News linked to both this project and an event.
According to CriptoNoticias, Argentina's Public Prosecutor's Office (MPF) conducted a specialized training course titled "Virtual Assets: Financial Analysis, Tracking, Detection and Confiscation" via Zoom on August 19 and September 2, 2026, for internal staff, officials, and judges. Led by anti-money laundering specialist Carmen Chena, the curriculum covered digital wallet asset analysis, domestic and international legal frameworks, the cryptocurrency ecosystem, and practical case studies on preservation measures. Previously, Argentina's judiciary had already accumulated extensive experience in cryptocurrency-related cases, including the freezing of 3 million USDT in December 2024 and the 2022 ruling ordering Binance to return stolen BTC.
According to CoinDesk, US cybersecurity firm CrowdStrike has partnered with federal law enforcement agencies to successfully dismantle the Russian botnet Sality, which has been operating for over two decades. Over the past eight years, the network has continuously stolen cryptocurrency through clipboard hijacking; its core payload, "EggJagger," resides on infected machines, monitoring the user's clipboard. Once a Bitcoin or Ethereum wallet address is detected, it is replaced with the attacker's address, causing victims to unknowingly complete transfers. Sality employs a decentralized P2P architecture with no central server, checking node online status every 40 minutes, and self-propagates via network-shared drives and USB devices. By exploiting an authentication vulnerability, CrowdStrike replaced legitimate node addresses with those of its own servers, successfully severing the network connections of over 15,000 infected machines. The operation was demonstrated live at the Day Zero summit in Las Vegas. Estimates indicate that the attackers stole at least 12.1 million rubles (approximately $150,000) over the eight-year period. Undisturbed crypto assets appreciated alongside the broader market, reaching a value of roughly $1.35 million by early 2025. Security experts advise users to always verify the first and last characters after pasting a wallet address to defend against such attacks.
Odaily News: CrowdStrike, in coordination with the U.S. Department of Justice, announced the dismantling of the Sality peer-to-peer botnet, isolating over 15,000 infected devices worldwide. The network has been active since 2003, and over the past eight years has primarily deployed a clipboard hijacking tool known as EggJagger to steal funds from Bitcoin and ETH transfers. EggJagger monitors cryptocurrency wallet addresses copied by victims and replaces them with addresses controlled by the attackers, redirecting transfer funds to the attackers. CrowdStrike estimates that this tool alone has stolen at least $150,000 in crypto assets; since most of the funds were not moved, the value of the associated holdings rose to approximately $1.35 million in January 2025. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service have seized related domains within the U.S., while police in Bulgaria, Hungary, and Romania have also shut down infrastructure in Europe. Currently, infected devices have been redirected to traffic reception servers controlled by CrowdStrike, but the original malware on the devices remains active until manually removed.
Odaily News: Blockchain intelligence firm TRM Labs reports that 32 price manipulation attacks have been recorded in 2026, surpassing the total of any previous full year; 2025 saw 12 incidents throughout the year. Such attacks account for roughly one-eighth of hacker incidents, up from one-seventeenth in 2022.Attackers typically first inflate the price of low-liquidity tokens, then use them as collateral to borrow other assets from lending protocols. Subsequently, they cause the collateral price to plummet and abandon the collateral, potentially leading to bad debt in the lending pools.According to DeFiLlama data, the total value locked in crypto-collateralized lending protocols has grown by approximately 56% over the past two years, approaching $50 billion, with active loan volume nearing $29 billion. The sector currently hosts over 570 lending protocols.Recently, Tectonic suffered losses exceeding $70 million after the TONIC price was artificially inflated, with the attacker ultimately extracting approximately $6 million in assets after the Cronos chain was rolled back; Moonwell also previously incurred losses of around $8.7 million due to manipulation of the MAMO oracle price. (Bitcoin.com News)
According to PeckShieldAlert, the cryptocurrency industry saw 50 major attack incidents in August 2026, an increase of 67% over the 30 incidents in July. Total losses reached approximately $136.3 million, a 49.5% decrease from the $270 million in July. The Tectonic.cro incident caused approximately $74 million in losses, ranking as the fourth-largest crypto theft of the year, behind only attacks associated with Drift, KelpDAO/LayerZero, and COLDCARDwallet. The attacker managed to cross-chain only around $6 million to Ethereum before Cronos suspended its entire network, leaving the rest of the funds mostly stranded on Cronos. The attacker has since started laundering the illicit proceeds and bridging a portion to Bitcoin, amounting to roughly $200,000 to date. Other significant attack incidents in August involved Moonwell, Termlabs, Coinsbuy, TAC, Injective, MANTRA, BounceBit, Cosmos Labs, and aquifer.
