exploit – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 06 Sep 2025 05:45:27 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 exploit – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Coinbase’s Go-To AI Coding Tool Found Vulnerable to ‘CopyPasta’ Exploit https://earlybirdsinvest.com/coinbases-go-to-ai-coding-tool-found-vulnerable-to-copypasta-exploit/ https://earlybirdsinvest.com/coinbases-go-to-ai-coding-tool-found-vulnerable-to-copypasta-exploit/#respond Sat, 06 Sep 2025 05:45:27 +0000 https://earlybirdsinvest.com/coinbases-go-to-ai-coding-tool-found-vulnerable-to-copypasta-exploit/

A new exploit targeting AI coding assistants has raised alarms across the developer community, opening companies such as crypto exchange Coinbase to the risk of potential attacks if extensive safeguards aren’t in place.

Cybersecurity firm HiddenLayer disclosed Thursday that attackers can weaponize a so-called “CopyPasta License Attack” to inject hidden instructions into common developer files.

The exploit primarily affects Cursor, an AI-powered coding tool that Coinbase engineers said in August was among the team’s AI tools. Cursor is said to have been used by “every Coinbase engineer.”

How the attack works

The technique takes advantage of how AI coding assistants treat licensing files as authoritative instructions. By embedding malicious payloads in hidden markdown comments within files such as LICENSE.txt, the exploit convinces the model that these instructions must be preserved and replicated across every file it touches.

Once the AI accepts the “license” as legitimate, it automatically propagates the injected code into new or edited files, spreading without direct user input.

This approach sidesteps traditional malware detection because the malicious commands are disguised as harmless documentation, allowing the virus to spread through an entire codebase without a developer’s knowledge.

In its report, HiddenLayer researchers demonstrated how Cursor could be tricked into adding backdoors, siphoning sensitive data, or running resource-draining commands — all disguised inside seemingly innocuous project files.

“Injected code could stage a backdoor, silently exfiltrate sensitive data or manipulate critical files,” the firm said.

Coinbase CEO Brian Armstrong said on Thursday that AI had written up to 40% of the exchange’s code, with a goal of reaching 50% by next month.

However, Armstrong clarified that AI-assisted coding at Coinbase is concentrated in user interface and non-sensitive backends, with “complex and system-critical systems” adopting more slowly.

‘Potentially malicious’

Even so, the optics of a virus targeting Coinbase’s preferred tool amplified industry criticism.

AI prompt injections are not new, but the CopyPasta method advances the threat model by enabling semi-autonomous spread. Instead of targeting a single user, infected files become vectors that compromise every other AI agent that reads them, creating a chain reaction across repositories.

Compared to earlier AI “worm” concepts like Morris II, which hijacked email agents to spam or exfiltrate data, CopyPasta is more insidious because it leverages trusted developer workflows. Instead of requiring user approval or interaction, it embeds itself in files that every coding agent naturally references.

Where Morris II fell short due to human checks on email activity, CopyPasta thrives by hiding inside documentation that developers rarely scrutinize.

Security teams are now urging organizations to scan files for hidden comments and review all AI-generated changes manually.

“All untrusted data entering LLM contexts should be treated as potentially malicious,” HiddenLayer warned, calling for systematic detection before prompt-based attacks scale further.

(CoinDesk has reached out to Coinbase for comments on the attack vector.)

]]>
https://earlybirdsinvest.com/coinbases-go-to-ai-coding-tool-found-vulnerable-to-copypasta-exploit/feed/ 0 57008
$2.4 Million Vanishes from Bunni DEX in Targeted Liquidity Exploit https://earlybirdsinvest.com/2-4-million-vanishes-from-bunni-dex-in-targeted-liquidity-exploit/ https://earlybirdsinvest.com/2-4-million-vanishes-from-bunni-dex-in-targeted-liquidity-exploit/#respond Tue, 02 Sep 2025 18:28:59 +0000 https://earlybirdsinvest.com/2-4-million-vanishes-from-bunni-dex-in-targeted-liquidity-exploit/

A recent exploit has forced decentralized exchange Bunni to pause its smart contracts after a vulnerability allowed an attacker to take around $2.4 million in stablecoins.

