盗币 · 154

BitBox: AI Finds Serious Vulnerabilities in Its Firmware, Updates to Fix It Have Been Released

According to Decrypt, Swiss hardware wallet manufacturer BitBox discovered two serious firmware vulnerabilities and a bootloader issue during an internal AI audit, and has released a security update for Dixence. Exploitation of the exploit requires a combination of phishing attacks and users unlocking the tampered device, but BitBox indicates that no user funds have been stolen, and the mnemonic phrase is unthreatened. A bootloader vulnerability affects the old BitBox02. Attackers can load malicious firmware to steal assets. This issue has been partially fixed in the July Oeschinen update; the second serious vulnerability affects the pre-initialization stage of Multi version devices and may allow arbitrary code execution; and the third issue involves the silent payment function, which cannot directly steal coins but may lock funds. The new Nova version is unaffected. BitBox warns users of old firmware to install updates as soon as possible, and there are currently no reports of loss of user funds.

3d ago

New developments in the Coldcard coin theft incident. The identity of the first wave of attackers may have been captured by the FBI

Comparatively, according to Bitcoin Magazine, the investigation into the large-scale coin theft incident of the Coldcard hardware wallet in July 2026 progressed. In the first wave of attacks, about 1082.65 BTC (about US$118 million) were still stored at the attackers' addresses. The investigation found that the attackers used a paid account with a blockchain data service provider. Internal logs “highly consistent” with the coin theft model, and related clues have been handed over to law enforcement. Galaxy Research analyst Alex Thorn said that the identity of the first wave of attackers “may have been captured by law enforcement.” A total of about 2,000 BTC were stolen in subsequent waves of attacks, of which about 76 BTC was stolen in the second wave. The operation mode was similar to the first wave, and it was probably the same actor. The incident stemmed from an entropy generation vulnerability introduced by Coinkite in the March 2021 code update. As a result, some devices using MK2 and later models, firmware 4.1 and above generated low-strength private keys, and seeds can be violently cracked. Coinkite has released fixed firmware and advised users to migrate assets, but the extent of the vulnerability is still being assessed.

3d ago
The founder responded three times. Why is the Gate coin theft case getting more and more dark?

The founder responded three times. Why is the Gate coin theft case getting more and more dark?

Author: Maher, Foresight News Original title: The founder responded several times, why didn't Gate's “PR” community buy it? On August 3, Gate's official Chinese-language Twitter account posted a screenshot of an external database query after coding to try to prove that user @jheioff's personal information had already been seriously leaked from outside the platform, rather than causing security issues due to its own reasons. However, some users in the comments section responded that user privacy was unboxed by Gate, and the impression was too poor. This move quickly escalated the dispute over account security and accountability into a privacy and PR crisis, and became the latest tipping point after the incident continued for nearly a month. This case, which began on July 8, has evolved into a typical centralized exchange trust storm. Users claim that about $1.7 million worth of assets have been stolen, while Gate insists that there are no systemic security breaches. The evidence chains between the two sides are in sharp conflict, and the community continues to raise questions. From breaking the news to the confrontation, the two sides held each other's arguments. On July 8, X user @jheioff publicly posted that he hadn't logged in to his Gate account for a few days, and when he checked again, he found that about $1.7 million in assets had been emptied. This includes 49.96 ETH, 746,475 HSK, and 1565,982 USDT. The user stressed that the account has enabled mobile verification, Google Authenticator, and email verification. The phone did not receive any verification codes during this period, and he never provided a video, handheld ID, or login screen recording. Foresight News previously wrote in “1.7 Million Gate Users Stolen, Has Face Recognition Been Hacked?” The cause and circumstances of the incident are described in detail in the article. One day after the incident unraveled, Gate had a net outflow of about $200 million, according to DeFilLama data. On July 11, in an announcement, Gate apologized for the initial communication attitude, admitting that it “did not put users' feelings first”, and expressed understanding of users' anxiety and acceptance of criticism. At the same time, it continued to assist the police and provide legal resource support, but insisted that there were no platform security risks. Around July 17, the stolen user officially filed a case with the public security authorities. Since then, the two sides have blamed each other over the submission of evidence and the degree of lawyers' involvement and cooperation. The stolen user claimed that Gate repeatedly requested the format of judicial investigation materials, identity verification, etc., causing delays. Gate, on the other hand, said that users have repeatedly refused the intervention of the lawyers' team, focusing on putting pressure on public opinion rather than tracking down hackers, so they decided to directly arrange for lawyers to cooperate with the police. The core controversy, however, is whether authentication and manual review actually fail. The stolen user insisted that the mobile phone verification, Google Authenticator, and email address originally tied to the account were not leaked, that he had never submitted a handheld ID video or live experience, and that the device model did not match Gate's back-office records. Users disclosed surveillance videos in an attempt to prove that they had not operated some of the alleged face recognition periods. The user questioned Gate, saying that the attackers were able to completely reset security items and withdraw 1.7 million US dollars using only forged handheld ID data, live video of someone other than their own, and an inactive Alipay account with no strong binding relationship with Gate. This in itself indicates a problem with the platform's review chain. Gate, on the other hand, presents a completely different chain of evidence. The platform emphasizes that the materials submitted by the applicant are highly consistent, including real-name information, transaction flow, and recordings of key Alipay historical transactions. The Gate technical team believes that Alipay has extremely strict real-time risk control. Changing the device to log in will force multiple verifications. This screen recording can only be recorded by yourself or someone who can access the Alipay account. Combined with multiple notifications and withdrawal delay protection windows within 4 days, Gate concluded that the attackers had deep control over users' external information and device permissions. This was the result of serious information leaks or device control on the user side, rather than a systemic vulnerability in the platform. On August 3, Gate posted a screenshot of a third-party data breach database query, saying that it had obtained evidence of serious external leaks from users (including IMEI), and the lawyer would hand it over directly to the police. After community users responded “out of the box,” Gate clarified that the entire screenshot was coded to prove that it was not an internal leak. Subsequent sensitive materials were only submitted through formal judicial channels. On the same day, Han Lin, founder of Gate, wrote that lawyers have stepped in throughout the process and resolutely cooperated with the police. As long as the government determines that Gate is responsible, double compensation will never be avoided, and 3.4 million US dollars will be linked to the chain...

