GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Over 1,800 BTC Stolen, Coinkite CTO Allegedly Ignored RNG Code Warnings a Year in Advance

Odaily Planet Daily reported that Bitcoin News posted on X platform, stating that new evidence suggests the anonymous account "switck," who wrote the LibNgU code, may actually be Peter Gray, Co-founder and CTO of Coinkite. This code is at the center of the COLDCARD entropy failure incident. Researchers claim that Gray's GPG key signed dozens of commits by switck, and other identifiers appear to link the two identities together. Bitcoin developer James O'Beirne stated that he had warned Coinkite in May 2025 that the RNG implementation of LibNgU looked suspicious and recommended removing it, but he said the other party responded that if there were issues, they would have already been discovered. Screenshots also show that as early as April 2021, users had already raised questions about the LibNgU rewrite. If these findings are accurate, it means that the engineer who introduced the code was later linked to the theft of over 1,800 BTC, and had received direct warnings about the RNG implementation more than a year before the vulnerability was publicly disclosed.

Coldcard vulnerability investigation escalates: At least 15 attackers identified, a single victim's findings reveal 12 BTC stolen

Galaxy Digital Head of Research Alex Thorn stated that based on new victim reports received following the incident, the number of attackers exploiting the Coldcard vulnerability has reached at least 15.Thorn noted that information provided by victims helped the research team uncover previously unidentified attack activity. Unlike thefts from centralized exchanges, correlations between the attackers in this vulnerability exploit require confirmation through on-chain analysis and victim feedback.He added that a single victim reporting less than 1 BTC stolen helped the team discover a previously unknown attack, which siphoned approximately 12 BTC from 126 addresses.According to Galaxy Research's earlier estimates, the Coldcard vulnerability has led to at least three rounds of attacks, with losses amounting to approximately $100 million in BTC. Additionally, Galaxy has identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million.Meanwhile, the incident has also sparked discussions regarding the security of Bitcoin self-custody. Dragonfly Managing Partner Haseeb Qureshi stated that "AI security hardening costing around $2" could potentially have prevented this vulnerability, and noted that some AI models were able to rediscover related vulnerabilities within a relatively short timeframe. However, industry insiders pointed out that current claims about the speed of AI discovering vulnerabilities lack rigorous blind testing and verification.Researchers believe that as AI model capabilities improve, the costs of vulnerability discovery and attacks in the crypto industry may continue to decline, requiring wallet developers to further strengthen code audits and security protections. (Cointelegraph)

Bitcoin Implied Volatility Drops to Two-Month Low, Coldcard Hack Fails to Trigger Market Panic

According to CoinDesk, the 30-day implied volatility index BVIV, which measures expected volatility in the Bitcoin options market, has continued to decline, now falling to 36%, the lowest level since May 31, significantly down from the high near 60% in early June. Recent influencing factors include the Coldcard wallet attack incident involving tens of millions of dollars, weak institutional demand, and uncertainty in the regulatory and macroeconomic environment, but there are no obvious signs of panic in the market. However, volatility has mean-reverting characteristics. When the indicator falls to historical lows, a rebound often follows. Currently, BVIV has approached levels that have previously formed support multiple times. If volatility rebounds quickly in the future, it may be accompanied by a significant directional move in Bitcoin; whether up or down, traders need to remain vigilant.

Coldcard vulnerability-related losses may reach $130 million, hardware wallet manufacturers warn of increased phishing attacks

Odaily News: Hardware wallet manufacturers Trezor and Foundation have warned that following the disclosure of a Coldcard firmware vulnerability, phishing attempts targeting hardware wallet holders have increased, with attackers soliciting recovery phrases and luring victims into downloading malware. Security firm Proofpoint has detected phishing emails impersonating Coldcard, inviting users to complete a "hardware audit" with links to a cloned website. After clicking, users download a batch file hosted on GitHub that installs the remote access tool ScreenConnect. Proofpoint stated that the fraudulent website also features a customer service chat window, where real people guide victims through the installation process. This remote access tool can provide attackers with a pathway to steal data and funds, or further deploy malicious programs such as ransomware. Galaxy Research has confirmed three rounds of theft since July 30, with high-confidence losses of 1,596 BTC, exceeding $100 million; if a fourth round not yet confirmed with victims is included, total losses could reach $130 million.