Security researchers reviewing blockchain records confirmed that the loss occurred due to a flaw in how Bunni calculates liquidity distribution.

The incident was confirmed by the Bunni team on X on September 2, where they announced the shutdown of all smart contract activity across supported blockchains while the situation is under review.

Is Your Crypto Safe? (5 Best Crypto Security Practices Explained)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Funds were drained from Bunni’s Ethereum
ETH


$4,289.92

contracts and moved into a single wallet. This wallet currently holds around $1.33 million in USDC
USDC


$0.9996

and another $1.04 million in USDT
USDT


$0.9992

.

Following the event, Bunni contributor @Psaul26ix urged users to exit the platform immediately and warned them to remove any remaining assets from its pools.

Bunni relies on Euler Finance to manage its lending and structured product offerings. Despite the connection, Euler’s CEO, Michael Bentley, made it clear that Euler’s own protocol was not impacted.

Instead of using the default Uniswap
UNI


$9.43

logic, Bunni uses its own Liquidity Distribution Function (LDF), designed to spread liquidity across different price levels to help providers earn better returns. However, this function appears to have been at the core of the issue.

Victor Tran, the co-founder of KyberNetwork, explained that the attacker had discovered a way to trick the system by making trades of exact sizes, which caused errors in the liquidity rebalancing process.

On September 1, attackers exploited a security flaw to steal WLFI tokens from Ethereum ETH wallets. How? Read the full story.


]]>
https://earlybirdsinvest.com/2-4-million-vanishes-from-bunni-dex-in-targeted-liquidity-exploit/feed/ 0 56420
Murky Panda hackers exploit cloud trust to hack downstream customers https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/ https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/#respond Sat, 23 Aug 2025 03:02:33 +0000 https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/

Chinese hacker

A Chinese state-sponsored hacking group known as Murky Panda (Silk Typhoon) exploits trusted relationships in cloud environments to gain initial access to the networks and data of downstream customers.

Murky Panda, also known as Silk Typhoon (Microsoft) and Hafnium, is known for targeting government, technology, academic, legal, and professional services organizations in North America.

The hacking group, under its numerous names, has been linked to numerous cyberespionage campaigns, including the wave of Microsoft Exchange breaches in 2021 that utilized the ProxyLogon vulnerability. More recent attacks, include those on the U.S. Treasury’s Office of Foreign Assets Control (OFAC) and the Committee on Foreign Investment.

In March, Microsoft reported that Silk Typhoon had begun targeting remote management tools and cloud services in supply chain attacks to gain access to downstream customers’ networks.

Exploiting trusted cloud relationships

Murky Panda commonly gains initial access to corporate networks by exploiting internet-exposed devices and services, such as the CVE-2023-3519 flaw in Citrix NetScaler devices, ProxyLogin in Microsoft Exchange, and CVE-2025-0282 in Ivanti Pulse Connect VPN.

However, a new report by CrowdStrike demonstrates how the threat actors are also known to compromise cloud service providers to abuse the trust these companies have with their customers.

Because cloud providers are sometimes granted built-in administrative access to customer environments, attackers who compromise them can abuse this trust to pivot directly into downstream networks and data.

In one case, the hackers exploited zero-day vulnerabilities to break into a SaaS provider’s cloud environment. They then gained access to the provider’s application registration secret in Entra ID, which allowed them to authenticate as a service and log into downstream customer environments. Using this access, they were able to read customers’ emails and steal sensitive data.

In another attack, Murky Panda compromised a Microsoft cloud solution provider with delegated administrative privileges (DAP). By compromising an account in the Admin Agent group, the attackers gained Global Administrator rights across all downstream tenants. They then created backdoor accounts in customer environments and escalated privileges, enabling persistence and the ability to access email and application data.

