News linked to both this project and an event.
As disclosed by security researcher V12 (@v12sec), the Rabby Wallet browser extension contains a silent signature extraction vulnerability that allows attackers to extract wallet signatures via malicious websites without user awareness, thereby draining wallet assets. The conditions required to trigger this vulnerability are extremely limited: users must simultaneously meet two conditions—connecting to a malicious website and manually setting the auto-lock timer to 10 minutes. Other timer settings are unaffected, and the mobile app is also unaffected. Rabby Wallet officially stated that a fix update was released on August 11 following the vulnerability's discovery. No actual exploitation cases have been detected so far. Users are advised to confirm as soon as possible that the extension has been updated to the latest version.
Odaily News - Bitcoin News announced on the X platform that BitBox has disclosed two severe hardware wallet vulnerabilities, stating there is currently no evidence that these vulnerabilities have been exploited or led to user fund theft. All disclosed issues have been fixed in firmware v9.26.5, and BitBox urges all users to update immediately. An internal security audit uncovered two severe vulnerabilities, along with new details regarding a previously fixed bootloader vulnerability. One vulnerability affecting BitBox Multi devices could allow a malicious host to execute arbitrary code and install malicious firmware on devices that have not yet completed setup. Another vulnerability in Silent Payments could allow an attacker to exploit a malicious host device to redirect funds to unintended addresses, resulting in Bitcoin being locked and potentially enabling extortion attacks. BitBox also disclosed that the previously fixed bootloader vulnerability could allow attackers to trick users into installing malicious firmware capable of stealing funds.
Odaily News: Crypto wallet service provider SafePal recently issued a security announcement stating that the company discovered a vulnerability in its order tracking plugin, which led to unauthorized access to certain customer information.SafePal stated that the incident affects approximately 39,798 users, involving customers who placed orders between March 2, 2025, and April 11, 2026. The leaked information includes names, email addresses, shipping addresses, phone numbers, and order-related data such as purchase records.The company emphasized that the incident did not involve users' wallet security data, including seed phrases, private keys, wallet passwords, other wallet credentials, bank account information, payment card numbers, and government-issued identification documents, all of which remain unaffected.SafePal stated that the relevant vulnerability has now been fixed, and additional security measures have been implemented to strengthen the order system's protection. Affected users have received individual notifications via email. Users can also check whether they have been affected through the official page by entering their order number and shipping country.SafePal reminds users to remain vigilant, not to disclose seed phrases, private keys, or passwords to anyone, and to be cautious of phishing emails or fraudulent activities such as impersonated customer service that may arise in connection with this incident.
Odaily News, DefiLlama founder 0xngmi, of the crypto data analytics platform, stated that the team spent months asking Apple to remove phishing apps impersonating DefiLlama from the App Store, which delayed the mobile app's launch until all such counterfeit apps had been removed. 0xngmi noted that after the team downloaded one of the malicious apps and documented a small crypto wallet being stolen, Apple removed it within days. In 2024, the App Store also saw counterfeit apps impersonating Rabby Wallet and Curve Finance; in November 2023, a fake Ledger Live app on the Microsoft Store siphoned off $588,000 across 38 transactions. (Cointelegraph)
: Cardano ecosystem wallet project SecondFi has announced the launch of a wallet migration tool and revealed a recovery plan for assets affected by the June 2026 security incident. As the project will cease operations, users are required to migrate remaining assets still held in SecondFi wallets. The migration tool is expected to go live on August 13, supporting the transfer of eligible ADA, Cardano native tokens, and NFTs to new Cardano wallets created with service providers of the users' choosing. Currently, the tool only supports Cardano network assets; non-Cardano assets must be transferred separately through corresponding network and wallet processes. SecondFi stated that the migration tool has passed an independent security assessment by security firm Bitdefender. For affected assets, SecondFi plans to launch a recovery portal before September 10, where users can verify wallet ownership via zero-knowledge proofs (ZK Proof) and submit asset claims. SecondFi reminds users to only rely on information published through official channels, including @secondfiapp, @secondfi_jp, and the official support website, to guard against phishing sites and impersonating accounts.
