News linked to both this project and an event.
Galaxy Digital Head of Research Alex Thorn stated that based on new victim reports received following the incident, the number of attackers exploiting the Coldcard vulnerability has reached at least 15.Thorn noted that information provided by victims helped the research team uncover previously unidentified attack activity. Unlike thefts from centralized exchanges, correlations between the attackers in this vulnerability exploit require confirmation through on-chain analysis and victim feedback.He added that a single victim reporting less than 1 BTC stolen helped the team discover a previously unknown attack, which siphoned approximately 12 BTC from 126 addresses.According to Galaxy Research's earlier estimates, the Coldcard vulnerability has led to at least three rounds of attacks, with losses amounting to approximately $100 million in BTC. Additionally, Galaxy has identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million.Meanwhile, the incident has also sparked discussions regarding the security of Bitcoin self-custody. Dragonfly Managing Partner Haseeb Qureshi stated that "AI security hardening costing around $2" could potentially have prevented this vulnerability, and noted that some AI models were able to rediscover related vulnerabilities within a relatively short timeframe. However, industry insiders pointed out that current claims about the speed of AI discovering vulnerabilities lack rigorous blind testing and verification.Researchers believe that as AI model capabilities improve, the costs of vulnerability discovery and attacks in the crypto industry may continue to decline, requiring wallet developers to further strengthen code audits and security protections. (Cointelegraph)
According to TechCrunch, Apple Inc. has formally applied for a preliminary injunction against OpenAI, requiring it to stop developing AI devices and related products based on Apple technology. Apple's latest investigation shows that, in addition to Senior Systems Engineer Chang Liu and Chief Hardware Officer Tang Yew Tan named in the previous complaint, another 11 former Apple employees may be involved in trade secret theft, with some having privately retained work equipment issued by Apple upon departure. Apple has simultaneously applied for an expedited discovery process, involving parties including OpenAI, its foundation, and the device startup io co-founded by Jony Ive. In response, OpenAI publicly stated that Apple's allegations are "based on misinformation and completely unnecessary," and counterclaimed that Apple has security procedure vulnerabilities, resulting in former employees still being able to access its internal systems.
Odaily News: Apple has limited the number of vulnerability reports a single researcher can submit at one time because its security team has received a large number of submissions generated by AI, many of which do not actually contain real flaws. Apple stated that researchers can request a higher limit at any time, and the company is also using AI internally to triage submissions.Bynario, a Milan-based cybersecurity startup, said it used OpenAI's ChatGPT to discover more than 50 vulnerabilities in the latest version of macOS within three weeks, including a privilege escalation chain that could give attackers full control of a Mac device.Bynario stated that it was unable to report this vulnerability because Apple had already rejected further submissions. Bynario CEO Alfredo Pesoli estimated the vulnerability's value on the criminal market at $100,000 to $200,000. Apple said it has reached out to the company and reviewed its work. In June, Apple added a submission cap and a 30-day cooldown period to its security portal. In a recent security update, Apple listed vulnerabilities discovered with the assistance of Anthropic and OpenAI software, with the number of fixes approximately five times that of a normal cycle. (Decrypt)
According to Onchain Lens monitoring, COLDCARD users have experienced another incident of stolen funds, with over 5,200 affected addresses seeing approximately 1,816 BTC stolen, worth around $114 million. The confirmed first to third waves involve 1,367.05 BTC, valued at approximately $88.6 million. The fourth wave, matching a pattern, involves 462 potential victims, adding 388.93 BTC. Onchain Lens is currently identifying associated clusters based on on-chain data. As of now, the attacker has not yet moved the stolen funds. The cluster remains active, with the latest transaction recorded just minutes ago.
Odaily News: Bitcoin wallet service provider Nunchuk has issued an important update regarding the recent Coldcard security incident, recommending that users with multisig wallets containing Coldcard-generated keys migrate their funds as soon as possible.Nunchuk has categorized response levels based on the number of affected Coldcard keys in a multisig wallet: if the number of Coldcard-generated keys has reached the signing threshold, attackers could theoretically transfer funds directly, and such users should migrate immediately; if the wallet contains only 1 Coldcard-generated key and it is below the signing threshold, a single compromised key cannot move funds independently, making the risk relatively lower, but migration is still strongly recommended. If users cannot confirm the exact number of Coldcard keys in their wallet, they should treat it as a high-risk situation.Additionally, Nunchuk announced that an upcoming mobile update will automatically enable the Slipstream channel for paid users. At that point, any auxiliary multisig wallet transaction containing at least one Coldcard key will bypass the public mempool and be submitted via Slipstream, reducing the risk of transaction monitoring and replacement. For users who wish to act immediately or for free-tier users, Nunchuk offers a manual migration option: users need to create a migration transaction, complete multisig signing without broadcasting, and then submit the raw transaction data to the Slipstream platform.
