News linked to both this project and an event.
Odaily News, Galaxy Research Head Alex Thorn stated on the X platform that attacks exploiting the Coldcard hardware wallet vulnerability have noticeably declined, but cumulative losses continue to rise as more victims come forward. The impact of this incident on the Bitcoin community is significant, as the victims are primarily long-term BTC holders who adhered to self-custody cold storage principles, rather than those who lost assets due to high-risk trading or DeFi activities.At a scale of $112 million, this incident ranks among the top 20 largest hacks in crypto history and is one of the most severe security breaches in the hardware wallet self-custody sector to date. Bitcoin culture may be entering a new phase—the era of relying solely on ideological advocacy and extreme self-custody promotion is coming to an end. The community needs to place greater emphasis on technical security, lower the barrier to entry for users, and avoid simply shifting the burden of security responsibility onto ordinary users. This crisis may ultimately drive the Bitcoin ecosystem to establish a more mature security framework.Galaxy Research has directly contacted 190 victims and has confirmed with high confidence that the exploit has led to the theft of 1,778.84 BTC (approximately $112.7 million) from over 8,600 addresses. This tally does not yet include certain moderately credible suspicious attack records, such as the unconfirmed "Wave 4." If these potential attack scopes are incorporated, total losses could expand to 2,417.35 BTC (approximately $153 million).Meanwhile, the incident is reshaping market perceptions of self-custody security. Galaxy noted that multisig wallets have emerged as the "winners" of this event, with no stolen transactions traced to multisig wallets so far. Multisig service providers including Casa, Unchained, Nunchuk, and Anchorwatch have all observed a notable increase in user registrations and BTC inflows.
Odaily News: After a firmware vulnerability in Coldcard hardware wallets was exploited, approximately 2,100 Bitcoin were stolen, with losses nearing $130 million. On-chain data shows that in the days surrounding the incident, wallets held by long-term holders transferred out approximately 233,000 Bitcoin, valued at around $15 billion. Casa CEO Nick Neuman stated that some of the transferred funds came from Coldcard users migrating to multi-signature wallets, with Ledger and Trezor users also taking similar measures after the event. During the same period, approximately 22,000 Bitcoin were transferred into exchanges. Coinkite has advised users who generated seed phrases using firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and immediately migrate to new seed phrases. These versions cover the period from March 2021 to July 2026. (Decrypt)
Odaily News: Bitcoin News posted on X platform that Xapo Bank users have reported the app now requires location data before allowing transactions. According to reports, one user was told they must share GPS coordinates to access their funds. Xapo Bank stated it will cross-check location information with other data to confirm that the account holder controls the account. @ToneVays warned that location requirements could become standard for regulated payment apps; Casa CEO @Nneuman said the measure may be aimed at countering large-scale social engineering attacks rather than traditional KYC.
Odaily News: Part of hardware wallet manufacturer Coldcard's firmware had a random number generation vulnerability in 2021, causing some mnemonic phrases generated by the devices to carry predictable risks. The vulnerability was only discovered years later, and by then approximately 5,200 addresses and around 2,000 BTC had been stolen, with losses totaling about $130 million. Following the incident, some investors turned to Wall Street custody products. U.S. spot Bitcoin ETFs saw net inflows of approximately $626 million within days of the event. ETF analyst Eric Balchunas noted that security incidents like this could further drive capital flows into ETFs. The Bitcoin core community continues to uphold the principle of self-custody. Casa co-founder Jameson Lopp said recent events should not weaken user confidence in self-custody, as third-party custody carries risks as well. Early Bitcoin Core developer Peter Todd stated that self-custody has a better long-term security track record than centralized institutions. Michael Tanguma, co-founder of Bitcoin custody platform Onramp, said both approaches have flaws: concentrating large amounts of assets in a single institution creates a "honey pot," while hardware wallets face risks related to supply chains, firmware, and random number generation. Michael Tanguma proposed a "multi-institution custody" approach, in which multiple regulated institutions each hold keys through a multi-signature mechanism, and any transaction requires joint signing by multiple institutions to reduce the risk of single points of failure. Critics argue that while multi-institution custody improves security, it also introduces permissioned management, which conflicts with the decentralized ideals Bitcoin originally pursued. As Bitcoin enters pension funds, trusts, and institutional asset allocation, the industry is seeking custody solutions suitable for long-term wealth management. How to strike a balance among security, decentralization, and usability remains a challenge facing the Bitcoin ecosystem.
Odaily News, Stacks co-founder Muneeb shared his views on the Coldcard wallet incident, summarizing lessons learned in three areas: Bitcoin storage strategy, quantum computing threats, and ecosystem security building. Regarding Bitcoin storage strategy, he noted that many industry security experts are not even familiar with Coldcard, and top-tier security research institutions may not have conducted thorough audits of its code. Muneeb believes the best approach going forward should be asset diversification rather than concentrating all funds in a single solution, and suggested:1. Allocate 20%-30% of BTC to ETFs, such as BlackRock's Bitcoin ETF IBIT, for professional custody and regulatory protection;2. Allocate 40%-50% of BTC to multisignature solutions like Casa, such as the three-key model, spreading keys across security companies, mobile devices, and hardware wallets;3. Allocate 20%-30% of BTC to more advanced self-custody approaches, combining different hardware wallets and diverse entropy sources.On the quantum computing threat, Muneeb stated that once quantum computers break through existing encryption systems in the future, Bitcoin users may experience a shock similar to "BTC suddenly being transferred out of cold wallets." The quantum threat is real, and the industry should prepare in advance rather than underestimate technological progress, especially against the backdrop of large language models accelerating scientific research breakthroughs.
Casa co-founder Jameson Lopp has warned of a new phishing attack, where attackers leverage legitimate Google account recovery forms to hide malicious links within large amounts of blank space. This technique involves embedding "invisible" or overlooked whitespace characters within long text, making the malicious link less noticeable to users, thereby tricking them into clicking and exposing their account information.Lopp advises users to remain vigilant when handling account recovery emails or forms, and to avoid clicking on links that are from unknown sources or intentionally hidden. (Cointelegraph)