CrowdStrike highlights that breaches via trusted-relationships are rare, they are less monitored than more common vectors such as credential theft. By exploiting these trust models, Murky Panda can more easily blend in with legitimate traffic and activity to maintain stealthy access for long periods.

In addition to their cloud-focused intrusions, Murky Panda also uses a variety of tools and custom malware to maintain access and evade detection.

The attackers commonly deploy the Neo-reGeorg open-source web shell and the China Chopper web shells, both widely associated with Chinese espionage actors, to establish persistence on compromised servers.

The group also has access to a custom Linux-based remote access trojan (RAT) called CloudedHope, which allows them to take control of infected devices and spread further in the network. 

Murky Panda also demonstrates strong operational security (OPSEC), including modifying timestamps and deleting logs to hinder forensic analysis.

The group is also known to use compromised small office and home office (SOHO) devices as proxy servers, allowing them to conduct attacks as if they were within a targeted country’s infrastructure. This allows their malicious traffic to blend in with normal traffic and evade detection.

Significant espionage threat

CrowdStrike warns that Murky Panda/Silk Typhoon is a sophisticated adversary with advanced skills and the ability to rapidly weaponize both zero-day and n-day vulnerabilities.

Their abuse of trusted cloud relationships poses a significant risk to organizations that utilize SaaS and cloud providers.

To defend against Murky Panda attacks, CrowdStrike recommends that organizations monitor for unusual Entra ID service principal sign-ins, enforce multi-factor authentication for cloud provider accounts, monitor Entra ID logs, and patch cloud-facing infrastructure promptly.

“MURKY PANDA poses a significant threat to government, technology, legal, and professional services entities in North America and to their suppliers with access to sensitive information,” concludes CrowdStrike.

“Organizations that rely heavily on cloud environments are innately vulnerable to trusted-relationship compromises in the cloud. China-nexus adversaries such as MURKY PANDA continue to leverage sophisticated tradecraft to facilitate their espionage operations, targeting numerous sectors globally.”

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/feed/ 0 54647
CrediX Goes Silent After Exploit Deal, $4.5 Million Still Missing https://earlybirdsinvest.com/credix-goes-silent-after-exploit-deal-4-5-million-still-missing/ https://earlybirdsinvest.com/credix-goes-silent-after-exploit-deal-4-5-million-still-missing/#respond Sat, 09 Aug 2025 05:27:19 +0000 https://earlybirdsinvest.com/credix-goes-silent-after-exploit-deal-4-5-million-still-missing/

CrediX Finance, a decentralized lending platform, has gone silent after losing around $4.5 million in a major hack.

The issue was first flagged on August 4 by CertiK, PeckShield, and SlowMist, who said that attackers had accessed key wallets tied to CrediX Finance.

Following the incident, CrediX took its website offline and stopped all deposits. On August 8, its X account had stopped posting, and its Telegram group had also disappeared.

What is a MetaMask Wallet? (And How to Use it - Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Before vanishing, the platform claimed it had reached a deal with the person behind the exploit. In a now-deleted post, CrediX said, “Reached successful parley with the exploiter who agreed to return the funds within the next 24-48 hours in return for money fully paid by the CrediX treasury”.

Meanwhile, Stability DAO, a decentralized group that was also affected, is working on a formal legal complaint. The DAO said it has been in touch with several other impacted teams, including Sonic Labs, Euler, Beets, and Trevee, to investigate what happened.

According to a statement, they are collecting evidence, tracking the stolen funds, and reaching out to the authorities.

Stability DAO also said it has access to identity documents for two members of the CrediX team, which will be included in the legal report.

On August 7, Koi Security reported that GreedyBear stole more than $1 million in cryptocurrency. How? Read the full story.


