News linked to this event type.
Odaily News: Jazzi Cooper, RippleX Product Lead, announced on X that the next version of XRP Ledger, xrpld 3.3.0, is set to launch next week. Upon release, it will introduce five new features to validators: confidential MPT, batch transactions, delegated permissions, fee sponsorship and reserves, and dynamic MPT. Among these, the amendments for batch transactions and delegated permissions were previously urgently withdrawn after security researchers discovered severe vulnerabilities. She noted that XRP Ledger already has the capacity to support tokenized assets at scale, and this upgrade will further drive the adoption of these assets in global transfers, trading, collateralization, and settlement scenarios.
PeckShield 数据显示,2026 年 7 月加密行业共发生 30 起重大黑客攻击事件,累计损失约 2.1 亿美元,较 6 月增长 177.2%。其中,Coldcard 相关事件损失约 7000 万美元,为今年第三大加密资产盗窃事件。
Odaily News, according to Bitcoin News monitoring, Nunchuk stated that some Nunchuk platform keys are generated by Coldcard Mk4, but these keys will not be used directly. Nunchuk derives independent keys through custom logic, making them less susceptible to lookup table attacks based on compromised Coldcard seeds. Nunchuk added that, given enough time, it believes attackers may eventually incorporate these derived keys as well.
Galaxy Research stated on Friday that over 1,000 BTC from nearly 1,200 addresses have been moved, valued at approximately $70 million, with the transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets.Earlier, Coldcard manufacturer Coinkite issued a warning on Thursday about an ongoing issue with seed phrases generated by Coldcard Mk3 devices. Out of caution, the company reminded all users who generated seed phrases using Mk3 devices with firmware version 4.0.1, released in March 2021, or later, that their funds may be at risk.Subsequently, Coinkite expanded the scope of its risk alert to include certain firmware versions of Mk4, Mk5, and Coldcard Q, and released emergency firmware updates for all affected models.Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday and stated that the company takes "full responsibility" for the firmware vulnerability, acknowledging that internal review processes failed to identify the issue.Novak also suggested that the vulnerability may have been discovered with the help of artificial intelligence, noting that this incident reflects a "sobering reality under the new AI paradigm." He warned that AI-assisted code review could identify potential vulnerabilities faster than experienced security experts, while also making it easier for attackers to exploit weaknesses in public code.
Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.
: Bitcoin News posted on X platform stating that Coinkite said the issue is not with Bitcoin's cryptography itself, but with the way COLDCARD generates wallet seeds. During the libNgU migration in March 2021, the wallet unexpectedly used a weaker software random number generator when creating new seed phrases, instead of the device-specific hardware random number generator. This reduced the randomness protection for some wallets, making certain seeds easier to guess than expected. The vulnerability has affected seed generation since March 2021, with Mk3 devices being the most affected. Mk4, Q and Mk5 have incorporated additional hardware-generated randomness, providing stronger protection, but they still rely on the same software component afterward. Coinkite stated that the error occurred because two pieces of software used the same function name, causing the wrong function to be selected during the build process without triggering an error. The company has changed its build process to prevent this from happening again.
SlowMist's Cosine stated on the X platform that in the COLDCARD hardware wallet weak random number security incident, if the mnemonic uses a Passphrase, the attack can be avoided. The Passphrase is not the wallet unlock PIN code, but a password specifically set for the mnemonic, and this mechanism is supported by mainstream hardware wallets.
