Useless Blockchain is a decentralized blockchain project with no practical value.
Odaily reports: In November 2023, Orlen Trading Switzerland, a subsidiary of Polish state-owned energy company Orlen, signed a contract to purchase 6 million barrels of Venezuelan crude oil and paid $230 million in unsecured advance payment to Dubai-based trading company Hannon International for conversion into USDT.Hannon International subsequently converted the funds through multiple intermediaries, with $135 million converted into only 85 million USDT, creating a $50 million shortfall. Between January and March 2024, private keys controlling over 132 million USDT were handed over via USB storage devices to brokers affiliated with Venezuela's state oil company.After the transaction, the relevant brokers became unreachable, and the Venezuelan state oil company failed to release the crude oil cargo. Ultimately, only one vessel loaded approximately 500,000 barrels of fuel oil, valued at $28.8 million; Orlen canceled the contract in March 2024, with estimated total losses of $378 million to $424 million.Polish prosecutors have launched a criminal investigation into the management of Orlen Trading Switzerland, with 3 former senior executives indicted and facing up to 25 years in prison. Orlen has initiated international arbitration in Dubai, seeking to recover the $230 million prepayment. (Bitcoin.com News)
Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following the emergency fix on July 31, addressing security risks brought by the previous mnemonic generation attack. Each newly generated mnemonic must now include at least one source of user entropy, including at least 65 irregular keystrokes, 50 physical dice throws, or 128 physical coin flips, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2. The new firmware also adds instant staged PSBT verification before signing, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks. The official reminder notes that updating the firmware cannot fix existing mnemonics generated by previously affected firmware. If users' mnemonics fall within the scope of this security advisory, they should first update the device, then generate and verify a completely new mnemonic, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signature of the downloaded firmware.
According to CoinDesk, US cybersecurity firm CrowdStrike has partnered with federal law enforcement agencies to successfully dismantle the Russian botnet Sality, which has been operating for over two decades. Over the past eight years, the network has continuously stolen cryptocurrency through clipboard hijacking; its core payload, "EggJagger," resides on infected machines, monitoring the user's clipboard. Once a Bitcoin or Ethereum wallet address is detected, it is replaced with the attacker's address, causing victims to unknowingly complete transfers. Sality employs a decentralized P2P architecture with no central server, checking node online status every 40 minutes, and self-propagates via network-shared drives and USB devices. By exploiting an authentication vulnerability, CrowdStrike replaced legitimate node addresses with those of its own servers, successfully severing the network connections of over 15,000 infected machines. The operation was demonstrated live at the Day Zero summit in Las Vegas. Estimates indicate that the attackers stole at least 12.1 million rubles (approximately $150,000) over the eight-year period. Undisturbed crypto assets appreciated alongside the broader market, reaching a value of roughly $1.35 million by early 2025. Security experts advise users to always verify the first and last characters after pasting a wallet address to defend against such attacks.
Odaily News: Cybersecurity firm Check Point Research has discovered that the StopAndProtect ransomware operation has been using nearly 2,000 compromised WordPress websites to spread malware, steal data, monitor victims, and deploy ransomware. The operation was first identified in mid-May.As of July 24, the operation had compromised more than 6,000 unique IP addresses, with 1,852 in the United States, and 630 each in Russia and India. The compromised websites were also used to host malware, relay commands, and store stolen files, screenshots, and activity logs.Attackers lured Windows users into running PowerShell commands through fake CAPTCHA prompts, enabling them to steal credentials and cryptocurrency wallet seed phrases, and spread further across networks and USB devices. Researchers collected more than 31,000 screenshots and over 700 compressed data archives, and believe the attackers may have accidentally infected themselves at some point. (Decrypt)
Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following the emergency fix on July 31, addressing security risks brought by the previous mnemonic generation attack. Each newly generated mnemonic must now include at least one source of user entropy, including at least 65 irregular keystrokes, 50 physical dice throws, or 128 physical coin flips, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2. The new firmware also adds instant staged PSBT verification before signing, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks. The official reminder notes that updating the firmware cannot fix existing mnemonics generated by previously affected firmware. If users' mnemonics fall within the scope of this security advisory, they should first update the device, then generate and verify a completely new mnemonic, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signature of the downloaded firmware.
