BTC $77,742.14 -3.20%
ETH $2,442.06 -2.89%
BNB $690.15 -3.10%
XRP $1.38 -4.71%
SOL $104.09 -4.70%
TRX $0.3417 +1.25%
DOGE $0.0851 -4.35%
ADA $0.2023 -5.60%
BCH $248.18 -8.20%
LINK $11.43 -4.46%
HYPE $80.92 -4.52%
AAVE $122.10 -5.08%
SUI $0.7413 -4.87%
XLM $0.1786 -4.83%
ZEC $800.36 -1.72%
BTC $77,742.14 -3.20%
ETH $2,442.06 -2.89%
BNB $690.15 -3.10%
XRP $1.38 -4.71%
SOL $104.09 -4.70%
TRX $0.3417 +1.25%
DOGE $0.0851 -4.35%
ADA $0.2023 -5.60%
BCH $248.18 -8.20%
LINK $11.43 -4.46%
HYPE $80.92 -4.52%
AAVE $122.10 -5.08%
SUI $0.7413 -4.87%
XLM $0.1786 -4.83%
ZEC $800.36 -1.72%

cati

All
Article
Flash

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

first_img Viewpoint: The AI application layer should not be priced based on tokens, but should be anchored to "recognizable work value."

a16z partner Sarah Wang recently published an article pointing out that AI application layer products should not price based on tokens like the model layer, but rather on "recognizable work units." The article argues that token pricing anchors the value of application products to a unit whose cost is continuously declining, making it difficult for customers to predict context length, retrieval volume, or reasoning time, and improperly compares applications to raw computing power.The article suggests a tiered pricing model based on value levels: model layer priced by tokens; application layer priced by recognizable work units for customers (such as account research briefs, code modifications, completed queries), which can be encapsulated through Credits; and scenarios that are attributable and have clear value priced directly by results (such as resolved customer service conversations, qualified leads). The design of Credits should map to different levels of work difficulty to protect gross margins and distinguish "work value" from "delivery cost." The article uses Clay as an example, where its new pricing separates Data Credits (third-party data) from Actions (orchestrated work), only passing on costs for reasoning models with significant cost fluctuations without markup. The author believes that pricing anchored to value rather than computing cost allows customers to understand spending in relation to value, while also benefiting product providers in maintaining profit margins.

The Sandbox: Compensation will be carried out based on the on-chain snapshot before the attack, and the compensation application process is expected to open within two weeks

The Sandbox released an update on the security vulnerability attack incident involving the SAND cross-chain bridge, stating that the attacker modified the verification mechanism to forge cross-chain deposit messages and mint unbacked SAND. This incident resulted in approximately 14.7423 million SAND being withdrawn, valued at about $697,000. Additionally, some uncollateralized SAND was profited through market trading, leading to an overall economic impact of approximately $1.497 million, of which the attacker actually obtained about $987,000.The Sandbox stated that the attack did not affect the supply of SAND on Ethereum and Polygon, with the total amount of SAND on Ethereum remaining unchanged at 3 billion. There were also no super administrator privileges stolen, and the attack stemmed from a vulnerability caused by the combination of the general call function in the token contract and the design of bridge permissions. Currently, the related addresses have been marked, and collaboration has begun with exchanges, security agencies, and the LayerZero team.For affected users, The Sandbox promises to compensate wallets holding legitimate bridged SAND with a 1:1 ratio of SAND on the Ethereum chain based on an on-chain snapshot taken before the attack. The compensation application process is expected to open within two weeks and will last for two weeks.

first_img Unstoppable Domains abandons ICANN application, refunds Web3 domain names

Matthew Gould, the founder of Unstoppable Domains, stated that the company did not submit an application for its Web3 top-level domains in ICANN's 2026 expansion round and will refund customers who purchased related domains. Gould mentioned that the compliance, application, and bidding costs of incorporating Web3 domains into the ICANN system exceeded the company's expected recoverable sales. This move ends the company's commitment since 2019 that domains like .crypto and .wallet would eventually be resolvable in standard browsers.The application window for this round of ICANN opened on April 30 and closed on August 12, receiving over 1,600 major applications. Gould stated that customers have been notified via email, but the list of affected extensions and refund terms have not been disclosed. Some holders questioned the scope of the refunds, claiming they held the domains based on Unstoppable's commitment to advance the ICANN application. Gould responded that Web3 domains will still serve as on-chain assets for cryptocurrency transactions.Unstoppable continues to participate in ICANN activities as a service provider and previously announced a partnership with Telegram to apply for the .gram domain. Meanwhile, ENS has chosen a different path, with token holders approving the restructuring of the ENS Foundation to pursue the .ens top-level domain in ICANN, but ENS will not apply for .eth, as it is reserved for ISO 3166-1 country codes.
app_icon
ChainCatcher Building the Web3 world with innovations.