GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Online/Update

News linked to both this project and an event.

Kraken Chief Security Officer: Coldcard Vulnerability Leads to Over $90 Million in Bitcoin Stolen, Hardware Wallet Industry Testing Mechanisms Require Urgent Overhaul

According to Cointelegraph, Coinkite, the manufacturer of Coldcard hardware wallets, disclosed that its devices have contained a random number generator (RNG) vulnerability persisting for up to five years since March 2021. The vulnerability stemmed from a firmware upgrade that mistakenly routed wallet seed generation to a less secure MicroPython pseudo-random number generator (PRNG), rather than the originally designed true random number generator (TRNG). Since code reviews only verified the existence of TRNG code without confirming whether it was actually invoked, the vulnerability remained undetected for a long period. To date, over 4,500 addresses have been compromised, with nearly $90 million worth of Bitcoin stolen. Kraken Chief Security Officer Nick Percoco stated that this incident should serve as a "wake-up call" for the hardware wallet industry, calling for the introduction of independent third-party testing mechanisms to mandate verification of whether the entropy sources actually invoked by production firmware are certified. Coinkite has suspended all device shipments and destroyed affected inventory after confirming the vulnerability, and stated it will cooperate with law enforcement agencies across multiple countries to trace the responsible parties.

Study shows Switzerland's cryptocurrency usage rate reaches 23%, twice that of Germany

According to Bitcoin.com, a recent survey report released by Bearingpoint shows that 23% of Swiss adults use cryptocurrency at least occasionally, far higher than 11% in Germany and 18% in Austria. The survey was conducted by YouGov in June 2026 among over 4,000 adults in Germany, Austria, and Switzerland. The report points out that Switzerland's leading advantage stems from its Distributed Ledger Technology Act (DLT Act) officially effective in 2021, which provides a clear legal framework for crypto assets, attracting a large number of enterprises to establish operations, and driving the expansion of the "Crypto Valley" ecosystem to 1,749 blockchain companies. Additionally, 37% of Swiss respondents consider cryptocurrency an asset worth investing in, and 45% support it becoming an international reserve currency, both leading Germany and Austria. In contrast, regarding Germany, although retail adoption rates lag behind, the "meinkrypto" platform under DZ Bank and Dekabank's crypto services for the savings bank network are expected to cover approximately 80 million customers, potentially gradually narrowing the gap with Switzerland.

Strategy starts tracking Bitcoin 200-week moving average

According to CoinDesk, Strategy founder Michael Saylor announced that the company has launched the Bitcoin 200-week moving average (200W MA) and its premium/discount tracking feature on its official website. Saylor stated that since the 200W MA data became available, Bitcoin has traded above this line 92% of the time, and the current price is almost exactly near this line.

Strategy-associated wallet transfers 299.84 BTC, worth approximately $18.91 million

Odaily News: A wallet associated with Strategy transferred 299.84 BTC, worth approximately $18.91 million. The company has not yet issued an official statement regarding this transfer. On-chain monitoring shows that this bitcoin was transferred to a new address, with timing similar to a previous transfer. Strategy sold 3,588 BTC between July 1 and July 5, amounting to approximately $216 million. Strategy currently holds 843,775 BTC, with a total acquisition cost of $63.69 billion and an average cost of $75,476 per coin. The company also added $525 million in cash reserves this month to pay preferred stock dividends and interest.

Trump’s 2025 crypto revenue totals approximately $1.4 billion; CLARITY Act faces objections from Senate Democrats

Odaily News – On July 30, the minority staff of the U.S. Senate Committee on Banking, Housing, and Urban Affairs released a new analysis raising Democratic objections to the amended draft of the CLARITY Act. The analysis states that Donald Trump’s 2025 crypto revenue amounts to approximately $1.4 billion, and that current ethics provisions still allow him to retain related business arrangements. The analysis reviews World Liberty Financial, the TRUMP meme coin, cryptocurrency investments, staking income, and other business activities, concluding that provisions restricting officials from issuing or sponsoring digital assets would not materially affect the aforementioned financial arrangements. Staff estimated approximately $799 million in revenue related to World Liberty Financial and approximately $635 million from the TRUMP meme coin. Trump’s annual financial disclosure report lists $635.1 million in royalties from a licensing agreement with CIC Digital LLC related to Celebration Coins, along with Bitcoin and Ethereum wallets each valued at over $50 million, and validator rewards obtained through staking agreements on Coinbase. The Senate draft of the CLARITY Act seeks to prohibit covered officials and their spouses from issuing or sponsoring digital assets for compensation during specified periods, while also establishing exceptions for qualified blind trusts, unauthorized third-party activities, continued use of an official’s likeness, and holding digital asset investments.

