News linked to this event type.
According to the latest report released by Grayscale Research Director Zach Pandl, as U.S. federal debt surpasses $40 trillion, Bitcoin's 90-day correlation with the Nasdaq 100 Index has dropped from over 60% to approximately 33%, while its correlation with gold has risen from near zero at the start of the year to above 50%, indicating that Bitcoin is shifting from a high-beta risk asset to an inflation-resistant store of value. Grayscale believes that expanding fiscal deficits and rising long-end interest rates will drive investors toward scarce alternative assets, positioning Bitcoin, Ethereum, and Zcash as primary beneficiaries. Among them, Zcash, featuring financial privacy, quantum resistance, and cross-chain interoperability, is considered to have the potential to challenge Bitcoin's network effect, despite its market capitalization currently accounting for less than 1% of Bitcoin's. Additionally, Grayscale notes that the current Bitcoin bear market has persisted for roughly 10 months, approaching the historical average bear market cycle of 11–12 months. Coupled with a macroeconomic environment that is becoming increasingly supportive, it suggests that current prices may represent a favorable entry point for long-term investors.
Odaily News: OneKey Anzen has reproduced the Ledger vulnerability and discovered that Ledger Ethereum app version 1.22.1 contains a transaction replacement vulnerability. When an affected user is attacked, the hardware screen still displays transaction A under review, but the device may sign transaction B, which the user never viewed. OneKey Anzen stated that the issue stems from a race condition between the transaction display logic and the underlying buffer, with the attack requiring the host side to already be compromised by a malicious DApp or intermediary software. Ledger's CTO previously responded that a fix had been rolled out approximately two weeks ago, and users simply needed to update the app. Public information shows that the official tag for version 1.22.2 on Ledger's GitHub appeared on August 24. Ledger's official website states that the issue has been fixed through app-level checksums and SDK-layer patches, with Ledger Secure SDK v26.6.1 released on August 21, and the related apps have been rebuilt and republished. Users need to update the app via Ledger Live — updating only the device firmware will not complete the fix. Ledger stated that there is currently no evidence that this vulnerability has been actively exploited.
According to Decrypt, privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on August 28. Developer Craig Raw stated that the update was driven by an AI-assisted code review, with the majority of fixes originating from it. This review was prompted by the recent seed generation code vulnerability exploit affecting Coldcard, as well as the release of unrestricted AI models in China, which has significantly enhanced vulnerability scanning capabilities across large codebases. Key updates include: validating the authenticity of transactions returned by Electrum servers, enforcing stricter BitBox02 hardware wallet security requirements (firmware v9.4.0 or higher required), patching local DNS leaks, and masking sensitive credentials in debug logs. Raw noted that there are no indications of any exploits being leveraged, user funds remain secure, and he still advises all users to update at their earliest convenience.
As reported by CNBC, CrowdStrike CEO George Kurtz stated that the rapid rise of AI is exposing vulnerabilities in corporate cybersecurity defenses, making it difficult for even heavily invested companies to remain secure. He noted that the emergence of Anthropic's Mythos model has made cyberattacks faster and more complex, driving a significant surge in market demand for cybersecurity platforms. Consequently, shares of both CrowdStrike and Palo Alto Networks have risen approximately 100% year-to-date.
Odaily News: OpenAI co-founder Greg Brockman reposted the open letter, with over 100 institutions including Anthropic, AWS, Google, Microsoft, OpenAI, and Oracle jointly calling for strengthened global cyber defense to address the rapidly evolving threat of AI-powered cyberattacks.The open letter states that AI-driven cyberattacks are expected to become more prevalent and sophisticated in the coming months, posing higher risks to critical systems such as hospitals, water treatment facilities, and internet infrastructure. All parties should seize the current window of opportunity in which AI can equally enhance defensive capabilities, accelerate the closure of long-standing security vulnerabilities, and prioritize AI tools with cybersecurity capabilities for critical infrastructure defense teams.The open letter also calls on companies, cybersecurity firms, governments, and frontier AI companies to jointly invest tools, funding, and technical support to strengthen threat intelligence sharing, vulnerability remediation, and continuous security monitoring.
