News linked to both this project and an event.
Galaxy Digital Head of Research Alex Thorn stated that based on new victim reports received following the incident, the number of attackers exploiting the Coldcard vulnerability has reached at least 15.Thorn noted that information provided by victims helped the research team uncover previously unidentified attack activity. Unlike thefts from centralized exchanges, correlations between the attackers in this vulnerability exploit require confirmation through on-chain analysis and victim feedback.He added that a single victim reporting less than 1 BTC stolen helped the team discover a previously unknown attack, which siphoned approximately 12 BTC from 126 addresses.According to Galaxy Research's earlier estimates, the Coldcard vulnerability has led to at least three rounds of attacks, with losses amounting to approximately $100 million in BTC. Additionally, Galaxy has identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million.Meanwhile, the incident has also sparked discussions regarding the security of Bitcoin self-custody. Dragonfly Managing Partner Haseeb Qureshi stated that "AI security hardening costing around $2" could potentially have prevented this vulnerability, and noted that some AI models were able to rediscover related vulnerabilities within a relatively short timeframe. However, industry insiders pointed out that current claims about the speed of AI discovering vulnerabilities lack rigorous blind testing and verification.Researchers believe that as AI model capabilities improve, the costs of vulnerability discovery and attacks in the crypto industry may continue to decline, requiring wallet developers to further strengthen code audits and security protections. (Cointelegraph)
According to CoinDesk, the 30-day implied volatility index BVIV, which measures expected volatility in the Bitcoin options market, has continued to decline, now falling to 36%, the lowest level since May 31, significantly down from the high near 60% in early June. Recent influencing factors include the Coldcard wallet attack incident involving tens of millions of dollars, weak institutional demand, and uncertainty in the regulatory and macroeconomic environment, but there are no obvious signs of panic in the market. However, volatility has mean-reverting characteristics. When the indicator falls to historical lows, a rebound often follows. Currently, BVIV has approached levels that have previously formed support multiple times. If volatility rebounds quickly in the future, it may be accompanied by a significant directional move in Bitcoin; whether up or down, traders need to remain vigilant.
Odaily News, According to blockchain detective Specter's monitoring, it has identified a cluster of wallets holding 28,600 BTC, valued at approximately $1.8 billion, suspected to be related to wallets previously attributed to the Zhimin Qian money laundering case. A few weeks ago, a Bitcoin wallet that had been dormant since 2017 transferred 1,020 BTC, valued at approximately $60 million, and began distributing funds to multiple addresses in a manner consistent with money laundering patterns. After tracing these transactions, Specter discovered that the related wallet cluster connects to addresses publicly associated with the UK's investigation into Zhimin Qian. Between 2014 and 2017, Zhimin Qian organized large-scale investment fraud in China, with over 128,000 victims. UK authorities later traced substantial criminal proceeds flowing into Bitcoin, and the Met Police ultimately seized 60,000 BTC, marking the largest cryptocurrency seizure in UK history at the time. In July 2021, UK authorities transferred the seized BTC, creating identifiable on-chain links. Following the recent transfer of 1,020 BTC, Specter identified additional wallets that collectively hold 28,600 BTC, valued at approximately $1.8 billion, and these wallets have remained largely dormant since June 2021. Based on on-chain evidence, it remains unclear whether these wallets are still controlled by the same actor, other custodians, or have already been identified by law enforcement.
According to Bitcoin.com, Fireblocks released the 2026 "Financial Grid" survey report, covering over 600 executives. The report shows that 99% of Continental European institutions and 100% of UK institutions expect regulatory policies to support digital asset development. Influenced by the clarity of the MiCA regulatory framework, 53% of European institutions have completed capital commitments before 2026, higher than the global average of 42%; as the UK's regulatory framework is still being formulated, this proportion is only 36%, but an additional 59% of UK institutions plan to complete budget allocations within 2026. In terms of product strategy, European institutions lead in tokenized money market funds (62% vs 45%) and tokenized securities; the UK is more aggressive in stablecoin issuance, with 50% of institutions planning to issue stablecoins independently, higher than Europe's 40%. Both markets list 24/7 settlement and real-time payments as primary application scenarios.
According to Cointelegraph, Coinkite, the manufacturer of Coldcard hardware wallets, disclosed that its devices have contained a random number generator (RNG) vulnerability persisting for up to five years since March 2021. The vulnerability stemmed from a firmware upgrade that mistakenly routed wallet seed generation to a less secure MicroPython pseudo-random number generator (PRNG), rather than the originally designed true random number generator (TRNG). Since code reviews only verified the existence of TRNG code without confirming whether it was actually invoked, the vulnerability remained undetected for a long period. To date, over 4,500 addresses have been compromised, with nearly $90 million worth of Bitcoin stolen. Kraken Chief Security Officer Nick Percoco stated that this incident should serve as a "wake-up call" for the hardware wallet industry, calling for the introduction of independent third-party testing mechanisms to mandate verification of whether the entropy sources actually invoked by production firmware are certified. Coinkite has suspended all device shipments and destroyed affected inventory after confirming the vulnerability, and stated it will cooperate with law enforcement agencies across multiple countries to trace the responsible parties.
