GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Galaxy 研究主管:出现更多小型攻击者和模仿者针对 Coldcard 剩余助记词展开攻击

Galaxy 研究主管 Alex Thorn 发文表示,围绕 Coldcard 钱包的攻击事件仍在持续发展,目前已经出现更多小型攻击者和模仿者,针对剩余 Coldcard 助记词展开攻击,他称通过协助已确认一名攻击事件中存款用户的身份,相关资金在 Duel 平台能够冻结之前已经被转出,而且涉及的资金并不属于 Galaxy Research 此前识别出的三轮主要攻击浪潮。 此前,Coldcard 疑似安全事件引发市场关注,多名研究人员发现部分由 Coldcard 生成的钱包地址出现异常资金转移。Galaxy Research 仍在持续追踪攻击地址,并提醒仍使用相关钱包种子的用户尽快采取安全措施。此次事件也进一步凸显了硬件钱包安全、私钥管理以及自托管风险防范的重要性。

Galaxy Research Head: Coldcard attack ongoing, will update affected address count statistics

Odaily News, Galaxy Research Head Alex Thorn posted on X platform, stating that the attack targeting wallet addresses with weak random numbers generated by Coldcard is still ongoing. Users who still hold funds in Coldcard single-signature wallets should immediately migrate to secure addresses. New victim addresses and attacker addresses are continuously being added to the investigation database, and Galaxy Research plans to release updated statistics on the number of affected addresses.He noted that the previously identified waves 1, 2, and 3 of the attack exhibit clear programmatic characteristics, and the stolen BTC currently remains in the attacker's addresses without any transfers. However, in recent times, smaller-scale attackers have begun exploiting the vulnerability to steal funds and move them through peeling chains, cross-chain services, and other methods. It is certain that single-signature wallet addresses generated by Coldcard after the March 2021 firmware upgrade are all potentially at risk, and users should migrate funds as soon as possible.Previously reported, Galaxy Research has disclosed that the Coldcard vulnerability attack has affected approximately 1,367.05 BTC (approximately $88.6 million), involving around 4,585 addresses.

Project Eleven Launches Bitcoin Wallet Ownership Proof Solution for Post-Q-Day Era

security firm Project Eleven has introduced a post-quantum proof technology designed to help users prove ownership of their Bitcoin wallets after quantum computers become capable of deriving private keys and generating valid signatures. Project Eleven CEO Alex Pruden stated that the technology utilizes the wallet's key derivation path, enabling users to prove control without disclosing the parent key, thus distinguishing legitimate owners from attackers. The solution was developed in collaboration with Jim Posen, a primary maintainer of the open-source Binius zero-knowledge proof system, and is based on the "signature lifting" technique proposed by Alon Sattath and Robert Wyborski. Project Eleven noted that the prototype has not yet been audited and requires blockchain protocol support before it can be deployed. It is primarily aimed at users who miss the window to migrate to quantum-resistant addresses in the future.

Opinion: Trump Signs Quantum Security Executive Order, Potentially Boosting Bitcoin Post-Quantum Security R&D

US President Trump signed two executive orders on Monday aimed at accelerating the nation's quantum computing capabilities and advancing the migration of government systems to post-quantum cryptography. While the orders do not directly mention Bitcoin, industry insiders believe this could benefit blockchain post-quantum security research and development.The two executive orders focus on defending against advanced cryptographic attacks and driving the frontier of quantum innovation. This includes a clear timeline: advancing quantum sensor construction by September 2028, and requiring federal high-value assets and high-impact systems to complete their post-quantum cryptography migration by the end of 2031.Alex Pruden, CEO of Project Eleven, stated that this means the US government will allocate funds and time to achieve post-quantum security goals. It may also extend these requirements to the entire federal contractor system, not just government agencies, thereby accelerating the practical application of post-quantum cryptographic technology.This policy comes amid growing attention within the blockchain industry to quantum threats. The Ethereum Foundation, Solana Foundation, and others have already begun advancing post-quantum security R&D, while the Bitcoin community is also discussing potential risks. Some Bitcoin held in publicly exposed addresses is considered vulnerable to private key derivation attacks once sufficiently powerful quantum computers emerge.Pruden noted that this executive order sets a clear deadline of 2031 for the adoption of post-quantum cryptography, which is more enforceable than the previous US government guidance which only proposed phasing out traditional cryptographic systems by 2035. For Bitcoin and the broader crypto industry, government-level investment in post-quantum security could accelerate the maturation of related tools, standards, and migration pathways.

Cybersecurity Leaders Jointly Call for Lifting Restrictions on Anthropic’s Mythos Model

According to Cointelegraph, cybersecurity leaders led by former Facebook Chief Security Officer Alex Stamos jointly penned a letter urging the Trump administration to lift restrictions on the use of Anthropic’s Mythos model. They argue that these restrictions harm defenders far more than attackers, hindering the overall development of the cybersecurity ecosystem.

