News linked to both this project and an event.
Odaily News, according to Bitcoin News monitoring, Nunchuk stated that some Nunchuk platform keys are generated by Coldcard Mk4, but these keys will not be used directly. Nunchuk derives independent keys through custom logic, making them less susceptible to lookup table attacks based on compromised Coldcard seeds. Nunchuk added that, given enough time, it believes attackers may eventually incorporate these derived keys as well.
Galaxy Research stated on Friday that over 1,000 BTC from nearly 1,200 addresses have been moved, valued at approximately $70 million, with the transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets.Earlier, Coldcard manufacturer Coinkite issued a warning on Thursday about an ongoing issue with seed phrases generated by Coldcard Mk3 devices. Out of caution, the company reminded all users who generated seed phrases using Mk3 devices with firmware version 4.0.1, released in March 2021, or later, that their funds may be at risk.Subsequently, Coinkite expanded the scope of its risk alert to include certain firmware versions of Mk4, Mk5, and Coldcard Q, and released emergency firmware updates for all affected models.Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday and stated that the company takes "full responsibility" for the firmware vulnerability, acknowledging that internal review processes failed to identify the issue.Novak also suggested that the vulnerability may have been discovered with the help of artificial intelligence, noting that this incident reflects a "sobering reality under the new AI paradigm." He warned that AI-assisted code review could identify potential vulnerabilities faster than experienced security experts, while also making it easier for attackers to exploit weaknesses in public code.
Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.
: Bitcoin News posted on X platform stating that Coinkite said the issue is not with Bitcoin's cryptography itself, but with the way COLDCARD generates wallet seeds. During the libNgU migration in March 2021, the wallet unexpectedly used a weaker software random number generator when creating new seed phrases, instead of the device-specific hardware random number generator. This reduced the randomness protection for some wallets, making certain seeds easier to guess than expected. The vulnerability has affected seed generation since March 2021, with Mk3 devices being the most affected. Mk4, Q and Mk5 have incorporated additional hardware-generated randomness, providing stronger protection, but they still rely on the same software component afterward. Coinkite stated that the error occurred because two pieces of software used the same function name, causing the wrong function to be selected during the build process without triggering an error. The company has changed its build process to prevent this from happening again.
据 Cointelegraph 报道,加拿大比特币硬件钱包制造商 Coinkite 警告 Coldcard Mk3 用户立即迁移资金,受影响固件版本为 2021 年 3 月发布的 4.0.1 至最终版本 5.0.3,Mk4、Q 及 Mk5 不受影响。与此同时,比特币安全专家正在调查一起涉及 594.48 枚 BTC(约 3830 万美元)的异常清仓事件,涉及 1324 个 UTXO 在三个区块内通过 500 笔交易被转移,所有地址均为单签名地址。
Odaily News: Canadian Bitcoin hardware manufacturer Coinkite has warned users of Coldcard Mk3 signing devices to migrate funds from wallets whose seed phrases were generated by affected firmware. Coinkite stated that seed phrases generated by Mk3 firmware version 4.0.1 and later, released in March 2021, may put funds at risk, with the impact extending to version 5.0.3, the final version supporting the Mk3. Coinkite said that Mk4, Q, and Mk5 models are not affected; affected users should generate new seed phrases on unaffected devices, verify backups and receiving addresses, send a small test transaction first, and then migrate the remaining funds. The company said its investigation is still ongoing and that a formal technical review will be published. Bitcoin security experts are examining a centralized transfer of unclear origin involving 594.48 BTC in single-signature addresses, valued at approximately $38.3 million. Rob Hamilton, CEO and co-founder of AnchorWatch, stated that 1,324 unspent transaction outputs were moved via 500 transactions within a three-block window, with 562 BTC subsequently consolidated into another address. Kevin Loaec, CEO of Wizardsardine, said the current hypothesis is that a low-entropy random number generator has caused insufficient randomness in some wallets' seed phrases, with the relevant flaw potentially stemming from a software library, secure element, specific device batch, or firmware version. He added that this hypothesis has not yet been confirmed, and wallets from which only partial funds were transferred may still face the risk of subsequent theft.
