BTC $77,523.23 +0.44%
ETH $2,508.76 -0.45%
BNB $721.61 -0.81%
XRP $1.37 +0.56%
SOL $100.84 -0.75%
TRX $0.3388 -0.16%
DOGE $0.0838 -1.06%
ADA $0.2069 +0.07%
BCH $223.34 -0.75%
LINK $11.35 -1.06%
HYPE $79.94 +1.11%
AAVE $125.73 -1.24%
SUI $0.7151 -1.00%
XLM $0.1812 +0.83%
ZEC $1,109.00 -2.15%
AAPL $328.82 -1.28%
AMZN $254.35 -0.98%
GOOGL $335.93 -1.54%
MSFT $493.32 -0.47%
META $641.04 -1.09%
NVDA $214.89 -1.19%
TSLA $361.04 -1.65%
SNDK $1,568.29 -3.44%
INTC $98.56 -2.80%
SPCX $148.68 -1.02%
MU $940.09 -2.82%
AMD $500.04 -2.67%
BTC $77,523.23 +0.44%
ETH $2,508.76 -0.45%
BNB $721.61 -0.81%
XRP $1.37 +0.56%
SOL $100.84 -0.75%
TRX $0.3388 -0.16%
DOGE $0.0838 -1.06%
ADA $0.2069 +0.07%
BCH $223.34 -0.75%
LINK $11.35 -1.06%
HYPE $79.94 +1.11%
AAVE $125.73 -1.24%
SUI $0.7151 -1.00%
XLM $0.1812 +0.83%
ZEC $1,109.00 -2.15%
AAPL $328.82 -1.28%
AMZN $254.35 -0.98%
GOOGL $335.93 -1.54%
MSFT $493.32 -0.47%
META $641.04 -1.09%
NVDA $214.89 -1.19%
TSLA $361.04 -1.65%
SNDK $1,568.29 -3.44%
INTC $98.56 -2.80%
SPCX $148.68 -1.02%
MU $940.09 -2.82%
AMD $500.04 -2.67%

verification

All
Article
Flash

Liquid Network releases emergency fix: Elements v23.3.4 fixes Proof verification cache vulnerability

Liquid Network has released the latest update stating that the emergency version Elements v23.3.4 is now online. Functionary nodes have immediately begun upgrading and all Liquid node operators are advised to synchronize updates. This version addresses the previously discovered Proof verification cache vulnerability and strengthens the cache keys used for Range Proof.Regarding network recovery, Blockstream states that it is still formulating a recovery plan, which is expected to proceed in three phases: restoring block production while continuing to suspend Peg operations; replaying verified valid transactions; and restoring Peg operations after the network status is fully restored and funds are confirmed to be returned. Currently, the first two phases are being tested in parallel, and any phase will only advance once safety is confirmed. Liquid Network indicates that Elements v23.3.4 has completed multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams.At the same time, Liquid Network reminds users to be vigilant against fraudulent upgrade websites exploiting this incident. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or recovery phrases.

first_img Thailand implements cryptocurrency travel regulations requiring verification of ownership of self-custody wallets

The Securities and Exchange Commission of Thailand (SEC) has officially approved the travel rule for crypto assets, requiring digital asset operators to verify the ownership or control of wallets when customers send or receive crypto assets to self-custody wallets, and to retain transaction-related information for at least five years for regulatory review. Pornanong Budsaratragoon, Secretary-General of the Thai SEC, stated that the rule aims to reduce the risk of digital asset operators being used for money laundering and terrorist financing.The new regulations were finalized after two rounds of public consultations this year, with the first round presenting a draft in March and a notification draft released in June. The Thai SEC stated that most stakeholders expressed support. As the travel rule is implemented, Thailand is considering expanding the access to regulated crypto products. On Monday, the Thai SEC proposed allowing intermediaries to offer specific crypto derivatives traded on regulated overseas exchanges to retail investors.In the days prior, regulators also advanced the draft rules for spot Bitcoin and Ethereum exchange-traded funds (ETFs) and simultaneously sought opinions on the foreign digital asset custodians used by funds investing in crypto assets. Thailand's move aligns with global regulatory trends, as the Financial Action Task Force (FATF) estimates that by 2026, 83% of surveyed jurisdictions will have enacted travel rule legislation.

Slow Mist Reveals Details of the Allbridge Cross-Chain Bridge Attack: Forged CCTP Messages, Flash Loans, Insufficient Minting Result Verification

The Slow Mist security team disclosed that the cross-chain bridge project Allbridge was attacked on August 19, 2026, resulting in a loss of approximately $190,000. Notably, this attack was not executed instantly; the attacker had begun laying the groundwork nearly a month prior and bypassed the verification mechanism by forging cross-chain messages. According to Slow Mist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as a CCTP style message, claiming that a transfer of 1 million USDC existed, but in reality, no USDC destruction operation took place. Subsequently, Circle generated a valid verification proof (attestation) for this complete message according to normal procedures.About 24 days later, on August 19, the attacker waited for the Base Router to receive a real CCTP deposit, increasing the balance to approximately 191,000 USDC, and initiated the attack just 6 seconds later. The attacker utilized the previously forged message and verification proof to call Allbridge's receiveCctpMessage function. Due to the project's lack of critical verification, the system mistakenly recognized the false cross-chain message as a real deposit and recorded a limit of 1 million USDC. The attacker then temporarily borrowed approximately 809,000 USDC through an Aave flash loan, matching the Router balance with the forged amount, and used the internal credit record to call the transfer function, ultimately transferring out approximately 999,000 USDC (after a 0.1% fee). After repaying the flash loan and fees, the attacker netted a profit of about $189,800. The root cause of this vulnerability lies in Allbridge's failure to verify the identities of the sender and receiver of the cross-chain message, as well as not confirming whether USDC was genuinely minted and whether the balance actually increased, instead directly trusting the amounts and message hash data constructed by the attacker. Slow Mist emphasizes that on-chain message verification does not equate to the actual arrival of real assets. Cross-chain protocols not only need to verify the authenticity of messages but must also ensure that the message source is trustworthy, that the receiver is Circle's official TokenMessengerV2, and that asset accounting can only proceed after confirming the actual minting of assets and changes in balance. This incident once again highlights the security risks of cross-chain bridges in the message verification and asset settlement processes.
app_icon
ChainCatcher Building the Web3 world with innovations.