Analysis: AI Will Accelerate Quantum Computing Threats, Crypto Industry May Enter an Era of Persistent Security Arms Race

multiple blockchain and post-quantum cryptography researchers have warned that artificial intelligence (AI) is accelerating the development of quantum computing and could potentially impact the security systems of mainstream blockchains, including Bitcoin and Ethereum, earlier than anticipated.Alex Pruden, CEO of Project Eleven, a firm focused on quantum-resistant infrastructure, stated that the combination of AI and quantum computing is fundamentally reshaping the future security landscape. "People will no longer be able to rely on existing security assumptions as they have in the past," he said.Researchers point out that AI is already being used to optimize quantum error correction, which is one of the key technical bottlenecks in the development of quantum computing. Illia Polosukhin also noted that AI has been accelerating scientific breakthroughs for years, and in the future, there may even be a circular acceleration effect where "AI helps build the next generation of quantum computers."One of the industry's biggest current concerns is the "Harvest Now, Decrypt Later" strategy, where governments or advanced attackers begin mass-collecting encrypted data now, waiting to decrypt it all at once once quantum computing matures. Polosukhin warned that if quantum computers become viable within a few years, "most of today's important data on the internet could be decrypted in the future."Given that most blockchain networks and internet infrastructure currently rely on elliptic curve cryptography (ECC), a sufficiently powerful quantum computer could theoretically derive a private key from a public key, directly breaking wallets and on-chain systems. Simultaneously, AI itself is strengthening hacking capabilities. Pruden stated that AI models are becoming increasingly adept at discovering software vulnerabilities and cryptography implementation flaws, and may even be able to crack some encryption algorithms directly in the future.However, AI is also being used by developers for code auditing, formal verification, and testing post-quantum security systems, creating a "long-term security arms race" with simultaneous upgrades on both the offensive and defensive sides. Researchers believe the most significant change brought by AI and quantum computing together is that the core assumption of "long-term cryptographic reliability" in the digital age is being challenged. Future security systems may shift from "static upgrades" to continuous dynamic evolution. (CoinDesk)

Bitcoin ATM operator Bitcoin Depot files for bankruptcy amid regulatory tightening and security vulnerabilities that rendered its business unsustainable

According to The Block, Bitcoin Depot (BTM), a Nasdaq-listed Bitcoin ATM operator, filed for Chapter 11 bankruptcy protection on the 18th in the U.S. District Court for the Southern District of Texas, announcing an orderly liquidation and asset sale. CEO Alex Holmes stated that increasingly stringent state-level compliance requirements, transaction limit restrictions, and operational bans in certain regions have rendered the company’s existing business model unsustainable. Previously, the company suffered a security breach in April 2026, resulting in a $3.7 million loss; its Q1 2026 revenue declined 49.2% year-on-year, with a net loss of $9.5 million. Currently, all over 9,000 Bitcoin ATMs operated globally by Bitcoin Depot have been taken offline, and its overseas entities—including those in Canada—will also be shut down.

Robinhood Phishing Attack Exploits Gmail’s “Dot Alias” Feature to Forge Official Emails and Lure Users into Logging In

According to Cointelegraph, Robinhood users have recently fallen victim to a phishing attack. Attackers exploited Gmail’s feature of ignoring periods (“.”) in email usernames, along with a vulnerability in Robinhood’s account creation process, to register accounts with email addresses highly similar to those of their targets. This enabled them to trick Robinhood’s official email server into delivering spoofed alert emails containing phishing links directly to victims’ inboxes. Cybersecurity researcher Alex Eckelberry noted that these emails pass SPF, DKIM, and DMARC authentication checks and thus appear to originate from Robinhood’s official domain. Robinhood stated that this incident does not involve any breach of its systems or customer accounts, and user funds and personal information remain unaffected. However, the company urges users to delete such emails and avoid clicking any suspicious links.

Researcher cracks 15-bit ECC key, earns 1 Bitcoin reward

According to Odaily, independent researcher Giancarlo Lelli was awarded the Q-Day Prize and 1 Bitcoin by quantum security startup Project Eleven for successfully cracking the encryption keys protecting Bitcoin. Giancarlo Lelli utilized publicly available quantum hardware and a variant of Shor's algorithm to crack a 15-bit encryption key among 32,767 possibilities. The difficulty of this quantum attack is 512 times greater than the 6-bit key record set in September 2025. Project Eleven CEO Alex Pruden stated that the resource requirements for such attacks continue to decline, with approximately 6.9 million Bitcoins currently held in vulnerable static addresses, including 1 million Bitcoins owned by Satoshi Nakamoto. The Bitcoin network has proposed BIP-360 to introduce quantum-resistant address types, while platforms such as Ethereum, Ripple, and Tron have also begun releasing plans for transitioning to post-quantum defenses.