GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

The maximum 1,159 BTC stolen assets remain frozen, and the COLDCARD attacker has begun cleaning smaller-scale funds

Odaily News: According to Bitcoin News monitoring, Galaxy Research stated that the largest known COLDCARD theft incident involves 1,159 BTC, distributed across seven attacker addresses, which remain untouched to date, with 0 BTC cashed out or transferred through mixers. The relevant BTC was stolen within 41 minutes, but approximately 600 attacker addresses have been flagged by law enforcement agencies, exchanges, and blockchain analysis firms. Meanwhile, a smaller-scale attacker appears to have begun cleaning funds. On-chain analysts have tracked 64 BTC entering mixers, of which only about 10 BTC initially completed mixing, 54 BTC returned as change, and were subsequently split into outputs of approximately 7 BTC each for further mixing. Analysts noted that these unusually large outputs remain easy to trace, making this cleaning attempt relatively transparent.

COLDCARD hacker identified by researchers through on-chain patterns such as fixed fee rates

Odaily News: According to Bitcoin News monitoring, Alex Thorn of Galaxy Research stated that researchers initially identified the first wave of COLDCARD thefts through a distinctive on-chain pattern: thousands of automated asset transfer transactions used the same fixed fee rate and exhibited identical transaction behavior. This characteristic enabled analysts to trace attacker activity across Bitcoin UTXO history and map out multiple rounds of coordinated theft.

Hackers Recently Attack Wall Street Institutions, Asset Management Giants Including Two Sigma, Citadel, and Point72 Become Targets

According to insiders, a recent wave of sophisticated cyberattacks has targeted multiple large asset management institutions on Wall Street, with attackers attempting to infiltrate the companies' information systems. Several major global hedge funds have become targets of the attacks, including Two Sigma Investments, Citadel, and Point72 Asset Management. In addition, multiple private equity firms have also been attacked.It is currently unclear who the attackers are, how the attacks were carried out, or whether sensitive data has been compromised. The insiders requested anonymity as the matter involves non-public information.This incident has once again drawn market attention to cybersecurity risks facing financial institutions. As asset management companies increasingly rely on complex information systems, algorithmic trading, and cloud infrastructure, the financial industry is becoming a key focus for cyber attackers. (Bloomberg)

Coinbase Builds AI Coding Platform Forge, Exploring a New "Multi-Agent Collaboration" Software Development Model

Odaily News: Crypto exchange Coinbase is exploring the next generation of software development models through its internal AI coding system, Forge. The platform has evolved from an early internal tool into an ecosystem encompassing multiple AI development capabilities, and has become a case study of enterprises adopting Agentic AI.It is understood that Forge was previously known as Cloudbot, and its early version was even named Claudebot. Currently, Forge has become an important part of OpenSWE, an open-source AI coding framework. OpenSWE aims to provide infrastructure similar to an "AI software engineer," including agent orchestration, cloud sandboxes, tool invocation, Slack/Linear/GitHub integrations, sub-agents, and automated Pull Request creation capabilities.One of Forge's most notable features is "Mux." The tool currently has around 600 internal users at Coinbase, allowing engineers to run multiple AI agents simultaneously, transforming traditional serial development processes into a parallel collaboration model. Additionally, Forge includes features such as Slack task routing and "bug-to-fix" automation flows, designed to reduce manual handling of repetitive development tasks.Coinbase's engineering lead, Chintan Turakhia, previously conducted an internal experiment in which nearly a thousand engineers were asked to pause using traditional IDE tools for two weeks, in order to explore which tasks in the development workflow could be automated by AI-driven processes. As AI coding tool usage has increased, Coinbase's AI spending has declined, while Token usage continues to grow. He noted that by building proprietary AI development tools, the company provides employees with an alternative to third-party AI coding services such as those from Anthropic and OpenAI.However, external independent feedback on Forge and Mux remains limited so far, with most public information coming from Coinbase management disclosures. The actual hands-on experience of rank-and-file engineers has not yet been fully shared publicly.Industry observers believe that Coinbase's Forge represents a new direction for enterprise AI applications: companies are no longer just calling general-purpose large models, but are building AI agent systems centered around their own business processes to improve development efficiency, reduce costs, and enhance internal productivity. (Forbes)

Coldcard vulnerability pushes Bitcoin's 7-day hot supply up 98% in a week, with approximately 890,000 BTC moved

