Zcash2026-09-30 03:53:43Zcash approves $1.5 million in bounty awards for Orchard bug finder Taylor HornbyVoting results for Zcash’s Q3 token holder-directed retroactive grants program show that both bounty proposals tied to Orchard counterfeit coin vulnerability finder Taylor Hornby have passed. One proposal covers a $750,000 bug bounty requested by Hornby, while the other is a $750,000 additional award nominated by community members. The combined amount comes to $1.5 million. The recipient must still complete KYC procedures and the fund distribution process before the grant is paid out. The update was reported by ChainCatcher in a 7x24 news brief.240
Relay2026-09-29 02:23:46Relay to Fully Reimburse Users After API Flaw Exposed Orders to Sandwich AttacksCross-chain execution protocol Relay said an earlier flaw in its API exposed pending order information before trades were executed, allowing MEV searchers to use routing state to carry out sandwich attacks. The incident affected about 5,600 users. Relay said the attackers made about $136,000, while the median user loss came to roughly $11.88. The team also said it paid a $50,000 bug bounty to Outputlayer, the security team that identified the issue. Relay plans to fully reimburse affected users for about $312,000 in total. According to the disclosure, users will not need to file claims or submit applications, as compensation will be sent automatically to the relevant wallet addresses. The details were reported by Odaily.230
OpenAI2026-09-20 04:36:05Hacktron says it used Claude and an SSO misconfiguration to reach OpenAI’s internal code repositorySecurity startup Hacktron said its three-member team chained together a libheif heap buffer overflow, an OpenAI single sign-on misconfiguration, and exploit code written with help from Claude Opus 5 to gain access to an OpenAI employee account and the company’s internal main code repository in under 72 hours. The group said it did not touch sensitive source code and instead opened a harmless pull request to prove access. OpenAI later paid a $6,500 bounty. According to Hacktron’s account, the attack began with an image uploaded to community.openai.com, a Discourse-based forum that processed HEIC and HEIF files through ImageMagick and libheif. The team said it moved from remote code execution in the production forum environment to admin access, then into an employee account whose Codex instance was connected to OpenAI’s GitHub organization. Hacktron argues the more serious issue was not the hosted forum alone, but the SSO setup that linked multiple services under the same login framework. The team also framed the incident as part of a broader shift in offensive capability, saying AI tools sharply increased what a small group could do with limited spending.460
DEEPCOIN2026-09-11 09:29:30DEEPCOIN says system-wide penetration test with HackenProof covered asset security, trading engine and APIsCrypto exchange DEEPCOIN said it has completed a broad penetration test in partnership with HackenProof, a bug bounty and crowdsourced security platform focused on Web3. According to the company, the review covered asset security, information security, the trading engine, API interfaces, smart contracts and client-side applications, with testing carried out by white-hat hackers and security researchers assembled by HackenProof. DEEPCOIN said the exercise simulated real-world attack scenarios across its core business modules. The company stated that the results showed strong defensive architecture in its core systems and a resilient risk-control framework, while potential risks were assessed and addressed through a closed-loop remediation process. Founder and CEO Ego said user asset protection remains the foundation of DEEPCOIN’s operations and growth, adding that proactive defense is preferable to passive response in an increasingly complex cybersecurity environment. HackenProof CEO Dmytro Matviiv said security testing should reflect real attack conditions, especially for exchanges that hold user funds and sensitive data, and described DEEPCOIN as proactive in identifying and resolving risks before they could turn into security issues. DEEPCOIN said it plans to deepen its strategic cooperation with HackenProof and explore a regular security inspection mechanism going forward.800
Blockstream2026-09-09 12:11:50White Hat Group in Liquid Incident Demands 10% Bug Bounty From BlockstreamA white hat hacker group tied to the Liquid exploit incident has accused Blockstream of spending only $1.5 million, or possibly no money at all, to secure assets worth $5 billion, according to monitoring cited by Bitcoin News. In a new on-chain message, the group said Blockstream should use its own funds to pay a bug bounty equal to 10% of the assets involved. It also warned that if Blockstream refuses to pay, holders would face a 15% loss. The group added that it plans to release the private key needed to decrypt earlier conversations with Blockstream. Previously, the group returned 3,400 BTC to the Liquid Federation, while about 600 BTC remain outstanding.960
Google Chrome2026-09-05 15:06:57Google Patches Chrome Zero-Day Exploited in Wild; Browser Wallet Security Under SpotlightGoogle has fixed a high-severity Chrome vulnerability (CVE-2026-85046) that was actively exploited in the wild, affecting the V8 engine. The patch is included in Chrome 152.7977.82/83 and will be rolled out in the coming days. The bug was reported by researcher Salvatore Gulizia on August 4, who received a $1,000 bounty. The update includes 12 security fixes, 9 of which are high-severity. Google has not linked the exploit to crypto thefts, but browser wallets and exchange accounts have been targeted previously.860
Cosmos2026-08-30 00:26:00Cosmos Labs EVM Security Report: $5.72M Stolen From 6 Chains in August BreachCosmos Labs has issued a security incident report on its EVM module, detailing how attackers stole roughly $5.72 million from six Cosmos chains between August 20 and August 25. The violation was first flagged by MANTRA, after which the Cosmos security team coordinated with about 40 chains to assess and mitigate the risk. Around $2.87 million in bridged assets were sold on DEXes, while another $2.85 million went through CEX accounts that have since been frozen pending investigation. Thirteen other networks that faced potential risk patched, halted chains, or applied other safeguards before any losses occurred. The underlying vulnerability had originally been reported on April 25 through a bug bounty program, but testers could not reproduce it in production configurations, so the team fixed it without a public security advisory. Going forward, Cosmos Labs says it will strengthen triage and remediation for critical vulnerabilities, widen the scope of security communications, and bring in external experts for a full audit of its security practices.870
0xbow.io2026-08-28 05:31:050xbow.io Awards $5,000 Bounty for Privacy Pools v1 SDK Bug DisclosureEthereum Foundation-backed 0xbow.io, a privacy and regulatory compliance tool, announced on X that it paid researcher ross.wei a $5,000 bounty for disclosing a vulnerability in the Privacy Pools v1 SDK. The flaw reduced the entropy of user account master key generation, according to the team. The bug was patched in March, a migration process was provided, and no user funds were lost.1100