Scan to download
BTC $68,640.46 -0.56%
ETH $2,095.67 -1.03%
BNB $598.59 -0.71%
XRP $1.32 -0.56%
SOL $79.81 -2.51%
TRX $0.3162 -0.84%
DOGE $0.0902 -2.10%
ADA $0.2454 -1.87%
BCH $434.90 +1.58%
LINK $8.77 -0.78%
HYPE $36.29 -1.74%
AAVE $92.76 -1.31%
SUI $0.8726 +0.19%
XLM $0.1557 -3.97%
ZEC $251.06 +2.56%
BTC $68,640.46 -0.56%
ETH $2,095.67 -1.03%
BNB $598.59 -0.71%
XRP $1.32 -0.56%
SOL $79.81 -2.51%
TRX $0.3162 -0.84%
DOGE $0.0902 -2.10%
ADA $0.2454 -1.87%
BCH $434.90 +1.58%
LINK $8.77 -0.78%
HYPE $36.29 -1.74%
AAVE $92.76 -1.31%
SUI $0.8726 +0.19%
XLM $0.1557 -3.97%
ZEC $251.06 +2.56%

history

Slow Fog: Pay attention to checking for malicious versions of axios and the exposure risk of global installation history for OpenClaw npm

Slow Fog has once again issued a security reminder stating to pay attention to checking for malicious versions of axios and the exposure risk of OpenClaw npm global installation history. axios@1.14.1 and axios@0.3.4 have been confirmed as malicious versions, both of which have injected the dependency plain-crypto-js@4.2.1, delivering cross-platform malicious payloads through the postinstall script.The impact of OpenClaw is assessed based on scenarios: source code builds are not affected, as the locked versions in the lock file are 1.13.5/1.13.6; however, users who installed via npm install -g openclaw@2026.3.28 face historical exposure risks due to the presence of optionalDependencies.axios@^1.7.4 in the dependency chain, which may resolve to axios@1.14.1 during the time window when the malicious version is still online. Currently, npm has reverted the resolution to axios@1.14.0, but environments that were installed during the attack window are still advised to be checked. Slow Fog has provided inspection commands and IoC paths for various platforms; if the plain-crypto-js directory is found, even if the package.json has been cleaned, it should still be regarded as high-risk execution traces. It is recommended that affected hosts immediately rotate credentials and conduct host-side inspections. Previously, Slow Fog founder Yu Xian reminded that OpenClaw version 3.28 may introduce a toxic version of axios, and users need to urgently check.

Kyle predicts that Solana's progress will surpass any period in history, becoming the on-chain cornerstone for complex financial applications

Former Multicoin co-founder Kyle Samani predicts that in the next 18 months, advancements in the microstructure of the Solana on-chain market will surpass any other period in cryptocurrency history. Notable expectations include:Alpenglow: A major upcoming consensus mechanism upgrade for Solana, representing one of the largest protocol-level changes in Solana's history.ACE (Application Controlled Execution): Application controlled execution is a key innovation in Solana's core roadmap.MCL (Multi-Concurrent Block Production): Future upgrades for Solana will allow multiple leaders to propose blocks simultaneously, significantly increasing throughput and reducing latency, while improving transaction inclusion times and censorship resistance.PropAMMs (Proprietary Automated Market Makers): Deployed privately by professional market makers/institutions, using real-time price oracles to update quotes and actively manage liquidity, typically not accepting permissionless deposits.Aggregators: Aggregators like Jupiter and Dflow aggregate liquidity from multiple DEXs, AMMs, PropAMMs, etc., to find the optimal execution path for users, providing the lowest slippage and best prices.Conditional liquidity: Prevents market makers from being front-run, allowing them to offer tighter spreads, ultimately resulting in better trade prices and deeper liquidity.Overall improvements to SVM and the scheduler: Including optimizations for compute units, asynchronous program execution (APE), scheduling algorithm upgrades, etc., making programs run faster, more resource-efficient, and supporting higher concurrency.

Benson Sun: Bitcoin's decline reached a rare -5.65σ, occurring only 4 times in history

Cryptocurrency KOL and former FTX community partner Benson Sun posted that Bitcoin experienced an extreme drop this morning. Calculating with a 200-day lookback period, BTC's decline reached -5.65 standard deviations (σ). The Six Sigma standard in manufacturing allows for only 3.4 defects per million occurrences, which defines "almost impossible" in human industrial civilization. Yesterday's BTC volatility was just 0.35 standard deviations away from this "industrial-grade impossibility."A -5.65σ occurrence has a theoretical probability of about one in ten million under normal distribution. Despite the fat tail effect in financial markets, this level of volatility has only occurred 4 times since BTC began trading in July 2010, accounting for about 0.07% of all trading days. Even during the deep bear phases of 2018 and 2022, such a rapid decline had not occurred within a rolling 200-day period. This poses a severe challenge to quantitative strategies.Currently, most quantitative models are built on data after 2015, and historical samples exceeding 5.65σ, apart from the anomalous "312" flash crash in 2020, occurred before 2015, leaving almost no reference precedent.CoinKarma's quantitative strategy has shown a paper loss in this round of market conditions, but due to maintaining low leverage (about 1.4 times) over the long term, it remains manageable, with a maximum drawdown of about 30%. While extreme market conditions are an expensive "tuition," contracts and on-chain data will become important nutrients for future risk control models.
app_icon
ChainCatcher Building the Web3 world with innovations.