GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Permissions opened: MARA Slipstream becomes a permissionless public service with no client software required

Bitcoin News posted on X platform, stating that MARA's Slipstream is now open as a permissionless public service, requiring no client software. This service is particularly important for users transferring funds from vulnerable COLDCARD wallets. Multi-signature spending exposes all public keys and spending conditions. If this transaction enters the public mempool, attackers can immediately match these keys against their pre-computed database of weak COLDCARD private keys, and if they control the majority of keys, broadcast a higher-fee double-spend transaction before the original transaction is confirmed. Slipstream submits transactions directly to miners, keeping them out of the public mempool until mined. MARA recommends using conservative fees to avoid transactions getting stuck. Aside from standard Bitcoin network fees, the service is currently free.

Nunchuk Issues Guidance on Coldcard Security Incident, Recommends Immediate Migration for High-Risk Multisig Wallet Users

Odaily News: Bitcoin wallet service provider Nunchuk has issued an important update regarding the recent Coldcard security incident, recommending that users with multisig wallets containing Coldcard-generated keys migrate their funds as soon as possible.Nunchuk has categorized response levels based on the number of affected Coldcard keys in a multisig wallet: if the number of Coldcard-generated keys has reached the signing threshold, attackers could theoretically transfer funds directly, and such users should migrate immediately; if the wallet contains only 1 Coldcard-generated key and it is below the signing threshold, a single compromised key cannot move funds independently, making the risk relatively lower, but migration is still strongly recommended. If users cannot confirm the exact number of Coldcard keys in their wallet, they should treat it as a high-risk situation.Additionally, Nunchuk announced that an upcoming mobile update will automatically enable the Slipstream channel for paid users. At that point, any auxiliary multisig wallet transaction containing at least one Coldcard key will bypass the public mempool and be submitted via Slipstream, reducing the risk of transaction monitoring and replacement. For users who wish to act immediately or for free-tier users, Nunchuk offers a manual migration option: users need to create a migration transaction, complete multisig signing without broadcasting, and then submit the raw transaction data to the Slipstream platform.

Kraken Chief Security Officer: Coldcard Vulnerability Leads to Over $90 Million in Bitcoin Stolen, Hardware Wallet Industry Testing Mechanisms Require Urgent Overhaul

According to Cointelegraph, Coinkite, the manufacturer of Coldcard hardware wallets, disclosed that its devices have contained a random number generator (RNG) vulnerability persisting for up to five years since March 2021. The vulnerability stemmed from a firmware upgrade that mistakenly routed wallet seed generation to a less secure MicroPython pseudo-random number generator (PRNG), rather than the originally designed true random number generator (TRNG). Since code reviews only verified the existence of TRNG code without confirming whether it was actually invoked, the vulnerability remained undetected for a long period. To date, over 4,500 addresses have been compromised, with nearly $90 million worth of Bitcoin stolen. Kraken Chief Security Officer Nick Percoco stated that this incident should serve as a "wake-up call" for the hardware wallet industry, calling for the introduction of independent third-party testing mechanisms to mandate verification of whether the entropy sources actually invoked by production firmware are certified. Coinkite has suspended all device shipments and destroyed affected inventory after confirming the vulnerability, and stated it will cooperate with law enforcement agencies across multiple countries to trace the responsible parties.

Losses may approach $114 million, Coldcard wallet vulnerability attack mainly impacts single-signature wallets

Odaily News: Galaxy Research Head Alex Thorn analyzed that a new wave of Bitcoin sweeping attacks targeting Coldcard wallet addresses is underway, and cumulative losses from vulnerabilities related to Coldcard hardware wallets could approach $114 million. This attack primarily affects single-signature wallets, with no multi-signature wallets found to be impacted so far. No direct victim reports have been received yet; the assessment is mainly based on on-chain transaction pattern analysis, with some attack transactions still in an unconfirmed state.