Odaily Odaily News: K33 Head of Research Vetle Lunde stated that the Coldcard attack likely drove the movement of approximately 890,000 BTC within 7 days, setting the highest 7-day active supply record for 2026. K33 estimates that around 7,300 addresses had approximately 1,596 BTC stolen at the time the report was prepared. The incident stems from a firmware flaw introduced by Coinkite in March 2021 in Coldcard hardware wallets, which may generate wallet seeds with insufficient randomness. Since July 30, coordinated transfers have removed approximately 1,600 BTC from thousands of addresses, worth over $100 million, and a possible fourth wave of attacks has pushed the total to nearly 2,000 BTC. On-chain data shows that Bitcoin's 7-day hot supply rose from 403,101.95 BTC on July 28 to 797,407.72 BTC on August 4, an increase of approximately 394,306 BTC in one week, or 98%. Sani from Timechainindex.com stated that since the Coldcard hack on Friday, exchanges have seen net inflows of 22,052 BTC. From July 30 to August 5, 39 dormant addresses moved a total of 1,486.09044782 BTC, worth over $95 million. Among them, one address created in 2010 moved 50 BTC, and five addresses created in 2013 collectively moved 620.00100547 BTC.

Boltz updates warrant canary, says no secret government data requests received

Bitcoin News posted on X platform, stating that Boltz has updated its PGP-signed warrant canary, a transparency measure used by privacy-related companies to publicly indicate that they have not received any secret government orders requiring them to hand over user data. The company's previous canary was dated May 31. Despite its commitment to update every 60 days, the canary expired around July 30, and its notice had asked users to "assume the worst" if it was not updated. Boltz stated that the expiration was due to negligence, as its team was dealing with an AI-assisted infrastructure attack that lasted for months, which ultimately led to the indefinite suspension of its swap services. The warrant canary has now been updated. Boltz stated that since the platform operates in a non-custodial model, user funds were never at risk.

BNB Chain Announces "Build the Era" Hackathon

BNB Chain announces the "Build the Era" Hackathon, soliciting proposals to build the best AI Agent trading platform on BNB Chain. The hackathon offers over $40,000 in prizes jointly provided by BNB Chain, @TermiX_AI, @PancakeSwap, @alt_layer, @binance Pay, and @AltanaNetwork. Both individuals and teams can register to participate.

Trump's Helicopter Involved in Flight Safety Incident

According to CCTV News reports, the helicopter carrying U.S. President Trump encountered a flight safety incident in Washington on the 4th. The White House stated that the incident did not pose a personal safety risk; however, the U.S. Federal Aviation Administration has launched an investigation. Reportedly, Trump departed from outside the White House on the afternoon of the 4th aboard the "Marine One" helicopter, heading to Joint Base Andrews, and then transferred to "Air Force One" to proceed to Los Angeles.

Luxembourg to Include Crypto Exchanges in FIU Alert System

Odaily News: Luxembourg has passed a new law authorizing the Financial Intelligence Unit (FIU) to send cross-institutional fraud alerts to traditional banks and cryptocurrency exchanges, with the relevant measures taking effect on August 8. The bill, numbered 8722, requires cryptocurrency exchanges operating in Luxembourg to receive alerts in sync with banks and payment institutions. The bill aims to close the loophole that allows fraudulent funds to move rapidly between traditional financial institutions and digital assets. Under previous rules, banks could only block transactions of flagged accounts within their own systems and were unable to notify another financial institution or cryptocurrency exchange to prevent funds from entering or leaving. Max Braun, head of Luxembourg's FIU, stated that incorporating cryptocurrency exchanges into the cross-departmental alert system will make it more difficult to cash out from flagged accounts. According to data from Luxembourg's Ministry of Justice, police recorded 6,382 fraud cases in the country in 2024, and financial practitioners submitted more than 18,000 reports of fraud and scams.

$120 Million Coldcard Wallet Hack Sparks Bitcoin Mempool Activity

Odaily News: The Coldcard wallet hack involves approximately $120 million. The related transactions briefly made the Bitcoin mempool highly active.

Model Autonomously Launched Social Engineering Attacks During UK AI Safety Institute Tests, Involving Identity Forgery and Malicious Code Insertion

Cybersecurity tests conducted by the UK AI Safety Institute found that AI models with unrestricted internet access, without being instructed, autonomously forged false identities, implanted malicious code into open-source projects, and launched social engineering attacks against real individuals and organizations.

$100M Coldcard Attack Prompts Swan CEO to Say Users Are Shifting Toward Stronger Custodial Protection

Odaily News: Swan CEO Cory Klippsten stated that the Coldcard attack has prompted Bitcoin holders to reassess their custody decisions. Cory Klippsten noted that his team has been organized to assist affected holders in moving tokens to secure locations, including those who are not Swan customers. He pointed out that affected users have not abandoned self-custody, but are instead turning to vault solutions that prevent a single compromised device from endangering funds.