According to QCP Group, the US Treasury, via the New York Fed, jointly purchased yen with the Japanese Ministry of Finance last Friday, marking the first US-Japan joint foreign exchange intervention action specifically to support the yen since 1998. Meanwhile, the US 30-year Treasury yield briefly rose to about 5.27%, hitting a new high since 2007, before falling back to 5.24%. QCP pointed out that the transmission path of this intervention to the crypto market mainly unfolds through yen carry trades—rapid yen appreciation may force investors holding yen funding positions to deleverage and buy back yen, subsequently affecting risk assets including BTC and ETH, reenacting the market volatility triggered by carry trade unwinding in August 2024. QCP reminded that current macro monitoring indicators should take the USD/JPY exchange rate, Japan funding costs, and US long-end Treasury yields into consideration; fiscal policy operations are increasingly becoming an important variable affecting the direction of global liquidity.
According to Bitcoin.com, a recent survey report released by Bearingpoint shows that 23% of Swiss adults use cryptocurrency at least occasionally, far higher than 11% in Germany and 18% in Austria. The survey was conducted by YouGov in June 2026 among over 4,000 adults in Germany, Austria, and Switzerland. The report points out that Switzerland's leading advantage stems from its Distributed Ledger Technology Act (DLT Act) officially effective in 2021, which provides a clear legal framework for crypto assets, attracting a large number of enterprises to establish operations, and driving the expansion of the "Crypto Valley" ecosystem to 1,749 blockchain companies. Additionally, 37% of Swiss respondents consider cryptocurrency an asset worth investing in, and 45% support it becoming an international reserve currency, both leading Germany and Austria. In contrast, regarding Germany, although retail adoption rates lag behind, the "meinkrypto" platform under DZ Bank and Dekabank's crypto services for the savings bank network are expected to cover approximately 80 million customers, potentially gradually narrowing the gap with Switzerland.
Odaily News Crypto analyst Murphy stated on X that on-chain data reveals a rare large-scale movement of coins by Bitcoin long-term holders (LTH) recently. Over the past two days, more than 65,000 BTC have moved on-chain each day (excluding internal transfers within the same entity), leading to a notable decline in LTH net positions.Data shows that LTH net positions had begun to deviate from their previous continuous growth trend since May this year, entering a plateau in July, with the recent large-scale transfers being relatively uncommon over the past year. Among these, approximately 14,000 BTC flowed into exchanges. Some of the funds include a transaction where a company under Trump's umbrella transferred 2,628 BTC to Crypto.com.Currently, aside from the portion flowing into exchanges, the destination and purpose of the remaining coins reduced by long-term holders remain unclear. Murphy stated that potential risks currently affecting the BTC market include: 1) Shifts in Fed monetary policy and rising rate hike expectations; 2) Inflationary pressure from Middle East tensions and oil price changes; 3) Valuation concentration in the AI sector and financing risks behind high capital expenditures; 4) Re-crowding of yen carry trade positions.
Odaily News – On July 30, the minority staff of the U.S. Senate Committee on Banking, Housing, and Urban Affairs released a new analysis raising Democratic objections to the amended draft of the CLARITY Act. The analysis states that Donald Trump’s 2025 crypto revenue amounts to approximately $1.4 billion, and that current ethics provisions still allow him to retain related business arrangements. The analysis reviews World Liberty Financial, the TRUMP meme coin, cryptocurrency investments, staking income, and other business activities, concluding that provisions restricting officials from issuing or sponsoring digital assets would not materially affect the aforementioned financial arrangements. Staff estimated approximately $799 million in revenue related to World Liberty Financial and approximately $635 million from the TRUMP meme coin. Trump’s annual financial disclosure report lists $635.1 million in royalties from a licensing agreement with CIC Digital LLC related to Celebration Coins, along with Bitcoin and Ethereum wallets each valued at over $50 million, and validator rewards obtained through staking agreements on Coinbase. The Senate draft of the CLARITY Act seeks to prohibit covered officials and their spouses from issuing or sponsoring digital assets for compensation during specified periods, while also establishing exceptions for qualified blind trusts, unauthorized third-party activities, continued use of an official’s likeness, and holding digital asset investments.