]]>
https://earlybirdsinvest.com/credix-goes-silent-after-exploit-deal-4-5-million-still-missing/feed/ 0 52270
Attackers exploit link-wrapping services to steal Microsoft 365 logins https://earlybirdsinvest.com/attackers-exploit-link-wrapping-services-to-steal-microsoft-365-logins/ https://earlybirdsinvest.com/attackers-exploit-link-wrapping-services-to-steal-microsoft-365-logins/#respond Mon, 04 Aug 2025 08:35:50 +0000 https://earlybirdsinvest.com/attackers-exploit-link-wrapping-services-to-steal-microsoft-365-logins/

A threat actor has been abusing link wrapping services from reputed technology companies to mask malicious links leading to Microsoft 365 phishing pages that collect login credentials.

The attacker exploited the URL security feature from cybersecurity company Proofpoint and cloud communications firm Intermedia in campaigns from June through July.

Some email security services include a link wrapping feature that rewrites the URLs in the message to a trusted domain and passes them through a scanning server designed to block malicious destinations.

Legitimizing phishing URLs

Cloudflare’s Email Security team discovered that the adversary legitimized the malicious URLs after compromising Proofpoint and Intermedia-protected email accounts, and likely used their unauthorized access to distribute the “laundered” links.

“Attackers abused Proofpoint link wrapping in a variety of ways, including multi-tiered redirect abuse with URL shorteners via compromised accounts,” the researchers said.

“The Intermedia link wrapping abuse we observed also focused on gaining unauthorized access to email accounts protected by link wrapping“ – Cloudflare Email Security

The threat actor added an obfuscation layer by first shortening the malicious link before sending it from a protected account, which automatically wrapped the link.

The researchers say that the attacker lured victims with fake notifications for voicemail or shared Microsoft Teams documents. At the end of the redirect chain was a Microsoft Office 365 phishing page that collected credentials.

Microsoft 365 phishing delivered by exploiting link-wrapping feature
Microsoft 365 phishing delivered by exploiting link-wrapping feature
source: Cloudflare Email Security

In the campaign that abused Intermedia’s service, the threat actor delivered emails pretending to be a “Zix” secure message notification for a viewing a secure document, or impersonated a communication from Microsoft Teams informing of a newly received message.

The link allegedly leading to the document was a URL wrapped by Intermedia’s service and redirected to a fake page from digital and email marketing platform Constant Contact hosting the phishing page.

Clicking on the reply button in the fake Teams notification led to a Microsoft phishing page that would collect login credentials.

By disguising the malicious destinations with legitimate email protection URLs, the threat actor increased the chances of a successful attack, the Cloudflare researchers said.

It should be noted that abusing legitimate services to deliver malicious payloads is not new but exploiting the link-wrapping security feature is a recent development on the phishing scene.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/attackers-exploit-link-wrapping-services-to-steal-microsoft-365-logins/feed/ 0 51383
MIT Brothers Must Face Trial Over $25 Million Ethereum Bot Exploit https://earlybirdsinvest.com/mit-brothers-must-face-trial-over-25-million-ethereum-bot-exploit/ https://earlybirdsinvest.com/mit-brothers-must-face-trial-over-25-million-ethereum-bot-exploit/#respond Thu, 24 Jul 2025 14:33:16 +0000 https://earlybirdsinvest.com/mit-brothers-must-face-trial-over-25-million-ethereum-bot-exploit/

Anton and James Peraire-Bueno, both graduates of MIT, will have to defend themselves in court after a judge declined to dismiss charges tied to a major crypto theft on Ethereum
ETH


$3,636.18

.

The brothers are accused of using a technical strategy to take $25 million worth of crypto by targeting trading bots on the Ethereum network.

On July 23, US District Judge Jessica Clarke ruled that the details in the indictment were enough to support claims of wire fraud, even though the method used was new.

How to Create an NFT: Easiest Way (Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

According to prosecutors, the pair exploited a system used by MEV bots. These bots scan upcoming blockchain transactions and look for ways to make a profit, usually by getting ahead of other trades.