Bitgo CEO deposits ~$6.3M in BTC, challenges Claude to move the funds

: Bitgo CEO Mike Belshe deposited 100 BTC into a public Bitcoin address on August 1, worth approximately $6.3 million at the time, and invited Anthropic's Claude model to attempt to move the funds out of the address. On-chain records show the wallet received the funds on July 31, and the balance had not been transferred out as of August 2. Anthropic previously disclosed that during 141,006 cybersecurity assessment runs, 3 incidents were found, with 6 evaluation sessions involving 3 models inadvertently interacting with real organizational systems. The models involved include Claude Opus 4.7, Claude Mythos 5, and an unreleased internal research model. The cause was a configuration error by third-party testing partner Irregular, which led to the test environment being connected to the internet. Anthropic stated that Claude Opus 4.7, during one evaluation, located a real website with the same name as a simulated company, exploited weak passwords and exposed services to recover infrastructure credentials, and accessed a production database containing hundreds of records. The company said the model was attempting to complete assigned tasks, not actively breaking constraints or pursuing independent goals. Belshe's challenge involves Bitgo's institutional custody platform, which uses multi-signature or multi-party computation technology to distribute signing authority across multiple independent keys. As of August 2, Anthropic had not publicly responded to the challenge.

Coldcard security incident loses 1,359.882 BTC, attacker address receives 10% coin-mixing offer

Odaily News: In the Coldcard security incident involving hardware wallet company Coinkite, the amount of stolen bitcoin has risen to approximately 1,359.882 BTC. According to statistics from the Coldcard Sweep Watch dashboard, most of the identified bitcoin remains in a small number of addresses controlled by the attacker. On August 1, one of the attacker's holding addresses received a transaction containing an OP_RETURN message. The message publicly offered a 10% fee for "washing" bitcoin, KYC assistance, and withdrawal services for stolen funds, along with a Telegram contact. Coinkite has released an urgent firmware update to fix the weak random number generation issue that caused the original vulnerability. The company stated that the new firmware only protects wallets created in the future and cannot fix seeds already generated on affected versions. Some users have reported that after installing the update, their devices remain stuck on an error screen, fail to boot, or appear bricked. This mainly affects Mk4 and Q devices, though some Mk3 users have also reported similar issues. As of August 2, Coinkite has not publicly confirmed a widespread firmware defect.

Coldcard Vulnerability Causes User Losses Exceeding $88 Million, Coinkite May Face Class Action Lawsuit

Odaily News: Coinkite, the company behind hardware wallet Coldcard, may face legal action from users who collectively lost over 1,300 BTC — valued at more than $88 million — due to a vulnerability in the mnemonic generator of certain models. Thomas Braziel, founder and managing partner of 117 Partners, is investigating product liability claims and potential class action lawsuits against Coinkite, while coordinating efforts to collect information from victims worldwide. Brazilian Bitcoin advocate Felipe Ojeda has filed a police report and will file a complaint against the company in Brazil. Cris Carrascosa, CEO of ATH21, stated that Coinkite does not assume custodial responsibility for user funds tied to its products, and any lawsuit would need to prove that Coldcard could have foreseen the attack. Ana Ojeda, head of institutional business development at Blend, noted that victims do not have an automatic right to full recovery of funds, but an investigation into liability issues can be pursued.

Strategy holds 843,775 BTC, Michael Saylor's post sparks accumulation expectations

On August 2, Strategy Executive Chairman Michael Saylor posted "Bitcoin Drive engaged" along with a chart tracking the company's Bitcoin reserves. The chart shows that Strategy holds 843,775 BTC, with a market value of approximately $53.25 billion, an average cost of $75,653 per coin, and an unrealized loss of $10.58 billion. Strategy's real-time ledger shows that the company has had a total of 116 disclosed treasury events, purchasing 843,775 BTC for approximately $63.69 billion, at an average price of $75,476 per coin. The ledger also shows that Strategy recently sold a total of 3,588 BTC in two transactions—1,363 and 2,225 coins respectively—reducing its holdings from 847,363 to 843,775 BTC. Strategy disclosed in an SEC filing that the BTC sales were used to pay preferred stock distributions and replenish dollar reserves. Recent disclosures also show that the company did not purchase BTC during the week ending July 26, and increased its dollar reserves to approximately $3.75 billion, enough to cover about 2.1 years of preferred stock dividends and debt interest.

Michael Saylor has once again released Bitcoin Tracker information, with potential disclosure of position changes next week

Odaily News: Michael Saylor, founder and Executive Chairman of the bitcoin treasury company Strategy, has once again published Bitcoin Tracker-related information. Based on previous patterns, Strategy typically discloses changes in its bitcoin holdings the day after such announcements.

