News linked to both this project and an event.
Galaxy Research stated on Friday that over 1,000 BTC from nearly 1,200 addresses have been moved, valued at approximately $70 million, with the transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets.Earlier, Coldcard manufacturer Coinkite issued a warning on Thursday about an ongoing issue with seed phrases generated by Coldcard Mk3 devices. Out of caution, the company reminded all users who generated seed phrases using Mk3 devices with firmware version 4.0.1, released in March 2021, or later, that their funds may be at risk.Subsequently, Coinkite expanded the scope of its risk alert to include certain firmware versions of Mk4, Mk5, and Coldcard Q, and released emergency firmware updates for all affected models.Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday and stated that the company takes "full responsibility" for the firmware vulnerability, acknowledging that internal review processes failed to identify the issue.Novak also suggested that the vulnerability may have been discovered with the help of artificial intelligence, noting that this incident reflects a "sobering reality under the new AI paradigm." He warned that AI-assisted code review could identify potential vulnerabilities faster than experienced security experts, while also making it easier for attackers to exploit weaknesses in public code.
According to Bitcoin.com, U.S. Senator Cynthia Lummis is pushing hard for the CLARITY Act to complete Senate voting before Congress adjourns. Section 303 of the bill grants the Treasury Department the authority to impose targeted digital asset sanctions on foreign jurisdictions, while Section 305 allows exchanges to freeze suspicious transactions for up to 180 days. On-chain data shows that North Korea's Lazarus Group stole approximately $643 million in the first half of 2026, accounting for two-thirds of the total global crypto theft during the same period ($972 million), including a $285 million attack on Drift Protocol in April and a $292 million attack on the KelpDAO cross-chain bridge. The group's cumulative theft amount has reached $6.75 billion since 2019. Currently, Galaxy Research has lowered the probability of the CLARITY Act passing within 2026 to 30%. The bill still requires 60 votes to advance, meaning at least 7 Democratic senators need to vote across party lines in support.
According to Decrypt, Galaxy Digital has officially launched the "Bitcoin Quantum Readiness Initiative," with three core pillars including: providing up to $5 million in post-quantum cryptography research grants to developers, publishing specialized research reports through Galaxy Research, and establishing a quantum advisory committee composed of scholars from multiple top universities. The initiative targets "Q-Day"—the critical moment when quantum computers utilize Shor's algorithm to crack Bitcoin's elliptic curve encryption, forge signatures, and steal wallet assets. Project Eleven predicts that quantum computers capable of cryptographic threats may emerge as early as 2030, at which point approximately 6.9 million BTC will face exposure risks. The Coinbase Quantum Advisory Committee has also called on developers to immediately initiate migration work. Meanwhile, Trump has signed an executive order setting the deadline for the U.S. federal government to complete post-quantum cryptography migration to December 2031.
Odaily报道 According to Ai Yi monitoring, a Galaxy Digital OTC-related address (0x16F...1Fde) has deposited 15,000 ETH, worth $34.74 million, to an exchange. These funds originated from 38,000 ETH withdrawn from Aave a week ago, which was the day when Kelp DAO was attacked, causing Aave to potentially face bad debt.
According to CoinDesk, cryptocurrency exchange Kraken was extorted by a criminal group that threatened to publicly release videos of its internal systems. Kraken stated that it had previously identified and addressed two incidents involving unauthorized access by internal personnel, affecting limited customer data from approximately 2,000 accounts—0.02% of its total user base—but emphasized that its systems were never breached and customer funds remained secure at all times. Nick Percoco, Kraken’s Chief Security Officer, explicitly affirmed the company would not capitulate to criminals. Kraken has notified affected users, enhanced security controls, and is cooperating with law enforcement authorities to advance the investigation; it believes existing evidence is sufficient to identify and apprehend those responsible. Separately, Galaxy Digital recently experienced a similar cybersecurity incident, though it likewise resulted in no loss of customer funds or data.