News linked to this event type.
Bitcoin News posted on X platform, stating that Boltz has updated its PGP-signed warrant canary, a transparency measure used by privacy-related companies to publicly indicate that they have not received any secret government orders requiring them to hand over user data. The company's previous canary was dated May 31. Despite its commitment to update every 60 days, the canary expired around July 30, and its notice had asked users to "assume the worst" if it was not updated. Boltz stated that the expiration was due to negligence, as its team was dealing with an AI-assisted infrastructure attack that lasted for months, which ultimately led to the indefinite suspension of its swap services. The warrant canary has now been updated. Boltz stated that since the platform operates in a non-custodial model, user funds were never at risk.
BNB Chain announces the "Build the Era" Hackathon, soliciting proposals to build the best AI Agent trading platform on BNB Chain. The hackathon offers over $40,000 in prizes jointly provided by BNB Chain, @TermiX_AI, @PancakeSwap, @alt_layer, @binance Pay, and @AltanaNetwork. Both individuals and teams can register to participate.
According to CCTV News reports, the helicopter carrying U.S. President Trump encountered a flight safety incident in Washington on the 4th. The White House stated that the incident did not pose a personal safety risk; however, the U.S. Federal Aviation Administration has launched an investigation. Reportedly, Trump departed from outside the White House on the afternoon of the 4th aboard the "Marine One" helicopter, heading to Joint Base Andrews, and then transferred to "Air Force One" to proceed to Los Angeles.
Odaily News: Luxembourg has passed a new law authorizing the Financial Intelligence Unit (FIU) to send cross-institutional fraud alerts to traditional banks and cryptocurrency exchanges, with the relevant measures taking effect on August 8. The bill, numbered 8722, requires cryptocurrency exchanges operating in Luxembourg to receive alerts in sync with banks and payment institutions. The bill aims to close the loophole that allows fraudulent funds to move rapidly between traditional financial institutions and digital assets. Under previous rules, banks could only block transactions of flagged accounts within their own systems and were unable to notify another financial institution or cryptocurrency exchange to prevent funds from entering or leaving. Max Braun, head of Luxembourg's FIU, stated that incorporating cryptocurrency exchanges into the cross-departmental alert system will make it more difficult to cash out from flagged accounts. According to data from Luxembourg's Ministry of Justice, police recorded 6,382 fraud cases in the country in 2024, and financial practitioners submitted more than 18,000 reports of fraud and scams.
Odaily News: The Coldcard wallet hack involves approximately $120 million. The related transactions briefly made the Bitcoin mempool highly active.
Cybersecurity tests conducted by the UK AI Safety Institute found that AI models with unrestricted internet access, without being instructed, autonomously forged false identities, implanted malicious code into open-source projects, and launched social engineering attacks against real individuals and organizations.
Odaily News: Swan CEO Cory Klippsten stated that the Coldcard attack has prompted Bitcoin holders to reassess their custody decisions. Cory Klippsten noted that his team has been organized to assist affected holders in moving tokens to secure locations, including those who are not Swan customers. He pointed out that affected users have not abandoned self-custody, but are instead turning to vault solutions that prevent a single compromised device from endangering funds.
CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.
Odaily News: The wallet associated with the Coldcard hacker has received multiple deposits since July 30, some of which include text messages attached via Bitcoin's OP_RETURN function. The messages include requests for the return of funds, as well as opportunistic promotional content, with one message offering to help launder the stolen funds for a 10% cut.
According to monitoring by blockchain security company SlowMist (@SlowMist_Team), its threat intelligence system MistEye detected a large-scale npm supply chain attack targeting the Keyv/Cacheable ecosystem. The attackers published over 2,000 malicious package versions in total, involving core components such as [email protected]. As a widely used key-value storage abstraction library, Keyv supports multiple backends including Redis, SQLite, PostgreSQL, and MongoDB, with weekly downloads reaching approximately 127 million, posing significant downstream supply chain exposure risks. This attack method is highly similar to the previous Shai-Hulud npm worm activity, characterized by high automation and scale. Potential risks include credential theft, environment variable leakage, CI/CD key leakage, remote payload delivery, and lateral penetration. SlowMist recommends security teams immediately investigate and remove affected package versions, upgrade to verified secure versions, review dependency lock files and build logs, monitor suspicious outbound connections, rotate exposed credentials, and rebuild relevant environments from trusted sources if intrusion is suspected.
Odaily News, Chainalysis posted on X platform stating that the Coldcard hack has been particularly devastating for Bitcoin holders in Canada. Our analysis of the attackers and victims found that Canadian BTC holders accounted for 25% of the attributable losses.According to aggregated estimates from Galaxy Research, losses have reached as high as $110 million. We analyzed the geographic distribution of this ongoing hacking campaign. Users in Australia, the United States, and Thailand have also suffered significant losses.
According to TechCrunch, the Open Safety AI Alliance (OSAA), led by Nvidia, has exceeded 120 member companies just one week after its establishment, including tech and financial giants such as Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa. During the Black Hat Cybersecurity Conference held in Las Vegas this week, the alliance established a working group named "Shared AI Findings Exchange" (SAFE) and has submitted multiple proposals open for public comment, managed by the Linux Foundation. The proposals cover confidential reporting mechanisms for AI cybersecurity incidents, alert processes for affected parties, and no-fault attribution analysis frameworks. Meanwhile, member companies are also actively contributing open-source technologies: Nvidia open-sourced the LLM vulnerability scanning tool Garak, Amazon contributed the agent building tool Strands Agents and authorization language Cedar, and Okta and Red Hat are advancing agent identity authentication and governance technologies respectively. Notably, Anthropic, OpenAI, and Google have not yet joined the alliance, although OpenAI and Google previously co-signed the open letter that spurred the creation of the alliance.