Odaily News: Galaxy Research Head Alex Thorn analyzed that a new wave of Bitcoin sweeping attacks targeting Coldcard wallet addresses is underway, and cumulative losses from vulnerabilities related to Coldcard hardware wallets could approach $114 million. This attack primarily affects single-signature wallets, with no multi-signature wallets found to be impacted so far. No direct victim reports have been received yet; the assessment is mainly based on on-chain transaction pattern analysis, with some attack transactions still in an unconfirmed state.
Odaily News — According to official sources, OKX.AI has announced that registration for its inaugural trading hackathon is now open. Following the previous Genesis hackathon for Agent Service Providers (ASP), this hackathon focuses on AI Agent live trading capabilities. Participants are required to deploy their trading strategies as Trading ASPs and conduct live trading with no less than 300 USDT in equivalent funds. Rankings will be updated in real time based on yield (PnL %). The total prize pool is $20,000, with the champion receiving a $5,000 reward.It is reported that OKX.AI is an economic system built specifically for Agents, where users and Agents can discover and utilize professional services provided by ASPs. This event supports two development frameworks: Onchain OS and Agent Trade Kit. Registration runs from July 31 to August 11 at 12:00 (UTC+8), and the competition will take place from August 11 to August 25.
Odaily News, OpenAI recently disclosed that it has successfully disrupted a cyber fraud organization based in Cambodia that used ChatGPT to assist in investment scams, romance scams, gambling fraud, and impersonation of law enforcement agencies. The investigation originated from leads shared with WhatsApp's security team. The organization was found to have used ChatGPT to create fake online identities, generate and translate scam scripts, produce promotional content for fraudulent schemes, and assist with daily operational tasks.OpenAI stated that it has banned ChatGPT accounts associated with the operation, shared relevant threat indicators with industry partners and concerned institutions, and taken measures to prevent these attackers from regaining access to its services. The specific financial losses caused by this fraud network have yet to be confirmed, but according to communications among the scammers themselves, the organization may have reached hundreds of victims, with some conversations mentioning victims losing thousands of dollars.
According to monitoring by on-chain analysis firm Galaxy Research (@glxyresearch), the ColdCard wallet hacking incident has developed into a third wave, with an additional 207.73 BTC stolen. Currently, the three waves of attacks have cumulatively stolen 1,367.05 BTC (approximately $88.6 million), involving 4,585 addresses. On-chain data shows that the three waves of attacks exhibit highly similar characteristics: identical fund consolidation topology, identical P2WPKH target addresses, and mixed derivation paths. Each wave occurred approximately 27 hours apart, suggesting they were carried out by the same attacker, but there is currently no direct evidence to confirm this. Currently, all terminal addresses controlled by the hackers hold a total of 1,366.39 BTC (approximately $88.6 million), all of which are in an unspent state on-chain. Galaxy Research noted that the above data is based solely on Bitcoin block data and UTXO set analysis, and has not yet computationally verified whether the victim addresses have vulnerabilities due to low-entropy generation.
Odaily News, according to Bitcoin News monitoring, Nunchuk stated that some Nunchuk platform keys are generated by Coldcard Mk4, but these keys will not be used directly. Nunchuk derives independent keys through custom logic, making them less susceptible to lookup table attacks based on compromised Coldcard seeds. Nunchuk added that, given enough time, it believes attackers may eventually incorporate these derived keys as well.