据 Cointelegraph 报道,加拿大比特币硬件钱包制造商 Coinkite 警告 Coldcard Mk3 用户立即迁移资金,受影响固件版本为 2021 年 3 月发布的 4.0.1 至最终版本 5.0.3,Mk4、Q 及 Mk5 不受影响。与此同时,比特币安全专家正在调查一起涉及 594.48 枚 BTC(约 3830 万美元)的异常清仓事件,涉及 1324 个 UTXO 在三个区块内通过 500 笔交易被转移,所有地址均为单签名地址。
Odaily News: Canadian Bitcoin hardware manufacturer Coinkite has warned users of Coldcard Mk3 signing devices to migrate funds from wallets whose seed phrases were generated by affected firmware. Coinkite stated that seed phrases generated by Mk3 firmware version 4.0.1 and later, released in March 2021, may put funds at risk, with the impact extending to version 5.0.3, the final version supporting the Mk3. Coinkite said that Mk4, Q, and Mk5 models are not affected; affected users should generate new seed phrases on unaffected devices, verify backups and receiving addresses, send a small test transaction first, and then migrate the remaining funds. The company said its investigation is still ongoing and that a formal technical review will be published. Bitcoin security experts are examining a centralized transfer of unclear origin involving 594.48 BTC in single-signature addresses, valued at approximately $38.3 million. Rob Hamilton, CEO and co-founder of AnchorWatch, stated that 1,324 unspent transaction outputs were moved via 500 transactions within a three-block window, with 562 BTC subsequently consolidated into another address. Kevin Loaec, CEO of Wizardsardine, said the current hypothesis is that a low-entropy random number generator has caused insufficient randomness in some wallets' seed phrases, with the relevant flaw potentially stemming from a software library, secure element, specific device batch, or firmware version. He added that this hypothesis has not yet been confirmed, and wallets from which only partial funds were transferred may still face the risk of subsequent theft.
Odaily News: Cross-chain infrastructure provider Wanchain has announced that it is proposing a white hat settlement to the attacker responsible for the July 20 exploit of the Wanchain Cardano cross-chain bridge, during which NIGHT tokens were stolen. The proposal requires the attacker to return 90% of the stolen NIGHT tokens before 20:00 Beijing time on August 6, and allows them to keep 10% as a white hat bounty. If the tokens are returned on time, Wanchain will regard the action as white hat behavior and will not pursue civil litigation.
Odaily News, July 30 – Anthropic released a report stating that during a review of cybersecurity assessment records, three incidents were discovered in which the Claude model accessed the internet in a third-party evaluation environment and further obtained unauthorized access to three real organizations' systems.Anthropic stated that the review covered 141,000 evaluation runs that could have potentially gained network access, and a total of three related incidents were found. All incidents occurred during Capture The Flag (CTF) cybersecurity tests, where the model was told the environment was a simulation with no internet access; however, due to configuration errors by the evaluation partner, the actual environment had internet connectivity.Among these, Claude Opus 4.7 accessed real company infrastructure during one test and obtained database permissions containing hundreds of production data records; Claude Mythos 5 built a malicious Python package and uploaded it to PyPI, resulting in the package being downloaded and run on 15 real systems; another internal research test model scanned approximately 9,000 targets and accessed a company's internet application through a public vulnerability.Anthropic stated that these incidents were not cases of the model actively seeking to escape or pursue its own goals, but rather the model mistakenly believed the real systems were within the test scope and continued executing the assigned cyberattack tasks. Notably, the newer internal research model stopped attacking after identifying that the targets might be real systems.Anthropic stated that these incidents primarily reflect issues with evaluation environment isolation and operational processes, rather than model alignment failures. The company has suspended related cybersecurity assessments, strengthened security controls in evaluation environments, continuously monitored test records, and will collaborate with third-party organizations to conduct further reviews.
据 Wanchain 官方 X 账号发文,2026 年 7 月 20 日,Wanchain Bridge Cardano 跨链桥遭到攻击,黑客盗取 NIGHT 代币。Wanchain 随即向攻击者发出公告,要求其在 8 月 6 日 UTC 12:00 前归还 90% 被盗 NIGHT 代币,可保留 10% 作为白帽赏金,并承诺不追究民事责任。 目前,有社区用户指出黑客已将 NIGHT 代币在 DEX 上完成兑换,NIGHT 代币价格下跌逾 30%,现报 0.0188 美元。
: Bitcoin News posted on X platform, stating that Bitcoin Core developer instagibbs claimed to have successfully reproduced the reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device, using only the number of button presses during the setup process, and said, "Sorry, now is the time to panic." He believes the issue affects MK2/MK3 devices, but stated that it is currently unable to confirm whether the MK4 has the vulnerability. Developer Antoine Poinsot stated that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller's True Random Number Generator (TRNG), while the MK3 does not. The proof of concept and mnemonic phrase verification are still under review.