Anthropic 向美国国会致函,指控中国科技巨头阿里巴巴通过大规模"蒸馏攻击"

此前消息,阿里巴巴涉嫌注册约 2.5 万个虚假账户,在三个月内发起 2880 万次提示-响应交互,累计提取约 576 亿个 token 的数字知识,所获数据疑被用于训练阿里巴巴自有大语言模型,重点涵盖代理推理等高级 AI 能力领域。据悉,上述操作被刻意设计为模拟正常用户行为,以规避检测。

Russian Law Enforcement Raids Moscow Crypto Exchange Office

According to The Block citing Bits Media, Russian law enforcement agencies recently raided the offices of multiple cryptocurrency exchanges in Moscow to investigate a theft case involving 144 million rubles (approximately $1.8 million). Investigators suspect the stolen funds were transferred through the exchanges and are currently reviewing whether relevant employees are involved.

Coldcard Hardware Wallet Vulnerability Leads to Outflow of Approximately 1,367 BTC, Bitcoin Drops Below $63,000

Odaily News: Major cryptocurrencies moved lower on Monday, with Bitcoin briefly falling to around $62,800 and Ether dropping to $1,858. Although expectations related to the geopolitical situation had improved earlier, the market failed to sustain a rebound. Following the expansion of the Coldcard hardware wallet vulnerability, approximately 1,367 BTC flowed out of roughly 4,585 addresses, valued at nearly $89 million, occurring across three rounds of attacks. The market's weakness stood in contrast to falling crude oil prices, a pullback in U.S. Treasury yields, and gains in stock index futures.

OKX.AI Launches Inaugural Trading Hackathon with $20,000 Total Prize Pool

Odaily News — According to official sources, OKX.AI has announced that registration for its inaugural trading hackathon is now open. Following the previous Genesis hackathon for Agent Service Providers (ASP), this hackathon focuses on AI Agent live trading capabilities. Participants are required to deploy their trading strategies as Trading ASPs and conduct live trading with no less than 300 USDT in equivalent funds. Rankings will be updated in real time based on yield (PnL %). The total prize pool is $20,000, with the champion receiving a $5,000 reward.It is reported that OKX.AI is an economic system built specifically for Agents, where users and Agents can discover and utilize professional services provided by ASPs. This event supports two development frameworks: Onchain OS and Agent Trade Kit. Registration runs from July 31 to August 11 at 12:00 (UTC+8), and the competition will take place from August 11 to August 25.

BitGo CEO Issues Public Challenge to Anthropic, Claims 100 BTC Deposited in Public Address

BitGo CEO Mike Belshe posted on social media stating that rather than hyping the narrative of "creating a hacker monster," it is better to conduct real verification. He stated that he has deposited 100 Bitcoins into a BitGo wallet, made the wallet address public, and issued a public challenge to Anthropic.

388.93 BTC Involved in Suspected Fourth Wave of Coldcard Attack, 462 Addresses Affected

Odaily News: According to monitoring by Galaxy's Head of Research, a suspected organized Coldcard attack is underway, with similar transactions still in the mempool awaiting confirmation. Previously confirmed transactions show RBF (Replace-By-Fee) enabled. Between blocks 960,778 and 960,792, 218 transactions occurred within approximately 2.5 hours, involving 462 victim addresses, 216 new destination addresses, and 388.92748828 BTC. None of the transactions had inputs predating the Coldcard firmware boundary. The sweep rate during this period was 13.8 times per block, compared to a baseline of 0.3 times per block in the pre-incident control window—approximately 45 times higher. The transaction topology is 1:1, with each victim address corresponding to a single new destination address. Only one destination address received two sweeps, and no consolidation addresses were observed. Some funds have already been swept to second-hop addresses.

