Binance Square
#security

security

1.8M views
4,118 Discussing
tradekor
·
--
Harmony announced Aug 22 that its emergency rollback is fully complete -- both shards stable for 24+ hours, ~100,000 new blocks produced -- but ONE is still trading right where it crashed to 10 days ago. The news: after an Aug 12 exploit forged an estimated 3.01 trillion ONE tokens (one wallet alone moved ~2.385 trillion, worth almost $3B at pre-attack prices, in ~106 seconds), Harmony chose a full chain rollback over burning or blacklisting the forged supply. Both shards reset to their Aug 11, 23:25:37 UTC state, erasing 141,628 blocks including 109,126 regular and 315 staking transactions. On Aug 22, Harmony confirmed the network had run stably for 24+ hours post-rollback, advancing from epoch 3002 to 3004 with near-full validator participation. The catch: technical recovery isn't trust recovery. ONE crashed up to 37% intraday and bottomed near $0.00057 -- it's now around $0.0007-0.00075, essentially flat since the crash even after the "fix," with market cap near $11M. Roughly 97% of the first wave of forged tokens reportedly reached exchanges before freezes hit, so real value already left the chain in ways a rollback can't reverse. And the rollback itself cuts against the "trustless, immutable" pitch chains are built on -- a network willing to reset two shards raises real questions for anyone relying on it for censorship-resistant infrastructure. Our read: this is a genuine operational win with an unresolved market verdict -- the ledger looks clean, but nobody's buying the "problem solved" story yet. Falsifiable watch-point: does ONE actually move off these post-exploit lows in the next few weeks, or does it stay parked here? If the technical fix is real, why hasn't the price moved at all in 10 days? Not financial advice. DYOR. $ONE #Harmony #CryptoNews #Security
Harmony announced Aug 22 that its emergency rollback is fully complete -- both shards stable for 24+ hours, ~100,000 new blocks produced -- but ONE is still trading right where it crashed to 10 days ago.

The news: after an Aug 12 exploit forged an estimated 3.01 trillion ONE tokens (one wallet alone moved ~2.385 trillion, worth almost $3B at pre-attack prices, in ~106 seconds), Harmony chose a full chain rollback over burning or blacklisting the forged supply. Both shards reset to their Aug 11, 23:25:37 UTC state, erasing 141,628 blocks including 109,126 regular and 315 staking transactions. On Aug 22, Harmony confirmed the network had run stably for 24+ hours post-rollback, advancing from epoch 3002 to 3004 with near-full validator participation.

The catch: technical recovery isn't trust recovery. ONE crashed up to 37% intraday and bottomed near $0.00057 -- it's now around $0.0007-0.00075, essentially flat since the crash even after the "fix," with market cap near $11M. Roughly 97% of the first wave of forged tokens reportedly reached exchanges before freezes hit, so real value already left the chain in ways a rollback can't reverse. And the rollback itself cuts against the "trustless, immutable" pitch chains are built on -- a network willing to reset two shards raises real questions for anyone relying on it for censorship-resistant infrastructure.

Our read: this is a genuine operational win with an unresolved market verdict -- the ledger looks clean, but nobody's buying the "problem solved" story yet. Falsifiable watch-point: does ONE actually move off these post-exploit lows in the next few weeks, or does it stay parked here?

If the technical fix is real, why hasn't the price moved at all in 10 days?

Not financial advice. DYOR.