Odaily News: Kostas Chalkias, co-founder and chief cryptographer of Mysten Labs, the development company behind the Sui blockchain, stated that he has leased a dedicated factory at a secret location and plans to scale up production of quantum-safe hardware wallet cards for Sui. The project aims to keep the cost of a single quantum card key under $10, with NFC quantum signing expected to take 1 to 2 seconds. Chalkias noted that the project is being advanced in his personal time outside of work and may include funding to provide cards for users who cannot afford them. The initiative is partly driven by a recent incident involving Coldcard hardware wallets, though the vulnerability was not a quantum attack. Coldcard manufacturer Coinkite disclosed that a firmware vulnerability in Coldcard, traceable to a 2021 update, bypassed the hardware random number chip and generated keys using a predictable software process linked to device serial numbers. Attackers have been moving funds since July 30, with losses climbing to approximately 2,055 BTC, affecting over 7,700 addresses and nearing a value of $130 million. At the protocol level, Sui plans to integrate two quantum-resistant signature schemes approved by the U.S. National Institute of Standards and Technology (NIST), designed for everyday accounts and high-value Move vaults, respectively. Existing accounts can be rotated to quantum-safe keys based on their original recovery phrases, without needing to migrate to new wallets. (Bitcoin.com News)
Odaily News – A long-dormant Bitcoin wallet moved nearly 50 BTC, worth approximately $3.2 million, on Thursday. The wallet received 49.97 BTC back in 2011, when Bitcoin was trading at around $10 per coin. The BTC was sent to a SegWit address that has previously transferred Bitcoin to institutional broker FalconX and received funds from wallets linked to Nexo and Prime Trust. The newly transferred BTC has not left this address. The transfer comes amid long-term holders rechecking their old storage setups following a major vulnerability exploit in Coldcard hardware wallets. There is currently no evidence linking the 2011 wallet to this vulnerability.
According to Cointelegraph, Bitcoin Lightning Network self-custodial wallet Zeus Wallet voluntarily took its infrastructure offline following a cybersecurity attack on Wednesday and is currently conducting a comprehensive audit of the system, with services to be restored upon completion. Zeus founder Evan Kaloudis stated that the attack was contained within hours, no customer fund losses were found, and there was no evidence that the Lightning node software was affected; the scope of the incident was limited to Zeus's own infrastructure. For users forced to close LSP channels during this incident, Zeus promised to provide replacement channels after services are restored. The company has not yet disclosed the specific nature of the attack or a timeline for resuming operations. Zeus stated that this incident will further drive its security development on Trusted Execution Environment (TEE) and Validating Lightning Signer (VLS) projects.
Odaily News: The Coldcard wallet hack involves approximately $120 million. The related transactions briefly made the Bitcoin mempool highly active.
CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.
Odaily News: The wallet associated with the Coldcard hacker has received multiple deposits since July 30, some of which include text messages attached via Bitcoin's OP_RETURN function. The messages include requests for the return of funds, as well as opportunistic promotional content, with one message offering to help launder the stolen funds for a 10% cut.
Odaily News: Hardware wallet manufacturer Ledger has stated that the recent Coldcard vulnerability indicates the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, as their recovery phrases are generated by a hardware random number generator built into a certified secure element. Coldcard manufacturer Coinkite disclosed last week that its air-gapped Coldcard Bitcoin hardware wallet contains a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, allowing certain private keys to be guessed, with related losses reaching approximately $130 million. Coinkite released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited — the flaw had existed in public code for over five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed. Charles Guillemet also said that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process has received independent certification.
Odaily Planet Daily Report: Bitcoin hardware wallet manufacturer Coinkite disclosed in late July 2026 that a firmware build error introduced in March 2021 caused some Coldcard wallets to generate mnemonics from a smaller range, reducing the randomness of user private keys. Galaxy Research analysts stated that the Coldcard exploit occurred in multiple rounds, with observed Bitcoin losses rising from approximately $88 million to nearly $114 million within days. Researchers warned that other vulnerable addresses could still become targets, prompting many Coldcard users to move their Bitcoin. Coldcard is a Bitcoin-only wallet that supports offline signing via microSD card and optional QR codes. Launched in 2017, it has long been regarded as one of the security-focused Bitcoin hardware wallets.