18d agoburnking
The aftermath of the Gate coin theft incident is still unresolved. Many executives left their jobs a few months before the explosion; Hynix plummeted; the meat cutting copywriting competition...

The aftermath of the Gate coin theft incident is still unresolved. Many executives left their jobs a few months before the explosion; Hynix plummeted; the meat cutting copywriting competition...

Dear readers, what have the KOLs on X been talking about in the past 24 hours? Note: The following content is compiled from the X platform. They are all personal opinions. They do not represent the platform's position, let alone constitute investment advice. The Gate user's coin theft incident made it difficult to calm public opinion. Many executives left their jobs a few months before it was revealed, and Hynix plummeted! Xi Jinping will attend the 2026 World Artificial Intelligence Conference and deliver a keynote speech at the Cut the Meat Copywriting Contest This article is sponsored by GENG, Build Your Fortune on GENG (https://geng.one)Twitter:https://twitter.com/BitpushNewsCN比推 TG Exchange Group: https://t.me/BitPushCommunity比推 TG Subscription: https://t.me/bitpush

39d agoWendy#KOL
Gate Owner Stole $1.7 Million: Who's Lying?

Gate Owner Stole $1.7 Million: Who's Lying?

The hottest topic of discussion in the crypto community over the past few days is the “theft case” of Gate users worth 1.7 million dollars. On July 8, an X ID user called “The First Beautiful Girl” (@jheioff) tweeted that the money in her Gate account was gone — 49.96 ETH, more than 740,000 HSK, and more than 1.56 million USDT, which added up to about 1.7 million US dollars. However, TA said that he hadn't received any verification codes from beginning to end, nor had face recognition, so the money just disappeared. Gate.io officially confirmed that the withdrawal actually occurred, but the statement given was completely different: the platform said that all operations had been fully verified, including face recognition, email verification codes, and fund passwords, and not a single step away. Both sides have thrown out a bunch of evidence, and both seem to have their share of it. There is no third party's conclusion on this matter until now, but all kinds of doubts and speculations have exploded. Let's take a quick look at the timeline of both parties. You'll find that the strangest part of this incident is that the details of the stories told by both sides are very specific, but there's just something wrong. Gate officially issued a detailed explanation on July 8, sorting out the entire process according to the timeline: on July 4, a new device initiated a request to reset the phone and email address. Gate requires live face verification, SMS verification code, and original email verification code. The reset was completed after all were passed. On July 5, the account party requested that the phone be untied. The customer service once again confirmed the face activity experience, and also requested the other party to provide a recording of the 2019 historical transaction (Alipay payment record) before unbinding. On July 6, the Google Authenticator was reset, and the login password and fund password were also changed—the email verification code and original fund password were verified at every step. On July 7, an old historical device (Mac web) logged in with the old passkey and then initiated a withdrawal to a new address. Gate asked again for a live face, Google verification code, and financial password, all of which passed. This address was then set as a “free verification address”, and 5 withdrawals were completed. On July 8, users only contacted customer service for the first time and said “funds have been lost”. Gate's conclusion is that this is not a system bug or platform security issue. All operations are traceable, are individual cases, and may be related to the user's own information disclosure. The victim's version is completely different: TA said he didn't actively reset or withdraw any security items from beginning to end. Gate claimed that the user used an iPhone to complete live face verification, but TA directly threw out a video of the home surveillance — in the picture, @jheioff was playing in the living room while holding the child, and hadn't touched the phone at all, let alone do any face recognition. @jheioff emphasized that this video can be submitted to the police and the judiciary for verification. Users claim that they don't have an iPhone 14 at all (the device mentioned in Gate records), and they haven't received any relevant notification emails or abnormal verification code alerts. Everything is fine with accounts on other exchanges; only Gate has problems. With the second round of clashes between the two sides, more details were shaken out, but it made things even more confusing. Gate further revealed that the IP for face recognition on July 4 was 42.200.39.1XX, and the device was an iPhone 14. The live test results were “low risk of inactivity” and “highly consistent” with the face on the KYC file. At around 3 a.m. on July 5, the account side also submitted a video showing the documents and handwritten documents for unbinding verification. At 9:26 p.m. on the same day, the 2019 Alipay recording was also submitted. Gate said that it had cross-checked with his transaction records and was accurate to the payment amount “22:28 on October 9, 2019.” The victims denied all of this: they used an iPhone 16 Pro, the old device was an iPhone 13, and there was no iPhone 14 at all; they went to bed at 3 a.m., and couldn't submit any videos; they didn't know the 2019 Alipay recording screen at all. However, TA acknowledged one detail — the Mac web login on July 7 is probably actually my own browser, because I am used to keeping the exchange page permanently in the browser. However, TA emphasized that the login was performed by the person himself, which does not mean that the latter operations were also performed by himself. What is the most likely cause? Right now, the community is most focused on three possibilities. The first is that AI face-swapping has bypassed face recognition. This isn't a sci-fi plot anymore. Deepfake technology in 2026 is very mature. As long as you have KYC photos or even a public video of the other party, you can generate enough...