The indictment describes how the brothers planned and carried out a four-part strategy they called “bait, block, search, and propagation”. They allegedly used this process to trick the bots, delay other transactions, and transfer money in their favor.

The brothers set up 16 Ethereum validator accounts using over 500 ETH. These validators gave them more control over the transaction order and helped them complete the entire operation in just 12 seconds.

Anton and James argued that what they did was allowed by Ethereum’s rules and claimed the bots were already using unfair trading tactics.

Their lawyers said the wire fraud law did not apply to this type of case. However, Judge Clarke stated that the law covered the kind of conduct described, regardless of the tools used to carry it out.

A Denver couple recently faced 40 charges after raising $3.4 million from their faith-based community through a crypto token. How did the case unfold? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/mit-brothers-must-face-trial-over-25-million-ethereum-bot-exploit/feed/ 0 49407
Hackers Exploit BigONE’s Systems, Steal Millions in Bitcoin and Ethereum https://earlybirdsinvest.com/hackers-exploit-bigones-systems-steal-millions-in-bitcoin-and-ethereum/ https://earlybirdsinvest.com/hackers-exploit-bigones-systems-steal-millions-in-bitcoin-and-ethereum/#respond Wed, 16 Jul 2025 15:05:52 +0000 https://earlybirdsinvest.com/hackers-exploit-bigones-systems-steal-millions-in-bitcoin-and-ethereum/

Crypto exchange BigONE has reported a security breach involving its hot wallet infrastructure, which resulted in an estimated $27 million loss.

The incident was detected by blockchain security platform SlowMist on July 16.

Hot Wallet Nightmare

SlowMist said that the production network was compromised, and the operating logic of account and risk control-related servers was modified, which allowed the attacker withdraw funds.

BigONE confirmed the breach after the exchange’s real-time monitoring system flagged abnormal asset movements and said it was caused by a third-party attack. The exchange, however, stated that all private keys remain secure and the attack path has been identified and contained to prevent further losses.

The exchange said that it is working with SlowMist to trace the attacker’s wallet addresses and monitor the movement of the stolen funds, which include 120 BTC, 350 ETH, and over 8 million USDT across four networks.

In a statement, BigONE has vowed to cover all user losses using its internal security reserves. The exchange said it aims to ensure that user assets remain intact while it continues investigations.

After a temporary suspension, the platform restored its services. BigONE exec Alex Ash stated,

“The system upgrade has been successfully completed. Deposit and trading services have now been fully restored, and you may log in via Web or App to resume your transactions. Thank you for your patience and continued support.”

On-chain sleuth ZachXBT remarked that he does not sympathize with the exchange, and alleged that it processed significant volumes tied to pig butchering, romance, and investment scams.

He added that if more “questionable” offshore exchanges like MEXC or KuCoin were hacked for large sums, it could benefit the crypto industry by acting as a “natural cleanse” without requiring government intervention.

GMX Hack

The incident comes days after decentralized trading platform GMX was exploited for $42 million. The hacker, however, returned $40.5 million less than 48 hours after the exploit. The penetration vector included a re-entrancy vulnerability in GMX’s V1 smart contracts on July , allowing the perpetrator to manipulate GLP token prices to drain funds. They later bridged them from Arbitrum to Ethereum.

GMX offered a 10% white hat bounty in exchange for the stolen assets, which the hacker accepted, keeping a profit of about $4.5 million. GMX confirmed its V2 protocol was not affected by the incident.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/hackers-exploit-bigones-systems-steal-millions-in-bitcoin-and-ethereum/feed/ 0 47977
Venn Network Stops $10 Million Smart Contract Exploit Before It Strikes https://earlybirdsinvest.com/venn-network-stops-10-million-smart-contract-exploit-before-it-strikes/ https://earlybirdsinvest.com/venn-network-stops-10-million-smart-contract-exploit-before-it-strikes/#respond Fri, 11 Jul 2025 04:02:46 +0000 https://earlybirdsinvest.com/venn-network-stops-10-million-smart-contract-exploit-before-it-strikes/

Venn Network researchers have stopped a security breach that could have stolen more than $10 million from decentralized finance (DeFi) projects.