according to Bloomberg, the U.S. Internal Revenue Service (IRS) is warning crypto asset holders that scammers are contacting some taxpayers by mailing fake letters in an attempt to steal their digital assets or personal data.The IRS stated that these letters may require taxpayers to register for a so-called "Digital Asset Compliance Portal," but this portal does not exist. The IRS also reminds users not to scan suspicious QR codes, and not to answer or comply with calls demanding payment.While phishing and digital scams are not new to the crypto industry, sending fake IRS notifications through physical mail appears to be a novel scam tactic. As the IRS has indeed sent taxpayers letters related to digital assets in the past, and the surge in crypto tax filing notices last year has led to confusion among many taxpayers, scammers may be exploiting this familiarity to disguise their attempts.As the U.S. tax system requires taxpayers to disclose their crypto asset activities on tax returns, communication between the IRS and digital asset holders has become more common. This also makes fake tax notices more deceptive. For crypto users, encountering "IRS letters" involving portal registration, QR code scanning, wallet connections, or payment demands warrants extra caution and should be verified through official channels.
According to Bitcoin News monitoring, approximately 594 BTC from 500 addresses were transferred within 25 minutes on Thursday, worth about $38 million, with the funds subsequently consolidated into another wallet. All affected holdings used single-signature addresses, with balances ranging from approximately 0.15 to 0.26 BTC, and many UTXOs had been dormant for years. Early speculation centered on Coldcard, as at least one victim used that device. Coldcard CEO NVK denied the existence of a device-wide vulnerability, stating that the user may have imported a seed that had previously been compromised or was weak, and noted that the transfers involved keys from different wallets. Jameson Lopp indicated that another victim only lost a portion of their UTXOs, not their entire wallet balance, which may suggest exposure of individual private keys rather than a full seed compromise. At present, the coordinated transfer event is confirmed, but the source remains unknown, with no evidence yet of a Coldcard RNG flaw, supply chain vulnerability, or a failure in Bitcoin cryptography.
: Anthropic's Claude Mythos Preview model discovered a flaw in the proposed HAWK digital signature scheme, effectively halving its minimum key strength. HAWK is one of the candidate schemes to replace current network and bank signatures in a post-quantum environment. This AI-driven attack took approximately 60 hours, with a computational cost of around $100,000, reducing the effort required to break HAWK's minimum parameter set from roughly 2^64 operations to 2^38 operations, and diminishing the attractiveness of larger compensating key sizes. Current Bitcoin and Ethereum signatures remain unaffected. The results indicate that the capabilities of classical cryptanalysis attacks are improving, while Bitcoin and other networks continue to discuss when and how to migrate to quantum-resistant cryptography.
according to Lookonchain monitoring, Lazarus Group hackers transferred 121.5 BTC, worth $7.74 million, an hour ago.
According to Yonhap News, IBM released the "2026 Cost of a Data Breach Report" on July 30. The report indicates that 25% of global malicious cyber infringement incidents were executed with the assistance of AI, representing a 56% increase compared to the previous year. Primary attack methods include deepfake impersonation and AI-driven malicious code. The average loss from AI-related infringement incidents reached $6 million, approximately $1 million higher than the average loss of all incidents, which stood at $4.99 million. Notably, 62% of AI attacks are concentrated in the critical infrastructure sector. The average loss for the financial services industry is $6.3 million, while for the energy industry, it is $5.2 million. On the defense side, enterprises that actively implement AI and automated security operations can save approximately $2 million in losses on average. 85% of enterprises stated they plan to increase security investment to address new-generation AI threats.
According to BeInCrypto, the official verified X account of U.S. Senator Cynthia Lummis was hacked on July 29. The account briefly posted a fake Solana Meme coin promotion post named $USA Token, featuring a pump.fun minting link. The post was deleted within approximately five minutes, accumulating around 5,600 views and 37 replies during that period. Crypto community users quickly issued warnings, and there are currently no records of financial losses. Lummis's office had not released any statement as of press time. The timing of this incident is sensitive, coinciding with the stalemate of the "Digital Asset Market Transparency Act" (CLARITY Act) championed by Lummis in Congress.
According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.