Over $114 Million in BTC Stolen, Over 5,200 COLDCARD User Addresses Affected

According to Onchain Lens monitoring, COLDCARD users have experienced another incident of stolen funds, with over 5,200 affected addresses seeing approximately 1,816 BTC stolen, worth around $114 million. The confirmed first to third waves involve 1,367.05 BTC, valued at approximately $88.6 million. The fourth wave, matching a pattern, involves 462 potential victims, adding 388.93 BTC. Onchain Lens is currently identifying associated clusters based on on-chain data. As of now, the attacker has not yet moved the stolen funds. The cluster remains active, with the latest transaction recorded just minutes ago.

Coldcard Vulnerability Has Resulted in Nearly $114 Million in Bitcoin Losses, With Insufficient Entropy in Some Wallet Mnemonics

Odaily Planet Daily Report: Bitcoin hardware wallet manufacturer Coinkite disclosed in late July 2026 that a firmware build error introduced in March 2021 caused some Coldcard wallets to generate mnemonics from a smaller range, reducing the randomness of user private keys. Galaxy Research analysts stated that the Coldcard exploit occurred in multiple rounds, with observed Bitcoin losses rising from approximately $88 million to nearly $114 million within days. Researchers warned that other vulnerable addresses could still become targets, prompting many Coldcard users to move their Bitcoin. Coldcard is a Bitcoin-only wallet that supports offline signing via microSD card and optional QR codes. Launched in 2017, it has long been regarded as one of the security-focused Bitcoin hardware wallets.

Boltz indefinitely suspends swap service due to AI-assisted attacks

Odaily News: Bitcoin News posted on X platform, stating that Boltzhq has indefinitely suspended its swap service after reporting an increase in AI-assisted attacks and multiple contained exploits. Due to its non-custodial design, user funds were never at risk, but wallets relying on Boltz for Lightning Network swaps, including AquaBitcoin and BULLBITCOIN, experienced service disruptions while alternative infrastructure is being deployed.

Permissions opened: MARA Slipstream becomes a permissionless public service with no client software required

Bitcoin News posted on X platform, stating that MARA's Slipstream is now open as a permissionless public service, requiring no client software. This service is particularly important for users transferring funds from vulnerable COLDCARD wallets. Multi-signature spending exposes all public keys and spending conditions. If this transaction enters the public mempool, attackers can immediately match these keys against their pre-computed database of weak COLDCARD private keys, and if they control the majority of keys, broadcast a higher-fee double-spend transaction before the original transaction is confirmed. Slipstream submits transactions directly to miners, keeping them out of the public mempool until mined. MARA recommends using conservative fees to avoid transactions getting stuck. Aside from standard Bitcoin network fees, the service is currently free.

Nunchuk Issues Guidance on Coldcard Security Incident, Recommends Immediate Migration for High-Risk Multisig Wallet Users

Odaily News: Bitcoin wallet service provider Nunchuk has issued an important update regarding the recent Coldcard security incident, recommending that users with multisig wallets containing Coldcard-generated keys migrate their funds as soon as possible.Nunchuk has categorized response levels based on the number of affected Coldcard keys in a multisig wallet: if the number of Coldcard-generated keys has reached the signing threshold, attackers could theoretically transfer funds directly, and such users should migrate immediately; if the wallet contains only 1 Coldcard-generated key and it is below the signing threshold, a single compromised key cannot move funds independently, making the risk relatively lower, but migration is still strongly recommended. If users cannot confirm the exact number of Coldcard keys in their wallet, they should treat it as a high-risk situation.Additionally, Nunchuk announced that an upcoming mobile update will automatically enable the Slipstream channel for paid users. At that point, any auxiliary multisig wallet transaction containing at least one Coldcard key will bypass the public mempool and be submitted via Slipstream, reducing the risk of transaction monitoring and replacement. For users who wish to act immediately or for free-tier users, Nunchuk offers a manual migration option: users need to create a migration transaction, complete multisig signing without broadcasting, and then submit the raw transaction data to the Slipstream platform.