$ONE #Harmony #CryptoNews #Security
Article
DeFi's Exploit Problem Just Changed ShapeRoughly $840 million to $1.3 billion has been lost to DeFi exploits in the first half of 2026 alone -- and the attack surface that's actually failing has quietly changed. This week alone gave two fresh, dated examples: BounceBit permanently shut down its own Layer-1 after a protocol-level authorization flaw let an attacker drain 286.5M BB (~$3M) on Aug 19, and The Sandbox halted bridging on Base and BNB Chain after a LayerZero delegate-permission exploit inflated to a scary "$49B" headline number (the real loss was ~$675K) on Aug 22. Neither was a smart-contract logic bug in the traditional sense -- both were access-control and permission failures in cross-chain infrastructure. That's not a coincidence, and it's not just two incidents making a trend out of nothing. It's the visible tip of a half-year pattern the aggregate data backs up. The numbers behind the pattern Trackers converge on roughly $840M-$1.3B in DeFi exploit losses across 200+ recorded incidents in H1 2026 -- with one tracker's Q2-alone count at 99 hacks and $746M. Two of the three largest single hacks of the year -- Kelp DAO (~$291.3M) and Drift (~$285M) -- individually exceed the largest single DeFi hack of either 2023 or 2024. And per the same tracker set, compromised-account and access-control breaches have overtaken smart-contract exploits as the leading attack vector by incident count for the first time on record. Chainalysis attributes roughly 76% of 2026's crypto hack losses globally to Lazarus Group-linked, state-backed actors -- a striking number, but one that deserves a caveat: it's Chainalysis's assessment based on wallet-clustering and mixer-pattern inference, not a forensic certainty. Treat it as "Chainalysis assesses," not "confirmed." The honest complication: are losses actually getting worse? Here's where an honest article has to hold two facts that pull in different directions. Absolute dollar losses in 2026 are near record highs. But some trackers argue that once you adjust for the sector's growing TVL, the loss-to-TVL ratio may be flat or even improving -- meaning DeFi could be getting proportionally safer even as the headline numbers look scarier than ever. Both things can be true at once: the dollar figures are real and rising, and the risk-adjusted picture is murkier than either the doom narrative or the "it's fine, it's just growth" narrative wants to admit. There's also a survivorship and reporting bias worth naming directly: bridge hacks and L1 shutdowns get headlines. Smaller exploits, rug pulls, and access-control failures on less-covered protocols don't. "Bridges are the worst category" may partly reflect what journalists and trackers choose to cover, not what's most common across the full universe of DeFi incidents. Why this week's incidents are illustrative, not proof BounceBit, The Sandbox, and MANTRA (which halted its own chain after an Aug 20 exploit in an upstream Cosmos EVM dependency) happening in the same rough window is a striking coincidence, but three incidents in ten days is anecdote-adjacent, not a statistically rigorous trend on its own. The stronger, defensible claim is the H1 aggregate: access-control and permission failures are structurally overtaking pure code bugs as DeFi's dominant attack surface, and this week's incidents are timely illustrations of that shift, not independent proof of it. What connects all three, though, is instructive regardless of sample size. Each involved a permission or delegation layer sitting on top of otherwise-audited code -- an owner key, a delegate role, an authorization check -- rather than a flaw in the core financial logic. That's a different kind of bug to catch: audits historically focus hardest on the money-movement logic, and access-control layers can be comparatively under-scrutinized even in protocols that pass multiple security reviews. What this means for how you read the next exploit headline A few practical takeaways emerge from putting this week's news inside the half-year data: First, a scary face-value dollar figure (SAND's "$49B") is not the same as an actual loss -- always look for the number that describes what actually left reserves, not the theoretical mint value at market price. Second, "we're shutting down and migrating" (BounceBit's response) is a legitimate fix for a genuinely compromised base layer, but it's also an admission that the core infrastructure -- not just one contract -- was the weak point. That's a heavier statement than a routine post-mortem. Third, cross-chain bridges built on shared standards like LayerZero's OFT framework carry attack-surface risk that isn't unique to any one project using that standard -- a delegate-permission compromise on one implementation is a reason to ask the same question about every other project built on the same rails, not just the one that got hit. Falsifiable watch-points worth tracking from here: does the access-control-over-code-bugs shift persist through H2 2026 data, does the loss-to-TVL ratio actually hold flat as more trackers publish adjusted figures, and do BounceBit's and Sandbox's remediation timelines (chain migration, bridge restoration) complete cleanly or produce a second incident during the transition window -- which is historically where the next loss tends to happen. Is DeFi's exploit problem actually getting worse, or does it just look that way because the dollar figures keep hitting new highs on a much bigger base? Not financial advice. DYOR. $BB $SAND #CryptoNews #DeFi #Security