Odaily News: Bitcoin News posted on X platform, stating that even if the mnemonic remains secure because it was generated via dice rolls or imported from an existing mnemonic, multiple Coldcard features may still be vulnerable due to the Yasmarang PRNG flaw. Affected features include paper wallets, device cloning, USB sessions, Secret Teleport, co-signing keys, password generator, and HSM mode. If the mnemonic was imported or generated through a sufficient number of dice rolls, the mnemonic itself remains secure, but using these features may still expose secret information generated by the flawed random number generator.
Odaily News: According to an official announcement, Binance Auto-Invest will support the following stocks and ETFs starting September 17, 2026 at 10:00 (UTC): ABNB, ACN, ADI, ADP, AEM, AEP, ALL, AMGN, AMT, AMX, ANET, AON, APD, APH, APO, APP, ASX, AXP, AZN, B, BA, BAM, BBVA, BCS, BE, BHP, BKNG, BMO, BMY, BN, BNS, BNY, BP, BTI, BUD, CAT, CB, CDNS, CEG, CI, CL, CM, CMCSA, CME, CMI, CNI, CNQ, COF, COP, CP, CRWD, CSCO, CSX, CTAS, CVS, DASH, DB, DDOG, DE, DELL, DLR, DUK, E, ECL, ELV, EMR, ENB, EOG, EQIX, EQNR, ETN, FCX, FDX, FTNT, GD, GE, GEV, GILD, GLW, GM, GOOG, GSK, HCA, HDB, HLT, HON, HPE, HSBC, HWM, IBM, IBN, ICE, IMO, ING, ITUB, ITW, JCI, KKR, KMI, LIN, LITE, LMT, LOW, LYG, MAR, MCK, MCO, MDLZ, MDT, MELI, MFC, MFG, MMM, MNST, MO, MPC, MRSH, MRVL, MSI, MUFG, NEE, NEM, NET, NGG, NOC, NSC, NTES, NU, NVO, NVS, NWG, ORLY, PBR, PBR.A, PCAR, PDD, PGR, PH, PLD, PM, PNC, PSX, PWR, RACE, RCL, REGN, RIO, ROST, RSG, RTX, RY, SAN, SAP, SCCO, SE, SHEL, SHOP, SHW, SKHY, SLB, SMFG, SNDK, SNPS, SNY, SO, SONY, SPCX, SPG, SPGI, SPOT, STX, SU, SYK, T, TD, TGT, TJX, TM, TMO, TMUS, TRP, TRV, TT, TTE, UBER, UBS, UL, UNP, UPS, USB, VLO, VRT, VRTX, VZ, WBD, WDC, WELL, WM, WMB, WPM.
Odaily News: Cybersecurity firm Check Point Research has discovered that the StopAndProtect ransomware operation has been using nearly 2,000 compromised WordPress websites to spread malware, steal data, monitor victims, and deploy ransomware. The operation was first identified in mid-May.As of July 24, the operation had compromised more than 6,000 unique IP addresses, with 1,852 in the United States, and 630 each in Russia and India. The compromised websites were also used to host malware, relay commands, and store stolen files, screenshots, and activity logs.Attackers lured Windows users into running PowerShell commands through fake CAPTCHA prompts, enabling them to steal credentials and cryptocurrency wallet seed phrases, and spread further across networks and USB devices. Researchers collected more than 31,000 screenshots and over 700 compressed data archives, and believe the attackers may have accidentally infected themselves at some point. (Decrypt)
Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following the emergency fix on July 31, addressing security risks brought by the previous mnemonic generation attack. Each newly generated mnemonic must now include at least one source of user entropy, including at least 65 irregular keystrokes, 50 physical dice throws, or 128 physical coin flips, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2. The new firmware also adds instant staged PSBT verification before signing, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks. The official reminder notes that updating the firmware cannot fix existing mnemonics generated by previously affected firmware. If users' mnemonics fall within the scope of this security advisory, they should first update the device, then generate and verify a completely new mnemonic, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signature of the downloaded firmware.
