硬件钱包 · 792

BitBox: AI Finds Serious Vulnerabilities in Its Firmware, Updates to Fix It Have Been Released

According to Decrypt, Swiss hardware wallet manufacturer BitBox discovered two serious firmware vulnerabilities and a bootloader issue during an internal AI audit, and has released a security update for Dixence. Exploitation of the exploit requires a combination of phishing attacks and users unlocking the tampered device, but BitBox indicates that no user funds have been stolen, and the mnemonic phrase is unthreatened. A bootloader vulnerability affects the old BitBox02. Attackers can load malicious firmware to steal assets. This issue has been partially fixed in the July Oeschinen update; the second serious vulnerability affects the pre-initialization stage of Multi version devices and may allow arbitrary code execution; and the third issue involves the silent payment function, which cannot directly steal coins but may lock funds. The new Nova version is unaffected. BitBox warns users of old firmware to install updates as soon as possible, and there are currently no reports of loss of user funds.

3d ago

New developments in the Coldcard coin theft incident. The identity of the first wave of attackers may have been captured by the FBI

Comparatively, according to Bitcoin Magazine, the investigation into the large-scale coin theft incident of the Coldcard hardware wallet in July 2026 progressed. In the first wave of attacks, about 1082.65 BTC (about US$118 million) were still stored at the attackers' addresses. The investigation found that the attackers used a paid account with a blockchain data service provider. Internal logs “highly consistent” with the coin theft model, and related clues have been handed over to law enforcement. Galaxy Research analyst Alex Thorn said that the identity of the first wave of attackers “may have been captured by law enforcement.” A total of about 2,000 BTC were stolen in subsequent waves of attacks, of which about 76 BTC was stolen in the second wave. The operation mode was similar to the first wave, and it was probably the same actor. The incident stemmed from an entropy generation vulnerability introduced by Coinkite in the March 2021 code update. As a result, some devices using MK2 and later models, firmware 4.1 and above generated low-strength private keys, and seeds can be violently cracked. Coinkite has released fixed firmware and advised users to migrate assets, but the extent of the vulnerability is still being assessed.

3d ago

A user's CEX account lost $750,000 in BTC due to Google verification cloud sync issues

According to GoPlus monitoring, according to GoPlus monitoring, a Bitcoin holder has just safely transferred assets from a Coldcard MK4 hardware wallet to a centralized exchange to avoid the risk of the hardware wallet itself being stolen, but his Google account was hacked within 12 hours after the transfer was completed. As a result, the exchange account was logged in and about 750,000 US dollars of bitcoins were emptied because Google Verification Cloud sync was enabled. GoPlus points out that such attacks usually do not rely on brute force cracking, but are achieved through social worker phishing and weak password crashing into databases. Common routes include: phishing pages inducing the input of Google passwords, malicious browser plug-ins or cracking software to steal cookies and passwords, reuse weak passwords, and resetting passwords after email or phone numbers have been taken over.

6d ago
Is the myth of “absolute safety” debunked? Trezor 14,000 encrypted user information leaked, a “wrench attack” is approaching

Is the myth of “absolute safety” debunked? Trezor 14,000 encrypted user information leaked, a “wrench attack” is approaching