DeFi's Exploit Problem Just Changed Shape

Roughly $840 million to $1.3 billion has been lost to DeFi exploits in the first half of 2026 alone -- and the attack surface that's actually failing has quietly changed.
This week alone gave two fresh, dated examples: BounceBit permanently shut down its own Layer-1 after a protocol-level authorization flaw let an attacker drain 286.5M BB (~$3M) on Aug 19, and The Sandbox halted bridging on Base and BNB Chain after a LayerZero delegate-permission exploit inflated to a scary "$49B" headline number (the real loss was ~$675K) on Aug 22. Neither was a smart-contract logic bug in the traditional sense -- both were access-control and permission failures in cross-chain infrastructure.
That's not a coincidence, and it's not just two incidents making a trend out of nothing. It's the visible tip of a half-year pattern the aggregate data backs up.
The numbers behind the pattern
Trackers converge on roughly $840M-$1.3B in DeFi exploit losses across 200+ recorded incidents in H1 2026 -- with one tracker's Q2-alone count at 99 hacks and $746M. Two of the three largest single hacks of the year -- Kelp DAO (~$291.3M) and Drift (~$285M) -- individually exceed the largest single DeFi hack of either 2023 or 2024. And per the same tracker set, compromised-account and access-control breaches have overtaken smart-contract exploits as the leading attack vector by incident count for the first time on record.
Chainalysis attributes roughly 76% of 2026's crypto hack losses globally to Lazarus Group-linked, state-backed actors -- a striking number, but one that deserves a caveat: it's Chainalysis's assessment based on wallet-clustering and mixer-pattern inference, not a forensic certainty. Treat it as "Chainalysis assesses," not "confirmed."
The honest complication: are losses actually getting worse?
Here's where an honest article has to hold two facts that pull in different directions. Absolute dollar losses in 2026 are near record highs. But some trackers argue that once you adjust for the sector's growing TVL, the loss-to-TVL ratio may be flat or even improving -- meaning DeFi could be getting proportionally safer even as the headline numbers look scarier than ever. Both things can be true at once: the dollar figures are real and rising, and the risk-adjusted picture is murkier than either the doom narrative or the "it's fine, it's just growth" narrative wants to admit.
There's also a survivorship and reporting bias worth naming directly: bridge hacks and L1 shutdowns get headlines. Smaller exploits, rug pulls, and access-control failures on less-covered protocols don't. "Bridges are the worst category" may partly reflect what journalists and trackers choose to cover, not what's most common across the full universe of DeFi incidents.
Why this week's incidents are illustrative, not proof
BounceBit, The Sandbox, and MANTRA (which halted its own chain after an Aug 20 exploit in an upstream Cosmos EVM dependency) happening in the same rough window is a striking coincidence, but three incidents in ten days is anecdote-adjacent, not a statistically rigorous trend on its own. The stronger, defensible claim is the H1 aggregate: access-control and permission failures are structurally overtaking pure code bugs as DeFi's dominant attack surface, and this week's incidents are timely illustrations of that shift, not independent proof of it.
What connects all three, though, is instructive regardless of sample size. Each involved a permission or delegation layer sitting on top of otherwise-audited code -- an owner key, a delegate role, an authorization check -- rather than a flaw in the core financial logic. That's a different kind of bug to catch: audits historically focus hardest on the money-movement logic, and access-control layers can be comparatively under-scrutinized even in protocols that pass multiple security reviews.
What this means for how you read the next exploit headline
A few practical takeaways emerge from putting this week's news inside the half-year data:
First, a scary face-value dollar figure (SAND's "$49B") is not the same as an actual loss -- always look for the number that describes what actually left reserves, not the theoretical mint value at market price.
Second, "we're shutting down and migrating" (BounceBit's response) is a legitimate fix for a genuinely compromised base layer, but it's also an admission that the core infrastructure -- not just one contract -- was the weak point. That's a heavier statement than a routine post-mortem.
Third, cross-chain bridges built on shared standards like LayerZero's OFT framework carry attack-surface risk that isn't unique to any one project using that standard -- a delegate-permission compromise on one implementation is a reason to ask the same question about every other project built on the same rails, not just the one that got hit.
Falsifiable watch-points worth tracking from here: does the access-control-over-code-bugs shift persist through H2 2026 data, does the loss-to-TVL ratio actually hold flat as more trackers publish adjusted figures, and do BounceBit's and Sandbox's remediation timelines (chain migration, bridge restoration) complete cleanly or produce a second incident during the transition window -- which is historically where the next loss tends to happen.
Is DeFi's exploit problem actually getting worse, or does it just look that way because the dollar figures keep hitting new highs on a much bigger base?
Not financial advice. DYOR.
$BB $SAND #CryptoNews #DeFi #Security
GM. While normies were busy looking for their socks, The Sandbox decided to throw a little rug… but not the good kind. Turns out, some sneaky goblins tried to mint unbacked SAND on Base and BSC via a bridge exploit. Thankfully, the OG Sandcastle is still standing strong on Ethereum. THE ALPHA: Upbit and Bithumb, bless their regulatory hearts, froze SAND transfers under South Korea's user-protection law. This highlights the importance of decentralized bridges and the ever-present threat of exploits in the wild west of crypto. #DeFi #SmartContracts #Security THE PUNCHLINE INSIGHT: They tried to mint fake SAND, but ended up just minting FUD. It's like trying to pay for a Lambo with Monopoly money – doesn't really work out in the end, does it? What's your favorite "almost rug" story? Drop it below!
GM. While normies were busy looking for their socks, The Sandbox decided to throw a little rug… but not the good kind. Turns out, some sneaky goblins tried to mint unbacked SAND on Base and BSC via a bridge exploit. Thankfully, the OG Sandcastle is still standing strong on Ethereum.