$282 Million in Bitcoin and Litecoin Stolen in Trezor Impersonation Support Scam

Odaily News, January 10 - A Bitcoin and Litecoin holder provided a 12-word recovery phrase to attackers impersonating Trezor support personnel, resulting in the theft of approximately $282 million in assets, including about $139 million in Bitcoin and $153 million in Litecoin. Blockchain forensics firm ZeroShadow stated that the incident stemmed from a social engineering attack, not a compromise of wallet software or private key infrastructure. The stolen funds were split via the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze approximately $700,000 in funds within 20 minutes. Under the BIP39 standard, a 12-word recovery phrase contains approximately 128 bits of entropy, while a 24-word phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of all mined Bitcoin is permanently inaccessible due to lost keys, involving millions of BTC, with causes including forgotten recovery phrases, damaged backups, and a lack of inheritance planning.

Galaxy Research Head: Coldcard attack ongoing, will update affected address count statistics

Odaily News, Galaxy Research Head Alex Thorn posted on X platform, stating that the attack targeting wallet addresses with weak random numbers generated by Coldcard is still ongoing. Users who still hold funds in Coldcard single-signature wallets should immediately migrate to secure addresses. New victim addresses and attacker addresses are continuously being added to the investigation database, and Galaxy Research plans to release updated statistics on the number of affected addresses.He noted that the previously identified waves 1, 2, and 3 of the attack exhibit clear programmatic characteristics, and the stolen BTC currently remains in the attacker's addresses without any transfers. However, in recent times, smaller-scale attackers have begun exploiting the vulnerability to steal funds and move them through peeling chains, cross-chain services, and other methods. It is certain that single-signature wallet addresses generated by Coldcard after the March 2021 firmware upgrade are all potentially at risk, and users should migrate funds as soon as possible.Previously reported, Galaxy Research has disclosed that the Coldcard vulnerability attack has affected approximately 1,367.05 BTC (approximately $88.6 million), involving around 4,585 addresses.

COLDCARD vulnerability may have originated from compiler bypass handling

Odaily News: Bitcoin News posted on X platform that a new technical analysis by Core-Lightning developer ddustin shows that the 2021 COLDCARD vulnerability may have originated when developers attempted to connect the wallet using Python code, MicroPython's C code, and the STM32 hardware random number generator. The custom code appears to have conflicted with MicroPython's existing implementation, potentially triggering a compiler error. Evidence suggests that developers subsequently set MICROPY_HW_ENABLE_RNG to 0, allowing the firmware to compile successfully. This change led to unintended consequences: when users created new wallets, the firmware no longer used the hardware random number generator, instead falling back to MicroPython's weaker Yasmarang software random number generator. The commit message left by the developers was only "runs." The analysis states that this serves as a reminder to developers not to release security-critical code they do not fully understand, especially when it protects billions of dollars in Bitcoin.

Michael Saylor: BIP-110 can no longer reach the 55% support threshold in this mining difficulty cycle

MicroStrategy Founder Michael Saylor stated that BIP-110 has failed to reach the 55% voluntary support threshold within the current Bitcoin mining difficulty adjustment cycle, believing that current miner signaling does not represent Bitcoin network consensus.

Michael Saylor: 100% Signaling Within the Specific BIP-110 Window Does Not Represent Bitcoin Consensus

Odaily News: Michael Saylor posted on the X platform, stating that before block 961,632, BIP-110 signaling was voluntary. From block 961,632 to 963,647, his software will reject every block that does not signal. Any "100% signaling" shown during this window reflects that rule, rather than voluntary support from miners or Bitcoin consensus.

Sygnum Integrates with Bancastato Online Banking, Supporting Swiss Clients in Trading BTC, ETH and 4 Other Assets

Odaily News: Zurich-based crypto bank Sygnum Bank has integrated its regulated cryptocurrency services into the Bancastato online banking system, allowing clients in the Swiss canton of Ticino to buy, hold, and sell BTC, ETH, LTC, and SOL via Bancastato's web and mobile platforms without needing to open a separate exchange account. Bancastato has become the first bank to offer cryptocurrency trading through Sygnum's application programming interface within an Avaloq software-as-a-service banking environment. Clients can place market orders based on cryptocurrency quantity or dollar value, with Sygnum handling trade execution while Bancastato retains the client relationship, brand, and front-end experience. Sygnum stated that its B2B platform has provided trading, custody, compliance, and settlement infrastructure to more than 25 banks and international financial institutions, including partners such as Zuger Kantonalbank, Luzerner Kantonalbank, Postfinance, and VZ Vermögenszentrum. Sygnum noted that these collaborations have delivered regulated digital asset services to over one-third of the Swiss population through existing banking relationships.

