Scan to download
BTC $76,853.67 -1.51%
ETH $2,288.96 -2.46%
BNB $623.35 -1.30%
XRP $1.39 -2.26%
SOL $84.55 -2.32%
TRX $0.3251 +0.36%
DOGE $0.0978 -0.89%
ADA $0.2456 -2.50%
BCH $448.09 -0.76%
LINK $9.23 -2.43%
HYPE $41.64 +0.68%
AAVE $96.95 +1.17%
SUI $0.9239 -1.95%
XLM $0.1649 -3.22%
ZEC $355.99 +0.49%
BTC $76,853.67 -1.51%
ETH $2,288.96 -2.46%
BNB $623.35 -1.30%
XRP $1.39 -2.26%
SOL $84.55 -2.32%
TRX $0.3251 +0.36%
DOGE $0.0978 -0.89%
ADA $0.2456 -2.50%
BCH $448.09 -0.76%
LINK $9.23 -2.43%
HYPE $41.64 +0.68%
AAVE $96.95 +1.17%
SUI $0.9239 -1.95%
XLM $0.1649 -3.22%
ZEC $355.99 +0.49%

vulnerabilities

Security Company: AI agent's encrypted payment infrastructure has significant security vulnerabilities, LLM router has led to the theft of a $500,000 wallet

According to CoinDesk, researchers from the University of California, Santa Barbara, the University of California, San Diego, blockchain security company Fuzzland, and World Liberty Financial have jointly published a paper warning that "LLM routers"—intermediary services located between users and AI models—have become a significant security risk for crypto assets.The researchers found that 26 LLM routers are secretly injecting malicious tool calls and stealing user credentials, with one incident leading to the emptying of a customer's crypto wallet worth $500,000.Additionally, the researchers were able to control about 400 downstream hosts within hours by "polluting" the router ecosystem. Since sensitive data such as private keys and API credentials are often transmitted in plaintext through these routers, users are effectively exposing their assets to risk without their knowledge.The researchers pointed out that as McKinsey predicts AI agents will mediate $30 trillion to $50 trillion in global consumer spending by 2030, Binance founder Changpeng Zhao also predicts that the payment volume of AI agents will be a million times that of humans. The current infrastructure security is severely lagging behind the pace of industry development, and the risk of the "weakest link" could trigger a systemic chain crisis.

The Ministry of Industry and Information Technology of China issued a risk alert regarding the timely update of specific iOS versions to prevent the exploitation of vulnerabilities

The Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) of the Ministry of Industry and Information Technology of China has monitored and found that attackers are using exploit tools targeting Apple Inc.'s terminal products to carry out cyber attack activities, which can lead to serious harms such as information theft and system control. The affected range includes Apple terminal products such as iPhone and iPad running iOS 13 to 17.2.1.Attackers induce users to use the Safari browser to visit web pages containing malicious code through methods such as SMS, email, or web poisoning, comprehensively utilizing security vulnerabilities present in the terminal devices to implant remote control Trojans into the victim's terminal products, stealing sensitive user information, gaining maximum privileges, and taking control.It is recommended that users of Apple terminal products conduct risk assessments, and promptly fix vulnerabilities through version upgrades and patch installations (refer to the Apple Security Updates). Pay attention to system update notifications and the latest security update announcements released by Apple, upgrade to the latest secure version in a timely manner, strengthen security awareness, avoid clicking on unknown links, and prevent the risk of cyber attacks.
app_icon
ChainCatcher Building the Web3 world with innovations.