquidity. The report emphasizes that this attack was not due to a contract code vulnerability, but rather a missing link in the treasury's offline process—the deposit limit for that Ark had been set to zero, yet it was still counted in the NAV of active assets.The attacker premeditatedly accumulated the required tokens three months in advance through multiple wallets and transferred part of the profits via Tornado Cash. After the incident, Guardian Multisig has suspended all on-chain treasuries and set the deposit limit to zero. The Lazy Summer DAO will discuss compensation plans for affected users and the treasury restart plan in the coming days.
app_icon
ChainCatcher Building the Web3 world with innovations.