据 Forbes 报道,微软针对 Windows 11 版本 25H2 及 24H2 发布了紧急带外安全更新(KB5121767),以修复此前 7 月补丁星期二更新(KB5101650)在部分戴尔设备上引发的性能问题及系统关机故障。 该问题源于最新 Windows USB-C 连接管理器接口与英特尔 Innovation Platform Framework 处理器驱动程序之间的冲突,已知受影响设备包括 Dell Pro Max 14/16 Premium 及 Dell XPS 17 9720/9730 等型号。微软表示,此次更新仅建议受影响的戴尔用户安装,未受影响的设备无需任何操作。
Odaily Odaily Planet Daily reports, according to official sources, MGBX will list CRCLB (Circle), SNDKB (SanDisk), and TSLAB (Tesla) for spot trading at 18:00 (SGT) on June 22, 2026.Deposit opening time: 16:00 (SGT) on June 22, 2026Trading opening time: 18:00 (SGT) on June 22, 2026Withdrawal opening time: 19:00 (SGT) on June 23, 2026CRCLB: CRCLB is a Binance bStocks tokenized security, corresponding to the underlying asset Circle Internet Group. Circle is the operator of the Circle Payments Network (CPN) and provides products and services to financial institutions participating in the network to assist them in accessing and integrating with CPN.SNDKB: SNDKB is a tokenized bStocks, corresponding to the underlying asset SanDisk. SanDisk Corporation is a global flash memory storage company that designs and manufactures products such as SD cards, USB flash drives, and solid-state drives for both consumers and enterprise users.TSLAB: TSLAB is a tokenized bStocks, corresponding to the underlying asset Tesla. Tesla is a vertically integrated sustainable energy company, also dedicated to advancing the global transition to electric mobility through the manufacturing of electric vehicles.
Odaily News: According to an official announcement, Binance Auto-Invest will support the following stocks and ETFs starting September 17, 2026 at 10:00 (UTC): ABNB, ACN, ADI, ADP, AEM, AEP, ALL, AMGN, AMT, AMX, ANET, AON, APD, APH, APO, APP, ASX, AXP, AZN, B, BA, BAM, BBVA, BCS, BE, BHP, BKNG, BMO, BMY, BN, BNS, BNY, BP, BTI, BUD, CAT, CB, CDNS, CEG, CI, CL, CM, CMCSA, CME, CMI, CNI, CNQ, COF, COP, CP, CRWD, CSCO, CSX, CTAS, CVS, DASH, DB, DDOG, DE, DELL, DLR, DUK, E, ECL, ELV, EMR, ENB, EOG, EQIX, EQNR, ETN, FCX, FDX, FTNT, GD, GE, GEV, GILD, GLW, GM, GOOG, GSK, HCA, HDB, HLT, HON, HPE, HSBC, HWM, IBM, IBN, ICE, IMO, ING, ITUB, ITW, JCI, KKR, KMI, LIN, LITE, LMT, LOW, LYG, MAR, MCK, MCO, MDLZ, MDT, MELI, MFC, MFG, MMM, MNST, MO, MPC, MRSH, MRVL, MSI, MUFG, NEE, NEM, NET, NGG, NOC, NSC, NTES, NU, NVO, NVS, NWG, ORLY, PBR, PBR.A, PCAR, PDD, PGR, PH, PLD, PM, PNC, PSX, PWR, RACE, RCL, REGN, RIO, ROST, RSG, RTX, RY, SAN, SAP, SCCO, SE, SHEL, SHOP, SHW, SKHY, SLB, SMFG, SNDK, SNPS, SNY, SO, SONY, SPCX, SPG, SPGI, SPOT, STX, SU, SYK, T, TD, TGT, TJX, TM, TMO, TMUS, TRP, TRV, TT, TTE, UBER, UBS, UL, UNP, UPS, USB, VLO, VRT, VRTX, VZ, WBD, WDC, WELL, WM, WMB, WPM.
