News linked to both this project and an event.
Odaily News reported that Galaxy Research tracking found that 6 bitcoin wallets, dormant since 2011, 2012, and 2014, transferred a total of 553.59 BTC between August 16 and 26, valued at $40.15 million at the time of transfer. Two of the wallets carry the "Salomon Client Dusted" tag linked to a New York lawsuit involving Noah Doe.One of the transfers involved 40 BTC from a wallet dormant since May 28, 2012, with the funds moved on August 26 to German crypto custodian bank Boerse Stuttgart Digital. Calculated at a cost of approximately $5, the funds appreciated by roughly 1,535,911%.The remaining transfers included 212 BTC, 150 BTC, and 132.31 BTC, originating from wallets inactive since 2012, 2014, and 2011, respectively. The Noah Doe lawsuit seeks to declare 39,069 dormant bitcoin addresses in New York State as lost property. Additionally, several long-term holding addresses moved funds following the July Coldcard hardware wallet vulnerability incident. (Decrypt)
Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)
According to Cointelegraph, the latest statistics from Galaxy Research show that the Coldcard hack involved 8,865 addresses, resulting in the theft of 1,789.28 Bitcoin valued at approximately $114.7 million based on the price at the time of the incident. Of this amount, 1,561 Bitcoin, representing roughly 87.3% of the stolen funds, have not yet been transferred and remain in aggregation or holding addresses controlled by the attackers.
Odaily News According to Galaxy's head of research, the Coldcard vulnerability incident involved 8,865 addresses, resulting in total losses of 1,789.28 BTC, valued at $114.7 million at the time of theft and currently valued at $138.8 million.By address, the median loss per address was 0.00152 BTC, with an average of 0.20184 BTC; the median dormancy period for affected addresses was 3.2 years, with an average of 3.6 years.Among 221 victim reports, the median loss was 1.04272 BTC, with an average of 3.57792 BTC; the median dormancy period was 3.25 years, with an average of 2.99 years. The losses reported by victims amount to 790.72 BTC, accounting for 44.2% of total losses. If medium-confidence losses are included and related losses remain unconfirmed, total losses would reach 1,824 BTC, valued at $140 million based on prices at the time of the incident.
Odaily News: Ethereum client Besu has fixed 5 security vulnerabilities discovered by blockchain security firm CertiK in version 26.7.1 released on July 27, and published 4 detailed security advisories on August 14. Vulnerability details were disclosed after a delay to allow node operators to complete upgrade deployments.Jialiang Chang, Director of Security Engineering and Senior Audit Partner at CertiK, stated that the arrangement of releasing patches first and details later provided an 18-day buffer period, allowing node operators to identify affected deployments, test new versions, and coordinate with validators or consortium participants to complete upgrades.The vulnerabilities involve block broadcast handling, caching of future-height consensus proposals, WebSocket subscription limits, and JSON-RPC filter creation. If left unpatched, attackers could exhaust node memory or thread resources, impacting node availability and consensus processing.Using the Chain Scan methodology, CertiK conducted adversarial testing on peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi-node test network, and provided reproducible testing tools to the Besu team. CertiK is updating Chain Scan to expand round-the-clock multi-node testing on public chain networks. (Bitcoin.com News)
Renowned gold bull and economist Peter Schiff posted on social media to refute Bitcoin advocates' strategy of bundling artificial intelligence (AI) with Bitcoin for speculative trading, bluntly stating that AI poses a threat to Bitcoin rather than offering any benefits. Schiff pointed out that AI and Bitcoin compete directly for speculative capital, electricity, and data center resources. More critically, AI could uncover vulnerabilities in Bitcoin's code, cryptographic algorithms, wallets, or network that remain undetected by humans, thereby undermining the foundations of its security and scarcity.