According to German newspaper DIE ZEIT, Berlin's administrative data network has been targeted by hackers for over two weeks. The hacker group Rhysida has threatened to make public a large volume of stolen sensitive data if Berlin refuses to pay a ransom of 30 bitcoins (approximately 2 million euros). The allegedly stolen data reportedly includes around 46,000 contracts, over 11,000 confidential documents, nearly 6,000 passwords, 16,000 emails, and 148 IBAN accounts. Citing "investigative strategy reasons," the Berlin state government has declined to disclose the ransom demands and details of the data breach. Governing Mayor Kai Wegner stated that Berlin will not succumb to extortion.
Odaily News: Bitcoin News posted on X platform that Blockstream stated Jade is not affected by the Coldcard random number generator vulnerability, and has released firmware 1.0.41 following a large number of AI-assisted security reviews.Jade stated that it has undergone dozens of automated AI scans and multiple manual reviews, focusing on sensitive areas such as random number generation and transaction signing.The new firmware strengthens stack protection, updates dependencies, audits sensitive memory cleanup processes, and upgrades the Jade runtime environment.Blockstream stated that Jade's random number generation mechanism uses multiple entropy sources, including hardware chip noise, timing data, sensor data, and camera noise, mixed via SHA-512 to prevent a single entropy source failure from affecting seed generation.The team stated that other lower-severity findings are still being addressed, and firmware 1.0.42 is expected to be released within a shorter development cycle.
Odaily News: The sandwich attack bot operated by JaredfromSubway.eth has extracted a cumulative total of 117,007 ETH since March 2023, worth approximately $295 million at current prices. In June 2026, an anonymous attacker deployed 66 counterfeit token contracts, exploiting the bot's automated trading logic to steal at least $7.5 million in ETH and stablecoins, and funneled the funds into Tornado Cash. The stolen assets have not yet been recovered.Sandwich attacks are a form of Maximal Extractable Value (MEV): the bot monitors large transactions in Ethereum's public mempool, buys ahead of the target transaction, and sells after the transaction pushes the price up, capturing profits from the spread. The bot's primary contract had received a cumulative total of 117,007 ETH as of August 28.MEV-Boost block construction is centralized among a small group of participants, with relay.ultrasound.money, Titan Relay, and bloXroute regulated relays collectively forwarding approximately 85% to 88% of related blocks within a 24-hour window; Titan's builder independently assembled 50.3% of the blocks. Monthly sandwich attack extraction amounts have declined from approximately $10 million in late 2024 to roughly $2.5 million in October 2025. (Bitcoin.com News)
Odaily News: Numa Lunah, co-founder of the crypto project Refi Hub, stated that he was hacked after using a download link provided in a Claude chat window to install a transcription application. The link pointed to a fake website bundled with malware, which attempted to steal all information from his device upon execution.Numa Lunah said he wiped and reinstalled the affected laptop and found no signs of sensitive data leakage. Subsequently, he discovered a contaminated Claude Code skill file named SKILL.md in his backups. The file was disguised as a style guide written by himself and contained instructions to re-download malware and steal credentials every time it was loaded.Microsoft Defender Experts previously warned that attackers have shifted from search engine optimization poisoning to large language model response poisoning. These tactics include recommending attacker-controlled download links, AI-branded fake installers, and contaminated code repositories and agent skills. Individuals working in the crypto industry may hold irrevocable credentials such as mnemonic phrases, private key files, hot wallet JSONs, exchange API keys with withdrawal permissions, and deployer keys. (Bitcoin.com News)
