Protecting humans from AI-native threats. Built by @Quantstamp.

Common Defense retweeted
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
618
662
3,701
1,981,334
Common Defense retweeted
Bitget Wallets Suspected of Security Breach, Over $170M in Assets Moved and Swapped to ETH Breaking: MLM monitoring indicates that Bitget may be experiencing an ongoing wallet security incident, with three hot wallets and one cold wallet suspected to have been compromised. More than $170 million worth of assets have reportedly been moved out and swapped into ETH, with activity linked to 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee. The affected wallets are said to still hold about $530 million in assets. The attack vector and total losses remain unconfirmed, and Bitget has not yet publicly responded.
57
93
421
114,710
Meet the Common Defense team in Seoul at @kbwofficial on September 28!
Zircuit Finance is heading to Seoul for @kbwofficial 💛 On September 28, we're hosting Security Night with @Quantstamp and @CommonDefenseAI, where @dr_zircuit will chat about how institutional yield moves onchain before the night turns to drinks and networking. luma.com/SecurityNight
1
2
90
Glad you got the account back Jev!
1
105
Common Defense retweeted
After co-inventing ChatGPT, I kept asking myself: why have superhuman chat models not led to AGI? I’ve spent the last 2 years in stealth building a new way to train models (RLCD), and a new type of frontier AI model that we are releasing today: Jev • 20-200x faster • 40-400x cheaper (w/ output tokens free) • Frontier composable intelligence optimized for decisions AFAICT the shortest path to AI-based economic revolution
4,038
8,267
76,266
39,658,496
TypeSafe AI’s official X account got phished and hijacked a few hours after launch. Hoping they get their account back soon!
our @typesafeai business account was compromised!! we're working hard on getting it back we didn't imagine #stoptypesafe would start off so soon 😅
6
8
334
Common Defense retweeted
How to check whether you were affected in Revolut’s blunder in handing over customer passports, driver’s licences, addresses, phone numbers etc In-app: —> Account (top left of screen) —> Chats
22
45
297
97,958
Revolut customers’ data were given to criminals after a fake government request. How to check if you were impacted: 1. Open Revolut app → Profile (top left) → Chats → Support. Ask if you were affected. 2. Affected customers were also emailed by Revolut.
2
2
5
267
How to check whether you were affected in Revolut’s blunder in handing over customer passports, driver’s licences, addresses, phone numbers etc In-app: —> Account (top left of screen) —> Chats
1
180
Creepy deepfakes are exploding. One guy got a call from “his wife” while she was sitting next to him. Another sent $2,000 after a call from “his mom” while she was sleeping. Follow these tips. It only takes a few seconds to protect you and your family. 1. Hang up and call back using a saved number. That extra second protects you from number spoofing. 2. Set up a family code word only you and your family know. Ask for it during emergencies or money calls. 3. Ask something a fake clone wouldn’t know, like “What did we eat last night?” 4. Watch for scam tells: wire transfers, gift cards, crypto, or “don’t tell anyone.” 5. Warn your parents and kids now, before the call happens. Things are getting weird in this new AI world. Share these tips with your family and stay safe out there.
7
7
14
1,423
Source
Just had the creepiest scam ever happen 20 minutes ago. I got a call from my wife telling me she forgot her wallet and needed the credit card to pay for her gas. Except my wife was at home with me, and drives a Tesla. Same voice, bit... off, weird cadence but 100% sounded just like her. If she wasn't there, and it wasn't about gas I would have fallen for it. I entertained it for awhile to get more out of it, I was so confused. Must be some sort of voice deepfake. The responses were too fast for ai, I think it was a voice filter. I wish I had thought to record it. The future is about to get fucked. Warn your loved ones, do verbal passwords with your kids. Bit taken aback
1
2
221
My phone rang at 2 AM. It was my mother’s exact voice, crying: "I got into a car accident, I need $2,000 for bail right now." ​Sent the money via Instant Transfer. ​Called her 10 minutes later to check in. She was fast asleep in bed. ​Scammers used a 5-second audio clip from her public TikTok video to clone her voice using AI. ​We entered an era where you can't even trust your own mother's voice on the phone.
2
119
Join us at @EthTaipei September 13-14!