Odaily News: Metaverse gaming platform The Sandbox has confirmed a vulnerability in its cross-chain bridge, allowing attackers to mint unbacked SAND on Base and BNB Smart Chain. Blockchain security firm PeckShield detected on August 21 that two addresses had collectively minted approximately 14.9 billion SAND. The Sandbox subsequently shut down bridging functionality on both networks.The Sandbox stated that the affected assets are bridged assets on Base and BNB Smart Chain, while SAND on Ethereum and Polygon, user wallet assets, and the Ethereum-locked assets backing the token remain unaffected. The proportion of genuinely collateralized assets involved in this incident is less than 0.01% of the total SAND supply.The Sandbox is developing a compensation plan for affected liquidity providers and advises users not to trade SAND on Base or BNB Smart Chain until bridging is restored. Coinbase plans to delist 10 perpetual futures contracts, including SAND, on August 26, with open positions to be automatically settled at that time. (Bitcoin.com News)
The U.S. Department of Justice announced an indictment charging 17 members of Iran's Mabna Institute with long-running cyber intrusion campaigns targeting 144 U.S. universities, 178 foreign universities, at least 42 U.S. companies, 11 foreign companies, and multiple government and non-governmental agencies, resulting in the theft of more than 31 TB of academic data, intellectual property, and sensitive information. The indictment alleges that the group has conducted hacking operations under contract from the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university entities since 2013, profiting by compromising accounts, stealing research materials and proprietary data, and selling portions of the illicitly acquired resources. Some individuals involved also participated in the HBO hacking incident, where internal data was exfiltrated and attempts were made to extort approximately $6 million in Bitcoin.
Odaily News: According to on-chain detective Specter's monitoring, the victim claimed that due to a Coldcard hack, funds were transferred from Bitcoin to Ethereum. However, on-chain data shows that the 73 BTC ($4.6 million) originally came from the Whirlpool coin mixer two weeks ago, with some of it bridged to Ethereum and subsequently deposited through a phishing Tornado Cash interface. Two coin mixers were used during the fund transfer process. The individual was also found to have appeared in Telegram groups involving private key searches and brute-force attacks. On-chain detective Specter stated that the victim may be a threat actor, and their funds may have been stolen by another threat actor.
Odaily News: BIP-110 supporters are discussing a hard fork to change the stalled minority chain's mining algorithm from SHA-256d to BLAKE2b. Transaction history before the fork remains shared by both chains. If transaction and signature rules remain consistent, the same transaction could be replayed on the other chain, creating a replay attack.BIP-110's peak miner support was approximately 2.53%. After the consensus rules took effect on August 8, the minority chain produced only two consecutive blocks before stalling, while the Bitcoin main chain continued operating and widening the block height gap. The BIP-110 proposal was subsequently marked as closed, and supporters shifted focus to discussing the BLAKE2b proof-of-work scheme.Bitcoin Knots plans to add a new signature hash option, but RDTS will still maintain compatibility with Bitcoin Core's existing signature hash types. Regular transactions may continue to be valid on both chains. Users will need to use the new option and rely on wallets or hardware signing firmware that support it to achieve asset separation.Luke Dashjr stated on August 18 that Bitcoin should bear the responsibility for replay protection, calling it "Spamcoin." If the BLAKE2b fork proceeds around September 1, exchanges, wallets, and holders will need to distinguish between cross-chain transactions and chain-specific transactions. (Bitcoin.com News)
Maya Protocol founder AaluxxMyth disclosed that the protocol was attacked, with approximately 20 BTC (around $1.4 million) and other assets (around $300,000) stolen. The team has suspended global operations to contain losses and is fixing vulnerabilities to restore trading. Most of the losses resulted from arbitrage and pool fees caused by extreme slippage. The team is communicating with relevant parties and plans to recoup the funds through methods such as investments in Aztec Chain. If the 20 BTC are returned to the pool, the CACAO token price will recover to $0.115. The team also hopes the attacker will accept the bug bounty and return the funds.