: Blockchain technology company Starkware stated that on August 26, a transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) scheme was mined on the Bitcoin mainnet, without requiring a soft fork, hard fork, or modification of consensus rules.The transaction consumed 10,000 sats and was processed through MARA Foundation's Slipstream service, as the non-standard format typically cannot propagate through Bitcoin's public mempool. The test consumed several hours of GPU computation, costing approximately $150 to $200.QSB employs hash-based quantum-resistant spending conditions and reduces quantum attack risks through signature trial mining, but still requires users to proactively migrate funds and cannot protect assets whose public keys have already been exposed. Starkware CEO Eli Ben-Sasson still supports introducing a protocol-level solution via a soft fork. (Bitcoin.com News)
Odaily News: Bitcoin News posted on X platform that Core Lightning version 26.06.7 has been released, fixing multiple vulnerabilities that were responsibly disclosed over the past three weeks. Recently, there has been an increase in AI-generated security reports targeting open-source Bitcoin projects. Specific vulnerability details will be kept confidential for two weeks to allow node operators to complete upgrades before technical details and source code are published. Developers warned that immediately disclosing the fixes could allow attackers to reverse-engineer the vulnerabilities and attack nodes that have not yet been updated. All Core Lightning node operators should upgrade immediately. Docker images are not yet available, and developers have explicitly warned users not to wait for the Docker image.
Odaily News: According to Lookonchain monitoring, Lazarus Group hackers transferred 244.148 BTC, worth $19.42 million, an hour ago.
Odaily News: Bitcoin News posted on X platform that U.S. spot Bitcoin ETFs have recorded net inflows for 8 consecutive days, totaling $2.8 billion. August has become the strongest month for capital inflows since 2026.As Bitcoin and gold rise in tandem, investors are increasingly seeking to hedge against risks including a weakening U.S. dollar, persistent inflation, and the widening U.S. fiscal deficit. Gold funds have also seen record demand.This shift is beginning to reflect in ETF trading. IBIT and GLD have rejoined the list of the top 10 most-traded ETFs, after semiconductor funds dominated for most of the summer.BlackRock noted that another significant source of demand comes from existing Bitcoin holders moving their tokens into ETFs. The company has so far processed approximately $5 billion in deferred-tax Bitcoin transfers into ETFs, and the minimum conversion amount has recently been lowered from $25 million to $1 million."As we continue to expand access, this scale will continue to grow," said Robbie Mitchnick, Head of Digital Assets at BlackRock.Mitchnick pointed out that incidents such as kidnappings, ransomware attacks, and custody failures are driving some Bitcoin holders to shift toward ETF custody.Bitcoin and gold are once again aligning with the core of the same macroeconomic logic, as the currency debasement trade makes a comeback.
According to the latest report released by Grayscale Research Director Zach Pandl, as U.S. federal debt surpasses $40 trillion, Bitcoin's 90-day correlation with the Nasdaq 100 Index has dropped from over 60% to approximately 33%, while its correlation with gold has risen from near zero at the start of the year to above 50%, indicating that Bitcoin is shifting from a high-beta risk asset to an inflation-resistant store of value. Grayscale believes that expanding fiscal deficits and rising long-end interest rates will drive investors toward scarce alternative assets, positioning Bitcoin, Ethereum, and Zcash as primary beneficiaries. Among them, Zcash, featuring financial privacy, quantum resistance, and cross-chain interoperability, is considered to have the potential to challenge Bitcoin's network effect, despite its market capitalization currently accounting for less than 1% of Bitcoin's. Additionally, Grayscale notes that the current Bitcoin bear market has persisted for roughly 10 months, approaching the historical average bear market cycle of 11–12 months. Coupled with a macroeconomic environment that is becoming increasingly supportive, it suggests that current prices may represent a favorable entry point for long-term investors.
