News linked to this event type.
比特币开发者 Kevin Loaec 警告,若 BIP-110 相关分叉发生,在缺少重放保护的情况下,用户出售分叉链资产可能导致真实 BTC 被同步转移。
Odaily News: The proposed Bitcoin fork is associated with the controversial BIP-110 proposal and could generate duplicate balances on both chains, potentially prompting holders to attempt selling seemingly free fork coins. Since both chains initially accept the same transactions, selling fork coins could trigger a replay attack and simultaneously spend the seller's real Bitcoin on the main chain. Developers have stated that built-in replay protection will be lacking at least until early September, and non-professional users should avoid transferring Bitcoin during the potential fork period.
Odaily News: Cryptocurrency exchange Bybit has filed a civil lawsuit against the Democratic People's Republic of Korea, its intelligence agency Reconnaissance General Bureau (RGB), and the state-sanctioned hacker group Lazarus Group over a $1.5 billion hacking incident. A U.S. federal court has issued a preliminary injunction prohibiting the transfer or dissipation of identified assets related to the case during the litigation.
Odaily News: Bitcoin News stated on the X platform that BTCPay Server has reported a critical vulnerability being actively exploited, which could result in loss of funds. Users should immediately update to BTCPay Server v2.4.2; those who cannot update immediately should shut down their BTCPay Server until the update can be installed, to prevent unauthorized access.
Odaily News – According to monitoring by Galaxy's Head of Research, the median dormancy period for stolen coins is 3.5 years, with 88% of stolen coins being over one year old. By address, the median loss is 0.014 BTC and the average loss is 0.212 BTC; over 250 victim reports have been received. Based on victim reports, the median loss is 1.022 BTC and the average loss is 4.04 BTC, with reported losses ranging from 624 satoshis to 58.97 BTC.
Bitcoin News posted on X platform that a Trezor user claimed their life savings were stolen after clicking a Google-sponsored search result impersonating Trezor. The phishing page was hosted on Google Sites and allegedly tricked the victim into entering their wallet recovery seed. Trezor stated that it is upgrading its handling of the report, proceeding with the removal of the website, and reminding users to never enter wallet backups or mnemonic phrases on any website or online form. Google-sponsored phishing ads remain an ongoing attack vector for crypto users.
Odaily News: Russia's Federal Security Service (FSB) conducted surprise raids on 9 unregistered cryptocurrency exchange service providers in Moscow, alleging they were involved in transferring funds obtained through fraud abroad via crypto assets. More than 20 employees were detained at the Moscow International Business Center.The FSB stated that these exchanges converted stolen funds from Russian phone scam victims into cryptocurrency and transferred them to accounts of what it claims are Ukrainian processors. The operation was carried out jointly by the FSB and the Russian Ministry of Internal Affairs.Russia's Ministry of Internal Affairs has launched a criminal investigation into large-scale fraud, which under Russian law carries a maximum sentence of 10 years in prison. The FSB said it is continuing to identify victims and assess potential compensation. (Cointelegraph)
Odaily News: Coinkite, the manufacturer of the hardware wallet Coldcard, stated that it is currently focusing on assisting customers affected by the security incident and will release a post-mortem of the multi-day attack after the full investigation is completed. At this stage, it will not speculate on the scale of customer losses. Coinkite noted that due to the privacy-focused design of its products, the company cannot independently verify external estimates of the stolen amounts; recent external research has raised the relevant loss estimates to approximately $130 million.
Odaily News: Coldcard stated that due to legal record-keeping obligations related to the security incident disclosed on July 30, the company has temporarily suspended the automatic deletion of customer data. Under its original policy, customer records were typically automatically deleted after 120 days, retaining only information such as email addresses and countries of residence. Currently, such records will be retained until further notice. Coldcard noted that customers may contact official support to request continued processing under the original data retention policy, and the company will resume the automatic deletion mechanism once permitted by law.
据 QCP Capital 8 月 7 日市场报告,BTC 本周从约 62,500 美元低点回升至 64,000 美元附近。尽管期间承压明显——Strategy 上周出售 1,638 枚 BTC(约 1.047 亿美元),Coldcard 安全事件波及约 5,000 个钱包、估计损失约 1,755 枚 BTC(约 1.1 亿美元)——市场并未出现持续性下跌。 期权市场同样未见恐慌情绪,7 日和 30 日平值隐含波动率分别为 28.8 和 32.6,处于近期区间低端;7 日 25-delta 风险逆转从 -7.39 快速收窄至 -2.10,显示短端下行偏斜明显缓解。 宏观层面,美国 7 月 ISM 制造业 PMI 升至 55.6(逾四年新高),但就业数据走软,ADP 私人就业仅新增 4.4 万人,市场等待当日晚些时候公布的非农数据(华尔街日报预期新增约 8.3 万人)。此外,霍尔木兹海峡局势仍未完全解除,布伦特原油重返 83 美元上方;日元干预及日本国债收益率走势持续牵动全球流动性预期。
According to IBTimes, Nobel laureate and "Godfather of AI" Geoffrey Hinton warned at the Ai4 conference in Las Vegas that as AI model capabilities rapidly improve, humans will find it increasingly difficult to exert effective control over them. He stated: "These systems are becoming smarter, and we will see them develop increasingly complex intentions, as well as increasingly strong abilities to escape control." Previously, OpenAI, Anthropic, and Meta successively disclosed that their experimental models accidentally gained internet access in test environments and infiltrated external systems. Hinton pointed out that the above incidents highlight the growing complexity of frontier AI models and warned that a large number of malicious cyber attacks will occur in the future. He estimates that the probability of advanced AI posing an existential threat to humanity is between 10% and 20%, and called on the industry to prioritize potential risks now, rather than waiting for problems to arise before responding.