AI has made scams cheaper, faster, and more convincing. How should the defense stack change? Alex Murashkin from @CommonDefenseAI is joining ETHTaipei 2026. His work spans operational and smart contract security, with experience across bridges, L2 systems, and the infrastructure surrounding them. In “Trust No Message: Scam Detection and Defense in the Age of AI,” Alex will break scam defense into two lines: catching malicious messages at the communication layer, and hardening the host so that anything slipping through can do less damage. From rules and safe-sender lists to lightweight ML and AI for harder cases, the talk looks at how layered defenses can help Web3 teams respond as scams become easier to produce at scale. Sep 13 · 11:00–11:30 · Genesis Stage Explore ETHTaipei 2026: ethtaipei.org/ Join us in Taipei: luma.com/8z5ys4rl
4
146
Common Defense retweeted
AI has made scams cheaper, faster, and more convincing. How should the defense stack change? Alex Murashkin from @CommonDefenseAI is joining ETHTaipei 2026. His work spans operational and smart contract security, with experience across bridges, L2 systems, and the infrastructure surrounding them. In “Trust No Message: Scam Detection and Defense in the Age of AI,” Alex will break scam defense into two lines: catching malicious messages at the communication layer, and hardening the host so that anything slipping through can do less damage. From rules and safe-sender lists to lightweight ML and AI for harder cases, the talk looks at how layered defenses can help Web3 teams respond as scams become easier to produce at scale. Sep 13 · 11:00–11:30 · Genesis Stage Explore ETHTaipei 2026: ethtaipei.org/ Join us in Taipei: luma.com/8z5ys4rl
2
4
350
Trezor's email provider was breached. Watch out for phishing emails and don't click on any links.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
81
NEW MILESTONE: Common Defense has now screened 2.1M+ messages and protected customers from 46,000+ threats across Telegram, Email, WhatsApp, Slack, and SMS. That's 34,000+ messages screened and 800+ threats caught every day. Protect your team today: commondefense.ai/
2
4
105
$75m was drained from Tectonic on Cronos through a pump and dump attack. Here’s a breakdown of how it happened. In April–June 2026 Tectonic phased DAI and USC collateral factors to 0% to “safeguard protocol integrity.” TONIC stayed at 20% CF, with a 50 trillion supply cap, and an internal oracle that updates twice an hour or on a 1% move. A thin governance token was left as collateral after two more liquid assets were retired. TONIC was listed as collateral on Tectonic and priced off VVS + Crypto.com. Attackers used that listing to pump TONIC, feed the oracle a fake price, and borrow real assets out of the pools. The attack sequence: - Buy TONIC in shallow VVS pools - Oracle follows the print (a 1% move is enough to update) - Inflated TONIC gets marked around $375m of collateral - 20% CF turns that into ~$75m of borrow power against USDC, CRO, and other deposits - $6.3m of the borrowed assets was bridged to Ethereum and swapped for ~2,592 ETH Cronos validators halted the network and rolled the chain back to before the attack. Blocks resumed from 90,896,189 at 23:49:01 UTC on Aug 30. Most of the on-chain drain was unwound, but the $6.3m already on Ethereum is lost. The same pattern hit Moonwell four days earlier. Its MAMO market was drained ~$9m on Aug 27. What’s next: - Tectonic has to take TONIC collateral to 0% or isolate it. A 20% CF on a thin governance token is a protocol design failure. - Other lending markets should check for the same gap: illiquid tokens as collateral, with an oracle that tracks spot. Cap them, isolate them, or don’t list them.
1
2
170
Source:
The Cronos Network is producing blocks again and is fully back online. The Cronos Network halted earlier today. This was a validator-consensus emergency action to protect users from an exploit on the Tectonic protocol. The chain state was restored to before the Tectonic exploit from this morning. Cronos is producing blocks again as of 2026-08-30 23:49:01 UTC, starting from block 90,896,189. Node operators can now restart on Cronos v1.7.8 using the latest mainnet snapshots from 2026-08-31 09:52:00 UTC [snapshot.cronos.com/?network…] The chain is under observation while we confirm stability, and some protocols, RPC providers, explorers and bridges will take longer to come back as they do the same. We will be releasing a full postmortem soon.
1
65