Bitcoin News posted on X platform, stating that France disclosed this month that its tax administration had been hacked, with data of approximately 678,000 individuals and businesses stolen. The stolen data allegedly includes names, addresses, income, and property information. Analysis of the alleged database found 26,805 records showing income exceeding €100,000, including 386 records exceeding €1 million. According to CertiK data, out of 52 verified cryptocurrency wrench attacks globally in the first half of 2026, France accounted for 33. French prosecutors have also accused a tax department employee of using government databases to identify cryptocurrency investors and selling personal information to criminals involved in physical assaults and extortion. The latest data breach has no publicly linked physical attacks yet, but sensitive financial and location data of hundreds of thousands of people may now no longer be under government control.
U.S. President Trump publicly stated that he is not currently concerned about Russia launching a military attack against NATO member states. This stance reflects core geopolitical positions and will directly impact global risk-off sentiment and macro asset pricing logic.
Odaily News: Between January 2025 and July 2026, a total of 245 security incidents were recorded. The top ten attack events accounted for over 72.5% of stolen funds. Supply chain and infrastructure vulnerabilities remain the primary security risks facing both CEXs and DEXs, with related losses exceeding $1.8 billion. Private key leakage is the most common risk for CEXs, while DApps lost approximately $546 million due to smart contract vulnerabilities. Among the 147 incidents involving platforms that had completed independent security audits, stolen funds accounted for 88.44% of total losses. Most attacks fell outside the scope of traditional audit coverage, with common causes including external infrastructure, unaudited code updates, and governance attacks. Only about 11% of incidents involved smart contract defects within audit scope.
Odaily News: On-chain analyst Specter has disclosed that a series of address poisoning attacks on the Tron network over the past 4 weeks have caused 15 victims to lose approximately $9.4 million in total. Among them, two victims each had $2.5 million stolen, while another lost $2 million. After succeeding, the attackers quickly converted all stolen assets into the stablecoin USDD and transferred them to a collection address, where all funds currently remain. Specter calls on wallet service providers in the Tron ecosystem to implement interception measures as soon as possible and reminds users to carefully verify addresses when making transfers.
GoPlus Security released a security alert stating that on August 25, realio[.]fund, a project under Realio Network, was attacked. The attacker took control of the platform's signing system and moved treasury and custody wallet assets across Ethereum, BNB Chain, Algorand, Stellar, and the Realio native chain. A total of approximately 127.9 million RIO tokens worth around $6.2 million were affected, with the attacker having cashed out approximately $317,000 so far.
According to monitoring by Blockaid, its vulnerability detection system detected suspicious activity on Moonwell on Base. The attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market. To date, approximately 50.6 cbBTC (valued at over $4 million) have been observed being transferred. More details remain to be disclosed.
Odaily News, The Sandbox has released a post-mortem report on the August 22 vulnerability incident. The report shows that attackers exploited vulnerabilities in contracts related to cross-chain configurations on Base and BNB Smart Chain (BSC), stealing 14,742,341.84 SAND from the Ethereum treasury, accounting for approximately 0.5% of the maximum supply, with an estimated economic impact of approximately $1.4968 million, of which about $987,000 was actually retained by the attackers. The Ethereum mainnet and Polygon network were not affected. Until further notice, please do not purchase or send SAND on Base or BNB Smart Chain. Contracts deployed on Base and BNB Smart Chain have been permanently deactivated and will not be reopened. The Sandbox stated that the team has reported the attacker's wallet address to blockchain analysis firms TRM Labs and Chainalysis, and has communicated directly with relevant exchanges. The Sandbox also announced a compensation plan, which will compensate wallets that legitimately held cross-chain SAND on Base or BSC prior to the incident at a 1:1 ratio in Ethereum SAND. Compensation funds will come from The Sandbox treasury, with no new tokens issued. The claim process will open within the next two weeks and remain open for two weeks.
1inch and HackenProof have jointly released the first-half 2026 Bug Bounty Report. The report shows that from January to June 2026, 1inch received a total of 1,055 submissions from security researchers across its 6 core bug bounty programs on HackenProof, of which 32 were rewarded.