Odaily News: A bitcoin wallet created in 2012 has moved 212 BTC after remaining dormant for 14 years, valued at $13.72 million based on the price at the time of transfer. The wallet address was created on August 10, 2012. These bitcoins were originally worth $2,346, with a per-coin price of $11.07; at the article's quoted price of $64,761, if sold in full, the holder would realize a gain of 584,725%. The wallet owner's identity remains unknown. The 212 BTC has been transferred from a legacy P2PKH wallet to an unlabeled Bech32 wallet, arriving in multiple batches before being consolidated. A Coldcard vulnerability led to the theft of nearly 2,000 BTC, which may have prompted some long-term holders to move their assets, but this address has not been linked to any known entity. (Bitcoin.com News)
Odaily News: Peer-to-peer cryptocurrency trading platform NoOnes announced that it will begin gradually winding down operations after running for over three years. The company stated that it had been continuously seeking to resolve and lift the sanctions imposed on NoOnes, but ultimately failed. The sanctions caused the platform to lose key partners, and blockchain monitoring firms also flagged transactions associated with NoOnes as high-risk, making it increasingly difficult for the platform to continue normal operations. According to the plan, the business contraction began on August 17, and the P2P marketplace will close at 23:59 UTC on August 21. Services such as Swap, NoOnes Visa, fiat withdrawals, the gift card store, and the Bitcoin Lightning Network will also be discontinued progressively. After that, the platform will only support withdrawals, and users will still be able to log in, view balances, and withdraw remaining assets. The company advises users to complete asset withdrawals as soon as possible, no later than August 23. Previously, on January 26, 2025, NoOnes revealed that the platform had suffered a major security breach earlier that month, resulting in losses of approximately $8 million in crypto assets. CEO Ray Youssef confirmed the news after on-chain detective ZachXBT disclosed the hacking incident on his Telegram channel.
Odaily News - Bitcoin News announced on the X platform that BitBox has disclosed two severe hardware wallet vulnerabilities, stating there is currently no evidence that these vulnerabilities have been exploited or led to user fund theft. All disclosed issues have been fixed in firmware v9.26.5, and BitBox urges all users to update immediately. An internal security audit uncovered two severe vulnerabilities, along with new details regarding a previously fixed bootloader vulnerability. One vulnerability affecting BitBox Multi devices could allow a malicious host to execute arbitrary code and install malicious firmware on devices that have not yet completed setup. Another vulnerability in Silent Payments could allow an attacker to exploit a malicious host device to redirect funds to unintended addresses, resulting in Bitcoin being locked and potentially enabling extortion attacks. BitBox also disclosed that the previously fixed bootloader vulnerability could allow attackers to trick users into installing malicious firmware capable of stealing funds.
Glassnode pointed out in its latest market report that although Bitcoin has rebounded slightly after retreating from the $65,000 zone last week, it remains clearly range-bound overall. Spot trading volume and on-chain transaction throughput continue to shrink, with market liquidity and participation willingness at low levels. The derivatives market also shows caution, with leverage expanding moderately, but aggressive taker activity in perpetual contracts continues to lean toward the sell side, reflecting more aggressive distribution behavior. Funding rates remain positive, indicating lingering long-side inclination, while the options market continues to price downside protection at a premium above actual volatility levels.Institutional demand has simultaneously weakened, with declining spot ETF volumes compounded by net outflows. Institutional positions are near their cost basis, limiting unrealized profit potential for regulated investors and causing a temporary pause in accumulation momentum. On-chain profitability is under pressure, with a large portion of supply in loss and realized losses consistently exceeding profit-taking.The report also noted that the broader pace of capital outflows has begun to slow, which could be an early signal that selling pressure is stabilizing. The overall market remains caught between short-term selling pressure and relatively resilient long-term holdings. Weak spot liquidity, deteriorating institutional flows, and elevated loss realization collectively point to a continuation of the consolidation pattern, while the slowing outflow pace suggests the market may be approaching a more balanced state before its next directional move.