: Bitcoin News posted on X platform, stating that Bitcoin Core developer instagibbs claimed to have successfully reproduced the reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device, using only the number of button presses during the setup process, and said, "Sorry, now is the time to panic." He believes the issue affects MK2/MK3 devices, but stated that it is currently unable to confirm whether the MK4 has the vulnerability. Developer Antoine Poinsot stated that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller's True Random Number Generator (TRNG), while the MK3 does not. The proof of concept and mnemonic phrase verification are still under review.
According to Bitcoin News monitoring, approximately 594 BTC from 500 addresses were transferred within 25 minutes on Thursday, worth about $38 million, with the funds subsequently consolidated into another wallet. All affected holdings used single-signature addresses, with balances ranging from approximately 0.15 to 0.26 BTC, and many UTXOs had been dormant for years. Early speculation centered on Coldcard, as at least one victim used that device. Coldcard CEO NVK denied the existence of a device-wide vulnerability, stating that the user may have imported a seed that had previously been compromised or was weak, and noted that the transfers involved keys from different wallets. Jameson Lopp indicated that another victim only lost a portion of their UTXOs, not their entire wallet balance, which may suggest exposure of individual private keys rather than a full seed compromise. At present, the coordinated transfer event is confirmed, but the source remains unknown, with no evidence yet of a Coldcard RNG flaw, supply chain vulnerability, or a failure in Bitcoin cryptography.
: Anthropic's Claude Mythos Preview model discovered a flaw in the proposed HAWK digital signature scheme, effectively halving its minimum key strength. HAWK is one of the candidate schemes to replace current network and bank signatures in a post-quantum environment. This AI-driven attack took approximately 60 hours, with a computational cost of around $100,000, reducing the effort required to break HAWK's minimum parameter set from roughly 2^64 operations to 2^38 operations, and diminishing the attractiveness of larger compensating key sizes. Current Bitcoin and Ethereum signatures remain unaffected. The results indicate that the capabilities of classical cryptanalysis attacks are improving, while Bitcoin and other networks continue to discuss when and how to migrate to quantum-resistant cryptography.
according to Lookonchain monitoring, Lazarus Group hackers transferred 121.5 BTC, worth $7.74 million, an hour ago.
According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.
区块链安全公司 AmericanFortress 提出新加密方案,可保护现有 BTC、ETH、SOL 钱包免受未来量子攻击,用户无需转移资金或更改地址。
According to Bitcoin.com, U.S. Senator Cynthia Lummis is pushing hard for the CLARITY Act to complete Senate voting before Congress adjourns. Section 303 of the bill grants the Treasury Department the authority to impose targeted digital asset sanctions on foreign jurisdictions, while Section 305 allows exchanges to freeze suspicious transactions for up to 180 days. On-chain data shows that North Korea's Lazarus Group stole approximately $643 million in the first half of 2026, accounting for two-thirds of the total global crypto theft during the same period ($972 million), including a $285 million attack on Drift Protocol in April and a $292 million attack on the KelpDAO cross-chain bridge. The group's cumulative theft amount has reached $6.75 billion since 2019. Currently, Galaxy Research has lowered the probability of the CLARITY Act passing within 2026 to 30%. The bill still requires 60 votes to advance, meaning at least 7 Democratic senators need to vote across party lines in support.
