Japan’s Ministry of Foreign Affairs Hits Garantex With Asset Freeze
Crypto exchange OKX files with the SEC to launch tokenized US stock trading....
Bitcoin zooms toward $87,000, nearly setting an eight-month high, then reverses
Spot Bitcoin ETFs Recorded $241 Million in Net Inflows Last Week, Marking Three Consecutive Weeks...
$113 Million in Short Positions Liquidated in 24 Hours as Crypto Market Shifts
Japan Bond Selloff Deepens As 30-Year Yield Breaks Every Record Since 1999
Why Is Crypto Market Going Up Today?
Trump Announces Creation of "Super Intelligence Force" to Coordinate Federal Government Efforts
Ether's bitcoin-beating Q3 rally came with a catch. Liquidity thinned.
Prediction Markets Beat Traditional Polls in Brazilian Election
Zcash activates NU7 on testnet ahead of November mainnet target
Payward Partners with Singapore Gulf Bank for 24/7 Digital Asset Settlement Services
Kraken parent company Payward and Singapore Gulf Bank (SGB), a fully licensed digital bank...
Machi's crypto trading hits 12 straight wins in a week, $PUMP cumulative profit reaches $2.14 million
Greenfield Capital Files Complaint Against Safe Ecosystem Foundation in Switzerland
On October 5, we'll be celebrating innovators and institutions expanding digital markets
Figure founder Brett Adcock: Personal AI product Hark to launch this week, first 100,000 registered users get paid plan free
Ethereum’s zkAPI Gives AI Payments a Privacy Cloak With a Catch
Machi(@machibigbrother) won 2 more trades on $PUMP, making it 12 wins in a row over the past week,...
Revolut Achieves $115 Billion Valuation, Becomes Europe's Most Valuable Startup
Drift Foundation responds to community concerns: DFX is not pegged to USDT, redemption value depends on Recovery Pool balance
Safe investor asks Swiss watchdog to intervene in governance dispute
Hong Kong SFC adds digital asset private fund "E Fund" to list of unlicensed companies
Illinois backs delay to crypto tax rule after months of industry pushback
OKX Applies to SEC to Launch Tokenized U.S. Stock Trading PlatformAccording to Bloomberg, OKX has...
OKX Applies to U.S. SEC for Tokenized Stock Trading Platform
Yilihua Identifies Key Challenges Facing Cryptocurrency Primary Market
Ex-SEC Chair Jay Clayton Named Trump’s AI Czar After Ripple XRP Lawsuit Era
Data: HYPE Spot ETF saw net inflow of $3.306 million last week
XRP spot ETFs saw net inflows of $4.7439 million last week
Glassnode: Bitcoin's Largest Short Liquidation Zone Is Near $90,000
Bitcoin spot ETFs saw $241 million in net inflows last week, marking three consecutive weeks of net inflows
Ethereum spot ETFs saw $138 million in net outflows last week, with Fidelity's FETH leading at $74.06 million
$ BNB SURPASSES $800....
Hyperliquid bought back and burned $10.15 million worth of HYPE tokens in the past 24 hours
Ethereum Liquidity Falls Below 50% of Bitcoin's Level
Binance Lite Loan Promotion Extended: Enjoy Simple Borrowing with 50% Off Service Fee!Binance is exc...
Zcash NU7 network upgrade activated on testnet at block height 4,465,026
SKY treasury company SDEV stock surges over 700% in 15 days, now at $7.48
Why XRP Appeals to Institutional Investors, Bitwise CIO Explains
OKX Files with SEC to Launch Tokenized-Stock Trading in the US
OKX Files With SEC to Launch Tokenized US Stock Trading Platform
U.S. Digital Asset Holders Face October 15 Tax Deadline for 2025 Returns
In Q3 2026, the TVL on #Tron increased by $3.3B, up...
Binance to Block Brazil Cross-Border Crypto Transfers From Nov. 1 Without Purpose and Counterparty...
Bitwise Launches PAPY Vault on Circle’s Arc for USDC Lending
Zcash Activates NU7 Network Upgrade on Testnet
Nikkei 225 breaks above 70,000 points, up 2.5% intraday
U.S. 2025 tax year extended filing deadline is October 15; crypto traders need to verify reported information
Smart trader Frank (@frankdegods) has been buying $EDEL since Oct 1, spending a total of $191K to...
Musk: Spreading superintelligence to the stars could be seen as a successful outcome for humanity
This Week in Crypto Law (October 4, 2026)
Aptos proposal aims to enable encrypted transaction pool to reduce front-running risk, vote has not yet reached threshold
El Salvador’s $666 million Bitcoin reserve survives IMF review
Patricio Worthalter(@worthalter) deposited 4,000 $ETH($10.79M) into #Gemini 8 hours...
Ethena-linked multisig address withdrew about 117.58 million ENA, worth roughly $27.96 million, from Bybit within 9 hours
Zcash gets a Washington lobbyist to push crypto policy
BOJ Deputy Governor Shinichi Uchida: AI is both a massive positive demand shock and could reshape core parameters of monetary policy
Data: Hyperliquid whale's ETH short position has unrealized loss of over $30 million
Bitcoin Price Knocks on $87K as Uptober Bulls Smell $94K
149,600,000 $USDC (149,607,779 USD) transferred from Unknown Whale 1 to #Aave...
S&P Global Ratings has launched a new risk assessment framework for onchain lending
KLEA Crypto Daily: Sunday, October 04, 2026
Grayscale's Zach Pandl to Present Zcash Investment Case at Digital Asset Yield Summit in Singapore
S&P Global Ratings Introduces Risk Assessment Framework for Onchain Lending Vaults
SEC Commissioner Hester Peirce: Strict Regulation Ended Up Favoring "Useless" Meme CoinsOutgoing...