The researchers identified a hidden weakness in thousands of smart contracts and secured the funds before the attacker could take advantage.

The problem was first spotted by @deeberiroz, a researcher with Venn Network. They found that many ERC-1967 proxy contracts were left uninitialized, which meant they had not yet been fully set up.

What is Balancer in Crypto? Beginner Friendly BAL Explainer

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

In a July 10 post on X, @deeberiroz said:

Venn Network just discovered a critical backdoor on thousands of smart contracts leaving over $10,000,000 at risk for months.

This left them vulnerable to being hijacked by an attacker, who could insert hidden access and maintain control even after the contracts were later initialized.

Once the issue was discovered, @deeberiroz reached out to other security experts, including @pcaversaccio, @dedaub, and @seal_911. They spent about 36 hours securing funds and fixing the vulnerable contracts before the attacker could act.

Berachain, a DeFi protocol, responded by pausing its incentive contract and transferring its funds to a new contract.

The Berachain Foundation announced on X that no user funds were lost and that incentive claims would resume within a day after updates were finished.

Recently, GMX V1, the platform’s first-generation decentralized exchange (DEX), was forced to suspend trading. What happened? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/venn-network-stops-10-million-smart-contract-exploit-before-it-strikes/feed/ 0 46959
GMX halts trading, token minting following $40 million exploit https://earlybirdsinvest.com/gmx-halts-trading-token-minting-following-40-million-exploit/ https://earlybirdsinvest.com/gmx-halts-trading-token-minting-following-40-million-exploit/#respond Wed, 09 Jul 2025 18:26:34 +0000 https://earlybirdsinvest.com/gmx-halts-trading-token-minting-following-40-million-exploit/

The GMX protocol halted trading on GMX V1 after a liquidity pool suffered an exploit on Wednesday, leading to $40 million in funds being stolen and sent to an unknown wallet.

GMX V1 is the first version of the GMX perpetual exchange deployed on the Arbitrum network. The attacked pool provides the liquidity provider of the GMX protocol with a basket of underlying digital assets including Bitcoin (BTC), Ether (ETH) and stablecoins, according to the GMX team.

The protocol has also announced a temporary suspension in minting and redemption of GLP tokens on both Arbitrum and the layer-1 Avalanche network to protect against any additional fallout from the cybersecurity exploit.

Users of the platform were instructed to disable leverage and change their settings to disable GLP minting.

Cybercrime, Cybersecurity, Hacks
GLP hacker transfers funds to their wallet. Source: Arbiscan

“The exploit does not affect GMX V2, its markets, or liquidity pools, nor the GMX token itself. Based on the available information, the vulnerability is limited to GMX V1 and its GLP pool,” the team said.

Blockchain security company SlowMist attributed the exploit to a design flaw that allowed hackers to manipulate the GLP token price through the calculation of the total assets under management.

Cybercrime, Cybersecurity, Hacks
Source: GMX

Hacks and cybersecurity crimes continue to be major pain points in the crypto industry, affecting both centralized platforms and decentralized exchanges. The hacks have caused billions of dollars in cumulative losses and discouraged new participants from adopting crypto due to the fear of victimization by sophisticated threat actors.

Related: Brazil’s central bank service provider hacked, $140M stolen

Crypto hacks continue to be a feature of the digital asset landscape

Losses from crypto hacks reached $2.5 billion in the first half of 2025, with approximately $1.4 billion in stolen funds resulting from the Bybit hack in February.

In June, Iranian crypto exchange Nobitex fell victim to a cyberattack from a pro-Israeli hacker group called Gonjeshke Darande.

