News linked to both this project and an event.
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.
Odaily News: The wallet associated with the Coldcard hacker has received multiple deposits since July 30, some of which include text messages attached via Bitcoin's OP_RETURN function. The messages include requests for the return of funds, as well as opportunistic promotional content, with one message offering to help launder the stolen funds for a 10% cut.
Odaily News: Hardware wallet manufacturer Ledger has stated that the recent Coldcard vulnerability indicates the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, as their recovery phrases are generated by a hardware random number generator built into a certified secure element. Coldcard manufacturer Coinkite disclosed last week that its air-gapped Coldcard Bitcoin hardware wallet contains a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, allowing certain private keys to be guessed, with related losses reaching approximately $130 million. Coinkite released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited — the flaw had existed in public code for over five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed. Charles Guillemet also said that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process has received independent certification.
Odaily Planet Daily Report: Bitcoin hardware wallet manufacturer Coinkite disclosed in late July 2026 that a firmware build error introduced in March 2021 caused some Coldcard wallets to generate mnemonics from a smaller range, reducing the randomness of user private keys. Galaxy Research analysts stated that the Coldcard exploit occurred in multiple rounds, with observed Bitcoin losses rising from approximately $88 million to nearly $114 million within days. Researchers warned that other vulnerable addresses could still become targets, prompting many Coldcard users to move their Bitcoin. Coldcard is a Bitcoin-only wallet that supports offline signing via microSD card and optional QR codes. Launched in 2017, it has long been regarded as one of the security-focused Bitcoin hardware wallets.
Odaily News: Bitcoin wallet service provider Nunchuk has issued an important update regarding the recent Coldcard security incident, recommending that users with multisig wallets containing Coldcard-generated keys migrate their funds as soon as possible.Nunchuk has categorized response levels based on the number of affected Coldcard keys in a multisig wallet: if the number of Coldcard-generated keys has reached the signing threshold, attackers could theoretically transfer funds directly, and such users should migrate immediately; if the wallet contains only 1 Coldcard-generated key and it is below the signing threshold, a single compromised key cannot move funds independently, making the risk relatively lower, but migration is still strongly recommended. If users cannot confirm the exact number of Coldcard keys in their wallet, they should treat it as a high-risk situation.Additionally, Nunchuk announced that an upcoming mobile update will automatically enable the Slipstream channel for paid users. At that point, any auxiliary multisig wallet transaction containing at least one Coldcard key will bypass the public mempool and be submitted via Slipstream, reducing the risk of transaction monitoring and replacement. For users who wish to act immediately or for free-tier users, Nunchuk offers a manual migration option: users need to create a migration transaction, complete multisig signing without broadcasting, and then submit the raw transaction data to the Slipstream platform.
According to Cointelegraph, Coinkite, the manufacturer of Coldcard hardware wallets, disclosed that its devices have contained a random number generator (RNG) vulnerability persisting for up to five years since March 2021. The vulnerability stemmed from a firmware upgrade that mistakenly routed wallet seed generation to a less secure MicroPython pseudo-random number generator (PRNG), rather than the originally designed true random number generator (TRNG). Since code reviews only verified the existence of TRNG code without confirming whether it was actually invoked, the vulnerability remained undetected for a long period. To date, over 4,500 addresses have been compromised, with nearly $90 million worth of Bitcoin stolen. Kraken Chief Security Officer Nick Percoco stated that this incident should serve as a "wake-up call" for the hardware wallet industry, calling for the introduction of independent third-party testing mechanisms to mandate verification of whether the entropy sources actually invoked by production firmware are certified. Coinkite has suspended all device shipments and destroyed affected inventory after confirming the vulnerability, and stated it will cooperate with law enforcement agencies across multiple countries to trace the responsible parties.
Odaily News: Major cryptocurrencies moved lower on Monday, with Bitcoin briefly falling to around $62,800 and Ether dropping to $1,858. Although expectations related to the geopolitical situation had improved earlier, the market failed to sustain a rebound. Following the expansion of the Coldcard hardware wallet vulnerability, approximately 1,367 BTC flowed out of roughly 4,585 addresses, valued at nearly $89 million, occurring across three rounds of attacks. The market's weakness stood in contrast to falling crude oil prices, a pullback in U.S. Treasury yields, and gains in stock index futures.
