News linked to both this project and an event.
Bitcoin payment processing service BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. Attackers exploited a severe vulnerability to obtain credentials and transfer funds. The number of affected operators and the total amount stolen have not yet been disclosed. This restriction affects external wallets such as Zeus that connect via BTCPay Server domains or Tor onion addresses in Docker deployments, but Lightning Network payments can still continue. BTCPay Server stated that remote access functionality will be restored once security is confirmed. BTCPay Server 2.4.2 will install LND 0.21.1 and automatically regenerate macaroon credentials during standard installation. Foundation and Citadel21 have respectively disclosed that funds from their Lightning Network nodes were swept. Foundation stated that hot wallets were not affected, and the specific amounts of losses have not been disclosed.
Odaily News: The Bitcoin minority fork chain created by BIP-110 supporters has produced only 2 blocks in approximately 8 hours and has essentially stalled; during the same period, the Bitcoin main chain has advanced 48 blocks. The proposal aims to temporarily prohibit the storage of non-financial data such as images and text in Bitcoin transactions. Supporters believe this move can reduce congestion and costs, while critics argue it restricts users' freedom to utilize block space they have already paid for. The fork chain has recently received only 2.53% mining support, and its block production speed is extremely slow, making it difficult to meet the threshold before the signaling deadline. Additionally, if users sell the fork coins while spending their main chain Bitcoin, they may face risks similar to replay attacks.
Odaily News: The Bitcoin Red Team volunteer security initiative has scanned approximately 150 Bitcoin-related code repositories and disclosed more than a dozen vulnerabilities. The team is developing an open-source AI platform to audit Bitcoin software, covering wallets, cryptographic libraries, infrastructure, and other projects. AnchorWatch CEO Rob Hamilton stated that the team has so far spent approximately $20,000 on various AI services, using Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable and Opus, as well as Z.ai's GLM 5.2 to identify vulnerabilities and generate related documentation. Pseudonymous Bitcoin developer Calle said that over the past 12 hours, the team has reported critical vulnerabilities to multiple projects, discovering on average roughly one critical vulnerability per person per hour, with daily spending of around $10,000. The team has not disclosed the affected projects or details of the vulnerabilities.
US spot Bitcoin ETFs recorded approximately $1 billion in net inflows this week, marking the best weekly performance since April; meanwhile, Coldcard hardware wallets were hacked, resulting in $116 million worth of BTC stolen.
Odaily News: Bitcoin added 2.27 million new wallets this week, with active wallet count reaching 751,000, marking the highest on-chain activity in months. On July 31, active addresses briefly approached 978,000—approximately 1.6 times the July daily average—while the first week of August averaged around 751,000 daily, up from July's average of roughly 610,000. Daily average exchange inflows stood at approximately $1.55 billion, down from July's $1.67 billion, with fund movements not accompanied by significant exchange buying activity. This surge in activity is linked to a firmware vulnerability in Coldcard devices from hardware wallet manufacturer Coinkite. The vulnerability affects certain Mk3, Mk4, Mk5, and Q models, where seed generation utilizes a software random number generator, reducing the actual randomness of some devices to approximately 40 or 72 bits. Since July 30, related bitcoin losses have exceeded $116 million. Holders of affected devices have transferred funds to new addresses and replaced them with unaffected hardware devices. Coinkite has released firmware patches and entropy remediation disclosure documents. This vulnerability stems from a random number generation issue in device firmware, not a flaw in the Bitcoin protocol layer.
Odaily News: Bloomberg ETF analyst Eric Balchunas said on X platform that Bitcoin ETF inflows reached approximately $1 billion this week, marking the best weekly performance since April and the third-best week since the Silent IPO disrupted market performance in October last year.Since the Coldcard hack, IBIT, FBTC and a few other Bitcoin ETFs have seen consecutive daily inflows, and the correlation makes it hard to ignore the causal relationship. He noted that if the seemingly worst-case scenario of a cold storage Bitcoin hack marks the start of the next rally, it would be ironic but also in line with its usual characteristics.
Bitcoin payment processing project BTCPay Server warns that a critical vulnerability on its servers is being actively exploited, potentially allowing attackers to gain unauthorized access and cause loss of funds. Users are urged to upgrade to version 2.4.2 and change relevant credentials.
比特币开发者 Kevin Loaec 警告,若 BIP-110 相关分叉发生,在缺少重放保护的情况下,用户出售分叉链资产可能导致真实 BTC 被同步转移。
Odaily News: The proposed Bitcoin fork is associated with the controversial BIP-110 proposal and could generate duplicate balances on both chains, potentially prompting holders to attempt selling seemingly free fork coins. Since both chains initially accept the same transactions, selling fork coins could trigger a replay attack and simultaneously spend the seller's real Bitcoin on the main chain. Developers have stated that built-in replay protection will be lacking at least until early September, and non-professional users should avoid transferring Bitcoin during the potential fork period.
Odaily News: Bitcoin News stated on the X platform that BTCPay Server has reported a critical vulnerability being actively exploited, which could result in loss of funds. Users should immediately update to BTCPay Server v2.4.2; those who cannot update immediately should shut down their BTCPay Server until the update can be installed, to prevent unauthorized access.
Odaily News – According to monitoring by Galaxy's Head of Research, the median dormancy period for stolen coins is 3.5 years, with 88% of stolen coins being over one year old. By address, the median loss is 0.014 BTC and the average loss is 0.212 BTC; over 250 victim reports have been received. Based on victim reports, the median loss is 1.022 BTC and the average loss is 4.04 BTC, with reported losses ranging from 624 satoshis to 58.97 BTC.