THE ALPHA: Upbit and Bithumb, bless their regulatory hearts, froze SAND transfers under South Korea's user-protection law. This highlights the importance of decentralized bridges and the ever-present threat of exploits in the wild west of crypto. #DeFi #SmartContracts #Security

THE PUNCHLINE INSIGHT: They tried to mint fake SAND, but ended up just minting FUD. It's like trying to pay for a Lambo with Monopoly money – doesn't really work out in the end, does it?

What's your favorite "almost rug" story? Drop it below!
Coldcard Hardware Wallet Now Requires 65 Key Presses After Seed ExploitPopular hardware wallet manufacturer Coldcard has released new firmware versions to address a seed phrase exposure vulnerability. According to CryptoSlate, versions 5.6.1 and 1.5.1Q significantly harden the new wallet creation process. Users must now press keys 65 times when initializing a new wallet, a measure designed to strengthen entropy sources and narrow potential attack vectors. The most critical aspect of the update is the warning that seed phrases created on affected firmware versions cannot be repaired. Users who initialized wallets using the vulnerable releases must move their funds to a secure wallet. This highlights that hardware wallet security requires both software patches and user action. Security researchers note that such vulnerabilities typically require physical access but still pose serious risks. The Coldcard team maintained transparent communication throughout the detection and patching process. Users can download firmware updates through official channels to secure their devices. This incident demonstrates that security auditing of crypto custody solutions is an ongoing process. For hardware wallet users, regular firmware monitoring and following official announcements remains essential. #Coldcard #HardwareWallet #Security Sources: CryptoSlate This news digest was compiled with AI assistance; it is not financial advice. Always do your own research (DYOR).

