[Ledger CTO: NPM Supply Chain Attack Contained] Ledger's Chief Technology Officer stated that the recent NPM supply chain attack targeting the crypto industry has been contained, with very few users affected. The attack was carried out through the NPM open-source package management system, targeting crypto industry users.
24/7 Flashes
More >BTC falls below the $111000 mark
OKX-BTC/USDT is currently trading at $110936, a decrease of 0.14% in 5 minutes. Please be aware of market fluctuations.
就业数据修正或推动美联储降息预期
[Employment Data Revision May Drive Fed Rate Cut Expectations] Michael James, Managing Director at Rosenblatt Securities, stated that the revision of U.S. employment data shows a significant decline in labor force growth, which could prompt the Federal Reserve to initiate a rate-cutting cycle this month. Market expectations around this have driven a rebound in U.S. stock market performance.
单一实体疑似通过女巫攻击从 MYX 空投中获取1.7亿美元代币
[Single Entity Suspected of Exploiting $170 Million in Tokens from MYX Airdrop via Sybil Attack] Blockchain analytics platform Bubblemaps posted on X, pointing out that a single entity is suspected of exploiting $170 million worth of tokens from the MYX airdrop through a Sybil attack. Bubblemaps tracked approximately 100 addresses whose on-chain activities were completely identical, showing a high degree of coordination. According to the analysis, these addresses received funding via OKX one month prior to the airdrop, with all transactions concentrated around 6:50 AM on April 19. Each address received a similar amount of BNB. Subsequently, these addresses claimed approximately 9.8 million MYX tokens, accounting for 1% of the total token supply. Most of the addresses initiated claims simultaneously around 5:30 AM on May 7, and prior to this, there was no on-chain activity from these addresses, indicating that their behavior was not random. Bubblemaps stated that this could be the largest Sybil attack on an airdrop in history.
DuckDB NPM账户遭入侵,恶意版本已发布
[DuckDB NPM Account Compromised, Malicious Versions Released] SlowMist Technology CISO stated that the DuckDB NPM account was compromised, and malicious versions of duckdb, duckdb-wasm, etc., released early this morning are consistent with the wallet-stealing software from yesterday's supply chain attack. Users are advised to be vigilant and take precautions against risks.
美司法部拟没收超500万美元SIM卡攻击盗窃比特币
[U.S. Department of Justice Seeks to Forfeit Over $5 Million in Bitcoin Stolen via SIM Card Attacks] The U.S. Department of Justice has filed a civil forfeiture lawsuit for Bitcoin worth over $5 million, stating that these funds were illicit proceeds from multiple SIM card swapping attacks. The case involves the theft of cryptocurrency wallets belonging to five victims, with the related thefts occurring between October 29, 2022, and March 21, 2023.