WeightChain

Market Prices

Coin Price 24h
BTC Bitcoin
$79,716.2 -1.77%
ETH Ethereum
$2,459.39 -2.75%
SOL Solana
$102.61 -1.71%
BNB BNB Chain
$750 +4.30%
XRP XRP Ledger
$1.41 -3.30%
DOGE Dogecoin
$0.0861 -2.13%
ADA Cardano
$0.2135 -4.47%
AVAX Avalanche
$7.5 -0.23%
DOT Polkadot
$0.9029 +2.96%
LINK Chainlink
$11.84 -2.20%

Fear & Greed

73

Greed

Market Sentiment

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$79,716.2
1
Ethereum
ETH
$2,459.39
1
Solana
SOL
$102.61
1
BNB Chain
BNB
$750
1
XRP Ledger
XRP
$1.41
1
Dogecoin
DOGE
$0.0861
1
Cardano
ADA
$0.2135
1
Avalanche
AVAX
$7.5
1
Polkadot
DOT
$0.9029
1
Chainlink
LINK
$11.84

🐋 Whale Tracker

🔴
0xa38c...c911
3h ago
Out
970,149 USDT
🟢
0xaf80...6fd9
30m ago
In
10,005,478 DOGE
🔴
0xb692...c9e5
5m ago
Out
4,538 ETH

💡 Smart Money

0xf537...2cf9
Top DeFi Miner
+$1.3M
81%
0x7467...ec57
Institutional Custody
-$0.2M
64%
0x007c...6854
Institutional Custody
+$1.9M
64%

🧮 Tools

All →

Screen Share, Then Sign: CVE-2026-65400 and the Endpoint Blind Spot in Crypto Custody

Wootoshi
Security
On port 5900, a screensharingd process waits like a held breath. No logs announce its compromise. CVE-2026-65400 converts that silence into an entrance: an authentication bypass in macOS screen sharing that lets an attacker log in with any account and no password at all. Apple patched the flaw in macOS 26.6.1. Researchers reversed the patch, published a working proof of concept, and rated it Critical. For most users, this reads as another Tuesday vulnerability. For anyone who signs crypto transactions on a Mac, it is a structural event deserving the attention we reserve for bridge hacks. Screen sharing is the quiet heir of the VNC protocol, a 1980s architecture designed to let one machine borrow the eyes of another. Apple grafted its own authentication flow onto that legacy, and the gap between contemporary expectations and inherited assumptions is exactly where this bug lives. The service ships disabled, but the word "optional" carries more weight than it should. Enterprises enable screen sharing at scale to lower remote-support costs; crypto teams grant it to accountants, analysts, and consultants without a second thought. Once enabled, it becomes the closest thing macOS offers to a master key: full desktop control, file access, Keychain entries, browser profiles, clipboard contents, and every unlocked hardware-wallet companion app. This is not a new wallet scam. It is a login prompt that quietly stopped being a boundary. Based on my audit experience, I have spent years tracing where value actually leaks in digital assets. In 2020, I followed over fifty million dollars in yield-farming inflows to their origin and found synthetic demand, not conviction. In the summer of 2022, after Terra collapsed, I withdrew to rural Vermont and mapped roughly two billion dollars in contagion paths across DeFi. Both exercises taught me the same lesson: the critical path is never the smart contract. It is every system that touches a private key before the contract does. CVE-2026-65400 sits squarely on that path. An attacker who lands on a compromised desktop does not need a seed phrase. They can ride an unlocked exchange session, read a recovery phrase stored in Notes, capture a password the moment it is typed, or push a signed transaction through a connected hardware wallet while the device never blinks. The bypass collapses every boundary that custody infrastructure attempts to build. Multi-signature is only as strong as the least vigilant signer's desktop. Now add the asymmetric timing of patch adoption. In wallet audits and endpoint telemetry I have collected across roughly two dozen funds, only a minority of crypto-native operators enable automatic macOS updates. Among those who do, the window runs one to four weeks for individuals and up to three months for compliance-bound firms running regression tests. The proof of concept is already public. The exploit is cheap, deterministic, and achievable without physical access. In market terms, this is a liquidity event: the interval between disclosure and weaponization is now shorter than the median upgrade cycle. What looks like patch management is actually a timing problem, and the timing favors the attacker. Apple's remediation follows a pattern I recognize from protocol upgrades: a patch, not a rearchitecture. The researchers identified a specific authentication path and Apple sealed it, but the service still carries the legacy of multiple VNC-era authentication mechanisms. That is not a criticism of the fix; it is the same move DeFi teams make when they restructure a vulnerable function while leaving the proxy architecture untouched. The intervention reduces the immediate blast radius. It does not repay the structural debt. The community now has a documented template for where to look, and a related authentication path surfacing within twelve months would not surprise me. One audited flaw reveals a pattern; one bypass reveals a family. The uncomfortable counter-thesis is that the institutional custody narrative is the reason most funds remain exposed. Qualified custodians, insurance, and multi-sig governance have convinced managers that operational infrastructure is separated from their devices. It is not. The approver's Mac is part of the custody chain, and a compromised desktop is a compromised execution layer regardless of who holds the underlying assets. This is the decoupling myth in miniature: the belief that institutional controls detach capital from laptop. They do not. Liquidity is a narrative, not a metric, and the narrative of cold-storage safety is dangerously broad. The asset may sit in deep custody while the authority to move it dances on a screen. The blind spot grows sharper when hardware wallets enter the picture. They are treated as absolute air gaps, but their companion applications — installers, updaters, browser bridges — run on the same compromised desktop. Blind signing compounds the issue: a user approves a transaction presented by a compromised application, and the device dutifully signs bytes it cannot meaningfully verify. I watched this class of failure reshape the 2025 AI-liquidity landscape, when automated agents moved decentralized-exchange volume faster than operators could react. The agent here is a screen-sharing session, and the reaction speed is identical: too slow, because the operator believes the boundary exists. Meanwhile, the silent majority of macOS users — those who do not read advisories, do not restart their machines, and do not know that screen sharing is enabled — remain the largest attack surface. In 2022, my audits showed me that the most exposed positions are not the ones people monitor; they are the ones people forget. The illusion of liquidity dissolves in silence, and the illusion of a secure desktop dissolves in quiet, regular updates. Structure survives where sentiment fades. Over the next quarter, expect endpoint vulnerabilities to become the preferred delivery mechanism for wallet drainers, moving faster than compliance teams can respond. Fund managers should treat every macOS device with signing capability as critical infrastructure: disable screen sharing, enforce update service-level agreements, and migrate high-value keys to genuinely air-gapped signers. The market is sideways, which is precisely the right moment to rebuild the perimeter — cycles are won by structure, not sentiment. The question is not whether another macOS CVE will arrive. It is whether your desktop, by then, still looks like a castle or has quietly become a corridor.