According to Bloomberg, the UK Government AI Safety Institute (established in 2023) disclosed on Tuesday that during safety evaluations of OpenAI's GPT-5.6-Sol and Anthropic's Mythos 5 models, both models exhibited "unauthorized" harmful behaviors, including actively intruding into real websites and attempting to inject malicious code into software, and these behaviors targeted real people and organizations. During the testing, the institute specifically granted the models internet access and disabled some safety filters to assess their extreme capabilities.
According to Decrypt, non-custodial Bitcoin exchange service provider Boltz announced an indefinite suspension of its Bitcoin exchange services, as the iteration speed of AI-assisted attacks has exceeded its team's vulnerability patching capability. Boltz stated that automated AI probing attacks have continued to increase over the past few months, and multiple vulnerability exploitation incidents have been handled, but recently the pace of attacks has significantly accelerated, and it is suspected that multiple well-resourced attack organizations are simultaneously launching attacks against its platform, rendering the team unable to operate safely during the patching period. Currently, Boltz's TVL is approximately $262,000. Since the platform adopts a non-custodial architecture, users retain custody of their funds throughout the process. The team confirmed that no user funds are at risk, and API refund channels and unilateral refund functions remain operational.
Odaily News: Non-custodial Bitcoin swap service Boltz has indefinitely suspended its Bitcoin swap service, stating that the service will remain offline until further notice, with no timeline for restoration provided. Boltz allows users to transfer Bitcoin between the Lightning Network and the Bitcoin base layer, without the company ever holding custody of user funds. Boltz stated that over the past few months, its infrastructure has faced a continuous increase in automated, AI-assisted probing, and the team has already handled multiple exploit incidents. The company said each incident was contained, but the speed at which attackers iterate has outpaced the team's ability to discover and patch vulnerabilities. Boltz disclosed that the pace of attacks has accelerated over the past few days, and after reviewing recent security scan results, the company concluded that it cannot responsibly re-enable the swap service. Its API remains available for processing collaborative refunds, unilateral refunds remain operational as they do not rely on Boltz infrastructure, and customer support remains accessible.
Odaily News: Hardware wallet manufacturer Ledger has stated that the recent Coldcard vulnerability indicates the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, as their recovery phrases are generated by a hardware random number generator built into a certified secure element. Coldcard manufacturer Coinkite disclosed last week that its air-gapped Coldcard Bitcoin hardware wallet contains a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, allowing certain private keys to be guessed, with related losses reaching approximately $130 million. Coinkite released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited — the flaw had existed in public code for over five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed. Charles Guillemet also said that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process has received independent certification.
Odaily Planet Daily reported that Bitcoin News stated on the X platform that Coinkite said the vulnerability existed at the boundary between two unrelated firmware submodules, rather than in its Bitcoin or encryption code, which allowed it to evade both manual and AI-assisted code reviews for years. Coinkite stated that after the incident, the company tested cutting-edge AI models including Kimi K3, Claude Fable, and Codex 5.6, none of which identified the flaw. Coinkite is now urging security-critical projects to specifically audit build systems and submodule boundaries, and warned that AI-assisted development could leave similar blind spots in the Bitcoin ecosystem.
Telegram founder and CEO Pavel Durov stated that Telegram was briefly removed from the App Store by Apple recently, after a user implanted illegal pornographic content in a public group. The app was restored within hours.Durov said the attacker exploited a technical vulnerability to insert AI-modified illegal content into old messages within active groups, hiding the content by editing historical messages, making it difficult for regular group members to detect and report in time. This type of attack constitutes "takedown extortion," where attackers use automated accounts to implant violative content in public groups and report it to platforms like Apple, attempting to force group administrators to pay a ransom, or else exploit platform rules to get the community banned.Durov added that Telegram continuously combats illegal content through mechanisms such as user reports, AI filtering, and content hashing. This incident is not a systemic issue with the platform, but rather a targeted attack exploiting rule loopholes. He also warned that Apple's removal of the app without prior contact with Telegram could pose a risk to all mobile applications offering user-generated content (UGC), and platform developers need to strengthen their defenses against malicious reporting and "takedown attacks."
Odaily Planet Daily reported that Bitcoin News posted on X platform, stating that new evidence suggests the anonymous account "switck," who wrote the LibNgU code, may actually be Peter Gray, Co-founder and CTO of Coinkite. This code is at the center of the COLDCARD entropy failure incident. Researchers claim that Gray's GPG key signed dozens of commits by switck, and other identifiers appear to link the two identities together. Bitcoin developer James O'Beirne stated that he had warned Coinkite in May 2025 that the RNG implementation of LibNgU looked suspicious and recommended removing it, but he said the other party responded that if there were issues, they would have already been discovered. Screenshots also show that as early as April 2021, users had already raised questions about the LibNgU rewrite. If these findings are accurate, it means that the engineer who introduced the code was later linked to the theft of over 1,800 BTC, and had received direct warnings about the RNG implementation more than a year before the vulnerability was publicly disclosed.