according to Bitcoin News monitoring, analysis by Galaxy Research (@glxyresearch) has identified distinct characteristics among various groups that exploited weakly secured COLDCARD seeds in their attacks. The 10 largest groups alone transferred approximately 1,700 BTC, with the biggest group moving over 1,080 BTC. Researchers differentiated the attackers based on patterns such as fee strategies, transaction timing, fund consolidation methods, and the destinations of the stolen BTC. Several of the largest groups are still suspected to hold nearly all of the stolen BTC. Victims of COLDCARD attacks can contact @intangiblecoins to assist in gathering evidence and reaching out to relevant authorities.
Odaily News, Tornado Cash founder Roman Storm stated that if the logic behind the U.S. Department of Justice's (DOJ) case against him holds, tech companies Google and OpenAI should also be held liable for North Korean hackers abusing their products. Those involved reportedly used ChatGPT to write code and Google Gemini for forgery and image manipulation. Storm was convicted in August 2025 of conspiracy to operate an unlicensed money-transmitting business. He pointed out that the Tornado Cash case could set a legal precedent where software developers are penalized for criminal acts committed by users, emphasizing that criminals should be held accountable rather than the developers of tools. The CLARITY Act for digital asset markets is intended to provide protections for software developers by distinguishing developer liability from the potential misuse of protocols for illegal activities. However, although a final motion for consideration of the bill has been scheduled for a vote, its current chances of passage remain low. (Bitcoin News)
Bitcoin News posted on X platform saying that Prince Filip learned about the COLDCARD hack while on vacation. As an Mk3 user, he faced the risk of his entire Bitcoin holdings being stolen at any moment.
Odaily News: Bitcoin News posted on X platform that a long-term Bitcoin holder had all assets withdrawn from their account within less than 12 hours of transferring BTC to a major Australian exchange. According to a friend of the holder, hackers had compromised their Google account for approximately 3 months, obtaining their email and Google Authenticator credentials backed up to the cloud, and then waited for them to deposit BTC into the exchange. The exchange identified the hacker as the account owner and approved the withdrawal, with the holder receiving a withdrawal approval notification at 3 AM. The post recommends disabling cloud backup for Google Authenticator and using hardware security keys such as YubiKey; setting up two keys can serve as a backup in case one is lost.
Odaily News, Galaxy Research Head Alex Thorn stated on the X platform that attacks exploiting the Coldcard hardware wallet vulnerability have noticeably declined, but cumulative losses continue to rise as more victims come forward. The impact of this incident on the Bitcoin community is significant, as the victims are primarily long-term BTC holders who adhered to self-custody cold storage principles, rather than those who lost assets due to high-risk trading or DeFi activities.At a scale of $112 million, this incident ranks among the top 20 largest hacks in crypto history and is one of the most severe security breaches in the hardware wallet self-custody sector to date. Bitcoin culture may be entering a new phase—the era of relying solely on ideological advocacy and extreme self-custody promotion is coming to an end. The community needs to place greater emphasis on technical security, lower the barrier to entry for users, and avoid simply shifting the burden of security responsibility onto ordinary users. This crisis may ultimately drive the Bitcoin ecosystem to establish a more mature security framework.Galaxy Research has directly contacted 190 victims and has confirmed with high confidence that the exploit has led to the theft of 1,778.84 BTC (approximately $112.7 million) from over 8,600 addresses. This tally does not yet include certain moderately credible suspicious attack records, such as the unconfirmed "Wave 4." If these potential attack scopes are incorporated, total losses could expand to 2,417.35 BTC (approximately $153 million).Meanwhile, the incident is reshaping market perceptions of self-custody security. Galaxy noted that multisig wallets have emerged as the "winners" of this event, with no stolen transactions traced to multisig wallets so far. Multisig service providers including Casa, Unchained, Nunchuk, and Anchorwatch have all observed a notable increase in user registrations and BTC inflows.