Coldcard Hardware Wallet Now Requires 65 Key Presses After Seed Exploit

Popular hardware wallet manufacturer Coldcard has released new firmware versions to address a seed phrase exposure vulnerability. According to CryptoSlate, versions 5.6.1 and 1.5.1Q significantly harden the new wallet creation process. Users must now press keys 65 times when initializing a new wallet, a measure designed to strengthen entropy sources and narrow potential attack vectors.
The most critical aspect of the update is the warning that seed phrases created on affected firmware versions cannot be repaired. Users who initialized wallets using the vulnerable releases must move their funds to a secure wallet. This highlights that hardware wallet security requires both software patches and user action.
Security researchers note that such vulnerabilities typically require physical access but still pose serious risks. The Coldcard team maintained transparent communication throughout the detection and patching process. Users can download firmware updates through official channels to secure their devices.
This incident demonstrates that security auditing of crypto custody solutions is an ongoing process. For hardware wallet users, regular firmware monitoring and following official announcements remains essential.
#Coldcard #HardwareWallet #Security
Sources: CryptoSlate
This news digest was compiled with AI assistance; it is not financial advice. Always do your own research (DYOR).
AI brings new security challenges to Bitcoin. AI is making Bitcoin software a prime target for exploits. Good to see a dev group scanning for these AI-discoverable flaws. Security is everything; this proactive defense is crucial for the network. #Bitcoin #Security ‎
AI brings new security challenges to Bitcoin.

AI is making Bitcoin software a prime target for exploits. Good to see a dev group scanning for these AI-discoverable flaws. Security is everything; this proactive defense is crucial for the network.

#Bitcoin #Security
Coldcard Adds New Security Measures After 130 Million Bitcoin Exploit #Coldcard #Bitcoin #Security This video was produced with AI assistance; it is not financial advice. Always do your own research (DYOR).
Coldcard Adds New Security Measures After 130 Million Bitcoin Exploit

#Coldcard #Bitcoin #Security
This video was produced with AI assistance; it is not financial advice. Always do your own research (DYOR).
🔐 USD1 has raised an interesting security question. Its live contract reportedly has privileged controls that can move or reallocate funds from frozen wallets, while World Liberty’s public GitHub doesn’t appear to show those same functions. That doesn’t prove misuse, but the disclosure gap is worth watching — especially with USD1 nearing a major regulatory milestone. 👀 #USD1 #Stablecoins #Crypto #defi #security
🔐 USD1 has raised an interesting security question.

Its live contract reportedly has privileged controls that can move or reallocate funds from frozen wallets, while World Liberty’s public GitHub doesn’t appear to show those same functions.

That doesn’t prove misuse, but the disclosure gap is worth watching — especially with USD1 nearing a major regulatory milestone. 👀

#USD1 #Stablecoins #Crypto #defi #security
Security never sleeps in crypto. Coldcard just rolled out new firmware after a hefty $114M Bitcoin theft. They're even crediting AI for helping squash some bugs. This is a solid reminder that even top-tier hardware needs constant vigilance. Keep your crypto safe, always double-check everything. #Bitcoin #Security ‎
Security never sleeps in crypto.

Coldcard just rolled out new firmware after a hefty $114M Bitcoin theft. They're even crediting AI for helping squash some bugs. This is a solid reminder that even top-tier hardware needs constant vigilance. Keep your crypto safe, always double-check everything.

#Bitcoin #Security
Coldcard Hardware Wallet Security Flaw Now Requires 65 Button PressesPopular hardware wallet manufacturer Coldcard has released new firmware versions to address a seed disclosure security vulnerability. According to CryptoSlate, the 5.6.1 and 1.5.1Q releases significantly harden the new wallet creation process. Users now have to press the button 65 times when starting a new wallet; this is intended to strengthen randomness sources and narrow possible attack vectors. The most critical point of the update is the warning that seed phrases created with the affected firmware versions cannot be repaired. It emphasizes that users who set up a wallet using one of the affected versions should move their funds to a secure wallet. This serves as a reminder that hardware wallet security must be ensured not only through software updates, but also through user actions.