Odaily News: Bitcoin wallet service provider Nunchuk has issued an important update regarding the recent Coldcard security incident, recommending that users with multisig wallets containing Coldcard-generated keys migrate their funds as soon as possible.Nunchuk has categorized response levels based on the number of affected Coldcard keys in a multisig wallet: if the number of Coldcard-generated keys has reached the signing threshold, attackers could theoretically transfer funds directly, and such users should migrate immediately; if the wallet contains only 1 Coldcard-generated key and it is below the signing threshold, a single compromised key cannot move funds independently, making the risk relatively lower, but migration is still strongly recommended. If users cannot confirm the exact number of Coldcard keys in their wallet, they should treat it as a high-risk situation.Additionally, Nunchuk announced that an upcoming mobile update will automatically enable the Slipstream channel for paid users. At that point, any auxiliary multisig wallet transaction containing at least one Coldcard key will bypass the public mempool and be submitted via Slipstream, reducing the risk of transaction monitoring and replacement. For users who wish to act immediately or for free-tier users, Nunchuk offers a manual migration option: users need to create a migration transaction, complete multisig signing without broadcasting, and then submit the raw transaction data to the Slipstream platform.
According to Cointelegraph, Coinkite, the manufacturer of Coldcard hardware wallets, disclosed that its devices have contained a random number generator (RNG) vulnerability persisting for up to five years since March 2021. The vulnerability stemmed from a firmware upgrade that mistakenly routed wallet seed generation to a less secure MicroPython pseudo-random number generator (PRNG), rather than the originally designed true random number generator (TRNG). Since code reviews only verified the existence of TRNG code without confirming whether it was actually invoked, the vulnerability remained undetected for a long period. To date, over 4,500 addresses have been compromised, with nearly $90 million worth of Bitcoin stolen. Kraken Chief Security Officer Nick Percoco stated that this incident should serve as a "wake-up call" for the hardware wallet industry, calling for the introduction of independent third-party testing mechanisms to mandate verification of whether the entropy sources actually invoked by production firmware are certified. Coinkite has suspended all device shipments and destroyed affected inventory after confirming the vulnerability, and stated it will cooperate with law enforcement agencies across multiple countries to trace the responsible parties.
Odaily News: Major cryptocurrencies moved lower on Monday, with Bitcoin briefly falling to around $62,800 and Ether dropping to $1,858. Although expectations related to the geopolitical situation had improved earlier, the market failed to sustain a rebound. Following the expansion of the Coldcard hardware wallet vulnerability, approximately 1,367 BTC flowed out of roughly 4,585 addresses, valued at nearly $89 million, occurring across three rounds of attacks. The market's weakness stood in contrast to falling crude oil prices, a pullback in U.S. Treasury yields, and gains in stock index futures.
Bloomberg Senior ETF Analyst Eric Balchunas commented on the Coldcard wallet security incident, questioning whether a company with only about 5 employees is suitable to undertake such critical Bitcoin storage responsibilities. He stated that the number of employees behind Coldcard "seems unbelievably low," asking whether people would be willing to store their life savings in a bank with only 5 employees headquartered in Canada. In the crypto industry, this might be viewed as a feature, but from a traditional finance perspective, it becomes a clear risk signal. Balchunas further stated that, in comparison, institutions with larger teams such as Coinbase and Ledger may hold advantages in security investment and operational capabilities, even if users need to bear higher transaction costs. Bitcoin ETFs offer another option: investors can obtain the security guarantees provided by large, professional, regulated financial institutions while also enjoying lower management fees.
Odaily News: In response to the persistent attacks on Coldcard wallets, Binance co-founder CZ reposted on X platform stating that for self-custody wallets, developers fixing vulnerabilities cannot resolve the risks associated with previously generated wallets, and developers are unable to directly contact users of air-gapped devices.CZ stated that users' wallets may still be exposed to attack risks before any action is taken. He emphasized that he still supports the self-custody model, but self-custody means users need to bear more security responsibilities.
According to monitoring by on-chain analysis firm Galaxy Research (@glxyresearch), the ColdCard wallet hacking incident has developed into a third wave, with an additional 207.73 BTC stolen. Currently, the three waves of attacks have cumulatively stolen 1,367.05 BTC (approximately $88.6 million), involving 4,585 addresses. On-chain data shows that the three waves of attacks exhibit highly similar characteristics: identical fund consolidation topology, identical P2WPKH target addresses, and mixed derivation paths. Each wave occurred approximately 27 hours apart, suggesting they were carried out by the same attacker, but there is currently no direct evidence to confirm this. Currently, all terminal addresses controlled by the hackers hold a total of 1,366.39 BTC (approximately $88.6 million), all of which are in an unspent state on-chain. Galaxy Research noted that the above data is based solely on Bitcoin block data and UTXO set analysis, and has not yet computationally verified whether the victim addresses have vulnerabilities due to low-entropy generation.