BTC $76,711.45 -0.66%
ETH $2,476.91 -1.81%
BNB $715.63 -1.81%
XRP $1.34 -1.72%
SOL $99.44 -2.61%
TRX $0.3383 -0.54%
DOGE $0.0825 -2.82%
ADA $0.2034 -1.90%
BCH $221.43 -2.15%
LINK $11.24 -2.35%
HYPE $77.76 -2.09%
AAVE $124.59 -1.33%
SUI $0.7007 -3.61%
XLM $0.1775 -1.32%
ZEC $1,058.77 -6.41%
AAPL $330.74 -0.70%
AMZN $254.68 -0.89%
GOOGL $335.41 -1.44%
MSFT $494.35 -0.34%
META $639.38 -1.50%
NVDA $214.55 -1.63%
TSLA $360.17 -2.15%
SNDK $1,560.06 -4.17%
INTC $98.58 -3.03%
SPCX $148.32 -1.29%
MU $937.05 -3.20%
AMD $499.84 -2.94%
BTC $76,711.45 -0.66%
ETH $2,476.91 -1.81%
BNB $715.63 -1.81%
XRP $1.34 -1.72%
SOL $99.44 -2.61%
TRX $0.3383 -0.54%
DOGE $0.0825 -2.82%
ADA $0.2034 -1.90%
BCH $221.43 -2.15%
LINK $11.24 -2.35%
HYPE $77.76 -2.09%
AAVE $124.59 -1.33%
SUI $0.7007 -3.61%
XLM $0.1775 -1.32%
ZEC $1,058.77 -6.41%
AAPL $330.74 -0.70%
AMZN $254.68 -0.89%
GOOGL $335.41 -1.44%
MSFT $494.35 -0.34%
META $639.38 -1.50%
NVDA $214.55 -1.63%
TSLA $360.17 -2.15%
SNDK $1,560.06 -4.17%
INTC $98.58 -3.03%
SPCX $148.32 -1.29%
MU $937.05 -3.20%
AMD $499.84 -2.94%

vulnerabilities

All
Article
Flash

first_img OpenAI's new model Astra can autonomously discover and exploit software vulnerabilities, rated as "critical" in cybersecurity capability level

OpenAI stated that its upcoming Astra model can autonomously discover previously unknown software vulnerabilities and convert them into usable attack vectors without human intervention, making it the company's first model to reach the "Critical" cybersecurity capability level threshold. In a blog post released on Tuesday, OpenAI mentioned that according to its Preparedness Framework, reaching this level means the model can discover zero-day vulnerabilities and develop usable exploit code in hardened real systems without human involvement, or design and execute attacks based solely on a high-level objective.In testing, Astra achieved a 100% score in benchmark tests for developing exploit code based on known vulnerabilities and discovered two previously unknown vulnerabilities in another internal test. Additionally, the model successfully broke through a hardened browser sandbox and executed commands on the host machine, while gaining root access by exploiting multiple weaknesses in the operating system. OpenAI stated that it has delayed some of Astra's development progress to enhance security measures and plans to make its advanced cybersecurity capabilities available only to selected testers.This capability is particularly relevant to the cryptocurrency industry, as software vulnerabilities can be converted into financial losses within minutes. CoinDesk reported in June that increasingly powerful AI models can compress the process of searching code, discovering misconfigurations, and assembling attacks from days or weeks to machine speed. Security researchers noted at the time that the significant change was not the emergence of new categories of attacks, but rather the dramatically increased speed at which existing vulnerabilities are discovered and exploited.

first_img Polygon has fixed security vulnerabilities through two hard forks, which were previously deployed privately

Polygon Labs disclosed that it has fixed a batch of security vulnerabilities in its proof-of-stake network through two hard forks, with the related fixes privately deployed before public disclosure. According to a forum post released on Wednesday, the team packaged the fixes into the Austin hard fork of the Bor client and the Kyoto hard fork of the Heimdall client, both of which followed the standard process for fixing issues that affect consensus: first validated on the Amoy testnet, and then publicly disclosed once the mainnet was activated and the network was secure.The Austin fork fixed two denial-of-service paths in block processing, including a vulnerability where malicious block producers could crash peer nodes by filling them with oversized field data. The Kyoto fork addressed a broader range of consensus hardening issues, with the most severe vulnerability allowing an attacker to force the entire validator set to perform costly and coordinated work with just one crafted transaction—the cost of constructing the transaction is low, but the network processing cost is high. Polygon emphasized that none of the vulnerabilities were observed to be exploited on the mainnet and have been proactively addressed. The two upgrades are now mandatory for node operators and have taken effect without the need for state migration or resynchronization.This disclosure comes at a critical transformation period for Polygon, which has completed the migration of the traditional MATIC token to POL as part of a comprehensive overhaul of its network architecture. The news did not boost the price of POL; according to CoinGecko data, POL traded at approximately $0.09983 on Sunday, down 2.3% in 24 hours, down about 6.8% over the past week, and down about 60.8% over the past year, with a market capitalization of approximately $1.07 billion.

