News linked to both this project and an event.
: Bitcoin News posted on the X platform stating that a security analysis revealed a repository distributed on GitHub, disguised as a proof-of-concept tool for a COLDCARD random number generator, is malicious in nature. The software claims to be a research tool that reproduces a flawed wallet random number generator to help recover Bitcoin wallets created with vulnerable seeds. According to the report, the tool contains a remote code execution backdoor that downloads an information-stealing program capable of collecting wallet mnemonic phrases, private keys, browser passwords, SSH keys, and other credentials, exfiltrating the data via Telegram while installing persistent malware on Windows, macOS, and Linux. Researchers stated that any user who has executed the code should treat the affected device as fully compromised, rotate credentials, transfer crypto assets to a newly generated wallet, and report the repository. The analysis also warned against running proof-of-concept code for vulnerabilities on devices containing wallets or sensitive data without independent verification.
: Bitcoin News posted on X platform stating that a new community honeypot test shows attackers are still prioritizing the most easily exploitable wallets affected by the Coldcard Mk3 RNG vulnerability. Researcher @ColeTU injected funds into 5 affected Mk3 wallets: 1 using only the vulnerable mnemonic seed, 3 protected respectively by 1-word, 2-word, and 3-word BIP39 passphrases, and 1 using a random account number. After 14 hours, only the unprotected wallet using just the mnemonic seed had its funds transferred out. Additionally, according to @jamesob's real-time tripwire dashboard, only 2 of the 17 honeypot wallets have been drained so far. Confirmed drained wallets all lacked added entropy, while all wallets protected by dice rolls, passphrases, multisig, or other complexity measures remain untouched. The test results show that attackers are currently focusing on wallets that are easiest to brute-force rather than investing resources in hardened targets—but affected users should still migrate funds immediately rather than relying on temporary protection.
According to reports from the Procuratorial Daily, an employee of a Shenzhen enterprise, under pressure from over 400,000 yuan in online loans, stole the company's core R&D data and disguised himself as an overseas hacker to demand a ransom of 0.88 Bitcoin and 90,000 USDT from the enterprise, and was ultimately sentenced to three years and three months for attempted extortion and fined 10,000 yuan.
据 Bitcoin Magazine 报道,在 Coldcard 硬件钱包漏洞事件引发行业关注后,由 Calle与 Anchorwatch 首席执行官 Rob Hamilton 推动的“比特币红队”已对 390 个比特币开源代码库展开 AI 驱动安全审计,累计提交 4,962 项问题,其中包括 85 项严重漏洞和 635 项高危问题。该项目已获得 OpenSats 支持,审计成本超过 4 万美元,并计划未来开源相关测试工具,以协助更多比特币企业和开发团队排查安全风险。
Odaily Odaily News: Bitcoin Red Team, a bitcoin security organization composed of 16 volunteers, stated that it identified nearly 5,000 potential issues during a rapid AI-assisted review of bitcoin ecosystem projects. The organization's members include AnchorWatch CEO Rob Hamilton and bitcoin developer Calle, among others. Calle stated that Bitcoin Red Team used AI tools combined with manual review to scan for vulnerabilities in open-source code repositories related to bitcoin, discovering an average of approximately 1 critical vulnerability per person per hour. Calle disclosed that within 29.8 hours of launch, the team had identified 4,962 potential issues across 390 projects, of which as many as 720 were classified as high-risk or critical. Currently, 21.4% of the findings have been reproduced. The security review initiative was launched just days after the Coldcard hardware wallet vulnerability incident, in which stolen bitcoin exceeded $100 million in value.
Odaily News: Bitcoin News stated on the X platform that ZEUS has temporarily taken its infrastructure offline following a cybersecurity incident over the past few hours. ZEUS said the attack has been mitigated and services will remain offline until it completes a full security audit and resumes operations. ZEUS stated that no customer funds have been lost, and no customer funds are currently at risk. Customers whose Lightning Service Provider channels were closed will receive replacement channels once services are restored. Based on the current investigation, ZEUS said the incident appears to be limited to its own infrastructure, with no evidence yet suggesting it was caused by a vulnerability in Lightning node software. ZEUS added that it has been strengthening its infrastructure using trusted execution environments and the Validating Lightning Signer project, noting that the project is designed to mitigate such attacks in its upcoming architecture. ZEUS said it will continue to provide updates as the investigation progresses.
Odaily News: According to Bitcoin News monitoring, Galaxy Research stated that the largest known COLDCARD theft incident involves 1,159 BTC, distributed across seven attacker addresses, which remain untouched to date, with 0 BTC cashed out or transferred through mixers. The relevant BTC was stolen within 41 minutes, but approximately 600 attacker addresses have been flagged by law enforcement agencies, exchanges, and blockchain analysis firms. Meanwhile, a smaller-scale attacker appears to have begun cleaning funds. On-chain analysts have tracked 64 BTC entering mixers, of which only about 10 BTC initially completed mixing, 54 BTC returned as change, and were subsequently split into outputs of approximately 7 BTC each for further mixing. Analysts noted that these unusually large outputs remain easy to trace, making this cleaning attempt relatively transparent.
Odaily News: According to Bitcoin News monitoring, Alex Thorn of Galaxy Research stated that researchers initially identified the first wave of COLDCARD thefts through a distinctive on-chain pattern: thousands of automated asset transfer transactions used the same fixed fee rate and exhibited identical transaction behavior. This characteristic enabled analysts to trace attacker activity across Bitcoin UTXO history and map out multiple rounds of coordinated theft.