Kraken Chief Security Officer: Coldcard Vulnerability Leads to Over $90 Million in Bitcoin Stolen, Hardware Wallet Industry Testing Mechanisms Require Urgent Overhaul

According to Cointelegraph, Coinkite, the manufacturer of Coldcard hardware wallets, disclosed that its devices have contained a random number generator (RNG) vulnerability persisting for up to five years since March 2021. The vulnerability stemmed from a firmware upgrade that mistakenly routed wallet seed generation to a less secure MicroPython pseudo-random number generator (PRNG), rather than the originally designed true random number generator (TRNG). Since code reviews only verified the existence of TRNG code without confirming whether it was actually invoked, the vulnerability remained undetected for a long period. To date, over 4,500 addresses have been compromised, with nearly $90 million worth of Bitcoin stolen. Kraken Chief Security Officer Nick Percoco stated that this incident should serve as a "wake-up call" for the hardware wallet industry, calling for the introduction of independent third-party testing mechanisms to mandate verification of whether the entropy sources actually invoked by production firmware are certified. Coinkite has suspended all device shipments and destroyed affected inventory after confirming the vulnerability, and stated it will cooperate with law enforcement agencies across multiple countries to trace the responsible parties.

Losses may approach $114 million, Coldcard wallet vulnerability attack mainly impacts single-signature wallets

Odaily News: Galaxy Research Head Alex Thorn analyzed that a new wave of Bitcoin sweeping attacks targeting Coldcard wallet addresses is underway, and cumulative losses from vulnerabilities related to Coldcard hardware wallets could approach $114 million. This attack primarily affects single-signature wallets, with no multi-signature wallets found to be impacted so far. No direct victim reports have been received yet; the assessment is mainly based on on-chain transaction pattern analysis, with some attack transactions still in an unconfirmed state.

Coldcard Hardware Wallet Vulnerability Leads to Outflow of Approximately 1,367 BTC, Bitcoin Drops Below $63,000

Odaily News: Major cryptocurrencies moved lower on Monday, with Bitcoin briefly falling to around $62,800 and Ether dropping to $1,858. Although expectations related to the geopolitical situation had improved earlier, the market failed to sustain a rebound. Following the expansion of the Coldcard hardware wallet vulnerability, approximately 1,367 BTC flowed out of roughly 4,585 addresses, valued at nearly $89 million, occurring across three rounds of attacks. The market's weakness stood in contrast to falling crude oil prices, a pullback in U.S. Treasury yields, and gains in stock index futures.

BitGo CEO Issues Public Challenge to Anthropic, Claims 100 BTC Deposited in Public Address

BitGo CEO Mike Belshe posted on social media stating that rather than hyping the narrative of "creating a hacker monster," it is better to conduct real verification. He stated that he has deposited 100 Bitcoins into a BitGo wallet, made the wallet address public, and issued a public challenge to Anthropic.

388.93 BTC Involved in Suspected Fourth Wave of Coldcard Attack, 462 Addresses Affected

Odaily News: According to monitoring by Galaxy's Head of Research, a suspected organized Coldcard attack is underway, with similar transactions still in the mempool awaiting confirmation. Previously confirmed transactions show RBF (Replace-By-Fee) enabled. Between blocks 960,778 and 960,792, 218 transactions occurred within approximately 2.5 hours, involving 462 victim addresses, 216 new destination addresses, and 388.92748828 BTC. None of the transactions had inputs predating the Coldcard firmware boundary. The sweep rate during this period was 13.8 times per block, compared to a baseline of 0.3 times per block in the pre-incident control window—approximately 45 times higher. The transaction topology is 1:1, with each victim address corresponding to a single new destination address. Only one destination address received two sweeps, and no consolidation addresses were observed. Some funds have already been swept to second-hop addresses.

Bitgo CEO deposits ~$6.3M in BTC, challenges Claude to move the funds

: Bitgo CEO Mike Belshe deposited 100 BTC into a public Bitcoin address on August 1, worth approximately $6.3 million at the time, and invited Anthropic's Claude model to attempt to move the funds out of the address. On-chain records show the wallet received the funds on July 31, and the balance had not been transferred out as of August 2. Anthropic previously disclosed that during 141,006 cybersecurity assessment runs, 3 incidents were found, with 6 evaluation sessions involving 3 models inadvertently interacting with real organizational systems. The models involved include Claude Opus 4.7, Claude Mythos 5, and an unreleased internal research model. The cause was a configuration error by third-party testing partner Irregular, which led to the test environment being connected to the internet. Anthropic stated that Claude Opus 4.7, during one evaluation, located a real website with the same name as a simulated company, exploited weak passwords and exposed services to recover infrastructure credentials, and accessed a production database containing hundreds of records. The company said the model was attempting to complete assigned tasks, not actively breaking constraints or pursuing independent goals. Belshe's challenge involves Bitgo's institutional custody platform, which uses multi-signature or multi-party computation technology to distribute signing authority across multiple independent keys. As of August 2, Anthropic had not publicly responded to the challenge.