According to CoinDesk, Eddy Zervigon, CEO of quantum computing security infrastructure company Quantum Xchange, stated that cryptocurrencies, due to their decentralized nature, will become the "canary in the coal mine" for quantum computing attacks—that is, the area where vulnerabilities will be exposed first. Latest assessments by Google researchers show that the number of physical qubits required to break Bitcoin's elliptic curve encryption has decreased 20-fold compared to previous estimates, and multiple institutions have brought forward the expected date of "Q-Day" (the day quantum computers can break existing encryption systems) to 2029. Deutsche Digital Assets pointed out that the real risk lies not in the encryption technology itself, but in the speed of governance—Bitcoin upgrades require 90% miner consensus, which has historically triggered hard forks (such as the 2017 SegWit upgrade leading to the birth of Bitcoin Cash), whereas traditional financial institutions only need a board resolution to complete encryption infrastructure migration. Additionally, experts caution that the quantum threat is not a binary event that "arrives suddenly on a certain day"; even if quantum computers require months to crack data, as long as the cracking is completed while the data is still valuable, the threat is established.
CZ expressed regret over BitMEX's closure announcement, recalling that BitMEX pioneered the 100x leveraged perpetual contract in the crypto market in 2014, driving industry development.CZ noted that BitMEX only supported BTC deposits and single-chain operations at the time, and adopted a once-daily, multi-signature wallet batch withdrawal process. These seemingly inconvenient designs, he said, actually helped the platform avoid hacker attacks over the long term.He also mentioned that BitMEX's four co-founders admitted to violating the Bank Secrecy Act (BSA) one month before their trial, each being fined $10 million and sentenced to home detention, with no prison time. However, CZ believes that BitMEX's business ultimately couldn't withstand the "War on Crypto" during the Biden administration.In conclusion, CZ stated that BitMEX is currently winding down in an orderly fashion, users can still withdraw assets, and he paid tribute to co-founder Arthur Hayes.
According to CoinDesk reports, algorithmic stablecoin Balance Coin suffered an oracle price manipulation attack on July 22. The coin price plummeted from near the $1 peg to about $0.0014, a drop of over 99%, and the nominal market cap of about $3.5 million nearly went to zero. According to analysis by security firm SlowMist, the attacker fed abnormally low false Bitcoin prices into the protocol, bypassing price rationality checks and liquidation delay mechanisms. They forcibly liquidated multiple ineligible collateral vaults in a single transaction, subsequently exchanged the acquired collateral for arbitrage, and ultimately profited about $912,000 from the protocol governance entity 42DAO.
According to Decrypt, Galaxy Digital has officially launched the "Bitcoin Quantum Readiness Initiative," with three core pillars including: providing up to $5 million in post-quantum cryptography research grants to developers, publishing specialized research reports through Galaxy Research, and establishing a quantum advisory committee composed of scholars from multiple top universities. The initiative targets "Q-Day"—the critical moment when quantum computers utilize Shor's algorithm to crack Bitcoin's elliptic curve encryption, forge signatures, and steal wallet assets. Project Eleven predicts that quantum computers capable of cryptographic threats may emerge as early as 2030, at which point approximately 6.9 million BTC will face exposure risks. The Coinbase Quantum Advisory Committee has also called on developers to immediately initiate migration work. Meanwhile, Trump has signed an executive order setting the deadline for the U.S. federal government to complete post-quantum cryptography migration to December 2031.
According to Bitcoin.com, the Kenyan government is investigating the hacking incident of President William Ruto's official website. The attackers temporarily tampered with the homepage content and demanded a payment of 5 Bitcoins, threatening to leak undisclosed information otherwise.
on-chain investigator ZachXBT stated that the cross-chain bridge protocol TeleSwap was suspected of being attacked on July 15, 2026, resulting in losses exceeding $735,000. However, as of five days after the incident, the project team has not yet publicly disclosed the relevant situation.ZachXBT stated that shortly after suspicious fund outflows were detected, TeleSwap's Bitcoin hot wallet stopped processing transactions. About two hours ago, the attacker transferred the stolen funds into the privacy mixing protocol Tornado Cash.
Bitcoin News posted on X platform stating that Dathon Pwn claims to have discovered a late-upgrade consensus vulnerability in BIP 110. This could cause nodes upgraded from older software to retain chain history, while newly deployed BIP 110 nodes would reject this history, potentially resulting in a hidden chain split.