The PPP Prediction Market Tool shows that the probability of a "ceasefire between the US and Iran before July 24" on Polymarket has dropped to 36%, down 15% in 24 hours.This event will settle as "Yes" if the US does not take any military actions that meet the defined criteria against Iran for 14 consecutive days before the specified deadline; otherwise, it will settle as "No."Qualifying military actions include only US-initiated airstrikes or surface-to-surface missile attacks that directly strike Iranian territory, including bombs, air-to-surface missiles, air-launched drones, cruise missiles, and ballistic missiles. Excluded actions include intercepted or destroyed munitions, surface-to-air missiles, small-scale skirmishes, ground operations, cyberattacks, naval shelling, artillery attacks, and unexecuted threats or authorized actions.If there is a dispute regarding the occurrence, attribution, or timing of relevant military actions, the event will await consensus from official information and credible media before being adjudicated. If disagreements persist after three full calendar days, a comprehensive judgment will be made based on all available information at that time. The settlement basis includes official information from the US and Iranian governments and militaries, as well as reports from credible media outlets.Join the PPP Signal Push Community to stay ahead and seize the opportunity.
The PPP Prediction Market Tool monitoring shows that the probability of "effective ceasefire between the US and Iran before July 31" on Polymarket has risen to 59%, up 19% in a single day.This event will settle as "Yes" if the US takes no qualifying military action against Iran for 14 consecutive days before the specified deadline; otherwise, it will settle as "No."Qualifying military actions include only US-initiated airstrikes or surface-to-surface missile attacks that directly strike Iranian territory, including bombs, air-to-surface missiles, air-launched drones, cruise missiles, and ballistic missiles.Actions not counted include intercepted or destroyed munitions, surface-to-air missiles, small-scale skirmishes, ground operations, cyber attacks, naval shelling, artillery attacks, and unexecuted threats or authorized actions.If there is a dispute regarding the occurrence, attribution, or timing of a military action, the event will await a consensus formed by official information and credible media before being adjudicated. If differences persist after three full calendar days, a comprehensive judgment will be made based on all available information at that time.Settlement will be based on official information from the US and Iranian governments and military, as well as credible media reports.Join the PPP Signal Push Community to stay ahead and seize the opportunity.
the WEMIX team has issued an announcement stating it is urgently investigating a potential security incident involving the WEMIX 3.0 network. Signs have been detected suggesting that contract ownership may have been compromised. The relevant team is currently verifying the facts and assessing the impact of the incident, and will release the investigation results and subsequent response measures as soon as possible based on the progress of the investigation. Until further official updates are released, WEMIX reminds users to exercise caution regarding unverified information and to maintain a high level of vigilance when transacting or investing in related assets.
the U.S. Department of Commerce's AI Standards and Innovation Center, in collaboration with the UK AI Safety Institute, tested the cyber attack capabilities of Kimi K3, emphasizing that "the United States still leads."However, the value of the evaluation is debated due to limitations in the testing scope. Due to hosting environment constraints, Kimi K3 only participated in partial testing, with its overall cyber capabilities estimated primarily based on 41 exploit benchmarks. In contrast, other models underwent more comprehensive testing, resulting in a larger margin of error for Kimi K3's results.In the exploit testing, Kimi K3 scored approximately 32%, higher than GLM-5.2's 24%, but lower than the average of approximately 76% for leading U.S. models. In a simulated attack chain test, Kimi K3 completed an average of 17 out of 32 steps in the attack chain and successfully breached the network once in 10 attempts, while U.S. frontier models completed an average of 28.5 steps.The report notes that Kimi K3 already possesses a certain level of autonomous attack capability, and its security guardrails did not prevent the model from developing exploits or executing attacks. However, the report also emphasizes that the testing scope was limited.
: BNB Chain Agent commercial clearing layer TermiX announced that Web3 security infrastructure GoPlus and smart contract security auditing firm Salus have officially become Provider Agents on the Agent.family platform. They have launched two production-grade security audit services, promoting the autonomous invocation and settlement of "security capability as a service" for AI Agents in on-chain commercial scenarios.GoPlus has packaged its verified token contract deep scanning capability as a standard Provider Agent service. DeepScan conducts comprehensive security checks on token contracts, identifying risk patterns such as Rug Pulls, honeypot scams, contract permission abuse, and trading restrictions, and generates structured audit reports.Salus has launched smart contract auditing and penetration testing services, encompassing formal verification, fuzz testing, machine learning-based vulnerability detection, and manual expert auditing. It covers high-risk vulnerability categories such as reentrancy attacks, access control issues, integer overflows, and DoS attacks. Salus, a seed-stage investment from Binance Labs, is a core security partner within the BNB Chain ecosystem.