HIVE fiscal year revenue up 158% to $298 million, AI GPU hourly revenue approximately 24 times that of mining equipment

HIVE Executive Chairman Frank Holmes stated that the company's cluster of 504 NVIDIA B200 GPUs at Bell Canada's Manitoba AI fabric generates approximately $2.90 per GPU per hour in revenue; by comparison, HIVE's Bitcoin mining equipment generates approximately $0.12 per hour. HIVE's total revenue for fiscal year 2026 reached $298 million, up 158% year-over-year; digital currency revenue from Bitcoin mining grew 164%. During the same period, average hash rate stood at 22.2 EH/s, up 290% year-over-year, accounting for approximately 3% of the Bitcoin network's total hash rate, and the company mined 2,885 BTC. HIVE's BUZZ HPC division, which houses its AI and high-performance computing business, generated revenue of $19.5 million, up 94% from $10 million in the prior fiscal year. The company also signed GPU cloud agreements worth approximately $220 million with Bell and AI company Cohere, and raised $75 million through a note issuance to fund AI infrastructure expansion. HIVE is building a 320-megawatt AI data center in the Greater Toronto Area, with plans to eventually house more than 100,000 GPUs. The company stated that if the facility becomes fully operational in the second half of 2027, it could generate approximately $360 million in annualized recurring revenue.

Galaxy Research: Bitcoin losses related to the Coldcard vulnerability have risen to $70 million

Galaxy Research stated on Friday that over 1,000 BTC from nearly 1,200 addresses have been moved, valued at approximately $70 million, with the transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets.Earlier, Coldcard manufacturer Coinkite issued a warning on Thursday about an ongoing issue with seed phrases generated by Coldcard Mk3 devices. Out of caution, the company reminded all users who generated seed phrases using Mk3 devices with firmware version 4.0.1, released in March 2021, or later, that their funds may be at risk.Subsequently, Coinkite expanded the scope of its risk alert to include certain firmware versions of Mk4, Mk5, and Coldcard Q, and released emergency firmware updates for all affected models.Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday and stated that the company takes "full responsibility" for the firmware vulnerability, acknowledging that internal review processes failed to identify the issue.Novak also suggested that the vulnerability may have been discovered with the help of artificial intelligence, noting that this incident reflects a "sobering reality under the new AI paradigm." He warned that AI-assisted code review could identify potential vulnerabilities faster than experienced security experts, while also making it easier for attackers to exploit weaknesses in public code.

Tether's Q2 Performance Weakens, Excess Reserves Decline by Over $4 Billion

Odaily Crypto Daily News: Tether released its financial report on Friday, stating that its excess reserves decreased by $4.1 billion in Q2 compared to the previous quarter, nearly halving.As of the end of Q1, USDT issuer Tether had stated that its assets exceeded its liabilities by $8.2 billion; however, in the latest data, this figure has dropped to $4.1 billion.The report also shows that Tether's financial result for the first half of this year was negative $3.2 billion. Given that the company reported a net profit of $1 billion in Q1, this suggests it may have recorded a loss of over $4 billion in Q2.On a year-over-year basis, Tether's performance has also clearly weakened. The company's net profit for Q2 2025 was $4.9 billion, while its net operating profit for Q2 this year was $1.5 billion. Net operating profit typically excludes unrealized gains or losses resulting from price fluctuations in assets such as Bitcoin and gold.

Analysts Support Strategy Increasing Cash Holdings, Saylor Says No Longer "100% Allocating to Bitcoin" in the Future

Odaily News, Strategy Executive Chairman Michael Saylor said at the company's Q2 earnings call that while the company has previously allocated nearly "100% of its funds to Bitcoin," it may adopt a combined strategy of holding both cash and BTC going forward. He stated, "Perhaps the best way to buy the most Bitcoin is not to buy the most Bitcoin immediately."TD Cowen and Benchmark both maintained their Buy ratings on Strategy following the Q2 earnings call. The two firms believe that the core goal of the company's current management has shifted toward bringing its STRC preferred stock price back to near par value, thereby restoring its ability to function as a financing tool.TD Cowen analyst Lance Vitanza said the most important takeaway from the call was management's strong focus on STRC. Company executives repeatedly emphasized that restoring STRC to par value is the core objective, and noted that despite recent price deviations in the security, institutional adoption continues to rise.Benchmark analyst Mark Palmer holds a similar view. He pointed out that Saylor and his team spent most of the 90-minute call focused on the same goal: restoring STRC to the $99–$100 range, making it once again the primary engine for the company to raise capital and purchase Bitcoin.