Home Blog Page 51

Announcing a Trillion Dollar Security grant for WEBCAT

0

The Ethereum Foundation’s Trillion Dollar Security (1TS) initiative is proud to announce a grant allocation to Freedom of the Press Foundation (FPF) to support the continued development of WEBCAT. WEBCAT is an open source tool that lets browsers verify that code served by an enrolled website matches what its developers published. The grant will also help bring that protection to Ethereum wallets and apps.

Closing the front-end verification gap

The grant targets a gap in how web applications are secured today. HTTPS authenticates the site you connect to and encrypts the connection, but it does not prove that the code the site serves matches what its developers published. Without an independent integrity check, a browser can run an altered front end without warning.

For Ethereum users, the risk lies in the app’s website itself. Your browser loads and executes the site’s code when you visit. Tampered code there can swap the recipient address or ask you to sign something other than what the page showed. Your wallet cannot determine from the connection alone whether the page has been altered.

Trillion Dollar Security has identified front-end hacks as an infrastructure risk and verifiable front ends as a next step. Compromised web interfaces can expose users to supply-chain attacks and UI manipulation, and can increase the impact of incidents like DNS hijacks.

About WEBCAT

WEBCAT, short for web-based code assurance and transparency, lets a browser verify that the resources served by an enrolled site match a signed manifest. If verification fails, the current alpha Firefox extension prevents the page from loading and displays a warning.

Developers sign a manifest describing the files and other assets covered by each release. A distributed, verifiable enrollment system maintains a public record. For each participating site, that record holds a cryptographic fingerprint of enrollment information that specifies the site’s authorized signing identities and validation rules. The extension periodically downloads and verifies a snapshot of the record, so it can verify enrolled sites locally without contacting a third party on every visit.

FPF developed WEBCAT in part because a future version of SecureDrop will need verifiable browser code. SecureDrop is FPF’s open source submission system for secure communication between journalists and anonymous sources.

Today, SecureDrop encrypts submissions on the newsroom’s server as they are uploaded. The server handles unencrypted content during upload but stores submissions in encrypted form. FPF is developing an end-to-end encryption protocol for a future version of SecureDrop. Under the intended design, the source’s browser would encrypt message content before sending it, so the server would store ciphertext rather than hold plaintext in memory until encrypted by the server. The protocol remains under development and does not yet cover file attachments.

Because the encryption code would still come from the server, a compromised server could send altered code that captures content before encryption. WEBCAT is intended to detect and block that kind of alteration. FPF has also tested WEBCAT with other browser-based secure applications through proof-of-concept integrations.

The same code-integrity risk applies when Ethereum users interact with browser-based app front ends, which is why a tool built to protect sources and journalists also fits wallets and apps.

What the grant funds

The grant funds the development of a WEBCAT verification library that wallets can integrate.

A wallet that includes the library can verify enrolled sites, so users get the protection without installing a separate extension. The grant also funds research into supporting Chrome and other Chromium browsers, help for teams adding WEBCAT to their apps, an independent security audit, and an Ethereum Request for Comments (ERC) standard ERC so wallet developers have a standard to follow.

The library will complement other 1TS work, including Clear Signing. Clear Signing helps users understand what they’re approving, while WEBCAT integration would help wallets verify that an enrolled app’s front end matches its signed manifest.

What’s next for wallet and app teams

Bringing this verification into wallets requires adoption on both sides. Wallet extensions must integrate the library, and app teams must enroll their domains and serve a signed manifest with each release. If you’re part of a wallet or app team interested in front-end integrity, we’d love to hear from you at trilliondollarsecurity@ethereum.org.

Read more about risk controls and priority work at trilliondollarsecurity.org.

Bybit Secures Austrian E-Money License for EU Payments

0

Bybit’s European payments subsidiary has secured an electronic money institution license in Austria, providing the exchange with a regulatory basis to add payment and e-money services to its regional platform. 