43d agoWendy#AI #Gate #Exchanges #original #security #hacks

ZachXBT: Indian fraud gang suspected social workers stealing money and calling the police to track down and freeze funds

Comparing news, “on-chain detective” ZachXBT published a case study saying that in a crypto asset case involving an Indian fraud gang, the relevant personnel reported the case to the law enforcement authorities themselves after the assets were frozen, which attracted attention. The incident stemmed from a user asking for help, claiming that approximately 5.73 BTC (approximately $475,000) was frozen in Changelly in March 2025. Subsequent on-chain analysis showed that the funds can be traced back to a number of social engineering attacks targeting US users and theft cases involving Bitcoin ATMs. The cumulative amount involved has exceeded 1 million US dollars, and there are many elderly victims. The investigation revealed that there were many changes in the parties' explanations of funding sources, including different statements such as “loans,” “boss transfers,” and “2014-2015 investments,” and there are clear contradictions in the evidence chain. What is more interesting is that the user filed a police report in India in December 2025 to try to recover frozen funds (case no. 3207-P/2025). Subsequent on-chain forensics and email data analysis showed that it may be a “mule (money carrier)” for fund transfers, and some bank documents are inconsistent with their identity information. ZachXBT said that such cases showed that social worker attacks and cross-border fund transfers continued to occur, and reminded users to avoid interacting with funds from suspicious sources to avoid triggering compliance freezes or legal risks.

64d ago

Huobi HTX's “First Lesson of the New Year” Lecture 2 is about to begin: Special guest Xiao Sa will discuss asset security coping strategies in detail

Comparing news, the second course in the Huobi HTX “First Lesson of the New Year” series will officially start on January 27 (this Tuesday) from 7 to 8 p.m. Xiao Sa, senior partner of Beijing Dacheng Law Firm and a senior legal expert in the field of crypto assets, was invited to give a lecture on the theme “From 'Fearful and Fear' to 'Absolute Control' to Building an Unbreakable Wealth Moat”. The core highlights of the course include two major modules: one is to teach the “Gold Self-Rescue Method” to help participants respond efficiently through standardized procedures when assets are frozen or stolen; the other is to provide a loss relief roadmap to systematically explain the full path of asset recovery from on-chain tracking to legal assistance. The course will be broadcast live on the Huobi app. The recorded content can later be viewed by searching “HTX Live” on the B site and Zhihu platform to watch the full version, providing a comprehensive wealth risk control learning channel for crypto asset investors.

207d ago

Slow Mist Cosine: Hacker groups use stolen Telegram accounts to spread worms

Comparing the news, Slow Mist Cosine posted an article on the X platform stating that some hacker groups use worm transmission engineering to contact contacts in both Chinese and English after obtaining permission for Telegram accounts, and use fake Zoom conferencing software, toxic code warehouses, and drugged third-party tools or game software to poison target contacts. After completing the coin and account theft, the hacker group will continue to carry out the next round of operations and continuously optimize worm transmission engineering techniques.