Cardano ecosystem wallet SecondFi announced that due to a cryptographic defect in its wallet software, approximately 16.1 million ADA (worth around $2.6 million) were stolen. The platform will gradually shut down the SecondFi and Yoroi wallet services. This incident has affected 374 wallets. SecondFi stated that an independent investigation by blockchain intelligence agency Groom Lake identified the attackers as a sophisticated external actor and found indicators potentially linked to North Korea's Lazarus Group, though attribution has not yet been confirmed. SecondFi is developing a recovery tool based on zero-knowledge proofs to help affected users recover assets while limiting the information that needs to be shared. The tool is still being tested and will undergo third-party audits before its planned release in August. SecondFi is also preparing a wallet export feature to allow users to migrate their assets to other services. The platform has not announced a direct compensation plan, nor has it indicated whether it will use its own funds to compensate users.
the cross-chain protocol Allbridge has issued an official statement confirming that an attacker has withdrawn approximately $1.65 million in assets from the Allbridge Core liquidity pool. A detailed analysis of the incident is currently being compiled, and the full investigation results will be published subsequently. The team emphasizes that there is no further risk to current user liquidity and that the Allbridge Next service is operating normally.In response to this incident, Allbridge plans to relaunch the Core version but will remove the liquidity pool design. Future cross-chain transfers will be facilitated via Circle CCTP and the LayerZero router to eliminate the risk of liquidity pool imbalance and the model vulnerabilities exploited in this attack. This incident has accelerated the previously initiated migration plan to fully transition to the more secure new infrastructure, Allbridge Next. According to the plan, Allbridge Core and Allbridge Classic will cease operations in their current form within the next three months, and users are advised to withdraw their relevant liquidity in advance.It is understood that this attack has exposed the risks inherent in the traditional cross-chain liquidity pool model and has further driven the protocol's transition towards a cross-chain architecture based on message passing and native asset transfer.
According to the latest report released by the Financial Action Task Force (FATF) on July 16, FATF conducted the seventh targeted review on the implementation of Recommendation 15 (R.15) across global jurisdictions. The report points out that since the last update in 2025, countries have continued to advance in the regulation of Virtual Assets (VA) and Virtual Asset Service Providers (VASP), including conducting risk assessments, improving licensing and registration frameworks, implementing the Travel Rule, and strengthening enforcement actions. However, the report also points out that significant gaps still exist, mainly reflected in: the difficulty in effectively translating risk assessment outcomes into mitigation measures, insufficient implementation of licensing and registration frameworks, difficulties in identifying entities engaged in VASP activities, and insufficient effectiveness of risk-based supervision and enforcement. Regarding emerging risks, the report focuses on the following areas: the intensified "industrialization" trend of organized crime groups using virtual assets to commit fraud, increased risk of stablecoin abuse, risks associated with non-custodial wallet peer-to-peer (P2P) transactions, offshore VASPs operating outside regulatory oversight, and ongoing challenges in the DeFi sector. FATF calls on the public and private sectors to jointly strengthen the implementation of R.15, enhance risk mitigation capabilities, and deepen domestic, international, and public-private cooperation mechanisms.
security firm Project Eleven has introduced a post-quantum proof technology designed to help users prove ownership of their Bitcoin wallets after quantum computers become capable of deriving private keys and generating valid signatures. Project Eleven CEO Alex Pruden stated that the technology utilizes the wallet's key derivation path, enabling users to prove control without disclosing the parent key, thus distinguishing legitimate owners from attackers. The solution was developed in collaboration with Jim Posen, a primary maintainer of the open-source Binius zero-knowledge proof system, and is based on the "signature lifting" technique proposed by Alon Sattath and Robert Wyborski. Project Eleven noted that the prototype has not yet been audited and requires blockchain protocol support before it can be deployed. It is primarily aimed at users who miss the window to migrate to quantum-resistant addresses in the future.
According to Odaily Planet Daily, Ethereum ZK Layer2 Starknet has officially launched the compliant privacy framework STRK20, providing native privacy transaction capabilities for various digital assets on-chain. The framework operates based on a privacy pool mechanism. Once user assets are deposited into the privacy pool, all transactions are encrypted, with details such as transfer addresses and amounts being invisible to the outside. Developers can quickly integrate this privacy system using the accompanying SDK and wallet API, catering to the private transfer needs of various ERC-20 assets. STRK20 incorporates a complete compliance process: users must undergo pre-screening before entering the privacy pool; only upon receiving a legally effective formal query request and after an independent assessment, will the platform selectively disclose specific users, corresponding time periods, or designated transfer records, without revealing the private data of unrelated users.