On Tuesday, Bybit said Bybit Payments GmbH received the license from Austria’s Financial Market Authority. The authorization provides a legal basis for future payment capabilities, which may include person-to-person payments, merchant payment solutions, open banking features and card products.

The payment services will be offered through Bybit.eu alongside services provided by Bybit EU GmbH, a separate Austrian entity authorized under the European Union’s Markets in Crypto-Assets Regulation since May 2025. Bybit.eu serves users across the European Economic Area (EEA), with Malta excluded. 

Bybit has not specified the reason why Malta was excluded, but said on its website that services are available only in jurisdictions where applicable MiCA passporting requirements have been met.

Bybit said the two entities will maintain distinct regulatory permissions and responsibilities. Bybit EU GmbH is authorized to provide crypto custody, exchange, placement and transfer services, while Bybit Payments GmbH will handle regulated electronic money and payment products as they are introduced.

The exchange said the new regulatory milestone could help strengthen its relationship with banks, payment providers and enterprises while reducing its reliance on third-party payment infrastructure. 

Related: Crypto exchange Bybit launches in Indonesia after NOBI acquisition

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Taiwan Plans Crypto Travel Rule Rollout in October

0

Cointelegraph is committed to providing independent, high-quality journalism across the crypto, blockchain, AI, and fintech industries.

All news, reviews, and analyses are produced with full journalistic independence and integrity. For more details on our standards and processes, please read our Editorial Policy.

MiCA list expands with 12 companies in fourth post-deadline update

0

ESMA’s latest MiCA update brings the number of authorized CASPs to 321 and adds three entities to its non-compliant register.

An AI credit bubble could set up bitcoin’s path to $1 million

0

Arthur Hayes thinks everyone has the AI trade filed under the wrong category.

In a new essay, the co-founder of crypto exchange BitMEX and crypto fund Maelstrom said the ongoing infrastructure buildout is a credit story like 2008, not an earnings story like the 2000 dot-com bust.

Hyperscalers, or computing frms borrow against their massive data centers, are stuffed with chips that depreciate fast, and lenders bankroll it believing they are financing technology when the underlying asset is closer to real estate.

The break comes when announced capex stops accelerating, which he pegs for late 2027 into 2028. Credit keeps flowing well past that point, the way mortgage lending did into 2007, until the weakest AI debt cracks and drags down whoever is over-levered on it.

Hayes expects Washington and Beijing to backstop the wreckage in the name of national security, printing more than they did in 2008, and that flood of liquidity is what bottoms bitcoin and drives it toward $1 million.

The nearer-term call is that the recent AI selloff, Korea’s leveraged unwind included, is a dip inside a bull market.

Bitcoin traded near $64,200 on Wednesday, flat on the week and still stuck in the range it has held since May.

This chart says bitcoin’s biggest bragging right over S&P 500 and Nasdaq may be over

0

For years, bitcoin trounced stocks and most other assets, and supporters pointed to that outperformance as proof it was the best store of value around. Now, one chart suggests that edge may be fading.

That chart is the S&P 500-to-bitcoin ratio. It measures how much bitcoin it takes to buy the index. Today it takes roughly 0.12 BTC, versus more than 300 BTC in 2012. The ratio moved largely lower in a steep downtrend since BTC’s inception in 2010, with the 200-week simple moving average, a barometer of long-term trend, acting like a ceiling holding a ball underwater. There were brief instances of stocks outperforming BTC, lifting the ratio, but never beyond that average.

Until now.

In recent weeks, the ratio hasn’t just topped the 200-week average, it’s established a firm foothold above it, clearly visible on the far right of the chart above. It’s not isolated to the S&P, either. The Nasdaq/BTC ratio is showing the same first-ever crossover above the 200-week average.

Bitwise Says Crypto Will Thrive Even Without CLARITY Act

0

A failure to pass the CLARITY Act this week will put the bill in a “walking dead” state, but won’t stop the crypto industry’s march forward, according to Bitwise chief investment officer Matt Hougan. 