DID YOU KNOW? Buying a hardware wallet is probably more dangerous than posting luxury cars on social media. Because from the moment you place an order, your name, phone number, and address are permanently tied to the “hold crypto assets” label. And this information is probably lying in an Excel table from a dark web seller right now. Trezor customers are being targeted. On August 13, the hardware wallet giant confirmed that its logistics partner ShipMonk had been accessed without authorization, and 11,742 customers' names, emails, phone numbers, and full delivery addresses had been obtained; the names, cities, and emails of 1,947 other customers had been leaked, for a total of 13,689 people. The affected users are located in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Note that Trezor's own system hasn't been broken, the hardware wallet is still safe, and the private keys are fine. So what's the problem? The reason — buying Trezor became a “target” in itself. This instantly turned an ordinary logistics database into a “list” in the eyes of potential attackers. From a phishing email to someone knocking on your door, there have been quite a few things that have happened in the crypto industry. In 2020, Ledger's e-commerce and marketing database was leaked. More than 1 million email addresses were leaked, and details such as the names, addresses, and phone numbers of about 272,000 customers were later made public. Since then, Ledger has had to remind customers for a long time to prevent phishing emails and scams impersonating official websites. But today in 2026, things aren't just about the internet. According to data released by Chainalysis in August this year, by the end of June, the world had recorded 46 violent attacks against crypto asset holders; more than half involved kidnapping, and more than one-third involved house robberies. Since 2026 alone, more than $30 million in crypto assets have been successfully stolen through violent coercion. Insiders call it a “$5 wrench attack” ($5 wrench attack). The name has a bit of dark humor, but the logic is scary: Hack a hardware wallet? It's so hard. But if I know you have coins and know where you live, then I only need to spend 5 dollars to buy a wrench and say “please” the mnemonic phrase at the door. In January 2025, Ledger co-founder David Balland and his partner were kidnapped at their home in France. The kidnapper demanded a cryptocurrency ransom and severely maimed Balland's hand. French police later rescued two people, and several suspects were arrested. In November 2025, Danylo K., the son of the deputy mayor of Kharkiv, Ukraine, and a 21-year-old student, was kidnapped in Vienna, tortured for a long time to obtain a password for his wallet, and then burned to death in gasoline. The suspect was later arrested in Ukraine and the associated crypto account has been emptied. There is also an American cross-state violent robbery gang. Several suspects are accused of posing as delivery workers or pizza delivery in California and other places, bundling and assaulting victims, and forcing money transfers. In one case, about 6.5 million US dollars of crypto assets were extorted in a single transaction; other gangs carried out similar attacks in several states, with cumulative losses of millions to tens of millions of US dollars. The latest one is even more outrageous: a young couple in the French province of Somme (farmers and bank employees, who don't play with coins at all) bought a second-hand house. The former homeowner is a retired crypto-rich man. After the former landlord's tax information and old address were leaked to the dark web, from June 24 to July 17, 2026, they were robbed three times in less than a month. Although the two suspects have been jailed in the local court, the victim's lawyer pointed out that the dark web leak made the new owners innocent, and the couple are now preparing to sell their house and move. This is where the “wrench attack” is really scary. You don't need coins; as long as others “think” you have them, you're no longer safe. After “Not your keys, not your coins,” the next problem was actually two weeks before Trezor's launch. Another wallet manufacturer, Coldcard, had just experienced a key generation vulnerability crisis. Galaxy Research later estimated that related losses had reached about 130 million US dollars. As a result, Galaxy made a very interesting judgment: self-hosting does not eliminate the risk of hosting; it only transfers the risk to hardware, software, and key generation. And this time, Trezor has taken the risk one step further: the risk will also be transferred to the logistics company, order database, your mobile phone number, and your home address. Hardware wallets can be signed offline, so that private keys never touch the internet, but from the moment the user places an order, they have already entered the other...

7d agoBitpushNews#Trezor #mnemonic #original #Bitcoin #hardware wallet #private key

Galaxy Research Director: Coldcard security incident impacted the Bitcoin community, industry security ideas may usher in a turning point

Comparing news, Alex Thorn, head of Galaxy Research, said on the X platform that attacks against the Coldcard hardware wallet vulnerability have now declined significantly, but cumulative losses continue to rise as more victim reports appear. The incident had a huge impact on the Bitcoin community, as the victims were mainly users who have held BTC for a long time and adhere to the concept of self-hosted cold storage, rather than loss of assets due to participation in high-risk transactions or DeFi activities. At a scale of $112 million, this incident has become one of the top 20 most expensive hacking incidents in crypto history, and is also one of the worst security incidents in the field of hardware wallet self-hosting so far. Bitcoin culture may have entered a new phase as a result. In the past, methods that relied solely on the dissemination of ideas and extreme self-hosting propaganda are coming to an end. The community needs to pay more attention to technical security, lower the entry threshold for users, and avoid simply blaming ordinary users for security responsibilities. This crisis may eventually push the Bitcoin ecosystem to establish a more mature security system. Galaxy Research has now directly contacted 190 victims and highly confirmed that the vulnerability incident has led to the theft of 1778.84 BTC (approximately $1127 million) from more than 8,600 addresses. This statistic does not include records of some moderately credible suspected attacks, such as “Wave 4,” which has yet to be confirmed. If these potential attacks were included, the scale of losses could increase to 2417.35 BTC (approximately $153 million). At the same time, the incident is changing the market's perception of self-hosted security. Galaxy said that multi-signature wallets (multisig) became the “winner” in this incident, and up to now, not a single stolen transaction came from a multi-signature wallet. Multi-signature service providers including Casa, Unchained, Nunchuk, and Anchorwatch all observed significant increases in user registrations and BTC inflows.