Odaily Odaily News: K33 Head of Research Vetle Lunde stated that the Coldcard attack likely drove the movement of approximately 890,000 BTC within 7 days, setting the highest 7-day active supply record for 2026. K33 estimates that around 7,300 addresses had approximately 1,596 BTC stolen at the time the report was prepared. The incident stems from a firmware flaw introduced by Coinkite in March 2021 in Coldcard hardware wallets, which may generate wallet seeds with insufficient randomness. Since July 30, coordinated transfers have removed approximately 1,600 BTC from thousands of addresses, worth over $100 million, and a possible fourth wave of attacks has pushed the total to nearly 2,000 BTC. On-chain data shows that Bitcoin's 7-day hot supply rose from 403,101.95 BTC on July 28 to 797,407.72 BTC on August 4, an increase of approximately 394,306 BTC in one week, or 98%. Sani from Timechainindex.com stated that since the Coldcard hack on Friday, exchanges have seen net inflows of 22,052 BTC. From July 30 to August 5, 39 dormant addresses moved a total of 1,486.09044782 BTC, worth over $95 million. Among them, one address created in 2010 moved 50 BTC, and five addresses created in 2013 collectively moved 620.00100547 BTC.
Bitcoin News posted on X platform, stating that Boltz has updated its PGP-signed warrant canary, a transparency measure used by privacy-related companies to publicly indicate that they have not received any secret government orders requiring them to hand over user data. The company's previous canary was dated May 31. Despite its commitment to update every 60 days, the canary expired around July 30, and its notice had asked users to "assume the worst" if it was not updated. Boltz stated that the expiration was due to negligence, as its team was dealing with an AI-assisted infrastructure attack that lasted for months, which ultimately led to the indefinite suspension of its swap services. The warrant canary has now been updated. Boltz stated that since the platform operates in a non-custodial model, user funds were never at risk.
Odaily News: The Coldcard wallet hack involves approximately $120 million. The related transactions briefly made the Bitcoin mempool highly active.
Odaily News: Swan CEO Cory Klippsten stated that the Coldcard attack has prompted Bitcoin holders to reassess their custody decisions. Cory Klippsten noted that his team has been organized to assist affected holders in moving tokens to secure locations, including those who are not Swan customers. He pointed out that affected users have not abandoned self-custody, but are instead turning to vault solutions that prevent a single compromised device from endangering funds.
CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.
Odaily News: The wallet associated with the Coldcard hacker has received multiple deposits since July 30, some of which include text messages attached via Bitcoin's OP_RETURN function. The messages include requests for the return of funds, as well as opportunistic promotional content, with one message offering to help launder the stolen funds for a 10% cut.
Odaily News, Chainalysis posted on X platform stating that the Coldcard hack has been particularly devastating for Bitcoin holders in Canada. Our analysis of the attackers and victims found that Canadian BTC holders accounted for 25% of the attributable losses.According to aggregated estimates from Galaxy Research, losses have reached as high as $110 million. We analyzed the geographic distribution of this ongoing hacking campaign. Users in Australia, the United States, and Thailand have also suffered significant losses.
According to Decrypt, non-custodial Bitcoin exchange service provider Boltz announced an indefinite suspension of its Bitcoin exchange services, as the iteration speed of AI-assisted attacks has exceeded its team's vulnerability patching capability. Boltz stated that automated AI probing attacks have continued to increase over the past few months, and multiple vulnerability exploitation incidents have been handled, but recently the pace of attacks has significantly accelerated, and it is suspected that multiple well-resourced attack organizations are simultaneously launching attacks against its platform, rendering the team unable to operate safely during the patching period. Currently, Boltz's TVL is approximately $262,000. Since the platform adopts a non-custodial architecture, users retain custody of their funds throughout the process. The team confirmed that no user funds are at risk, and API refund channels and unilateral refund functions remain operational.
Odaily News: Non-custodial Bitcoin swap service Boltz has indefinitely suspended its Bitcoin swap service, stating that the service will remain offline until further notice, with no timeline for restoration provided. Boltz allows users to transfer Bitcoin between the Lightning Network and the Bitcoin base layer, without the company ever holding custody of user funds. Boltz stated that over the past few months, its infrastructure has faced a continuous increase in automated, AI-assisted probing, and the team has already handled multiple exploit incidents. The company said each incident was contained, but the speed at which attackers iterate has outpaced the team's ability to discover and patch vulnerabilities. Boltz disclosed that the pace of attacks has accelerated over the past few days, and after reviewing recent security scan results, the company concluded that it cannot responsibly re-enable the swap service. Its API remains available for processing collaborative refunds, unilateral refunds remain operational as they do not rely on Boltz infrastructure, and customer support remains accessible.
Odaily News: Hardware wallet manufacturer Ledger has stated that the recent Coldcard vulnerability indicates the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, as their recovery phrases are generated by a hardware random number generator built into a certified secure element. Coldcard manufacturer Coinkite disclosed last week that its air-gapped Coldcard Bitcoin hardware wallet contains a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, allowing certain private keys to be guessed, with related losses reaching approximately $130 million. Coinkite released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited — the flaw had existed in public code for over five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed. Charles Guillemet also said that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process has received independent certification.
Odaily Planet Daily reported that Bitcoin News stated on the X platform that Coinkite said the vulnerability existed at the boundary between two unrelated firmware submodules, rather than in its Bitcoin or encryption code, which allowed it to evade both manual and AI-assisted code reviews for years. Coinkite stated that after the incident, the company tested cutting-edge AI models including Kimi K3, Claude Fable, and Codex 5.6, none of which identified the flaw. Coinkite is now urging security-critical projects to specifically audit build systems and submodule boundaries, and warned that AI-assisted development could leave similar blind spots in the Bitcoin ecosystem.