According to Decrypt, privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on August 28. Developer Craig Raw stated that the update was driven by an AI-assisted code review, with the majority of fixes originating from it. This review was prompted by the recent seed generation code vulnerability exploit affecting Coldcard, as well as the release of unrestricted AI models in China, which has significantly enhanced vulnerability scanning capabilities across large codebases. Key updates include: validating the authenticity of transactions returned by Electrum servers, enforcing stricter BitBox02 hardware wallet security requirements (firmware v9.4.0 or higher required), patching local DNS leaks, and masking sensitive credentials in debug logs. Raw noted that there are no indications of any exploits being leveraged, user funds remain secure, and he still advises all users to update at their earliest convenience.
Bitcoin News posted on X platform, stating that France disclosed this month that its tax administration had been hacked, with data of approximately 678,000 individuals and businesses stolen. The stolen data allegedly includes names, addresses, income, and property information. Analysis of the alleged database found 26,805 records showing income exceeding €100,000, including 386 records exceeding €1 million. According to CertiK data, out of 52 verified cryptocurrency wrench attacks globally in the first half of 2026, France accounted for 33. French prosecutors have also accused a tax department employee of using government databases to identify cryptocurrency investors and selling personal information to criminals involved in physical assaults and extortion. The latest data breach has no publicly linked physical attacks yet, but sensitive financial and location data of hundreds of thousands of people may now no longer be under government control.
According to The Block, StarkWare announced it has successfully executed the first post-quantum Bitcoin transaction. Avihu Levy, Head of Applications, used a "signature grinding" approach to repeatedly generate millions of candidate signatures before the transaction entered the Bitcoin mempool, thereby avoiding the exposure of mathematical data related to public keys that could be exploited by future quantum computers to forge signatures. This method incurs significant computational costs, with a single transaction potentially taking several hours. Because the transaction format is unrecognized by standard Bitcoin nodes, it bypassed the public mempool and was submitted directly to miners for inclusion via MARA’s Slipstream service. StarkWare noted that while this technique can serve as a transitional safeguard, Bitcoin will still require protocol-level upgrades or a hard fork to systematically mitigate quantum computing threats.
According to The Defiant, the Core Lightning (CLN) maintainers for the Bitcoin Lightning Network have notified node operators that if they are unable to upgrade to the upcoming patched version, they should run their nodes offline using the --offline parameter. The team stated it will release binaries containing fixes for multiple disclosed vulnerabilities, but specific vulnerability details will remain confidential for two more weeks; as of press time, the relevant binaries and security advisory have not been published. CLN had previously noted that it received several AI-generated CVE reports over the past ten days, and the team is working with open-source contributors to verify, classify, and patch them. The latest public release is v26.06.6, issued on July 22, and the v26.09 release, originally slated for late September, continues to proceed as planned.
Bitcoin News stated on the X platform that BTC Sessions said their team spent weeks assisting Bitcoin holders affected by the Coldcard vulnerability in moving funds to safety, estimating that tens of millions of dollars worth of Bitcoin were protected during this period. But for many, it was too late. A member of their local Bitcoin community lost 90% of their Bitcoin, and another woman they spoke with lost all of her Bitcoin. BTC Sessions stated that this could be the most severe self-custody incident in Bitcoin's history. BTC Sessions said this experience prompted them to rethink asset custody, with diversified security measures emerging as a key lesson.
: Bitcoin News posted on X that Core Lightning developers have received a large number of AI-generated CVE reports over the past 10 days, and have verified the existence of vulnerabilities that need to be fixed. The team has now escalated its response, will release signed binaries, and will keep vulnerability details confidential for a two-week period. Core Lightning strongly urges all users to upgrade during this period; users who have not upgraded should take their nodes offline. Previous versions, including 26.04, will no longer be supported.