‹ BackNewsOn-Chain Security

On-Chain Security

Blockstream Refuses to Pay Ransom After Liquid Bitcoin Exploit
SlowMist says ether.fi AtomicQueue flaw led to theft of about 15.45 ETH
SlowMist says BeatXswap on BSC lost about $77,500 in price manipulation attack
ChainCatcher
2026-09-08 02:11:43

ChainCatcher Morning Brief: Korean memory inventory warning and Hunter Biden’s LAPTOP token plan lead a packed crypto cycle

ChainCatcher’s latest morning roundup spans a wide mix of crypto, macro, security and tech-capex developments from the past 24 hours. Bitcoin slipped nearly 1% to around $79,700 as rising oil prices, linked in the report to an escalation between the U.S. and Iran, added fresh pressure to risk assets. At the same time, spot crypto ETFs kept attracting money, with Bitcoin spot ETFs posting $987 million in weekly net inflows and Ethereum spot ETFs drawing $218 million, both marking a third straight week of net inflows. Beyond price action, several project and security updates stood out. Vitalik Buterin pushed back on claims that AI could break Bitcoin’s security assumptions, while Galaxy Research said roughly 45% of the assets stolen in the Coldcard “Wave 3” incident have now moved into cross-chain or mixing paths. Liquid Network and SideSwap also remained in focus after an exploit involving 4,000 L-BTC, and Blockstream said the vulnerability tied to the incident had been patched. On the corporate and policy front, KB Securities warned that Samsung Electronics and SK Hynix have memory inventories below 10 days, pointing to a tighter supply picture as AI infrastructure spending expands. The Wall Street Journal separately reported that Hunter Biden plans to launch a meme coin called LAPTOP on Base on Sept. 9, with a detailed token allocation, lockup and burn-or-charity framework tied to preset future events.

760
ChainCatcher Morning Brief: Korean memory inventory warning and Hunter Biden’s LAPTOP token plan lead a packed crypto cycle
Liquid attacker broadcasts return of 3,400 BTC, keeps 598 BTC after on-chain negotiation
SlowMist warns of copycat exploit setup on BSC using recent Notional Finance attack pattern
AI Agent
2026-09-02 08:33:10

After the KelpDAO exploit, the harder question is who verifies what AI agents see and sign

The April 18, 2026 exploit of KelpDAO’s rsETH bridge exposed a familiar weakness in crypto systems: the failure point was not core cryptography, but the chain of authority around who could sign, what data they relied on, and how those checks were configured. According to LayerZero’s incident report, attackers used social engineering to obtain a developer session key, poisoned an internal RPC used by LayerZero Labs’ DVN, and suppressed external RPC endpoints with a denial-of-service attack, leading the signing service to certify forged messages. KelpDAO had also shifted its validation path from 2-of-2 to 1-of-1 DVN, removing an independent cross-check. CrowdStrike and Mandiant attributed the attack with high confidence to the North Korea-linked TraderTraitor group, also tracked as UNC4899. The article argues that this matters even more as AI agents gain onchain execution power through smart accounts, strategy wallets, and limited signing services. A valid signature can show that an authorized path was invoked, but not that the input data was sound, the decision matched policy, or the trade should have happened at that moment. It reviews the limits of oracles, dispute resolution, multisig bridges, MPC custody, and TEE-based systems, then examines DeepSafe’s CRVA design, which combines hidden committee selection, Ring-VRF, threshold MPC, and TEE. The model aims to reduce validator exposure and signing concentration, but it does not automatically determine whether the result being verified is actually correct.

980
After the KelpDAO exploit, the harder question is who verifies what AI agents see and sign