7d ago
Kimi K3 Coin Circle Diagnosis: Scanned 501 Projects and 1,280 High-Risk Hazards in Two Weeks

Kimi K3 Coin Circle Diagnosis: Scanned 501 Projects and 1,280 High-Risk Hazards in Two Weeks

Author: Claude, Deep Wave TechFlow Original title: Kimi K3 Coin Circle Diagnosis: Sweeping 501 Bitcoin Projects and 1280 High-Risk Hidden Hazards Deep Wave Guide: A volunteer “Bitcoin Red Team” used Kimi K3 from the dark side of the Moon to sweep 501 Bitcoin open source projects in two weeks, recording 7958 discoveries, of which 1,280 were rated as high-risk or serious. The Chinese model did this because OpenAI and Anthropic rejected these defenders on security grounds. If your coins are in a wallet or node software that hasn't been updated in years, this is worth reading. On August 13, Calle, a member of Bitcoin Red Team and founder of the Cashu Protocol, summed up the phased conclusions of this operation on X, and the tweet received nearly 260,000 views. His original statement was straightforward: “Decades of open source code collided with two weeks of Kimi K3, and the result was that everything was broken and Bitcoin was burning.” It all started with a $100 million wallet bug on July 30. The hardware wallet Coldcard was revealed to have a firmware flaw: the device fell back to a predictable software process when generating mnemonics. The security chip only provided 32 bits of entropy, and there were only about 4.3 billion possibilities left in the effective key space. The attackers followed the map and emptied users' wallets in multiple waves, confirming losses of more than $100 million, and the total loss is suspected to be close to $130 million. Bitcoin Magazine issued a rare “Immediate Transfer of Funds” emergency notice. This disaster directly spawned the Bitcoin Red Team. Calle and Rob Hamilton, CEO of escrow insurance company AnchorWatch, led by dozens of contributors. The non-profit organization OpenSats reimbursed most of its computing power expenses and conducted an AI audit of almost the entire Bitcoin open source ecosystem. After cleaning 501 projects in two weeks, the discovery was not equal to a bug. By August 8, the team spent hundreds of hours cleaning 501 projects, recorded 7,958 discoveries, and 1,280 were rated as high-risk or serious. These numbers need to be broken down: on the 108th hour node, only 24.7% of findings were dynamically reproduced, 29.4% were reported to the project party, AI audits would be misreported and repeated, and manual verification was still ongoing. However, the “moisture theory” cannot stop the toughest case. According to the official release records of the payment software BTCPay Server, a serious vulnerability (two-factor authentication bypass) reported by Red Team members Bruno Garcia and Ben Carman was actually exploited before it was fixed. The attackers used this to obtain the node's management credentials, thereby controlling the associated Lightning Network wallet. BTCPay released two secure versions in a row. The community set up recovery rewards for victims, and the foundation allocated another 0.21 bitcoins to the Red Team Fund. The maintainers used their actions to vote of confidence in this group of findings. The American model is apologizing, and the Chinese model is looking for loopholes. Why is the main force Kimi K3 and not GPT or Claude? Because American models don't take on this job. Rob Hamilton stated that after completing all authentication, he used OpenAI's model to analyze a publicly disclosed codebase and was rejected in less than 20 minutes. The comparison between Bitcoin's core contributor PortlandHodl went viral in the community: in the same code, America's leading model's answer was “You're right!” China's open source model directly identified 78 serious vulnerabilities. Hamilton's comment is even more serious: “I'm basically asking Xi not to let my software be hacked right now.” On August 10, more than 70 custodians, exchanges, mining companies, and development organizations jointly signed an open letter from the Bitcoin Policy Institute requesting that cutting-edge AI labs open access to credible defenders. Alex Thorn, head of research at Galaxy, wrote in a joint message: “Americans should not be forced to rely on Chinese AI to protect themselves. The red team needed these models.” However, we also need to pour cold water on the carnival: a joint evaluation by the British AI Security Research Institute and CAISI in the US showed that Kimi K3 was better than GLM-5.2 in vulnerability development tests, but it still lags behind the strongest closed source model in the US. The defense didn't choose the strongest one,...