The hack caused over $81 million in losses for the Iranian exchange, which was forced to pause services temporarily to mitigate the effects of the hack.

The United States Treasury’s Office of Foreign Assets Control (OFAC) announced sanctions on Song Kum Hyok, a group of North Korea state-affiliated hackers, on Wednesday.

Song Kum Hyok infiltrated several crypto companies and defense contracting businesses, intending to exploit these organizations from the inside with both social engineering scams and cybersecurity breaches.

Magazine: North Korea crypto hackers tap ChatGPT, Malaysia road money siphoned: Asia Express

]]> https://earlybirdsinvest.com/gmx-halts-trading-token-minting-following-40-million-exploit/feed/ 0 46700 Exploit details for max severity Cisco IOS XE flaw now public https://earlybirdsinvest.com/exploit-details-for-max-severity-cisco-ios-xe-flaw-now-public/ https://earlybirdsinvest.com/exploit-details-for-max-severity-cisco-ios-xe-flaw-now-public/#respond Sun, 01 Jun 2025 21:29:32 +0000 https://earlybirdsinvest.com/exploit-details-for-max-severity-cisco-ios-xe-flaw-now-public/

Cisco

Technical details about a maximum-severity Cisco IOS XE WLC arbitrary file upload flaw tracked as CVE-2025-20188 have been made publicly available, bringing us closer to a working exploit.

The write-up by Horizon3 researchers does not contain a ‘ready-to-run’ proof of concept RCE exploit script, but it does provide enough information for a skilled attacker or even an LLM to fill in the missing pieces.

Given the immediate risk of weaponization and widespread use in attacks, it is recommended that impacted users take action now to protect their endpoints.

The Cisco IOS XE WLC flaw

Cisco disclosed the critical flaw in IOS XE Software for Wireless LAN Controllers on May 7, 2025, which allows an attacker to take over devices.

The vendor said it is caused by a hard-coded JSON Web Token (JWT) that allows an unauthenticated, remote attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.

The bulletin noted that CVE-2025-20188 is only dangerous when the ‘Out-of-Band AP Image Download’ feature is enabled on the device, in which case, the following device models are at risk:

  • Catalyst 9800-CL Wireless Controllers for Cloud
  • Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches
  • Catalyst 9800 Series Wireless Controllers
  • Embedded Wireless Controller on Catalyst APs

Horizon3’s attack example

Horizon3’s analysis shows that the flaw exists due to a hardcoded JWT fallback secret (“notfound”) used by the backend Lua scripts for upload endpoints combined with insufficient path validation.

Specifically, the backend uses OpenResty (Lua + Nginx) scripts to validate JWT tokens and handle file uploads, but if the ‘/tmp/nginx_jwt_key’ file is missing, the script falls back to the string “notfound” as the secret to verify JWTs.

This basically allows attackers to generate valid tokens without knowing any secrets by simply using ‘HS256’ and ‘notfound.’

Horizon3’s example sends an HTTP POST request with a file upload to the ‘/ap_spec_rec/upload/’ endpoint via port 8443 and uses filename path traversal to drop an innocuous file (foo.txt) outside the intended directory.

Request to  regenerate the JWT using the notfound secret key
Request to regenerate the JWT using the notfound secret key
Source: Horizon3

To escalate the file upload flaw to remote code execution, the attacker could overwrite configuration files loaded by backend services, drop web shells, or abuse monitored files to trigger unauthorized actions.

Horizon3’s example abuses the ‘pvp.sh’ service that monitors specific directories, overwrites the config files it depends on, and triggers a reload even to run attacker commands.

Given the elevated risk of exploitation, users are recommended to upgrade to a patched version (17.12.04 or newer) as soon as possible.

As a temporary workaround, admins can turn off the Out-of-Band AP Image Download feature to close the vulnerable service.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

]]>
https://earlybirdsinvest.com/exploit-details-for-max-severity-cisco-ios-xe-flaw-now-public/feed/ 0 39582