Bitcoin News posted on X platform that a Trezor user claimed their life savings were stolen after clicking a Google-sponsored search result impersonating Trezor. The phishing page was hosted on Google Sites and allegedly tricked the victim into entering their wallet recovery seed. Trezor stated that it is upgrading its handling of the report, proceeding with the removal of the website, and reminding users to never enter wallet backups or mnemonic phrases on any website or online form. Google-sponsored phishing ads remain an ongoing attack vector for crypto users.
据 QCP Capital 8 月 7 日市场报告,BTC 本周从约 62,500 美元低点回升至 64,000 美元附近。尽管期间承压明显——Strategy 上周出售 1,638 枚 BTC(约 1.047 亿美元),Coldcard 安全事件波及约 5,000 个钱包、估计损失约 1,755 枚 BTC(约 1.1 亿美元)——市场并未出现持续性下跌。 期权市场同样未见恐慌情绪,7 日和 30 日平值隐含波动率分别为 28.8 和 32.6,处于近期区间低端;7 日 25-delta 风险逆转从 -7.39 快速收窄至 -2.10,显示短端下行偏斜明显缓解。 宏观层面,美国 7 月 ISM 制造业 PMI 升至 55.6(逾四年新高),但就业数据走软,ADP 私人就业仅新增 4.4 万人,市场等待当日晚些时候公布的非农数据(华尔街日报预期新增约 8.3 万人)。此外,霍尔木兹海峡局势仍未完全解除,布伦特原油重返 83 美元上方;日元干预及日本国债收益率走势持续牵动全球流动性预期。
Odaily News: DefiLlama data shows that hackers stole $247 million in crypto assets in July, making it the second-highest month since 2026, trailing only April's $644 million; this figure represents a significant increase from June's $75 million and May's $60 million. Galaxy Digital stated that the Coldcard vulnerability was the largest attack event of the month, confirming three rounds of attacks involving 7,300 wallets, with at least $100 million in Bitcoin stolen; the firm also identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million. DefiLlama's hack tracker estimates losses related to this vulnerability at $115 million. Other attacks in July include a $9 million exploit on decentralized finance protocol Bonzo Lend, a $2.6 million theft from Cardano-based wallet SecondFi, a $24 million theft from Arbitrum-based perpetual trading platform AFX, and a $7.5 million theft from the Verus Ethereum Bridge.
Odaily News: Bitcoin Red Team, a volunteer security audit team composed of Bitcoin developers and security researchers, has released its latest audit findings. In approximately 30 hours, the team reviewed 391 Bitcoin-related codebases and identified a total of 4,962 security issues, of which 720 were rated as high-risk or critical vulnerabilities. Only one codebase was found to have no issues at all. Currently, only 147 vulnerabilities have been submitted to project maintainers for resolution.Bitcoin Red Team is a volunteer security audit team made up of Bitcoin developers and security researchers, initiated following the Coldcard hardware wallet vulnerability incident. Key contributors include Calle, a developer of the Cashu protocol, among others. (Beincrypto)
Odaily News: According to Lookonchain monitoring, the hacker who stole 2,055 BTC (valued at $130 million) from Coldcard is active again. An hour ago, the hacker transferred 30.185 BTC (worth $1.94 million) to a new wallet.
Odaily News – A long-dormant Bitcoin wallet moved nearly 50 BTC, worth approximately $3.2 million, on Thursday. The wallet received 49.97 BTC back in 2011, when Bitcoin was trading at around $10 per coin. The BTC was sent to a SegWit address that has previously transferred Bitcoin to institutional broker FalconX and received funds from wallets linked to Nexo and Prime Trust. The newly transferred BTC has not left this address. The transfer comes amid long-term holders rechecking their old storage setups following a major vulnerability exploit in Coldcard hardware wallets. There is currently no evidence linking the 2011 wallet to this vulnerability.
Bloomberg analyst Eric Balchunas says the Coldcard security vulnerability enhances the appeal of spot Bitcoin ETFs, with the incident involving approximately $88.6 million in losses.
According to Cointelegraph, Bitcoin Lightning Network self-custodial wallet Zeus Wallet voluntarily took its infrastructure offline following a cybersecurity attack on Wednesday and is currently conducting a comprehensive audit of the system, with services to be restored upon completion. Zeus founder Evan Kaloudis stated that the attack was contained within hours, no customer fund losses were found, and there was no evidence that the Lightning node software was affected; the scope of the incident was limited to Zeus's own infrastructure. For users forced to close LSP channels during this incident, Zeus promised to provide replacement channels after services are restored. The company has not yet disclosed the specific nature of the attack or a timeline for resuming operations. Zeus stated that this incident will further drive its security development on Trusted Execution Environment (TEE) and Validating Lightning Signer (VLS) projects.
According to CoinDesk, the S&P 500 index has risen 3.12% this month, adding approximately $2.1 trillion in market value (equivalent to the total market cap of the entire crypto market), reaching a record high total market cap of $70.5 trillion, but Bitcoin has only risen about 2% this month, hovering near $64,600. Analysts point out that this round of stock market rise is mainly driven by AI and semiconductor individual stock narratives, rather than a broad-based recovery in risk appetite at the macro level, and Bitcoin lacks direct beneficial exposure to this. Meanwhile, the crypto market also faces multiple internal pressures: the Coldcard platform suffered a $120 million exploit, the prospects of the "Clarity Act" remain uncertain, MicroStrategy has reduced its BTC holdings for three consecutive months, and stablecoin supply continues to shrink—USDT's market cap dropped from $190 billion in April to $183 billion, and USDC's dropped from $79.5 billion to $72 billion.