BTC $79,600.16 -0.26%
ETH $2,489.89 -1.73%
BNB $706.56 -0.63%
XRP $1.42 -1.02%
SOL $106.24 +1.63%
TRX $0.3392 +0.88%
DOGE $0.0874 -1.96%
ADA $0.2092 -2.83%
BCH $261.91 -4.23%
LINK $11.66 -1.59%
HYPE $83.43 +1.42%
AAVE $125.30 -2.87%
SUI $0.7598 -1.75%
XLM $0.1836 -1.96%
ZEC $788.62 -0.45%
BTC $79,600.16 -0.26%
ETH $2,489.89 -1.73%
BNB $706.56 -0.63%
XRP $1.42 -1.02%
SOL $106.24 +1.63%
TRX $0.3392 +0.88%
DOGE $0.0874 -1.96%
ADA $0.2092 -2.83%
BCH $261.91 -4.23%
LINK $11.66 -1.59%
HYPE $83.43 +1.42%
AAVE $125.30 -2.87%
SUI $0.7598 -1.75%
XLM $0.1836 -1.96%
ZEC $788.62 -0.45%

pro

All
Article
Flash

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

first_img Members of the Abu Dhabi royal family are reported to support a cryptocurrency banking project associated with Trump

According to a report by The Wall Street Journal citing informed sources, Sheikh Tahnoon bin Zayed Al Nahyan, a member of the Abu Dhabi royal family, is the backer behind StringZ Holding RSC, which holds a 49% stake in WLTC Holdings, the parent company of World Liberty Financial, associated with the Trump family, which is proposing a U.S. trust bank. It is said that entities linked to the Trump family hold an additional 38% stake in the company.The Office of the Comptroller of the Currency (OCC) granted preliminary conditional approval to World Liberty Trust Company on August 14. The decision announced by the OCC confirms that StringZ is an investor in WLTC Holdings and has signed a commitment not to interfere with the bank, but does not specify Tahnoon as its backer or disclose his shareholding percentage. The trust bank must meet OCC's pre-operational requirements and obtain final approval before it can begin operations.Tahnoon previously supported the acquisition of a 49% stake in World Liberty Financial for $500 million, prompting U.S. Democratic senators to call for hearings on the deal and investigate whether it affects U.S. policy towards the UAE. Tahnoon currently serves as the UAE's National Security Advisor and is also the chairman of the artificial intelligence company G42. Cointelegraph reached out to the Trump Organization for comment, but had not received a response by the time of publication.

first_img Analysis: The demand for AI infrastructure is longer than that of the internet, and general programming still drives ARR

Analysis of the AI semiconductor and infrastructure cycle indicates that the demand for AI infrastructure will continue to exceed that of the internet era, as user penetration and per capita token are multiplied and converted into tokens, significantly raising the ceiling. User penetration has surpassed 50%, with growth primarily coming from the still-early per capita token; the median monthly AI spending per employee in U.S. companies is about $12, which could long-term approach around 10% of white-collar salaries, approximately $1,000 per month, leaving nearly two orders of magnitude of space in between. Unlike the flat subscriptions and extremely low marginal hardware consumption of the internet, the high costs of inference make the marginal cost of a single access higher, requiring greater infrastructure intensity.After developers program, the next ARR growth will still mainly come from broad programming: non-programmers use programming infrastructure to complete non-programming tasks across industries, with programming becoming the default execution kernel for agents. Tasks related to broad programming account for about 60% to 70% of ARR. As of June 2026, Codex accounted for 64% of the total output tokens from Codex and ChatGPT among OpenAI's enterprise clients; since February, Codex has seen a much higher weekly growth in verticals such as law, sales recruitment, and marketing compared to engineering. In Anthropic's revenue, narrow development/software accounts for about 40%, while finance and insurance exceed 20%, with law, life sciences, retail, and others also having considerable shares.The demand-side token growth logic remains, with a high overlap between funders and beneficiaries.
app_icon
ChainCatcher Building the Web3 world with innovations.