8d agoburnking#AI #Anthropic #OpenAI #Bitcoin #wallets

Hardware wallet Trezor customer data was leaked by carriers, and sensitive customer information was stolen from over 13,000 customers

According to Twitter news, hardware wallet Trezor revealed that its fulfillment partner ShipMonk had a data breach that resulted in the personal data of 13,689 Trezor customers being exposed. Of these, 11,742 people's full names, phone numbers, email addresses, and delivery addresses were stolen, and 1,947 people's names, cities, and mailboxes were leaked. The affected customers all placed orders between May 10 and August 8, and delivery addresses include the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor stressed that its own systems have not been compromised, that device, private keys, and wallet backups have not been affected, and that the scope of the leak is currently under control. Trezor warned affected customers to be wary of phishing attacks, never enter wallet mnemonics or backups online, and be suspicious of any unexpected contacts. This article is sponsored by GENG, Build Your Fortune on GENG (https://geng.one)

9d agoburnking

Approximately 233,000 bitcoins were transferred to safe haven, and the Coldcard attack involved about $15 billion

Comparatively, after the Coldcard hardware wallet firmware vulnerability was exploited, about 2,100 bitcoins were stolen, and the loss was close to US$130 million. According to on-chain data, long-term holders' wallets transferred about 233,000 bitcoins worth about $15 billion a few days before and after the incident. Nick Neuman, CEO of Casa, said that some of the funds transferred came from Coldcard users migrating to multi-signature wallets, while Ledger and Trezor users also took the same steps after the incident. Approximately 22,000 bitcoins were transferred to the exchange during the same period. Coinkite has asked users who use the 4.1 to 4.1.9 firmware to generate mnemonics to consider the relevant wallet to be compromised and immediately migrate to the new mnemonic. The above version covers March 2021 to July 2026.

9d ago#On-chain dynamics

The Coldcard vulnerability boosts the weekly increase of new Bitcoin addresses by more than 330,000

Comparatively, according to The Block, the number of new Bitcoin addresses climbed from about 260,000 to over 330,000 last week due to wallet migrations caused by the Coldcard vulnerability, reversing the downward trend of most of 2026. Since July 30, Coinkite hardware wallet users have lost at least 1,816 BTC (approximately $116 million) in four waves of attacks. The vulnerability stemmed from a 2021 firmware flaw — a less secure software random number generator was used to generate mnemonics rather than the device's built-in hardware entropy source, and attackers can violently crack wallets generated offline. Coinkite has recommended that users who generate wallets between March 2021 and the release of the security patch migrate to the new wallet. This incident highlights the risks of implementing autonomous escrow, and users are re-evaluating the advantages and disadvantages of custodian solutions such as autonomous and centralized exchanges or ETFs.

10d ago

Coldcard hack damage estimated at 1,816 bitcoins, CryptoQuant confirms 1,432

Comparing news, the hardware wallet Coldcard was hacked, and the total amount of losses has not yet been determined. Blockchain analysis platform CryptoQuant confirmed the loss of 1,432 bitcoins, and Galaxy Research gave a highly credible minimum value of 1,730 bitcoins. Other analyses suggest that the scale of the losses may have been higher. Research agency Galaxy Research said its earlier estimate of 1,816 bitcoins is a potential value and is not a confirmed total amount. As of Tuesday, the agency confirmed a high credible minimum loss of 1,730 bitcoins, of which more than 450 bitcoins were confirmed directly based on victims' reports. Blockchain intelligence firm TRM Labs estimates that the attackers transferred approximately 5,200 bitcoins from more than 1,816 addresses in four stages. CryptoQuant said its confirmation data only included addresses publicly disclosed by victims and verified by an on-chain model, and the statistics are likely to rise as more victims disclose information. This article is sponsored by GENG, Build Your Fortune on GENG (https://geng.one)

11d agoburnking#On-chain dynamics