Odaily News: Coinkite, the company behind hardware wallet Coldcard, may face legal action from users who collectively lost over 1,300 BTC — valued at more than $88 million — due to a vulnerability in the mnemonic generator of certain models. Thomas Braziel, founder and managing partner of 117 Partners, is investigating product liability claims and potential class action lawsuits against Coinkite, while coordinating efforts to collect information from victims worldwide. Brazilian Bitcoin advocate Felipe Ojeda has filed a police report and will file a complaint against the company in Brazil. Cris Carrascosa, CEO of ATH21, stated that Coinkite does not assume custodial responsibility for user funds tied to its products, and any lawsuit would need to prove that Coldcard could have foreseen the attack. Ana Ojeda, head of institutional business development at Blend, noted that victims do not have an automatic right to full recovery of funds, but an investigation into liability issues can be pursued.
Odaily News: Hardware wallet company Coinkite's Coldcard wallet series has experienced a seed generation randomness vulnerability, with threat actors stealing over 1,000 BTC in the past two days. Galaxy Research data shows that as of Saturday 17:36 ET, the incident involved 1,367 BTC, with losses exceeding $88 million. To notify potentially affected users, Coinkite sent security alerts to email addresses retained through its store and newsletter system since 2019. Coldcard confirmed that the emails originated from Coinkite and stated that it has contacted all reachable addresses to the best of its ability. Coinkite has faced criticism for retaining customer email data. The company stated that its public policy explains that purchase email addresses are saved so customers can log in and verify that other information has been cleared, but it did not specify a deletion timeline, saying these addresses would be kept "temporarily." Coinkite co-founder and CEO Rodolfo Novak previously stated that the company does not store customer information, deletes customer data 90 days after purchase, and offers anonymous purchase options.
Odaily News, Stacks co-founder Muneeb shared his views on the Coldcard wallet incident, summarizing lessons learned in three areas: Bitcoin storage strategy, quantum computing threats, and ecosystem security building. Regarding Bitcoin storage strategy, he noted that many industry security experts are not even familiar with Coldcard, and top-tier security research institutions may not have conducted thorough audits of its code. Muneeb believes the best approach going forward should be asset diversification rather than concentrating all funds in a single solution, and suggested:1. Allocate 20%-30% of BTC to ETFs, such as BlackRock's Bitcoin ETF IBIT, for professional custody and regulatory protection;2. Allocate 40%-50% of BTC to multisignature solutions like Casa, such as the three-key model, spreading keys across security companies, mobile devices, and hardware wallets;3. Allocate 20%-30% of BTC to more advanced self-custody approaches, combining different hardware wallets and diverse entropy sources.On the quantum computing threat, Muneeb stated that once quantum computers break through existing encryption systems in the future, Bitcoin users may experience a shock similar to "BTC suddenly being transferred out of cold wallets." The quantum threat is real, and the industry should prepare in advance rather than underestimate technological progress, especially against the backdrop of large language models accelerating scientific research breakthroughs.
Bloomberg Senior ETF Analyst Eric Balchunas commented on the Coldcard wallet security incident, questioning whether a company with only about 5 employees is suitable to undertake such critical Bitcoin storage responsibilities. He stated that the number of employees behind Coldcard "seems unbelievably low," asking whether people would be willing to store their life savings in a bank with only 5 employees headquartered in Canada. In the crypto industry, this might be viewed as a feature, but from a traditional finance perspective, it becomes a clear risk signal. Balchunas further stated that, in comparison, institutions with larger teams such as Coinbase and Ledger may hold advantages in security investment and operational capabilities, even if users need to bear higher transaction costs. Bitcoin ETFs offer another option: investors can obtain the security guarantees provided by large, professional, regulated financial institutions while also enjoying lower management fees.
According to the South China Morning Post, researchers from the People's Public Security University of China have developed an AI framework capable of detecting illegal cryptocurrency transactions, with an overall accuracy of 89.4%, a precision of 89.1% for illegal transactions, and a recall rate of 64.5%. The system combines dynamic graph neural networks, memory modules, and large language models. By analyzing transaction structures, fund flows, and historical illegal transaction patterns, it generates risk scores and reasoning chains, providing regulatory agencies with a traceable basis for decision-making. The research results were published in the peer-reviewed journal Journal of Intelligence, with the test dataset sourced from the public Elliptic Bitcoin transaction dataset, containing over 200,000 transaction nodes.
as the suspected hacking incident involving Coldcard wallets continues to unfold, Bitcoin small-value transfers have surged significantly, reaching their highest level since the FTX exchange collapse, reigniting market discussions on Bitcoin self-custody security.Julio Moreno, Head of Research at CryptoQuant, disclosed data on X platform showing that the number of on-chain Bitcoin transfers below 1 BTC has risen to its highest level since November 2022, with approximately 39,600 BTC transferred in a single day—only about 300 BTC below the record of 39,900 BTC set on November 16, 2022, just days after FTX filed for bankruptcy. He believes that users proactively taking action to address risks is a positive signal. Additionally, Eric Balchunas, Senior ETF Analyst at Bloomberg, noted that Bitcoin ETFs, backed by a mature regulatory framework and convenience, may offer some users a safer investment approach.However, industry insiders point out that the Coldcard incident more likely reflects issues with a single wallet provider or specific security processes, rather than indicating a failure of the entire Bitcoin self-custody system. This event once again highlights the importance of security awareness, risk diversification, and wallet usage habits in personal asset management.
