News linked to both this project and an event.
According to CoinDesk, Bitcoin Core 32.0 entered its final testing phase on September 14, with its official release scheduled for October 10. This update adds a transaction fee estimator based on real-time mempool status, enabling fee estimates to be lowered more quickly once network congestion subsides. It also enables multi-threaded parallel reading of transaction data to speed up node blockchain synchronization, defaulting to 8 threads. Security-wise, it resolves a wallet naming vulnerability on non-Windows systems since version 24.0 that allowed attackers to execute arbitrary commands on the node host via a specially crafted wallet name. Additionally, it patches an out-of-memory vulnerability in the newly added built-in web server; testing indicates that 16 unauthenticated connections can spike node memory usage from 46MB to roughly 3GB in approximately one minute. This update does not include any changes to Bitcoin's consensus rules.
According to EU-Startups, Lyon-based AI-driven Vulnerability Operations Center (VOC) Hackuity has announced the completion of a €16 million funding round (approximately $19 million), led by Forgepoint Capital International alongside Bright Pixel, Bpifrance, and Seventure Partners, bringing its cumulative funding to €32 million. The funds will be allocated toward product innovation, AI capability enhancements, and expansion into European and Asian markets. Hackuity’s platform integrates data from over 130 security tools, automating vulnerability prioritization and remediation through a proprietary risk scoring engine. It currently serves more than 6,000 users, protects over 2 million assets, and manages 1 billion security findings, with enterprise clients including ENGIE, BPCE, and Orange Cyberdefense.
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
Odaily News: Binance stated that in the first half of 2026, the Binance Wallet Security Center helped users avoid approximately $540 million in potential losses, filtering about 206 million spam transfers, identifying 4.93 million high-risk transactions, and approximately 996,000 malicious authorizations during the period. Binance noted that AI is being used by attackers to mass-generate malicious code, phishing websites, and fake identities, shifting attacks from broad-based approaches to more targeted fraud.
Odaily News: The decentralized lending protocol Secured Finance's lending market was attacked on September 5, resulting in a loss of approximately $104,000. The root cause was that collateral was priced based on the average execution price of the order book for the current block, allowing attackers to influence the price through self-trading, causing fraudulent lending positions to be counted as valid collateral. The attacker initially deployed the contract but did not execute immediately, then used flash loans and self-trading to inflate the price and withdraw USDC. The original attacking wallet was rolled back due to insufficient gas fees; approximately 48 seconds later, the general-purpose sandwich bot coffeebabe took about 0.9 WBTC, worth approximately $72,000, and transferred about 28.8 ETH of it to the ultra sound money builder, keeping only about $29 for itself. Subsequently, another bot took part of the USDC.
: The G7 cybersecurity working group stated in its latest report that quantum computing poses both a security threat and an economic threat to public and private institutions, and related organizations should immediately begin migrating to post-quantum cryptography (PQC).The working group noted that the migration process could take several years, as attackers can already collect and store encrypted data today and decrypt it once sufficiently powerful quantum computers emerge. Quantum computing could also break digital signatures, leading to identity theft and exposing companies and their supply chains.The report did not mention cryptocurrencies, but similar public-key cryptography is used for blockchain wallets and transaction authorization. Current quantum computers are not yet capable of breaking Bitcoin's cryptography, but developers are considering post-quantum solutions such as BIP-360.Ethereum researchers plan to replace multiple cryptographic components used by accounts, validators, and applications. The Solana Foundation has tested post-quantum signatures on its testnet and launched an optional hash-based vault. The G7 working group also urged governments to support related research, public-private cooperation, and national PQC strategies. (Decrypt)
Odaily News – According to Bitcoin News monitoring, hackers linked to the third wave of Coldcard wallet thefts have begun moving stolen funds for the first time, converting Bitcoin into ETH via THORChain. Galaxy Research's Alex Thorn stated that approximately 10% of the stolen BTC has been moved, while the remaining 90% remains untouched. The attacker reportedly encountered difficulties during the fund conversion, with multiple THORChain transactions being returned and retried. Researchers have traced the related swap activity to a new Ethereum address, which Alex Thorn noted has been shared with relevant authorities and cryptocurrency companies. Galaxy Research indicated that the broader Coldcard exploit has resulted in losses of at least 1,789 BTC across 8,865 addresses, valued at approximately $115 million based on prices at the time of the theft.