Bloomberg Senior ETF Analyst Eric Balchunas commented on the Coldcard wallet security incident, questioning whether a company with only about 5 employees is suitable to undertake such critical Bitcoin storage responsibilities. He stated that the number of employees behind Coldcard "seems unbelievably low," asking whether people would be willing to store their life savings in a bank with only 5 employees headquartered in Canada. In the crypto industry, this might be viewed as a feature, but from a traditional finance perspective, it becomes a clear risk signal. Balchunas further stated that, in comparison, institutions with larger teams such as Coinbase and Ledger may hold advantages in security investment and operational capabilities, even if users need to bear higher transaction costs. Bitcoin ETFs offer another option: investors can obtain the security guarantees provided by large, professional, regulated financial institutions while also enjoying lower management fees.
Odaily News: In response to the persistent attacks on Coldcard wallets, Binance co-founder CZ reposted on X platform stating that for self-custody wallets, developers fixing vulnerabilities cannot resolve the risks associated with previously generated wallets, and developers are unable to directly contact users of air-gapped devices.CZ stated that users' wallets may still be exposed to attack risks before any action is taken. He emphasized that he still supports the self-custody model, but self-custody means users need to bear more security responsibilities.
According to monitoring by on-chain analysis firm Galaxy Research (@glxyresearch), the ColdCard wallet hacking incident has developed into a third wave, with an additional 207.73 BTC stolen. Currently, the three waves of attacks have cumulatively stolen 1,367.05 BTC (approximately $88.6 million), involving 4,585 addresses. On-chain data shows that the three waves of attacks exhibit highly similar characteristics: identical fund consolidation topology, identical P2WPKH target addresses, and mixed derivation paths. Each wave occurred approximately 27 hours apart, suggesting they were carried out by the same attacker, but there is currently no direct evidence to confirm this. Currently, all terminal addresses controlled by the hackers hold a total of 1,366.39 BTC (approximately $88.6 million), all of which are in an unspent state on-chain. Galaxy Research noted that the above data is based solely on Bitcoin block data and UTXO set analysis, and has not yet computationally verified whether the victim addresses have vulnerabilities due to low-entropy generation.
Odaily News: Binance founder CZ reposted on X platform about a user's encounter with a Coldcard wallet attack and stated that software will always have vulnerabilities; the key lies in how the team behind it handles the problems.CZ added that Trust Wallet faced a similar issue years ago, when a non-truly random pseudo-random number generator led to losses of approximately $12 million, but the team ultimately covered the user losses.Previous report: A third wave of attacks suspected to target addresses generated by Coldcard has emerged, with the attacker transferring approximately 207.7294 BTC again. Data shows that the scale of Coldcard-related attacks observed so far has expanded to about 1,367.05 BTC, involving approximately 4,585 addresses, valued at around $88.6 million at current prices.
According to Cointelegraph, Singapore stablecoin payment company Triple-A confirmed its treasury wallet was accessed without authorization, with on-chain investigator Specter estimating losses at approximately $11.8 million. The company stated that customer funds are held in separate trust accounts and were not affected by this incident, and the relevant losses will be covered by the company's own financial reserves. Triple-A has currently restored all services and is collaborating with cybersecurity experts, blockchain forensic agencies, and the Singapore Police Force to investigate and track the stolen assets.
according to official sources, OKX, in collaboration with Elliptic, SlowMist, and OttoSec, has released the "H1 2026 Web3 Security and Risk Control Report." The report indicates that the focus of Web3 attacks is shifting from smart contract code to more complex scenarios such as signature processes, user devices, operational infrastructure, and AI Agents.Data shows that in the first half of 2026, OKX's risk control system intercepted over 5.7 million high-risk transactions, including approximately 2.41 million related to hacking and theft, about 1.48 million phishing-related transactions, and roughly 990,000 fraud-related transactions. OKX Web3's on-chain intelligence label library now boasts over 1.1 billion labels, covering more than 420 chains. It has also integrated capabilities such as address screening, transaction monitoring, and sanctioned address control into infrastructure like DEX and Exchange OS.Furthermore, in terms of user protection, OKX has intercepted over 7 million risky website visits, completed more than 200,000 device risk detections, identified over 60,000 high-risk Apps, and blocked or alerted on over 4 million high-risk signature operations. The report also introduces the "proactive risk control" design in scenarios such as Exchange OS, Outcomes, RWA, and Agentic Wallet.