Odaily News: According to monitoring by Galaxy's Head of Research, a victim's Coldcard wallet was compromised in a hacker attack involving nearly 30 BTC, of which 17 BTC were swapped for ETH via THORChain and subsequently deposited into Duel.comcasino. The victim and a researcher have sent emails to all known addresses associated with Duel.comcasino, requesting that the relevant funds be frozen, and provided all transaction and deposit information. The hacker deposited 229.72497255 ETH, valued at $445,000, into Duel.comcasino—funds originating from the Coldcard attack involving approximately 30 BTC. The victim stated that Duel.comcasino responded by saying that the police would need to contact their team. Duel.comcasino's anti-money laundering policy claims it enforces Know Your Customer (KYC) procedures and complies with all applicable laws. Duel.comcasino was notified within minutes of the deposit being completed. To date, Duel.comcasino has not frozen the relevant funds. Since most of the Western world had already passed midnight at the time of the incident, police reports cannot be filed until at least Monday. If Duel.comcasino fails to freeze the funds, the victim will pursue legal action against them. Duel.comcasino's X account has been suspended, and Galaxy's Head of Research has also flagged individuals on X suspected of being associated with the platform, including team members and dealers: @korraflow, @atrois7, @MiaMalkova.
Odaily News, Galaxy Research Head Alex Thorn posted on X platform, stating that the attack targeting wallet addresses with weak random numbers generated by Coldcard is still ongoing. Users who still hold funds in Coldcard single-signature wallets should immediately migrate to secure addresses. New victim addresses and attacker addresses are continuously being added to the investigation database, and Galaxy Research plans to release updated statistics on the number of affected addresses.He noted that the previously identified waves 1, 2, and 3 of the attack exhibit clear programmatic characteristics, and the stolen BTC currently remains in the attacker's addresses without any transfers. However, in recent times, smaller-scale attackers have begun exploiting the vulnerability to steal funds and move them through peeling chains, cross-chain services, and other methods. It is certain that single-signature wallet addresses generated by Coldcard after the March 2021 firmware upgrade are all potentially at risk, and users should migrate funds as soon as possible.Previously reported, Galaxy Research has disclosed that the Coldcard vulnerability attack has affected approximately 1,367.05 BTC (approximately $88.6 million), involving around 4,585 addresses.
According to Livecoins, during a routine inspection of a scrap factory in Belo Horizonte, the Brazilian Minas Gerais State Military Police discovered an illegal Bitcoin mining farm on the second floor. At least 15 ASIC miners (suspected to be Bitmain Antminer S17 series) and three servers were seized on site, with the equipment valued at over 200,000 reais. Local energy company Cemig confirmed that the mining farm had been operating using stolen electricity for a long time, causing monthly losses of approximately 60,000 reais. A 37-year-old employee was arrested on the spot for theft and fencing stolen goods after failing to provide the source and invoices for the equipment, and two company executives were also placed under investigation. The police stated, "There may be some kind of criminal organization behind this," and are currently tracing the flow of the cryptocurrency mined by the farm.
Galaxy Research stated in a post on X that the attack targeting wallet addresses generated with weak randomness by Coldcard is still ongoing. The team urges users to immediately migrate funds from affected Coldcard single-signature wallets to secure addresses.They stated that approximately 600 suspected attacker addresses have been submitted to federal investigators, industry compliance bodies, and cross-industry cybersecurity investigators. These addresses are believed to hold funds stolen from Coldcard wallets with weak randomness.The team also noted that victims have proactively shared wallet addresses and transaction hashes, helping researchers establish on-chain attack patterns and further identify more affected wallets and attack addresses. Currently, multiple parties within the Bitcoin and crypto industry are assisting in user asset protection and attack tracing efforts.Galaxy Research previously stated in a post on X that a third wave of attacks suspected to target Coldcard-generated addresses has emerged, with 207.7294 BTC already transferred out. According to on-chain tracking data, the Coldcard wallet attack incident has so far involved approximately 1,367.05 BTC, valued at approximately $88.6 million, affecting 4,585 addresses.
: Michael Saylor posted on X platform that the company announced its BTC monetization plan on June 29, which was earlier than the release of its second-quarter earnings, and it was not introduced after incurring losses.He stated that the company has never adopted a policy of "never selling Bitcoin," and the BTC monetization plan does not necessarily mean the company must sell Bitcoin. The company expects to continue being a net buyer of Bitcoin in the future.