Odaily News, September 3 — WEEX Exchange announced that the WEEX Hackathon Season 2, themed "AI Wars II: The Algorithm Era," is now officially live. Global AI developers, quantitative traders, Web3 builders, teams, and individuals are invited to join Team AI or Team Human to compete in five rounds of live market trading battles, vying for rankings and rewards based on PnL% performance. The total prize pool stands at 600,000 USDT, with multi-tiered incentives designed to accommodate different participation methods.The early registration phase runs from September 3 to 6, during which the first 2,000 registrants can share in the 100,000 USDT Early Bird prize pool. Additionally, users who register early can complete event tasks ahead of time to accumulate activity points for the upcoming competition.
: Blockchain technology company Starkware stated that on August 26, a transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) scheme was mined on the Bitcoin mainnet, without requiring a soft fork, hard fork, or modification of consensus rules.The transaction consumed 10,000 sats and was processed through MARA Foundation's Slipstream service, as the non-standard format typically cannot propagate through Bitcoin's public mempool. The test consumed several hours of GPU computation, costing approximately $150 to $200.QSB employs hash-based quantum-resistant spending conditions and reduces quantum attack risks through signature trial mining, but still requires users to proactively migrate funds and cannot protect assets whose public keys have already been exposed. Starkware CEO Eli Ben-Sasson still supports introducing a protocol-level solution via a soft fork. (Bitcoin.com News)
blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)
According to Cointelegraph, the latest statistics from Galaxy Research show that the Coldcard hack involved 8,865 addresses, resulting in the theft of 1,789.28 Bitcoin valued at approximately $114.7 million based on the price at the time of the incident. Of this amount, 1,561 Bitcoin, representing roughly 87.3% of the stolen funds, have not yet been transferred and remain in aggregation or holding addresses controlled by the attackers.
According to BeInCrypto, Kylie Jenner’s X account appears to have been compromised, with an attacker posting the ticker and Pump.fun page link for the Solana-based memecoin kylie before the post was subsequently deleted. The token’s market cap briefly spiked to approximately $1.19 million before retreating by around 68%; at press time, it stood at roughly $378,500.
Odaily News According to Galaxy's head of research, the Coldcard vulnerability incident involved 8,865 addresses, resulting in total losses of 1,789.28 BTC, valued at $114.7 million at the time of theft and currently valued at $138.8 million.By address, the median loss per address was 0.00152 BTC, with an average of 0.20184 BTC; the median dormancy period for affected addresses was 3.2 years, with an average of 3.6 years.Among 221 victim reports, the median loss was 1.04272 BTC, with an average of 3.57792 BTC; the median dormancy period was 3.25 years, with an average of 2.99 years. The losses reported by victims amount to 790.72 BTC, accounting for 44.2% of total losses. If medium-confidence losses are included and related losses remain unconfirmed, total losses would reach 1,824 BTC, valued at $140 million based on prices at the time of the incident.
Odaily News: Ethereum co-founder Vitalik Buterin has published his latest article "Obfuscation (Part 3): Local Mixing," providing an in-depth introduction to an emerging cryptographic obfuscation approach — "Local Mixing" — and describing it as a potential new fundamental cryptographic tool following elliptic curves, RSA, and lattice-based cryptography.Vitalik noted that current mainstream obfuscation techniques primarily rely on complex mathematical assumptions but often incur extremely high computational costs. Local mixing, by contrast, takes a completely different approach. Rather than depending on elliptic curves, large integer factorization, or lattice cryptography, it draws on design principles from symmetric cryptography and hash functions, continuously shuffling, restructuring, and hiding circuit architecture to eliminate information leakage while preserving functionality.He explained that the local mixing technique mainly involves steps such as reversibility, hardening, mixing, splitting, crossing walk, and "gadgetization." By introducing random structures into circuits, rearranging logic gates, and employing nonlinear hiding mechanisms, it makes it difficult for attackers to recover the original computational logic.Vitalik pointed out that the technique remains in its early stages, with security not yet subject to long-term validation, and it still faces challenges such as random attacks and linear analysis. Nevertheless, he believes local mixing represents an entirely new path of cryptographic exploration aimed at building more efficient indistinguishability obfuscation (iO) schemes.He stated that if local mixing achieves a breakthrough, it could lead to new quantum-resistant public-key encryption schemes and advance the development of general-purpose obfuscation techniques. While the field still requires years of cryptanalysis and optimization validation, AI-assisted research could significantly accelerate this maturation process.Vitalik described obfuscation as the "final frontier" of cryptography, as theoretically all other cryptographic primitives can be constructed from obfuscation and one-way functions. Local mixing not only has the potential to reduce the cost of traditional obfuscation schemes but could also become an important direction for future cryptographic infrastructure.
Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following the emergency fix on July 31, addressing security risks brought by the previous mnemonic generation attack. Each newly generated mnemonic must now include at least one source of user entropy, including at least 65 irregular keystrokes, 50 physical dice throws, or 128 physical coin flips, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2. The new firmware also adds instant staged PSBT verification before signing, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks. The official reminder notes that updating the firmware cannot fix existing mnemonics generated by previously affected firmware. If users' mnemonics fall within the scope of this security advisory, they should first update the device, then generate and verify a completely new mnemonic, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signature of the downloaded firmware.
Odaily News: The KITE Foundation has provided an update on the handling of a token security incident. A new KITE ERC-20 contract has been deployed on the Ethereum mainnet, with the total token supply remaining unchanged. Old KITE tokens will be migrated to the new contract at a 1:1 ratio. Addresses confirmed to be controlled by the attacker will be excluded and will not receive new tokens.The migration snapshot is based on Ethereum mainnet block height 25,692,498. Regular self-custody wallet users will receive the new tokens directly without needing to redeem or authorize anything. Exchange users will have their migration coordinated between the exchange and the KITE team. Cross-chain channels will remain paused until migration and verification are complete.Previously, KITE detected abnormal transfers on August 6 and confirmed it had been attacked by hackers. The team stated that this incident did not result in any asset losses for users or the project, and the impact is currently under control.
Odaily News: A bitcoin wallet created in 2012 has moved 212 BTC after remaining dormant for 14 years, valued at $13.72 million based on the price at the time of transfer. The wallet address was created on August 10, 2012. These bitcoins were originally worth $2,346, with a per-coin price of $11.07; at the article's quoted price of $64,761, if sold in full, the holder would realize a gain of 584,725%. The wallet owner's identity remains unknown. The 212 BTC has been transferred from a legacy P2PKH wallet to an unlabeled Bech32 wallet, arriving in multiple batches before being consolidated. A Coldcard vulnerability led to the theft of nearly 2,000 BTC, which may have prompted some long-term holders to move their assets, but this address has not been linked to any known entity. (Bitcoin.com News)
according to Bitcoin News monitoring, analysis by Galaxy Research (@glxyresearch) has identified distinct characteristics among various groups that exploited weakly secured COLDCARD seeds in their attacks. The 10 largest groups alone transferred approximately 1,700 BTC, with the biggest group moving over 1,080 BTC. Researchers differentiated the attackers based on patterns such as fee strategies, transaction timing, fund consolidation methods, and the destinations of the stolen BTC. Several of the largest groups are still suspected to hold nearly all of the stolen BTC. Victims of COLDCARD attacks can contact @intangiblecoins to assist in gathering evidence and reaching out to relevant authorities.
Z.ai releases GLM-5.3, based on the same foundation model as GLM-5.2, achieving capability improvements through expanded post-training. According to the official announcement, GLM-5.3 improves by 50% over GLM-5.2 on the internal Z.ai Code Bench coding benchmark, and reaches a leading level among open models in public benchmarks such as Terminal Bench 3.0 and Agents' Last Exam. In terms of cybersecurity, GLM-5.3 achieved a score of 84.5% in the CyberGym vulnerability discovery test, and significantly improved compared to the previous generation in exploit chain-related tests such as ExploitBench and ExploitGym.
Odaily News: Kostas Chalkias, co-founder and chief cryptographer of Mysten Labs, the development company behind the Sui blockchain, stated that he has leased a dedicated factory at a secret location and plans to scale up production of quantum-safe hardware wallet cards for Sui. The project aims to keep the cost of a single quantum card key under $10, with NFC quantum signing expected to take 1 to 2 seconds. Chalkias noted that the project is being advanced in his personal time outside of work and may include funding to provide cards for users who cannot afford them. The initiative is partly driven by a recent incident involving Coldcard hardware wallets, though the vulnerability was not a quantum attack. Coldcard manufacturer Coinkite disclosed that a firmware vulnerability in Coldcard, traceable to a 2021 update, bypassed the hardware random number chip and generated keys using a predictable software process linked to device serial numbers. Attackers have been moving funds since July 30, with losses climbing to approximately 2,055 BTC, affecting over 7,700 addresses and nearing a value of $130 million. At the protocol level, Sui plans to integrate two quantum-resistant signature schemes approved by the U.S. National Institute of Standards and Technology (NIST), designed for everyday accounts and high-value Move vaults, respectively. Existing accounts can be rotated to quantum-safe keys based on their original recovery phrases, without needing to migrate to new wallets. (Bitcoin.com News)