Cardano ecosystem wallet SecondFi announced that due to a cryptographic defect in its wallet software, approximately 16.1 million ADA (worth around $2.6 million) were stolen. The platform will gradually shut down the SecondFi and Yoroi wallet services. This incident has affected 374 wallets. SecondFi stated that an independent investigation by blockchain intelligence agency Groom Lake identified the attackers as a sophisticated external actor and found indicators potentially linked to North Korea's Lazarus Group, though attribution has not yet been confirmed. SecondFi is developing a recovery tool based on zero-knowledge proofs to help affected users recover assets while limiting the information that needs to be shared. The tool is still being tested and will undergo third-party audits before its planned release in August. SecondFi is also preparing a wallet export feature to allow users to migrate their assets to other services. The platform has not announced a direct compensation plan, nor has it indicated whether it will use its own funds to compensate users.
according to Zilliqa's monitoring, it has learned of a security incident involving a CEX partner, where some ZIL has been stolen from a cold wallet. The incident is currently under investigation, and the team is working with relevant parties to determine the root cause and the scope of the impact. As a precautionary measure, Zilliqa has notified all CEX partners to temporarily suspend ZIL deposits and withdrawals to prevent the stolen funds from being transferred or sold through centralized platforms. The official stated that further updates will be released after verifying the information and reminded the community to only follow information published through official channels.
security researchers have discovered an information-stealing malware targeting MacOS devices that is attacking crypto users. It can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Affected wallets and applications include: Exodus, Atomic, Electrum, Wasabi, Monero, and others.Security experts advise that users with potentially infected devices should immediately treat them as "untrusted devices," terminate all active Telegram sessions, and change both their Telegram two-factor authentication password and desktop app password. Additionally, users should not enter seed phrases, private keys, or wallet passwords on the infected device, and should generate a new wallet and migrate their assets. (FinanceFeeds)
security firm Project Eleven has introduced a post-quantum proof technology designed to help users prove ownership of their Bitcoin wallets after quantum computers become capable of deriving private keys and generating valid signatures. Project Eleven CEO Alex Pruden stated that the technology utilizes the wallet's key derivation path, enabling users to prove control without disclosing the parent key, thus distinguishing legitimate owners from attackers. The solution was developed in collaboration with Jim Posen, a primary maintainer of the open-source Binius zero-knowledge proof system, and is based on the "signature lifting" technique proposed by Alon Sattath and Robert Wyborski. Project Eleven noted that the prototype has not yet been audited and requires blockchain protocol support before it can be deployed. It is primarily aimed at users who miss the window to migrate to quantum-resistant addresses in the future.
According to PeckShield monitoring, the previously detected unusual fund activity in the LayerZero Executor wallet was not an attack incident, but part of normal operational adjustments. User funds are not at risk.
Odaily reports: A court in the state of São Paulo, Brazil, has ordered Coinbase to refund nearly $100,000 to a user who claimed funds deposited in their Coinbase Wallet disappeared in an unauthorized transaction. Coinbase argued that the private keys to the wallet were entirely under the user's control. However, it failed to prove that the transaction was initiated by the wallet holder or that adequate security measures were in place to prevent the incident. The court ruled based on relevant provisions of the Consumer Protection Code and ordered Coinbase to return the full amount plus statutory interest. (Bitcoin.com News).
According to The Block, Ledger's security research team Donjon disclosed a security vulnerability in Tangem hardware wallet cards. After obtaining the physical card, attackers can use laser fault injection equipment to bypass recovery state verification in the firmware and reset the password, thereby controlling the wallet and initiating transactions. The research states that this vulnerability affects all Tangem cards currently in circulation, and since the product does not support firmware updates, it cannot be fixed via patches.