211d ago
Panoramic review of the Bitcoin protocol layer in 2025

Panoramic review of the Bitcoin protocol layer in 2025

Source: ChainFeeds ResearchBitcoin Optech's annual summary has historically been viewed as a technical weather vane for the Bitcoin ecosystem. It doesn't focus on currency price fluctuations; it only records the most realistic pulsations of the Bitcoin protocol and critical infrastructure. The 2025 report revealed a clear trend: Bitcoin is experiencing a paradigm shift from “passive defense” to “active evolution.” Over the past year, the community was no longer satisfied with fixing bugs, but began to systematically address survival-level threats (such as quantum computing) and aggressively explore the boundaries of scalability and programmability without sacrificing decentralization. This report is not only a memorandum from developers, but also a key index for understanding Bitcoin's asset attributes, cybersecurity, and governance logic in the next five to ten years. Core Findings Looking at 2025, Bitcoin's technological evolution showed three core characteristics. This is also the key to understanding the following 10 major events: Preemption: Defense roadmap against quantum threats has become clear and practical for the first time, and security thinking extends from the “now” to the “post-quantum era.” Functional stratification: High-density discussions on the soft fork proposal and the “hot plug” evolution of the Lightning network show that Bitcoin is achieving the architectural goals of “stable at the bottom and flexible at the top layer” through hierarchical protocols. Decentralized infrastructure: From mining protocols (Stratum v2) to node verification (uTreexo/SwiftSync), significant engineering resources have been invested in lowering participation thresholds and improving censorship resistance, with the aim of countering the centralized gravitational pull of the physical world. Bitcoin Optech's annual report covers hundreds or thousands of code submissions, mailgroup discussions, and BIP proposals over the past year. To extract the real signal from technical noise, I excluded updates limited to “local optimization” and screened out the following 10 events that had a structural impact on the ecology. 1. Systematic Defense of Quantum Threats and the “Hardening Roadmap” [Status: Research and Long-term Proposals] 2025 marks a qualitative change in the Bitcoin community's attitude towards quantum computing threats, shifting from theoretical discussions to engineering preparations. BIP360 received a number and changed its name to P2TSH (Pay to Tapscript Hash). This is seen both as an important stepping stone on the quantum hardening route, and more generally serves certain Taproot use cases (such as promise structures that don't require internal keys). At the same time, the community thoroughly discussed more specific quantum security verification solutions, including using OP_CAT to construct Winternitz signatures, discussing STARK verification as a native scripting capability, and optimizing the on-chain cost of hash signature schemes (such as SLH-DSA/SPHINCS+) on the premise of introducing corresponding scripting capabilities in the future (such as re-introducing OP_CAT or adding signature verification operation codes). The reason this topic is at the top is because it touches on the mathematical cornerstone of Bitcoin. If quantum computing actually weakens the discrete logarithm hypothesis of elliptic curves in the future (thereby threatening the security of ECDSA/Schnorr signatures), it will cause systemic migration pressure and secure stratification of historical output. This forces Bitcoin to prepare an upgrade path ahead of time at the protocol and wallet layers. For long-term holders, choosing a hosting plan with an upgrade roadmap and security audit culture, and focusing on possible future migration windows will become compulsory courses in asset preservation. 2. Blowout of soft fork proposals: the cornerstone of building a “programmable vault” [Status: High Density Discussion/Draft Stage] This year was a high-intensity discussion year for soft fork proposals, focusing on how to unleash the expressive power of scripts while maintaining minimalism. Contractual proposals such as CTV (BIP119) and CSFS (BIP348), as well as technologies such as LUNHANCE and OP_TEMPLATEHASH, are all trying to introduce more secure “restrictive clauses” for Bitcoin. In addition, OP_CHECKCONTRACTVERIFY (CCV) became BIP443, and various arithmetic operation code and script recovery proposals are waiting for consensus. These seemingly obscure upgrades actually add new “laws of physics” to global value networks. They are expected to make the native “vaults (vaults)” structure simpler, more secure, and standardisable, so that users can set up deferred withdrawals...

242d agoWendy#2026 topics #Bitcoin protocol layer #Bitcoin layer #quantum computing

Slowfog Cosine: Leaked wallet private keys, etc. of some users of NoFX open source automated trading system

Comparing news, Yu Xian, the founder of Slow Mist, tweeted that friends using NoFX, an open source automated trading system, noticed that the risks we have disclosed have already occurred in actual coin theft incidents, and some users' private wallet keys and CEX/DEX API keys have been leaked as a result. In order to minimize risk, we and relevant security teams will notify affected users as much as possible before disclosing details in this article.

278d ago