News linked to both this project and an event.
On-chain analyst ZachXBT (@zachxbt) disclosed that the recently launched 10K PFP NFT project zkSNARKs on the Zcash chain is allegedly a rug pull. The project attracted a total of 16,971 bids via a blind auction, ultimately completing the allocation of 8,000 items at a clearing price of 1.5 ZEC (approximately $2,190). Total trading volume reached 25,305 ZEC (approximately $36.94 million), and refunds totaling 13,309 ZEC (approximately $19.43 million) have been progressively returned. ZachXBT noted that the project raised approximately $17 million, while incorporating a 10% team allocation, 5% royalties, and a minting fee of around $2,000, yet offered zero utility. This mirrors the typical "rug pull" strategy commonly seen in Ordinals-style projects.
Odaily Planet Daily reported that Bitcoin News stated on the X platform that Coinkite said the vulnerability existed at the boundary between two unrelated firmware submodules, rather than in its Bitcoin or encryption code, which allowed it to evade both manual and AI-assisted code reviews for years. Coinkite stated that after the incident, the company tested cutting-edge AI models including Kimi K3, Claude Fable, and Codex 5.6, none of which identified the flaw. Coinkite is now urging security-critical projects to specifically audit build systems and submodule boundaries, and warned that AI-assisted development could leave similar blind spots in the Bitcoin ecosystem.
Galaxy Digital Head of Research Alex Thorn stated that based on new victim reports received following the incident, the number of attackers exploiting the Coldcard vulnerability has reached at least 15.Thorn noted that information provided by victims helped the research team uncover previously unidentified attack activity. Unlike thefts from centralized exchanges, correlations between the attackers in this vulnerability exploit require confirmation through on-chain analysis and victim feedback.He added that a single victim reporting less than 1 BTC stolen helped the team discover a previously unknown attack, which siphoned approximately 12 BTC from 126 addresses.According to Galaxy Research's earlier estimates, the Coldcard vulnerability has led to at least three rounds of attacks, with losses amounting to approximately $100 million in BTC. Additionally, Galaxy has identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million.Meanwhile, the incident has also sparked discussions regarding the security of Bitcoin self-custody. Dragonfly Managing Partner Haseeb Qureshi stated that "AI security hardening costing around $2" could potentially have prevented this vulnerability, and noted that some AI models were able to rediscover related vulnerabilities within a relatively short timeframe. However, industry insiders pointed out that current claims about the speed of AI discovering vulnerabilities lack rigorous blind testing and verification.Researchers believe that as AI model capabilities improve, the costs of vulnerability discovery and attacks in the crypto industry may continue to decline, requiring wallet developers to further strengthen code audits and security protections. (Cointelegraph)