BTC $77,190.23 -1.44%
ETH $2,406.73 -2.16%
BNB $684.89 -0.85%
XRP $1.34 -2.08%
SOL $99.64 -3.35%
TRX $0.3217 -3.08%
DOGE $0.0811 -2.09%
ADA $0.1970 -1.06%
BCH $246.37 -0.32%
LINK $11.18 -1.31%
HYPE $83.09 -1.01%
AAVE $127.32 +2.60%
SUI $0.7220 -0.80%
XLM $0.1751 -1.24%
ZEC $831.82 -1.90%
BTC $77,190.23 -1.44%
ETH $2,406.73 -2.16%
BNB $684.89 -0.85%
XRP $1.34 -2.08%
SOL $99.64 -3.35%
TRX $0.3217 -3.08%
DOGE $0.0811 -2.09%
ADA $0.1970 -1.06%
BCH $246.37 -0.32%
LINK $11.18 -1.31%
HYPE $83.09 -1.01%
AAVE $127.32 +2.60%
SUI $0.7220 -0.80%
XLM $0.1751 -1.24%
ZEC $831.82 -1.90%

users

All
Article
Flash

Ledger CTO responds to vulnerability FUD: The issue was fixed before it was disclosed, and users can safely use it by updating in a timely manner

Ledger's Chief Technology Officer Charles Guillemet stated that there has recently been "FUD" targeting Ledger in the market, as a smart contract security company claimed to have discovered vulnerabilities in the Ledger Ethereum application. Guillemet mentioned that there indeed were vulnerabilities related to certain Clear Signing processes in the Ledger Ethereum application, but these vulnerabilities were discovered by Ledger's security research team Donjon using AI-driven vulnerability research tools, and the fixes were completed and deployed two weeks ago. Users can obtain protection by timely updating their Ledger device firmware and applications.The relevant security company contacted Ledger's bug bounty program only after the fixes were completed, did not follow responsible disclosure processes, and did not communicate with the bug bounty team, yet implied in subsequent content that the issue had not been resolved. This approach is not true security research but rather a way to create panic for attention. AI is changing the cybersecurity landscape, and both attackers and defenders can enhance efficiency with AI, but AI-driven security research can only truly enhance the security of the entire ecosystem when basic security principles such as responsible disclosure and pre-release verification are followed.Guillemet finally reminded Ledger users to keep their device firmware, Ledger applications, and related software up to date to automatically receive the latest security fixes and research results. Users should not be influenced by the related "FUD" and should timely update their software and maintain safe habits.

first_img Aave iOS app has opened early access, while Android and Web users are still pending access

Aave began opening its iOS mobile application to early users on Wednesday, pushing its consumer savings product into early access, while Android and Web users still need to wait on the waiting list. Aave founder Stani Kulechov stated that the Ghost Pass allows users to invite friends to skip the waiting list.The app is positioned as a savings application, supporting bank account and stablecoin deposits, allowing users to connect bank accounts and debit cards, with stablecoin wallets supporting deposits and withdrawals on Arbitrum. Funds deposited generate returns through the public lending market, with assets supplied to the lending pool, and the interest paid by borrowers flowing to depositors. Aave Labs stated in July that there were about 50,000 registered users on the iOS waiting list.Aave describes the app as self-custodial, although it has login and recovery features similar to fintech applications. The app's terms state that the embedded wallet generates and stores private keys locally, and Aave Labs does not hold user assets or keys, managing wallet setup and gas through smart account abstraction. This release is part of Aave's initiative to expand retail distribution following the acquisition of Stable Finance in October 2025, with Stable Vaults now providing a savings layer for the Aave app and open to fintech companies seeking embedded stablecoin yields.

Jason Fung, Head of Global Partnerships: The prediction market should not only be a "trading market," but should also become an open ecosystem for users to create markets

On August 21, the GATE ZONE fireside chat event took place in the Summer Bay area of Coinfest Asia, where Gate Head of Global Partnerships Jason Fung shared insights on the theme "Predicting the Biggest Market Opportunities." He discussed the competitive landscape of prediction markets, user-created markets, the Builder ecosystem, and future market opportunities. Jason Fung stated that as on-chain prediction markets continue to develop, industry competition will no longer focus solely on liquidity and trading volume. Instead, lowering the barriers to market creation, diversifying market types, and enabling more users to participate in market building will become important directions for the future development of prediction markets.Regarding the recent launch of the event contract Builder by Gate DexBuilder, Jason Fung mentioned that enabling users to create markets independently is an important step towards the openness of prediction markets. By lowering the barriers to creating and launching event markets, users can quickly build markets around popular events and explore more niche themes and potential demands, thereby driving the evolution of prediction markets from a product form dominated by a few platforms to a more open market ecosystem.Jason Fung believes that there are still many opportunities in prediction markets that have not been fully explored, and their application scope is expected to continue extending from popular fields such as politics, sports, crypto, AI, and entertainment. As more developers and entrepreneurs enter this space, the Builder ecosystem, market diversity, and user experience will become important driving forces for industry development, and on-chain event markets are expected to further expand from early user groups to a broader user market.

Coldcard releases new firmware to enhance security; affected users need to regenerate their mnemonic phrases and migrate their assets

Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following an emergency fix, focusing on addressing the security risks posed by previous mnemonic phrase generation attacks. Each newly generated mnemonic phrase must include at least one user entropy source, such as irregular key presses at least 65 times, physical dice rolls 50 times, or physical coin tosses 128 times, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2.The new firmware also adds pre-signing phased PSBT verification, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard states that this update aims to further reduce the risk of the device being attacked.The official reminder is that updating the firmware cannot fix existing mnemonic phrases generated by previously affected firmware. If a user's mnemonic phrase falls within the scope of this security announcement, they should first update the device, then generate and verify a brand new mnemonic phrase, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signatures of the downloaded firmware.
app_icon
ChainCatcher Building the Web3 world with innovations.