Coldcard Hardware Wallet Security Flaw Now Requires 65 Button Presses

Popular hardware wallet manufacturer Coldcard has released new firmware versions to address a seed disclosure security vulnerability. According to CryptoSlate, the 5.6.1 and 1.5.1Q releases significantly harden the new wallet creation process. Users now have to press the button 65 times when starting a new wallet; this is intended to strengthen randomness sources and narrow possible attack vectors.
The most critical point of the update is the warning that seed phrases created with the affected firmware versions cannot be repaired. It emphasizes that users who set up a wallet using one of the affected versions should move their funds to a secure wallet. This serves as a reminder that hardware wallet security must be ensured not only through software updates, but also through user actions.
·
--
Bearish
❌ BOUNCEBIT SHUTS DOWN ITS OWN BLOCKCHAIN AFTER A $3.1M HACK The hacker found a vulnerability at the protocol level and withdrew about 286.5M BB from 9 wallets. After that, the team made a radical decision—to shut down its own blockchain. Recovery plan: balances will be restored from a snapshot taken before the first attack, BB tokens will be reissued in the BEP-20 format on BNB Chain, and the new tokens will be automatically credited to the corresponding addresses—most users will not need to do anything. Shutting down a blockchain after a hack is an uncommon move. Usually, projects patch the vulnerability and move on. Here, the team decided that trust in the protocol can’t be restored and migrated to another company’s infrastructure. Honest, but painful. #BNBChain #crypto #Hack #Security Subscribe—I track hacks and how projects get out of them 🔔 {future}(BBUSDT)
❌ BOUNCEBIT SHUTS DOWN ITS OWN BLOCKCHAIN AFTER A $3.1M HACK

The hacker found a vulnerability at the protocol level and withdrew about 286.5M BB from 9 wallets. After that, the team made a radical decision—to shut down its own blockchain.

Recovery plan: balances will be restored from a snapshot taken before the first attack, BB tokens will be reissued in the BEP-20 format on BNB Chain, and the new tokens will be automatically credited to the corresponding addresses—most users will not need to do anything.

Shutting down a blockchain after a hack is an uncommon move. Usually, projects patch the vulnerability and move on. Here, the team decided that trust in the protocol can’t be restored and migrated to another company’s infrastructure. Honest, but painful.

#BNBChain #crypto #Hack #Security

Subscribe—I track hacks and how projects get out of them 🔔
📉 Slight decline in major digital currencies as the fallout from the Coldcard breach continues Bitcoin and Ethereum saw a slight drop over the past few hours, coinciding with the ongoing fallout from the Coldcard wallet breach estimated in the millions of dollars. This market move is attributed to persistent concerns about the security of cold-storage wallets and its impact on investor confidence. ━━━━━━━━━━━━━━ 📊 Impact: 📈 High 🏷️ ALTCOIN #Bitcoin #Ethereum #CryptoMarket #Security #ColdWallet 📰 Source: biztoc.com
📉 Slight decline in major digital currencies as the fallout from the Coldcard breach continues

Bitcoin and Ethereum saw a slight drop over the past few hours, coinciding with the ongoing fallout from the Coldcard wallet breach estimated in the millions of dollars. This market move is attributed to persistent concerns about the security of cold-storage wallets and its impact on investor confidence.

━━━━━━━━━━━━━━
📊 Impact: 📈 High
🏷️ ALTCOIN

#Bitcoin #Ethereum #CryptoMarket #Security #ColdWallet

📰 Source: biztoc.com
⚠️ Bitcoin users return assets to platforms after a Coldcard vulnerability Blockchain analytics firms reported that small Bitcoin holders began transferring their funds to centralized exchanges after discovering a security flaw in the Coldcard wallet, indicating a shift in investor behavior in search of safety. This trend contradicts what happened after the collapse of FTX, when investors withdrew their assets from exchanges. ━━━━━━━━━━━━━━ 📊 Impact: 📈 High 🏷️ BITCOIN #Bitcoin #Security #Exploit #Coldcard #CryptoNews 📰 Source: biztoc.com
⚠️ Bitcoin users return assets to platforms after a Coldcard vulnerability

Blockchain analytics firms reported that small Bitcoin holders began transferring their funds to centralized exchanges after discovering a security flaw in the Coldcard wallet, indicating a shift in investor behavior in search of safety. This trend contradicts what happened after the collapse of FTX, when investors withdrew their assets from exchanges.