According to Bloomberg, sources familiar with the matter revealed that the US government department responsible for investigating chip export control violations is currently systematically reviewing the ways Chinese AI companies obtain advanced Nvidia chips through legal channels, with a particular focus on their practice of renting computing power in third countries. This move stems from recent consecutive technical breakthroughs by Chinese AI companies, indicating that they still possess the capability to acquire and use top-tier hardware under US chip export restrictions on China. Analysts believe that this review may drive the US to further tighten regulatory rules on computing power leasing in third countries to plug loopholes in the current export control system.
据 CoinPost 报道,日本金融厅于 8月 7 日公布"主要行等综合监督指针"部分修订案,将包括加密资产交换业者在内的 17 个监管领域的网络安全事件报告样式统一为共通格式。新增"其他网络攻击等事案共通样式",与现行的 DDoS 攻击及勒索软件专用样式共同构成三类报告区分体系。经过渡措施,2027年 3 月底前非特定社会基础设施事业者仍可沿用旧版报告书,意见征集截止日期为 2026年 9月 7 日。
Odaily News: DefiLlama data shows that hackers stole $247 million in crypto assets in July, making it the second-highest month since 2026, trailing only April's $644 million; this figure represents a significant increase from June's $75 million and May's $60 million. Galaxy Digital stated that the Coldcard vulnerability was the largest attack event of the month, confirming three rounds of attacks involving 7,300 wallets, with at least $100 million in Bitcoin stolen; the firm also identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million. DefiLlama's hack tracker estimates losses related to this vulnerability at $115 million. Other attacks in July include a $9 million exploit on decentralized finance protocol Bonzo Lend, a $2.6 million theft from Cardano-based wallet SecondFi, a $24 million theft from Arbitrum-based perpetual trading platform AFX, and a $7.5 million theft from the Verus Ethereum Bridge.
Odaily News: Bitcoin Red Team, a volunteer security audit team composed of Bitcoin developers and security researchers, has released its latest audit findings. In approximately 30 hours, the team reviewed 391 Bitcoin-related codebases and identified a total of 4,962 security issues, of which 720 were rated as high-risk or critical vulnerabilities. Only one codebase was found to have no issues at all. Currently, only 147 vulnerabilities have been submitted to project maintainers for resolution.Bitcoin Red Team is a volunteer security audit team made up of Bitcoin developers and security researchers, initiated following the Coldcard hardware wallet vulnerability incident. Key contributors include Calle, a developer of the Cashu protocol, among others. (Beincrypto)
Odaily News: According to Lookonchain monitoring, the hacker who stole 2,055 BTC (valued at $130 million) from Coldcard is active again. An hour ago, the hacker transferred 30.185 BTC (worth $1.94 million) to a new wallet.
Odaily News – A long-dormant Bitcoin wallet moved nearly 50 BTC, worth approximately $3.2 million, on Thursday. The wallet received 49.97 BTC back in 2011, when Bitcoin was trading at around $10 per coin. The BTC was sent to a SegWit address that has previously transferred Bitcoin to institutional broker FalconX and received funds from wallets linked to Nexo and Prime Trust. The newly transferred BTC has not left this address. The transfer comes amid long-term holders rechecking their old storage setups following a major vulnerability exploit in Coldcard hardware wallets. There is currently no evidence linking the 2011 wallet to this vulnerability.
据链上分析平台 Lookonchain 监测,Jaredfromsubway 事件攻击者在资金操作中出现明显损失。该地址一个月前窃取约 770 万美元 资金后将其兑换为 以太坊,随后以约 1695 美元 的价格卖出 2327 枚以太坊,总价值约 394 万美元;又于约 10 小时前 以约 1912 美元 的价格回购 2063 枚以太坊,同样耗资约 394 万美元。按此计算,其此次操作累计亏损 264 枚以太坊,约合 50.5 万美元。
According to monitoring by on-chain analyst Ai Yi (@ai_9684xtpa), the hacker address that previously attacked the MEV bot Jaredfromsubway.eth and caused over $7.5 million in losses has shown unusual fund activity again after one month. Approximately 10 hours ago, the address used the remaining 2.44 million DAI to buy 1,277 ETH. Analysis suggests that the relevant funds may next be mixed via Tornado Cash, and this asset may also be the hacker's last pending on-chain funds.
Odaily News According to on-chain analyst Ai Yi's monitoring, the hacker who attacked the MEV bot Jaredfromsubway.eth and caused it to lose over $7.5 million spent the final 2.44 million DAI to purchase 1,277 ETH 10 hours ago. This amount represented the hacker's last pending funds on-chain, and the next step may involve mixing the funds through Tornado Cash.