CertiK:与 Coldcard Wallet 攻击相关资金经 THORChain 跨链后转入 Tornado Cash

CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。

Coldcard Hacker Wallet Becomes "Blockchain Message Wall," Holding Over $36 Million in Stolen BTC

According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.

$36 Million Coldcard Hacker-Related Wallet Receives Multiple Deposits with Messages

Odaily News: The wallet associated with the Coldcard hacker has received multiple deposits since July 30, some of which include text messages attached via Bitcoin's OP_RETURN function. The messages include requests for the return of funds, as well as opportunistic promotional content, with one message offering to help launder the stolen funds for a 10% cut.

SlowMist: npm Supply Chain Under Massive Attack, Over 2000 Malicious Package Versions Published in Keyv Ecosystem

According to monitoring by blockchain security company SlowMist (@SlowMist_Team), its threat intelligence system MistEye detected a large-scale npm supply chain attack targeting the Keyv/Cacheable ecosystem. The attackers published over 2,000 malicious package versions in total, involving core components such as [email protected]. As a widely used key-value storage abstraction library, Keyv supports multiple backends including Redis, SQLite, PostgreSQL, and MongoDB, with weekly downloads reaching approximately 127 million, posing significant downstream supply chain exposure risks. This attack method is highly similar to the previous Shai-Hulud npm worm activity, characterized by high automation and scale. Potential risks include credential theft, environment variable leakage, CI/CD key leakage, remote payload delivery, and lateral penetration. SlowMist recommends security teams immediately investigate and remove affected package versions, upgrade to verified secure versions, review dependency lock files and build logs, monitor suspicious outbound connections, rotate exposed credentials, and rebuild relevant environments from trusted sources if intrusion is suspected.

Coldcard Security Losses Show Regional Disparities: Canadian BTC Holders Absorb 25% of Attributable Losses, Followed by Australia, the US, and Thailand

Odaily News, Chainalysis posted on X platform stating that the Coldcard hack has been particularly devastating for Bitcoin holders in Canada. Our analysis of the attackers and victims found that Canadian BTC holders accounted for 25% of the attributable losses.According to aggregated estimates from Galaxy Research, losses have reached as high as $110 million. We analyzed the geographic distribution of this ongoing hacking campaign. Users in Australia, the United States, and Thailand have also suffered significant losses.

One week after the NVIDIA-led AI Safety Alliance OSAA was established, it has already gathered over 120 companies.

According to TechCrunch, the Open Safety AI Alliance (OSAA), led by Nvidia, has exceeded 120 member companies just one week after its establishment, including tech and financial giants such as Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa. During the Black Hat Cybersecurity Conference held in Las Vegas this week, the alliance established a working group named "Shared AI Findings Exchange" (SAFE) and has submitted multiple proposals open for public comment, managed by the Linux Foundation. The proposals cover confidential reporting mechanisms for AI cybersecurity incidents, alert processes for affected parties, and no-fault attribution analysis frameworks. Meanwhile, member companies are also actively contributing open-source technologies: Nvidia open-sourced the LLM vulnerability scanning tool Garak, Amazon contributed the agent building tool Strands Agents and authorization language Cedar, and Okta and Red Hat are advancing agent identity authentication and governance technologies respectively. Notably, Anthropic, OpenAI, and Google have not yet joined the alliance, although OpenAI and Google previously co-signed the open letter that spurred the creation of the alliance.

UK AI Safety Institute: "Unauthorized" Attack Behavior Detected in Testing of OpenAI and Anthropic Flagship Models

According to Bloomberg, the UK Government AI Safety Institute (established in 2023) disclosed on Tuesday that during safety evaluations of OpenAI's GPT-5.6-Sol and Anthropic's Mythos 5 models, both models exhibited "unauthorized" harmful behaviors, including actively intruding into real websites and attempting to inject malicious code into software, and these behaviors targeted real people and organizations. During the testing, the institute specifically granted the models internet access and disabled some safety filters to assess their extreme capabilities.

Bitcoin bridge service Boltz indefinitely suspends exchange services due to uncontrolled AI attack speed

According to Decrypt, non-custodial Bitcoin exchange service provider Boltz announced an indefinite suspension of its Bitcoin exchange services, as the iteration speed of AI-assisted attacks has exceeded its team's vulnerability patching capability. Boltz stated that automated AI probing attacks have continued to increase over the past few months, and multiple vulnerability exploitation incidents have been handled, but recently the pace of attacks has significantly accelerated, and it is suspected that multiple well-resourced attack organizations are simultaneously launching attacks against its platform, rendering the team unable to operate safely during the patching period. Currently, Boltz's TVL is approximately $262,000. Since the platform adopts a non-custodial architecture, users retain custody of their funds throughout the process. The team confirmed that no user funds are at risk, and API refund channels and unilateral refund functions remain operational.