In a blog post on Wednesday, Hougan said while many, including himself, have called it the “make or break” week for the CLARITY Act, the reality is that the crypto industry has made too much progress to “go back in the bottle.” 

“The reality is that Washington is always late to major technology shifts, and it has rarely mattered as much as people feared,” said Hougan. 

His comments come as the Senate faces an Aug. 5 deadline to advance the landmark crypto market structure bill before its summer recess, with many concerned that failure to pass this week could see the bill pushed into the next year as lawmakers focus on the midterm elections in November. 

Prospects for CLARITY this year fade

Market observers are increasingly pessimistic about the CLARITY Act’s passage this year. In July, Galaxy Research lowered its probability of the CLARITY Act passing in 2026 to 30%, while Polymarket currently shows a 23% chance of it being signed into law this year, down from 82% in February. 

On July 24, NYDIG global head of research Greg Cipolaro said the latest draft was more complete but still lacked sufficient bipartisan support.

“The central investor takeaway is that Republicans have produced a substantially more complete bill, but not yet one with a credible path to 60 votes,” Cipolaro said.

According to sources speaking to Punchbowl News, without signs of progress from the White House on a bipartisan ethics deal, and movement on illicit finance and stablecoin yield, Senate Democrats will deny cloture for the crypto bill. 

Polymarket odds for the CLARITY Act passing in 2026 are at 23%. Source: Polymarket

Hougan said failure to pass the bill will put it in a “walking dead” state, stalled, but not permanently defeated. He said there is some hope that the bill could pass in September, or even in December, when Congress returns for a lame duck session.

“Congress often bundles multiple bills into a year-end “omnibus” package, forcing legislators to vote on a single bill that includes things they like and things they hate. Maybe the Clarity Act can pass that way.”

“Crypto will be fine,” Bitwise’s Hougan says

If the CLARITY Act fails to pass this year, Hougan said that the industry will fall back to the SEC-CFTC’s joint interpretation issued in March, which classifies Bitcoin and other assets as digital commodities and replaces the SEC’s 2019 staff guidance. 

SEC Chair Paul Atkins reinforced this last week, saying his agency is “ready, willing, and able to come out with rules that address the same issues as CLARITY and other aspects of the crypto market.” 

Related: CLARITY Act failure could send crypto valuations lower: Bernstein

However, the rules issued by the two regulators aren’t as durable as legislation, and could be challenged in court or reversed by a future administration. Atkins even acknowledged this in March when the two agencies released the interpretation. 

Source: Cynthia Lummis

“Only Congress can ensure that regulation in this area is future-proofed through comprehensive market structure legislation,” Atkins said.

WisdomTree chief legal officer Ryan Louvar has argued that the absence of legislation would continue to impede the market, despite the regulators’ efforts.

“A market cannot function well when its participants cannot tell in advance which agency’s rules apply to them,” Louvar said at a July congressional hearing.

Hougan said “crypto will be fine” despite this, as it would still give the industry two and a half years to accelerate before a new administration could potentially install a new SEC.

“Washington is dysfunctional. It seems crazy to me that we can’t get our act together to pass legislation that would improve investor protections and spark new innovation,” said Hougan.

“But it’s not a referendum on crypto’s validity as a pillar of the global financial infrastructure. That ship has long since sailed. At this point, crypto has enough momentum that it will reshape finance for decades, regardless of what happens in the next few days.” 

Magazine: CLARITY hopes fade, BitMEX shuts as lawsuit looms: Hodler’s Digest, July 26 

Bitcoin is 49% below its record while the S&P 500 hits all-time highs

0

SK Hynix rose 6.4% after the Seoul open and Nvidia added over 2% after hours, though AMD dropped 9% on a soft sales outlook and SpaceX fell 7.5% on higher projected AI spending.

Brent crude fell 1.1% to about $78.50 a barrel after Axios reported Washington, Tehran and Oman were close to an agreement to reopen the Strait of Hormuz, with an announcement targeted for Wednesday. Treasuries and gold both advanced as traders trimmed bets on further rate hikes.

