Topic
security
20 stories
Coldcard seed bug drives a spike in new Bitcoin addresses as users flee 2021-era wallets
Coinkite users have lost at least 1,816 BTC — roughly $116 million — in four theft waves since July 30, traced to a 2021 firmware bug that generated wallet seeds with a weak software random number generator.
Immunefi puts July crypto hack losses at $110 million — and uses the occasion to market its audit competitions
Immunefi says crypto lost about $110 million to hacks in July and paid researchers $2.32 million, in a statement that also markets its own audit-competition product against rival auditors.
BTCPay Server warns of critical flaw under active exploitation; patch details not yet public
BTCPay Server has warned that a critical flaw in the self-hosted Bitcoin payment processor is under active exploitation, though no CVE number or patched release has surfaced in public reporting yet.
BTCPay Server tells users to patch or power down, citing an actively exploited critical bug
BTCPay Server told users on Aug. 7 to upgrade to version 2.4.2 or shut down their servers, saying a critical flaw is already being exploited and funds may be at risk.
Ethereum Foundation funds a front-end integrity tool built for journalists, aimed at wallets
The Ethereum Foundation's Trillion Dollar Security initiative is funding Freedom of the Press Foundation to build a WEBCAT front-end verification library for crypto wallets, though the announcement names no grant amount, timeline or committed integrators.
Coldcard's seed flaw is still live, and an exchange is already selling the moral
Coinkite says the entropy flaw behind up to $114 million in stolen bitcoin is still live and requires manual migration, while OKX claims the theft is driving record deposits to exchanges.
Fourth Coldcard sweep is running live, with estimated losses near $114 million
Galaxy's Alex Thorn says a fourth wave of sweeps against Coldcard-generated bitcoin addresses began Monday, putting estimated losses since July 30 near 1,816 BTC, or roughly $114 million.
Coldcard wallet drain reaches $88 million, per Decrypt — with the mechanism still unspecified
Decrypt reports that losses from an exploit hitting Coldcard bitcoin wallets have reached $88 million and are still climbing, with the attack vector and vendor response not yet specified.
CZ warns Bitcoin holders after reported $70 million Coldcard exploit
Decrypt reported on August 1 that Binance founder Changpeng Zhao warned Bitcoin holders after a roughly $70 million exploit involving Coldcard hardware wallets, with the attack path still unspecified.
Coldcard key flaw: third sweep takes 208 BTC, running total hits 1,367
A third sweep of wallets seeded by a flawed March 2021 Coldcard firmware build drained 208 bitcoin from 1,912 addresses, pushing the running total to 1,367 BTC.
Galaxy puts the Coldcard drain at 1,082 BTC across 1,196 wallets — roughly double the first count
Galaxy Research says an attacker swept 1,082.65 BTC from 1,196 Coldcard wallets in 41 minutes on July 30 by reconstructing weakly generated seeds offline, without touching a single device.
Crypto 'wrench attacks' hit 52 in first half of 2026, with money targeted up more than tenfold
CertiK recorded 52 crypto "wrench attacks" — physical assaults and extortion targeting holders — in the first half of 2026, with total money demanded or stolen jumping more than tenfold to $124 million, most of it concentrated in France.
Trezor executive concedes hardware wallets are "clunky" but rejects ZachXBT's "complete garbage" verdict
On-chain investigator ZachXBT called all hardware wallets "complete garbage" for high-stakes use; Trezor's commercial chief conceded the tools are "clunky" but rejected the blanket verdict, while Tornado Cash's Roman Storm sided partly with ZachXBT.
Ethereum Foundation: AI agents found real protocol bugs, but the triage is where the work is
Ethereum Foundation's Protocol Security team says coordinated AI agents found real bugs in protocol code, including a disclosed libp2p flaw, but that verifying the findings — not generating them — is now the hard part.
BitGo says it will ship quantum-risk tools for institutional Bitcoin wallets 'in coming weeks'
BitGo said Thursday it will roll out tools in the coming weeks to help institutions measure and cut Bitcoin wallets' exposure to a future quantum-computing attack, built on its existing multi-signature setup.
Bitcoin Core ships a test build to fix the privacy feature that leaked privacy
Bitcoin Core has published v31.1rc1 for testing, a minor release whose headline fix closes a privacy bug in the new private-broadcast feature that could leak a sender's IP address to a peer.
Bitcoin Core discloses a high-severity node-crash bug, CVE-2024-52911, fixed in version 29.0
Bitcoin Core disclosed CVE-2024-52911, a high-severity use-after-free bug that let a miner crash nodes running versions from 0.14.0 up to 29.0 by broadcasting a specially crafted invalid block.
Bitcoin Core discloses five patched vulnerabilities, including a high-severity remote-crash bug that lingered for eight years
Bitcoin Core disclosed five node vulnerabilities patched in earlier releases, led by a high-severity use-after-free crash bug that went unnoticed for roughly eight years.
Ethereum Foundation launches "Clear Signing" standard to kill blind transaction approvals
The Ethereum Foundation released ERC-7730, an open "Clear Signing" standard that gives wallet users human-readable descriptions of transactions to eliminate blind signing approvals.
Crypto theft dipped to $76M in June, with Humanity Protocol's $31M–$36M hack the largest single loss
Blockchain security firm PeckShield tallied about $76 million stolen across 40 crypto incidents in June, a 7% dip from May, led by Humanity Protocol's private-key breach.