News linked to this event type.
1inch and HackenProof have jointly released the first-half 2026 Bug Bounty Report. The report shows that from January to June 2026, 1inch received a total of 1,055 submissions from security researchers across its 6 core bug bounty programs on HackenProof, of which 32 were rewarded.
According to The Block, StarkWare announced it has successfully executed the first post-quantum Bitcoin transaction. Avihu Levy, Head of Applications, used a "signature grinding" approach to repeatedly generate millions of candidate signatures before the transaction entered the Bitcoin mempool, thereby avoiding the exposure of mathematical data related to public keys that could be exploited by future quantum computers to forge signatures. This method incurs significant computational costs, with a single transaction potentially taking several hours. Because the transaction format is unrecognized by standard Bitcoin nodes, it bypassed the public mempool and was submitted directly to miners for inclusion via MARA’s Slipstream service. StarkWare noted that while this technique can serve as a transitional safeguard, Bitcoin will still require protocol-level upgrades or a hard fork to systematically mitigate quantum computing threats.
Odaily News: Ledger Chief Technology Officer Charles Guillemet stated that a smart contract security company recently claimed to have discovered a vulnerability in the Ledger Ethereum app. The Ledger Ethereum app did previously contain a vulnerability related to certain Clear Signing processes, but it was identified by Ledger's in-house security research team, Donjon, using an AI-driven vulnerability research tool, and was fixed and deployed two weeks ago. The security company in question only contacted Ledger's bug bounty program after the fix had already been completed, failing to follow responsible disclosure procedures and without communicating with the bug bounty team, then published content implying that the issue remained unresolved. Guillemet stated that users who promptly update their Ledger device firmware, Ledger apps, and related software will receive the latest security fixes.
According to The Defiant, the Core Lightning (CLN) maintainers for the Bitcoin Lightning Network have notified node operators that if they are unable to upgrade to the upcoming patched version, they should run their nodes offline using the --offline parameter. The team stated it will release binaries containing fixes for multiple disclosed vulnerabilities, but specific vulnerability details will remain confidential for two more weeks; as of press time, the relevant binaries and security advisory have not been published. CLN had previously noted that it received several AI-generated CVE reports over the past ten days, and the team is working with open-source contributors to verify, classify, and patch them. The latest public release is v26.06.6, issued on July 22, and the v26.09 release, originally slated for late September, continues to proceed as planned.
Bitcoin News stated on the X platform that BTC Sessions said their team spent weeks assisting Bitcoin holders affected by the Coldcard vulnerability in moving funds to safety, estimating that tens of millions of dollars worth of Bitcoin were protected during this period. But for many, it was too late. A member of their local Bitcoin community lost 90% of their Bitcoin, and another woman they spoke with lost all of her Bitcoin. BTC Sessions stated that this could be the most severe self-custody incident in Bitcoin's history. BTC Sessions said this experience prompted them to rethink asset custody, with diversified security measures emerging as a key lesson.
: Bitcoin News posted on X that Core Lightning developers have received a large number of AI-generated CVE reports over the past 10 days, and have verified the existence of vulnerabilities that need to be fixed. The team has now escalated its response, will release signed binaries, and will keep vulnerability details confidential for a two-week period. Core Lightning strongly urges all users to upgrade during this period; users who have not upgraded should take their nodes offline. Previous versions, including 26.04, will no longer be supported.
Odaily News reported that Galaxy Research tracking found that 6 bitcoin wallets, dormant since 2011, 2012, and 2014, transferred a total of 553.59 BTC between August 16 and 26, valued at $40.15 million at the time of transfer. Two of the wallets carry the "Salomon Client Dusted" tag linked to a New York lawsuit involving Noah Doe.One of the transfers involved 40 BTC from a wallet dormant since May 28, 2012, with the funds moved on August 26 to German crypto custodian bank Boerse Stuttgart Digital. Calculated at a cost of approximately $5, the funds appreciated by roughly 1,535,911%.The remaining transfers included 212 BTC, 150 BTC, and 132.31 BTC, originating from wallets inactive since 2012, 2014, and 2011, respectively. The Noah Doe lawsuit seeks to declare 39,069 dormant bitcoin addresses in New York State as lost property. Additionally, several long-term holding addresses moved funds following the July Coldcard hardware wallet vulnerability incident. (Decrypt)
Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)
According to Odaily, an investigation into the security vulnerability exploit of the Cosmos EVM module reveals that the primary attacker (0x9AE7) purchased $250,000 worth of NES and bridged it to Nesa Chain, exploiting a balance vulnerability to inflate holdings to 200 times their original size, then bridged approximately $50 million worth of NES back to Ethereum. The attacker's initial funding for the wallet originated from Monero. Through multiple wallets, the attacker exchanged NES for ETH on DEXs and deposited the proceeds into centralized exchanges. Due to rapid liquidity withdrawal, most exchanges suffered extreme slippage, and the attacker ultimately sold for only $315,000, netting a profit of approximately $60,000 after deducting costs.
According to Bloomberg, digital asset exchange Kraken stated that some customer accounts were temporarily locked after receiving small cryptocurrency transfers from wallets linked to the sanctioned exchange HTX. Kraken refers to such transfers as "dust attacks," which involve sending tiny involuntary transactions to disrupt or manipulate other cryptocurrency users. In this incident, Kraken believes the attackers' objective was likely to trigger the platform's compliance review by spreading sanctioned funds.