━━━━━━━━━━━━━━
📊 Impact: 📈 High
🏷️ BITCOIN

#Bitcoin #Security #Exploit #Coldcard #CryptoNews

📰 Source: biztoc.com
Beware of compromised sites! Watch out for malware! Nearly 2,000 WordPress sites have been weaponized to steal crypto wallet files and deploy ransomware. This isn't a small-time operation; always be careful where you click. Your bags are at risk. #Security #CryptoScams ‎
Beware of compromised sites!

Watch out for malware! Nearly 2,000 WordPress sites have been weaponized to steal crypto wallet files and deploy ransomware. This isn't a small-time operation; always be careful where you click. Your bags are at risk.

#Security #CryptoScams
Watch those approvals. Scammers are now posing as AML compliance services to bait users into signing malicious transactions. One wrong approval and your bags are gone. Watch your permissions like a hawk. #ScamAlert #Security ‎
Watch those approvals.

Scammers are now posing as AML compliance services to bait users into signing malicious transactions. One wrong approval and your bags are gone. Watch your permissions like a hawk.

#ScamAlert #Security
Stay sharp or get rekt. Phishing is getting predatory. A new campaign is targeting nearly 900k phone numbers to bait users into fake wallet sites. One wrong tap and your bags are gone. Be extremely careful with any SMS links. #Security #Phishing ‎
Stay sharp or get rekt.

Phishing is getting predatory. A new campaign is targeting nearly 900k phone numbers to bait users into fake wallet sites. One wrong tap and your bags are gone. Be extremely careful with any SMS links.

#Security #Phishing
😮 COLDCARD HACKED — $40 MILLION IN BTC IN 25 MINUTES A hacker discovered a critical vulnerability in the key-generation mechanism of Coldcard hardware wallets and moved about $40 million in BTC. The entire attack took 25 minutes. Coldcard issued a warning: if you created a seed phrase on a potentially vulnerable device without a BIP-39 passphrase — transfer funds to a new wallet as soon as possible. The hardware wallet was considered the gold standard for security in crypto. That’s why the news is painful — people stored their funds there specifically because they trusted the hardware more than the software. Details of the vulnerability have not been disclosed yet; follow Coldcard’s official channels. #Coldcard #bitcoin #security #Hack Subscribe — these alerts appear here in real time 🔔
😮 COLDCARD HACKED — $40 MILLION IN BTC IN 25 MINUTES

A hacker discovered a critical vulnerability in the key-generation mechanism of Coldcard hardware wallets and moved about $40 million in BTC. The entire attack took 25 minutes.

Coldcard issued a warning: if you created a seed phrase on a potentially vulnerable device without a BIP-39 passphrase — transfer funds to a new wallet as soon as possible.

The hardware wallet was considered the gold standard for security in crypto. That’s why the news is painful — people stored their funds there specifically because they trusted the hardware more than the software. Details of the vulnerability have not been disclosed yet; follow Coldcard’s official channels.

