The cause of the exploit has been identified. The exploit was NOT caused by a compromise of the guardian keys, contrary to some early external reports.
The team is now fully focused on recovery and remediation efforts. We are working around the clock to address the impact of this incident and support affected users.
Our next update will be shared on Monday. Throughout next week, we will provide additional information regarding the recovery process for users with ALPH locked in the bridge, further details on the exploit and its cause, and a comprehensive postmortem.
We sincerely thank our community for its patience and support while we work through this situation.
Today, we share a breakthrough on the planar unit distance problem, a famous open question first posed by Paul Erdős in 1946.
For nearly 80 years, mathematicians believed the best possible solutions looked roughly like square grids.
An OpenAI model has now disproved that belief, discovering an entirely new family of constructions that performs better.
This marks the first time AI has autonomously solved a prominent open problem central to a field of mathematics.
🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @antv ecosystem.
The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool.
DEPLOYED 💥
The moment you have all been waiting for…
Just seconds ago, our Core dApp, “Powfi”, was launched on Public Testnet.
Alephium’s Unifying DeFi Layer is now open for testing.
Link below.
I've recently been approached by several community members about repeated attacks from Kushti toward Alephium, both privately and publicly. Until now, I've preferred not to respond. I'm not interested in internet fights, and public arguments rarely create value.
However, it feels like the situation has crossed a line. I want to address it once, clearly, and then get back to building.
I've always respected Ergo, Kushti, and their early community. We come from similar roots and care about similar principles. So the level of hostility directed at Alephium has been surprising. PoW is already a niche part of the current market. Attacking other PoW projects doesn't strengthen anyone, it only weakens the broader ecosystem.
One recurring claim is that Alephium is a "company-owned project." That's simply incorrect. Alephium is a permissionless network, open to anyone to build on, and everything is open-sourced. Like Ethereum, Zcash, Solana, and many others, we have a entity that supports core development and ecosystem growth. As far as I'm aware, Ergo also has a foundation coordinating development. This is not unusual, complex infrastructure requires organization and continuity.
What matters more in the short to medium term is how effectively resources are used. And I'm proud of what the core team has delivered with comparatively minimal funding:
- A scalable stateful UTXO model
- Native sharding
- A new VM and programming language
- Multiple wallets, an explorer
- A multi-chain bridge
- A growing ecosystem from scratch
Our approach has always been community-first. When strong teams step up to build, we support them. We only build in-house when the ecosystem lacks an alternative. A recent example is our decision to build the core dApp for the community because we haven't yet seen a production-grade CLMM emerge organically; a very complex and foundational piece of infrastructure, critical to Alephium's next stage of growth.
That said, our long-term goal is for more of the ecosystem to be built by the community itself, and we actively encourage and fund that.
This will be my only post on the matter. I prefer to spend my time building rather than arguing on X. The work speaks for itself, and that's where we'll continue to focus.
🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.
The malicious payload works by silently swapping crypto addresses on the fly to steal funds.
If you use a hardware wallet, pay attention to every transaction before signing and you're safe.
If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.
It’s still unclear whether the attacker is also stealing seeds from software wallets directly at this stage.
Excellent report here: https://t.co/5CtiZJHYsN
My dad always told me "watch out where you put your signature and your..." 🤫
Both Alephium mobile and desktop wallet now display the simulated output of a transaction during signing, before you sign it. This is safer than blindly signing a bytecode.
Now is the time to activate.
As the ecosystem grows, every builder benefits.
Alignment strengthens the network, the network strengthens opportunities.
The next era of Alephium begins! Stay close.
While others chose PoS, we scaled PoW.
Scaling without sacrifice. Performance without trade-offs.
A single, coherent Layer 1, secure, composable, reliable.
This isn’t a promise. It’s live. Tested. Proven.
No hype cycles. No empty promises.
Value loops that sustain themselves through usage, staking, and deflationary tokenomics.
Composability. Sustainability. Deflation by design.