Bitgo CEO deposits ~$6.3M in BTC, challenges Claude to move the funds

: Bitgo CEO Mike Belshe deposited 100 BTC into a public Bitcoin address on August 1, worth approximately $6.3 million at the time, and invited Anthropic's Claude model to attempt to move the funds out of the address. On-chain records show the wallet received the funds on July 31, and the balance had not been transferred out as of August 2. Anthropic previously disclosed that during 141,006 cybersecurity assessment runs, 3 incidents were found, with 6 evaluation sessions involving 3 models inadvertently interacting with real organizational systems. The models involved include Claude Opus 4.7, Claude Mythos 5, and an unreleased internal research model. The cause was a configuration error by third-party testing partner Irregular, which led to the test environment being connected to the internet. Anthropic stated that Claude Opus 4.7, during one evaluation, located a real website with the same name as a simulated company, exploited weak passwords and exposed services to recover infrastructure credentials, and accessed a production database containing hundreds of records. The company said the model was attempting to complete assigned tasks, not actively breaking constraints or pursuing independent goals. Belshe's challenge involves Bitgo's institutional custody platform, which uses multi-signature or multi-party computation technology to distribute signing authority across multiple independent keys. As of August 2, Anthropic had not publicly responded to the challenge.

CZ: The Biggest Challenge of Self-Custody Is Safely Storing Seed Phrases—They Must Be Neither Leaked Nor Lost

Odaily News: Binance co-founder CZ reposted user Rager's experience with a hardware wallet malfunction on the X platform. CZ stated that protecting wallet backup seed phrases is an extremely challenging task. The seed phrase must not be seen by others, or it could be copied or exploited, and it must also be protected from accidental damage caused by fires, floods, or other incidents, while also preventing hackers from gaining access. More importantly, users themselves must not lose the seed phrase.

Coldcard security incident loses 1,359.882 BTC, attacker address receives 10% coin-mixing offer

Odaily News: In the Coldcard security incident involving hardware wallet company Coinkite, the amount of stolen bitcoin has risen to approximately 1,359.882 BTC. According to statistics from the Coldcard Sweep Watch dashboard, most of the identified bitcoin remains in a small number of addresses controlled by the attacker. On August 1, one of the attacker's holding addresses received a transaction containing an OP_RETURN message. The message publicly offered a 10% fee for "washing" bitcoin, KYC assistance, and withdrawal services for stolen funds, along with a Telegram contact. Coinkite has released an urgent firmware update to fix the weak random number generation issue that caused the original vulnerability. The company stated that the new firmware only protects wallets created in the future and cannot fix seeds already generated on affected versions. Some users have reported that after installing the update, their devices remain stuck on an error screen, fail to boot, or appear bricked. This mainly affects Mk4 and Q devices, though some Mk3 users have also reported similar issues. As of August 2, Coinkite has not publicly confirmed a widespread firmware defect.

1367 BTC stolen, @KevinKelbie tracks 4,620 drained addresses

Odaily News: According to Bitcoin News monitoring, @KevinKelbie is tracking 1,367 BTC stolen since the 2021 RNG vulnerability, involving 4,620 drained addresses. Each BTC has been traced from the victim's wallet to its current location, with a complete timeline of transfers recorded up to July 2026.

Coldcard Vulnerability Causes User Losses Exceeding $88 Million, Coinkite May Face Class Action Lawsuit

Odaily News: Coinkite, the company behind hardware wallet Coldcard, may face legal action from users who collectively lost over 1,300 BTC — valued at more than $88 million — due to a vulnerability in the mnemonic generator of certain models. Thomas Braziel, founder and managing partner of 117 Partners, is investigating product liability claims and potential class action lawsuits against Coinkite, while coordinating efforts to collect information from victims worldwide. Brazilian Bitcoin advocate Felipe Ojeda has filed a police report and will file a complaint against the company in Brazil. Cris Carrascosa, CEO of ATH21, stated that Coinkite does not assume custodial responsibility for user funds tied to its products, and any lawsuit would need to prove that Coldcard could have foreseen the attack. Ana Ojeda, head of institutional business development at Blend, noted that victims do not have an automatic right to full recovery of funds, but an investigation into liability issues can be pursued.