Odaily reports: In November 2023, Orlen Trading Switzerland, a subsidiary of Polish state-owned energy company Orlen, signed a contract to purchase 6 million barrels of Venezuelan crude oil and paid $230 million in unsecured advance payment to Dubai-based trading company Hannon International for conversion into USDT.Hannon International subsequently converted the funds through multiple intermediaries, with $135 million converted into only 85 million USDT, creating a $50 million shortfall. Between January and March 2024, private keys controlling over 132 million USDT were handed over via USB storage devices to brokers affiliated with Venezuela's state oil company.After the transaction, the relevant brokers became unreachable, and the Venezuelan state oil company failed to release the crude oil cargo. Ultimately, only one vessel loaded approximately 500,000 barrels of fuel oil, valued at $28.8 million; Orlen canceled the contract in March 2024, with estimated total losses of $378 million to $424 million.Polish prosecutors have launched a criminal investigation into the management of Orlen Trading Switzerland, with 3 former senior executives indicted and facing up to 25 years in prison. Orlen has initiated international arbitration in Dubai, seeking to recover the $230 million prepayment. (Bitcoin.com News)
According to CoinDesk, US cybersecurity firm CrowdStrike has partnered with federal law enforcement agencies to successfully dismantle the Russian botnet Sality, which has been operating for over two decades. Over the past eight years, the network has continuously stolen cryptocurrency through clipboard hijacking; its core payload, "EggJagger," resides on infected machines, monitoring the user's clipboard. Once a Bitcoin or Ethereum wallet address is detected, it is replaced with the attacker's address, causing victims to unknowingly complete transfers. Sality employs a decentralized P2P architecture with no central server, checking node online status every 40 minutes, and self-propagates via network-shared drives and USB devices. By exploiting an authentication vulnerability, CrowdStrike replaced legitimate node addresses with those of its own servers, successfully severing the network connections of over 15,000 infected machines. The operation was demonstrated live at the Day Zero summit in Las Vegas. Estimates indicate that the attackers stole at least 12.1 million rubles (approximately $150,000) over the eight-year period. Undisturbed crypto assets appreciated alongside the broader market, reaching a value of roughly $1.35 million by early 2025. Security experts advise users to always verify the first and last characters after pasting a wallet address to defend against such attacks.
Odaily News: Cybersecurity firm Check Point Research has discovered that the StopAndProtect ransomware operation has been using nearly 2,000 compromised WordPress websites to spread malware, steal data, monitor victims, and deploy ransomware. The operation was first identified in mid-May.As of July 24, the operation had compromised more than 6,000 unique IP addresses, with 1,852 in the United States, and 630 each in Russia and India. The compromised websites were also used to host malware, relay commands, and store stolen files, screenshots, and activity logs.Attackers lured Windows users into running PowerShell commands through fake CAPTCHA prompts, enabling them to steal credentials and cryptocurrency wallet seed phrases, and spread further across networks and USB devices. Researchers collected more than 31,000 screenshots and over 700 compressed data archives, and believe the attackers may have accidentally infected themselves at some point. (Decrypt)
Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following the emergency fix on July 31, addressing security risks brought by the previous mnemonic generation attack. Each newly generated mnemonic must now include at least one source of user entropy, including at least 65 irregular keystrokes, 50 physical dice throws, or 128 physical coin flips, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2. The new firmware also adds instant staged PSBT verification before signing, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks. The official reminder notes that updating the firmware cannot fix existing mnemonics generated by previously affected firmware. If users' mnemonics fall within the scope of this security advisory, they should first update the device, then generate and verify a completely new mnemonic, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signature of the downloaded firmware.
Odaily News: Bitcoin News posted on X platform, stating that even if the mnemonic remains secure because it was generated via dice rolls or imported from an existing mnemonic, multiple Coldcard features may still be vulnerable due to the Yasmarang PRNG flaw. Affected features include paper wallets, device cloning, USB sessions, Secret Teleport, co-signing keys, password generator, and HSM mode. If the mnemonic was imported or generated through a sufficient number of dice rolls, the mnemonic itself remains secure, but using these features may still expose secret information generated by the flawed random number generator.