Odaily News - Digital asset manager Grayscale's Zcash ETF began trading on NYSE Arca on Tuesday under the ticker ZCSH. The product is the world's first exchange-traded product offering spot exposure to Zcash, allowing investors to track ZEC prices through securities accounts without needing to directly purchase or store the token.ZCSH was formerly known as the Grayscale Zcash Trust, established in October 2017 through a private placement. Grayscale filed an application with the U.S. Securities and Exchange Commission in November 2025 to convert the trust into an ETF, with shareholders holding shares that track the fund's ZEC holdings rather than holding ZEC directly.In May of this year, security researcher Taylor Hornby, using Anthropic's Claude Opus 4.8, discovered a vulnerability in Zcash's Orchard shielded pool that had existed for four years, which could potentially allow attackers to mint counterfeit ZEC. Developers deployed an emergency patch on June 1, but due to privacy mechanisms, it was not possible to cryptographically confirm whether the vulnerability had been exploited.Zcash activated the Ironwood upgrade in July, replacing Orchard with a new shielded pool and introducing accounting rules that limit the amount of ZEC exiting the old shielded pool to no more than the amount entering. Grayscale stated it will monitor the adoption of the Ironwood upgrade, network security, exchange support, and regulatory conditions for privacy assets. (Decrypt)
According to Cointelegraph, the latest statistics from Galaxy Research show that the Coldcard hack involved 8,865 addresses, resulting in the theft of 1,789.28 Bitcoin valued at approximately $114.7 million based on the price at the time of the incident. Of this amount, 1,561 Bitcoin, representing roughly 87.3% of the stolen funds, have not yet been transferred and remain in aggregation or holding addresses controlled by the attackers.
Odaily News, L1 blockchain Decred stated that between August 16 and 17, its mainnet inflation vulnerability was exploited, resulting in the generation of approximately 2,077.97 DCR. This vulnerability has existed in the consensus code since the mainnet launch in February 2016, stemming from improper handling of edge cases when the regular transaction tree interacts with the stake transaction tree, allowing for double-spending of inputs. The vulnerability was submitted via a bounty program on August 12, but was exploited before a fix could be implemented. Decred has decided not to roll back to minimize the impact on users. The approximately 2,000 DCR minted through this exploit do not affect the 21 million hard cap and are far lower than historical shortfalls in subsidies due to missed votes and other causes, which exceed 215,000 DCR. Currently, the team has developed an additional double-spend monitoring service and plans to improve the emergency upgrade signaling mechanism.
According to BeInCrypto, Kylie Jenner’s X account appears to have been compromised, with an attacker posting the ticker and Pump.fun page link for the Solana-based memecoin kylie before the post was subsequently deleted. The token’s market cap briefly spiked to approximately $1.19 million before retreating by around 68%; at press time, it stood at roughly $378,500.
According to monitoring by PeckShield, the Term Labs attacker address deposited 300 ETH into Tornado Cash, worth approximately $741,000.
Cosmos Labs stated that a security incident is occurring in the Cosmos EVM module and has already affected relevant users. Its security and engineering teams are addressing the situation and have advised the contacted Cosmos EVM chains to require validators to suspend chain operations. Cosmos Labs has not yet disclosed vulnerability details, the affected chains, or specific losses, stating that an incident report will be published after the matter is resolved.
According to a post by ZachXBT, after reviewing relevant evidence, he stated that two U.S. investment platforms, BitcoinIRA and iTrustCapital, are suspected of having suffered data breaches this year, though neither appears to have publicly disclosed the incidents to date. The compromised data reportedly includes user profiles, portfolio holdings, banking information, custodian details, and verification statuses. ZachXBT noted that in June 2026, an attacker leveraged information from the relevant database to target a BitcoinIRA user, stealing more than $1.2 million in assets.
TAC tweeted that on August 22, an attacker exploited a vulnerability in the Cosmos EVM precompile layer, transferring 2,985,651,403 TAC from a single account on the TAC network. The project team subsequently paused the network at block height 24,671,475 to halt the attack.
Odaily News According to Galaxy's head of research, the Coldcard vulnerability incident involved 8,865 addresses, resulting in total losses of 1,789.28 BTC, valued at $114.7 million at the time of theft and currently valued at $138.8 million.By address, the median loss per address was 0.00152 BTC, with an average of 0.20184 BTC; the median dormancy period for affected addresses was 3.2 years, with an average of 3.6 years.Among 221 victim reports, the median loss was 1.04272 BTC, with an average of 3.57792 BTC; the median dormancy period was 3.25 years, with an average of 2.99 years. The losses reported by victims amount to 790.72 BTC, accounting for 44.2% of total losses. If medium-confidence losses are included and related losses remain unconfirmed, total losses would reach 1,824 BTC, valued at $140 million based on prices at the time of the incident.
Odaily News: According to on-chain detective Specter's monitoring, three separate incidents last week involved over $40 million in stolen cryptocurrency, with each victim suffering losses in the tens of millions of dollars. Specter noted that a large amount of capital flowed into the market last week, while social engineering, phishing links, and wallet-draining scams also persisted. Specter reminded that cryptocurrency is not an industry where you can simply buy assets and stop paying attention; asset security is part of the investment. It's important to stay updated on the latest attack incidents, wallet exploits, and phishing campaigns. If you're not active on crypto Twitter or security forums, you should at least follow one reliable source that continuously publishes security updates.