Coldcard security incident loses 1,359.882 BTC, attacker address receives 10% coin-mixing offer

Odaily News: In the Coldcard security incident involving hardware wallet company Coinkite, the amount of stolen bitcoin has risen to approximately 1,359.882 BTC. According to statistics from the Coldcard Sweep Watch dashboard, most of the identified bitcoin remains in a small number of addresses controlled by the attacker. On August 1, one of the attacker's holding addresses received a transaction containing an OP_RETURN message. The message publicly offered a 10% fee for "washing" bitcoin, KYC assistance, and withdrawal services for stolen funds, along with a Telegram contact. Coinkite has released an urgent firmware update to fix the weak random number generation issue that caused the original vulnerability. The company stated that the new firmware only protects wallets created in the future and cannot fix seeds already generated on affected versions. Some users have reported that after installing the update, their devices remain stuck on an error screen, fail to boot, or appear bricked. This mainly affects Mk4 and Q devices, though some Mk3 users have also reported similar issues. As of August 2, Coinkite has not publicly confirmed a widespread firmware defect.

1367 BTC stolen, @KevinKelbie tracks 4,620 drained addresses

Odaily News: According to Bitcoin News monitoring, @KevinKelbie is tracking 1,367 BTC stolen since the 2021 RNG vulnerability, involving 4,620 drained addresses. Each BTC has been traced from the victim's wallet to its current location, with a complete timeline of transfers recorded up to July 2026.

Coldcard Vulnerability Causes User Losses Exceeding $88 Million, Coinkite May Face Class Action Lawsuit

Odaily News: Coinkite, the company behind hardware wallet Coldcard, may face legal action from users who collectively lost over 1,300 BTC — valued at more than $88 million — due to a vulnerability in the mnemonic generator of certain models. Thomas Braziel, founder and managing partner of 117 Partners, is investigating product liability claims and potential class action lawsuits against Coinkite, while coordinating efforts to collect information from victims worldwide. Brazilian Bitcoin advocate Felipe Ojeda has filed a police report and will file a complaint against the company in Brazil. Cris Carrascosa, CEO of ATH21, stated that Coinkite does not assume custodial responsibility for user funds tied to its products, and any lawsuit would need to prove that Coldcard could have foreseen the attack. Ana Ojeda, head of institutional business development at Blend, noted that victims do not have an automatic right to full recovery of funds, but an investigation into liability issues can be pursued.

Coldcard Vulnerability Leads to Over $88 Million in Losses, Coinkite Criticized for Retaining Customer Emails

Odaily News: Hardware wallet company Coinkite's Coldcard wallet series has experienced a seed generation randomness vulnerability, with threat actors stealing over 1,000 BTC in the past two days. Galaxy Research data shows that as of Saturday 17:36 ET, the incident involved 1,367 BTC, with losses exceeding $88 million. To notify potentially affected users, Coinkite sent security alerts to email addresses retained through its store and newsletter system since 2019. Coldcard confirmed that the emails originated from Coinkite and stated that it has contacted all reachable addresses to the best of its ability. Coinkite has faced criticism for retaining customer email data. The company stated that its public policy explains that purchase email addresses are saved so customers can log in and verify that other information has been cleared, but it did not specify a deletion timeline, saying these addresses would be kept "temporarily." Coinkite co-founder and CEO Rodolfo Novak previously stated that the company does not store customer information, deletes customer data 90 days after purchase, and offers anonymous purchase options.

COLDCARD RNG vulnerability discovered, 2023 video warning about weak seeds generated by dice rolls gains renewed attention

Odaily News: Bitcoin News posted on X platform that a 2023 video shows hardware wallet educator @YTCryptoGuide warning that COLDCARD Mk4 allows users to create a wallet with just a single dice roll, which could easily lead users to inadvertently generate extremely weak seeds. He also warned that the interface may lead users to believe their dice roll results would be mixed with the device's hardware RNG, but in certain operational flows, this is not the case. Many advanced users choose to use dice rolls because they do not fully trust hardware RNG. With the discovery of the COLDCARD RNG vulnerability, this video now carries new significance.