Coldcard Vulnerability Leads to Over $88 Million in Losses, Coinkite Criticized for Retaining Customer Emails

Odaily News: Hardware wallet company Coinkite's Coldcard wallet series has experienced a seed generation randomness vulnerability, with threat actors stealing over 1,000 BTC in the past two days. Galaxy Research data shows that as of Saturday 17:36 ET, the incident involved 1,367 BTC, with losses exceeding $88 million. To notify potentially affected users, Coinkite sent security alerts to email addresses retained through its store and newsletter system since 2019. Coldcard confirmed that the emails originated from Coinkite and stated that it has contacted all reachable addresses to the best of its ability. Coinkite has faced criticism for retaining customer email data. The company stated that its public policy explains that purchase email addresses are saved so customers can log in and verify that other information has been cleared, but it did not specify a deletion timeline, saying these addresses would be kept "temporarily." Coinkite co-founder and CEO Rodolfo Novak previously stated that the company does not store customer information, deletes customer data 90 days after purchase, and offers anonymous purchase options.

COLDCARD RNG vulnerability discovered, 2023 video warning about weak seeds generated by dice rolls gains renewed attention

Odaily News: Bitcoin News posted on X platform that a 2023 video shows hardware wallet educator @YTCryptoGuide warning that COLDCARD Mk4 allows users to create a wallet with just a single dice roll, which could easily lead users to inadvertently generate extremely weak seeds. He also warned that the interface may lead users to believe their dice roll results would be mixed with the device's hardware RNG, but in certain operational flows, this is not the case. Many advanced users choose to use dice rolls because they do not fully trust hardware RNG. With the discovery of the COLDCARD RNG vulnerability, this video now carries new significance.

Community users used AI to audit Coldcard code, discovering a critical vulnerability in just 8 minutes

Developers on Reddit used Claude Code to scan the Coldcard open-source firmware for vulnerabilities, pinpointing the core issue within 8 minutes: When generating private keys, the firmware invoked a software pseudo-random number generator instead of a hardware true random number generator, and it was this vulnerability that led to the theft of approximately $70 million in BTC from 1,196 wallets. Meanwhile, community users also reported that using Zhipu GLM 5.2 (trained on June 16, offline) for an independent scan similarly discovered this vulnerability. This bug has existed in the open-source wallet code for over five years.

Stacks Co-founder Shares Lessons from Coldcard Security Incident: Don't Put All Your BTC in One Basket

Odaily News, Stacks co-founder Muneeb shared his views on the Coldcard wallet incident, summarizing lessons learned in three areas: Bitcoin storage strategy, quantum computing threats, and ecosystem security building. Regarding Bitcoin storage strategy, he noted that many industry security experts are not even familiar with Coldcard, and top-tier security research institutions may not have conducted thorough audits of its code. Muneeb believes the best approach going forward should be asset diversification rather than concentrating all funds in a single solution, and suggested:1. Allocate 20%-30% of BTC to ETFs, such as BlackRock's Bitcoin ETF IBIT, for professional custody and regulatory protection;2. Allocate 40%-50% of BTC to multisignature solutions like Casa, such as the three-key model, spreading keys across security companies, mobile devices, and hardware wallets;3. Allocate 20%-30% of BTC to more advanced self-custody approaches, combining different hardware wallets and diverse entropy sources.On the quantum computing threat, Muneeb stated that once quantum computers break through existing encryption systems in the future, Bitcoin users may experience a shock similar to "BTC suddenly being transferred out of cold wallets." The quantum threat is real, and the industry should prepare in advance rather than underestimate technological progress, especially against the backdrop of large language models accelerating scientific research breakthroughs.

Bloomberg ETF Analyst Questions Coldcard Team Size: Approximately 5-Person Team Undertaking Critical Wallet Security Responsibilities Poses Risk

Bloomberg Senior ETF Analyst Eric Balchunas commented on the Coldcard wallet security incident, questioning whether a company with only about 5 employees is suitable to undertake such critical Bitcoin storage responsibilities. He stated that the number of employees behind Coldcard "seems unbelievably low," asking whether people would be willing to store their life savings in a bank with only 5 employees headquartered in Canada. In the crypto industry, this might be viewed as a feature, but from a traditional finance perspective, it becomes a clear risk signal. Balchunas further stated that, in comparison, institutions with larger teams such as Coinbase and Ledger may hold advantages in security investment and operational capabilities, even if users need to bear higher transaction costs. Bitcoin ETFs offer another option: investors can obtain the security guarantees provided by large, professional, regulated financial institutions while also enjoying lower management fees.