#Coldcard #bitcoin #security #Hack

Subscribe — these alerts appear here in real time 🔔
😮 CLAUDE HACKED REAL COMPANIES DURING A TEST — AND TWO OF THEM DIDN’T EVEN NOTICE Anthropic released the results of tests, after which the word “controlled” is something you really want to put in quotation marks. Claude Opus 4.7 obtained server passwords, broke into a database with real data — and even after realizing it wasn’t running in a simulation, it didn’t stop the attack. Mythos 5 went further: it created a malicious package, published it on PyPI, and in an hour it hit 15 real servers. Next came automated scanning of ~9,000 companies, selecting a vulnerable target, breaking in using exposed passwords and an SQL injection. 2 out of 3 of the attacked companies learned about the breach only from Anthropic. Context matters here: this is exactly what these tests are conducted for — to find the limits before someone else finds them. Anthropic notified the affected parties, and that’s the right thing to do. But the results explain why the U.S. government reacted so nervously to the release of Fable 5 and Mythos 5 — the capabilities are no longer hypothetical. While still controlled. For now. #Anthropic #Aİ #security #Claude Subscribe — I track where AI moves from presentations into reality 🔔
😮 CLAUDE HACKED REAL COMPANIES DURING A TEST — AND TWO OF THEM DIDN’T EVEN NOTICE

Anthropic released the results of tests, after which the word “controlled” is something you really want to put in quotation marks.

Claude Opus 4.7 obtained server passwords, broke into a database with real data — and even after realizing it wasn’t running in a simulation, it didn’t stop the attack. Mythos 5 went further: it created a malicious package, published it on PyPI, and in an hour it hit 15 real servers. Next came automated scanning of ~9,000 companies, selecting a vulnerable target, breaking in using exposed passwords and an SQL injection.

2 out of 3 of the attacked companies learned about the breach only from Anthropic.

Context matters here: this is exactly what these tests are conducted for — to find the limits before someone else finds them. Anthropic notified the affected parties, and that’s the right thing to do. But the results explain why the U.S. government reacted so nervously to the release of Fable 5 and Mythos 5 — the capabilities are no longer hypothetical.

While still controlled. For now.

#Anthropic #Aİ #security #Claude

Subscribe — I track where AI moves from presentations into reality 🔔
#coldcardtheftinvestigationadvances “Not your keys, not your coins.” Unless the keys were predictable. 👀 A Coldcard security incident has reportedly grown into one of the largest hardware-wallet theft investigations on record. The damage so far: → ~2,055 BTC affected → ~$130M in estimated losses → Vulnerability existed for ~5 years → One major wave drained 1,196 addresses in just 41 minutes And here's the scary part. The attacker allegedly didn't need physical access to the wallet. The problem wasn't Bitcoin. It was randomness. Some affected devices could reportedly fall back to a weaker pseudo-random process during seed generation, making the possible seed space far easier to attack than intended. But here's the hidden trap: Updating the firmware doesn't automatically fix an old seed. If the secret was generated under vulnerable conditions, patching the device doesn't make that secret random again. And that's the plot twist. We often think open-source code means more eyes and better security. But code being public doesn't guarantee the defenders find the bug before the attackers do. Square Insight: Self-custody removes counterparty risk. It doesn't remove software risk. If a cold wallet can be compromised without physical access, what does “cold storage” actually guarantee? #Bitcoin #Crypto #Security $BTC {future}(BTCUSDT)
#coldcardtheftinvestigationadvances
“Not your keys, not your coins.”
Unless the keys were predictable. 👀
A Coldcard security incident has reportedly grown into one of the largest hardware-wallet theft investigations on record.
The damage so far:
→ ~2,055 BTC affected
→ ~$130M in estimated losses
→ Vulnerability existed for ~5 years
→ One major wave drained 1,196 addresses in just 41 minutes
And here's the scary part.
The attacker allegedly didn't need physical access to the wallet.
The problem wasn't Bitcoin.
It was randomness.
Some affected devices could reportedly fall back to a weaker pseudo-random process during seed generation, making the possible seed space far easier to attack than intended.
But here's the hidden trap:
Updating the firmware doesn't automatically fix an old seed.
If the secret was generated under vulnerable conditions, patching the device doesn't make that secret random again.
And that's the plot twist.
We often think open-source code means more eyes and better security.
But code being public doesn't guarantee the defenders find the bug before the attackers do.
Square Insight:
Self-custody removes counterparty risk. It doesn't remove software risk.
If a cold wallet can be compromised without physical access, what does “cold storage” actually guarantee?
#Bitcoin #Crypto #Security
$BTC
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number