Nikkei 225 opens up 756.45 points, up 1.11%
149,600,000 $USDC (149,603,889 USD) transferred from #Aave to Unknown Whale 1...
Zcash Advocacy Group Registers First Lobbyist in Washington, D.C.
Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours
Anthropic’s Claude helped three security researchers breach OpenAI accounts and reach an internal code repository within 72 hours.
Researchers at cybersecurity startup Hacktron chained an image-processing vulnerability with a flaw in OpenAI’s identity infrastructure in July to gain access to multiple employees’ ChatGPT and Codex accounts.
One compromised Codex account was connected to OpenAI’s GitHub organization, giving the researchers a path into the company’s internal software environment.
The team stopped after instructing the compromised employee’s Codex account to create a harmless pull request inside OpenAI’s private openai/openai monorepo. Hacktron said the researchers did not inspect proprietary source code.
This week, Hacktron disclosed the vulnerabilities and ended further testing.
OpenAI reportedly fixed the identity-side flaw roughly 14 hours after receiving the report and later paid the company a $6,500 bounty.
Anthropic's Opus 5 cleared a hurdle its predecessor could not
The OpenAI attack accelerated after Anthropic released Claude Opus 5, which overcame an exploitation hurdle that its predecessor had repeatedly failed to solve.
Hacktron began examining the image-upload pipeline used by OpenAI’s Discourse community forum on July 23. HEIC and HEIF files were processed through ImageMagick and the underlying libheif decoding library, giving attacker-controlled images a path into vulnerable code.
The researchers supplied Claude Opus 4.8 with a Discourse Docker image and asked it to inspect the installed libheif package for security weaknesses. The model identified missing fixes that left a heap buffer overflow, enabling out-of-bounds reads and writes.
By July 24, Opus 4.8 had produced an exploit that achieved code execution when address space layout randomization (ASLR) was disabled. But repeated attempts to make the exploit work reliably against Discourse’s normal configuration with ASLR enabled failed.
Anthropic released Opus 5 later that day, giving the researchers another route.
Hacktron opened a fresh session with the new model, which produced a working ARM64 exploit for a local Mac within about three hours. The researchers then asked it to adapt the exploit to the x86-64 architecture and jemalloc memory configuration used by Discourse.
By 6 a.m. on July 25, the team had a working exploit that could execute code through a malicious image upload.
With that foothold established, the researchers next tested whether Claude could reproduce the attack against a remote environment with less human intervention.
Hacktron placed the model in an autonomous loop against its own Discourse Cloud instance. The company said Claude initially refused to develop an exploit directly against a remote system, prompting the team to proxy the test environment so it resembled a capture-the-flag security challenge.
Four hours later, the agent had reproduced the attack against the remote test environment.
The researchers then used the resulting exploit against OpenAI’s community forum, where they gained administrative access. A separate weakness in OpenAI’s single-sign-on system allowed them to move from the forum into ChatGPT and Codex accounts.
One compromised employee had connected Codex to OpenAI’s GitHub organization, creating the path the researchers later used to demonstrate access to the company’s internal repository.
Hacktron co-founder Mohan “s1r1us” Pedhapati said the episode showed how quickly AI was compressing exploit-development timelines that once required far more specialized labor.
He said:
“Our main takeaway from hacking OpenAI: AI is reducing the amount of scarce expertise needed to develop exploits. Work that once took months can now take days. Even leading AI labs can be vulnerable.”
However, Hacktron stressed that the operation still depended on experienced human researchers. The company noted:
“This was not completely autonomous hacking, and skilled human guidance remained important.”
Robert Reith, founder of blockchain security firm Accretion, said experienced researchers still supplied much of the judgment needed to turn AI-generated work into a successful attack, but warned that the advantage may erode as models improve.
According to him:
“There’s still a large gap between what skilled researchers + AI can do vs. general population + AI. The scary part is that this gap may become smaller as AI absorbs this knowledge and intuition over time.”
AI Coding agents expand the blast radius of a compromised account
The same coding agents that accelerated the exploit also increased its potential reach once the researchers gained control of an OpenAI employee account.
ChatGPT and Codex can connect to external services, meaning a compromised account may expose whatever integrations a user has authorized. Hacktron cited GitHub, Slack, and email as services that could become reachable, depending on an account’s configuration.
In this case, the employee’s GitHub connection provided the path into OpenAI’s internal repository.
Security agents warned that this concentration of permissions around AI coding tools could make them increasingly attractive targets as Codex, Claude Code and similar agents become more deeply embedded in corporate development workflows.
Codey Blakeney, research lead at Arcee, said:
“The more popular Codex and Claude Code get, the more people are going to try and target them.”
Blakeney said the risk could grow if software development becomes concentrated around a small number of AI providers, creating broader points of failure across engineering teams.
He noted that if regulation moves us to fewer players, it means less choice and more single points of failure. Blakeney added:
“The entire way software engineering works at most places has completely changed with coding agents, and if just one company has a bad day, it’s going to mess up your roadmap and timelines.”
Maxime Fournes, CEO of AI safety advocacy group PauseAI, said the breach also highlighted a longstanding imbalance between attackers and defenders that could become more consequential as AI lowers the cost of developing sophisticated exploits.
According to him, attackers need to find one overlooked weakness, while defenders must secure a much broader attack surface. He noted:
“It’s massively harder and more expensive to defend against all possible flaws than to exploit a single one.”
OpenAI tightened access after the disclosure, while Discourse prepared a patch by July 27 and added further sandboxing around its image-processing system.
Source: CryptoSlate