According to The Block, StarkWare announced it has successfully executed the first post-quantum Bitcoin transaction. Avihu Levy, Head of Applications, used a "signature grinding" approach to repeatedly generate millions of candidate signatures before the transaction entered the Bitcoin mempool, thereby avoiding the exposure of mathematical data related to public keys that could be exploited by future quantum computers to forge signatures. This method incurs significant computational costs, with a single transaction potentially taking several hours. Because the transaction format is unrecognized by standard Bitcoin nodes, it bypassed the public mempool and was submitted directly to miners for inclusion via MARA’s Slipstream service. StarkWare noted that while this technique can serve as a transitional safeguard, Bitcoin will still require protocol-level upgrades or a hard fork to systematically mitigate quantum computing threats.
Odaily News: Ledger Chief Technology Officer Charles Guillemet stated that a smart contract security company recently claimed to have discovered a vulnerability in the Ledger Ethereum app. The Ledger Ethereum app did previously contain a vulnerability related to certain Clear Signing processes, but it was identified by Ledger's in-house security research team, Donjon, using an AI-driven vulnerability research tool, and was fixed and deployed two weeks ago. The security company in question only contacted Ledger's bug bounty program after the fix had already been completed, failing to follow responsible disclosure procedures and without communicating with the bug bounty team, then published content implying that the issue remained unresolved. Guillemet stated that users who promptly update their Ledger device firmware, Ledger apps, and related software will receive the latest security fixes.
According to The Defiant, the Core Lightning (CLN) maintainers for the Bitcoin Lightning Network have notified node operators that if they are unable to upgrade to the upcoming patched version, they should run their nodes offline using the --offline parameter. The team stated it will release binaries containing fixes for multiple disclosed vulnerabilities, but specific vulnerability details will remain confidential for two more weeks; as of press time, the relevant binaries and security advisory have not been published. CLN had previously noted that it received several AI-generated CVE reports over the past ten days, and the team is working with open-source contributors to verify, classify, and patch them. The latest public release is v26.06.6, issued on July 22, and the v26.09 release, originally slated for late September, continues to proceed as planned.
Bitcoin News stated on the X platform that BTC Sessions said their team spent weeks assisting Bitcoin holders affected by the Coldcard vulnerability in moving funds to safety, estimating that tens of millions of dollars worth of Bitcoin were protected during this period. But for many, it was too late. A member of their local Bitcoin community lost 90% of their Bitcoin, and another woman they spoke with lost all of her Bitcoin. BTC Sessions stated that this could be the most severe self-custody incident in Bitcoin's history. BTC Sessions said this experience prompted them to rethink asset custody, with diversified security measures emerging as a key lesson.
: Bitcoin News posted on X that Core Lightning developers have received a large number of AI-generated CVE reports over the past 10 days, and have verified the existence of vulnerabilities that need to be fixed. The team has now escalated its response, will release signed binaries, and will keep vulnerability details confidential for a two-week period. Core Lightning strongly urges all users to upgrade during this period; users who have not upgraded should take their nodes offline. Previous versions, including 26.04, will no longer be supported.
Odaily News reported that Galaxy Research tracking found that 6 bitcoin wallets, dormant since 2011, 2012, and 2014, transferred a total of 553.59 BTC between August 16 and 26, valued at $40.15 million at the time of transfer. Two of the wallets carry the "Salomon Client Dusted" tag linked to a New York lawsuit involving Noah Doe.One of the transfers involved 40 BTC from a wallet dormant since May 28, 2012, with the funds moved on August 26 to German crypto custodian bank Boerse Stuttgart Digital. Calculated at a cost of approximately $5, the funds appreciated by roughly 1,535,911%.The remaining transfers included 212 BTC, 150 BTC, and 132.31 BTC, originating from wallets inactive since 2012, 2014, and 2011, respectively. The Noah Doe lawsuit seeks to declare 39,069 dormant bitcoin addresses in New York State as lost property. Additionally, several long-term holding addresses moved funds following the July Coldcard hardware wallet vulnerability incident. (Decrypt)
Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)