Core Lightning, the Bitcoin Lightning Network software, issued an emergency warning due to the discovery of multiple real vulnerabilities in an AI report

According to CoinDesk, the developers of the Bitcoin Lightning Network payment software Core Lightning (CLN) issued an urgent warning to node operators after the team received a large number of AI-generated security reports, revealing several real vulnerabilities. The development team advised operators not to directly shut down the machine power but to restart the software in "--offline" mode, which stops communication with other Lightning Network nodes while still keeping it operational to continuously monitor the Bitcoin blockchain and protect the funds in the payment channels.The Core Lightning team began receiving a large number of AI-generated vulnerability reports since early August, some of which have been confirmed to be valid. Developers will keep the details confidential for two weeks to complete the patch development and plan to release a signed patch version for operators to verify the source. The source code and vulnerability details will be made public after the confidentiality period ends.This is the second AI-related security incident in the Lightning Network this month. Earlier in early August, BTCPay Server experienced a vulnerability that led to the leakage of credentials for some Lightning Network nodes and theft of funds. Additionally, the "Bitcoin Red Team," composed of 16 developers, used AI models to scan 390 Bitcoin code repositories at the end of July, discovering nearly 5,000 issues, 85 of which were rated as critical.

Maya Protocol Attacked: Six Linked Vulnerabilities Result in Approximately $1.7 Million Stolen, Liquidity Pool Shrinks by $11 Million

The cross-chain liquidity protocol Maya Protocol was attacked on August 18, with the attacker exploiting six interconnected software vulnerabilities to create false account balances, stealing approximately 20.83 BTC (about $1.34 million) and other assets, resulting in a total direct loss of about $1.65 million. The incident led to the suspension of trading on the MAYAChain network, with its token CACAO plummeting nearly 89% from $0.115 to $0.013, before recovering to around $0.03.Technical reviews show that the attack began when MAYAChain mistakenly judged a transaction to be lost and triggered a compensation mechanism, but the mechanism miscalculated, adding about 49 million CACAO to a small liquidity pool, while the protocol's reserves only held about 168,000 CACAO. After the transfer failed, the system incorrectly saved the new balance, and the attacker subsequently deposited a very small amount into the liquidity pool, acquiring over 99% of the pool's share and immediately withdrawing 48.87 million CACAO, which was then exchanged for Bitcoin, Ethereum, and other assets.The incident caused the total value of the Maya Protocol liquidity pool to decrease by about $10.9 million, of which approximately $6.4 million was due to the depreciation of CACAO, and about $2.9 million came from arbitrage trading. The team expressed hope that the attacker would return the funds in the form of a bug bounty; otherwise, they would seek to recover losses through investments in channels like Aztec Chain. Maya Protocol has not yet announced a specific time for resuming trading. This incident once again exposed the security risks within the complex logic of DeFi protocols.

Bitcoin Red Team has completed a foundational scan of the Bitcoin open-source ecosystem and discovered a large number of serious and high-risk vulnerabilities

Bitcoin News posted on the X platform that after two weeks of using cutting-edge AI to scan almost the entire Bitcoin open-source ecosystem for vulnerabilities, Bitcoin Red Team member @callebtc stated, "The easily discoverable vulnerabilities have been addressed," and maintainers are verifying "a large number" of serious and high-risk vulnerabilities.@callebtc indicated that the main findings include: decades of accumulated open-source technical debt are being exposed alongside AI capabilities that can discover vulnerabilities at speeds and scales unattainable by human researchers; Lightning seems particularly vulnerable, with its complexity meaning its security status is "worse than average"; unmaintained Bitcoin projects should be considered vulnerable until their security is confirmed.Projects that began building AI security and auditing processes months ago are now in a completely different position compared to those that have been waiting until now. The Bitcoin Red Team has now completed a foundational scan of almost the entire Bitcoin open-source ecosystem. Easily discoverable vulnerabilities have mostly been addressed, but as AI capabilities improve, external red team testing may need to continue indefinitely. Despite discovering and reporting "a large number" of real serious and high-risk vulnerabilities, @callebtc believes this process will ultimately make Bitcoin stronger. The same AI security review will soon expand to areas far beyond Bitcoin.
app_icon
ChainCatcher Building the Web3 world with innovations.