Equities are printing records while bitcoin sits roughly 49% below the $126,000 it reached last October, and the second-largest asset is falling on the week.

Cheaper oil, easing rate expectations and a risk-on equity bid have now failed to move crypto for three straight sessions, which points the drag inward rather than at the macro.

Watch what happens if the Hormuz announcement lands Wednesday as reported. That is the cleanest macro catalyst crypto will get this week, and a market that cannot rally on a confirmed deal after failing to rally on the prospect of one is telling you the buyers are elsewhere.

Ethereum Proposal to Slash Staking Rewards Sparks Backlash

0

A group of six Ethereum researchers and developers, including Ethereum Foundation’s Justin Drake, has proposed changing the network’s issuance policy to cut validator rewards more sharply as the proportion of staked ETH rises. 

The draft, called the Tapered Issuance Burn and currently being assigned the provisional number EIP-8363, would burn an increasing fraction of validators’ consensus rewards as the amount of staked ETH approaches a fixed threshold of 60.25 million ETH (around 50% of the current ETH supply), at which point the deduction hits 100%. The changes would phase in over 18 months. 

Tapered Issuance Burn Ethereum Improvement Proposal. Source: Github

The proposal has triggered backlash from developers, stakers and DeFi founders, who warn that the reward cuts could force out solo validators before larger institutions are affected, weaken institutional demand for ETH, and disrupt DeFi markets built around staking yield. 

One of the proposal’s authors, Jérôme de Tychey, said the changes are needed to address the rising share of Ether being staked, which passed 33% in April. The authors argue continued staking growth could concentrate ETH in large custodians and liquid staking providers, while unchecked issuance erodes Ether’s role as a neutral, trustless store of value. 

“Ever-growing issuance is a dilution tax on every holder: stake, or be diluted. At high ratios, LSTs and other staking derivatives displace raw ETH as the ecosystem’s working money, thus swapping the most neutral, trustless asset for intermediated claims on issuers,” he said.

Although EIP-8363 remains an early draft, its publication just two days before a deadline for proposals targeting Ethereum’s Hegotá upgrade has also raised concerns about whether there is enough time to consider the impacts on Ethereum’s tokenomics.

EIP-8363 authors’ argument to cut issuance 

The proposal’s authors argue that under the current curve, staking yield never drops below 1.5% even with all ETH in existence being staked. 

“The incentive to stake never switches off. Where does it stop? It doesn’t,” said de Tychey. 

With no changes, a worst-case scenario could see more than 55% of Ethereum supply locked in staking by 2028, he said. 

“Maximal neutrality & minimal dilution: those are the two fundamentals of a store of value. This EIP not only hardens both, it sets a bar no other blockchain clears.” 

The proposed policy would see issuance peak at 0.5% of ETH supply per year at its highest (around 20% of ETH is staked), declining to zero when the staking ratio of Ethereum hits the 60.25 million ETH threshold. 

Related: Ethereum treasury firms lean on staking as ETF pressure builds: Report

“ETH supply growth will be bounded and more predictable. Combined with the EIP-1559 and Blob burn, the supply will more often decrease. Ethereum, the most mature of all the protocols, with a sustainable security budget, will also be the least dilutive of all protocols,” said de Tychey.

The proposal’s broader direction has also received support from Grayscale. In May, Grayscale’s head of research Zach Pandl said limiting staking incentives would be “positive for the price of Ether over time.”

Critics say it’s punishing Ethereum’s growth

Aave founder Stani Kulechov said reducing staking rewards would weaken institutional demand for ETH and borrowing activity across DeFi, arguing the proposal “doesn’t achieve the outcome it tries to achieve and is actually hurtful for Ethereum.” 

Another argument is that the proposal would impact solo validators as they have generally higher relative costs and are more susceptible to reward changes, leading to a more concentrated validator set. 

“This will self evidently push out solo stakers who aren’t subsidized by the EF or others,” said Mike Silagadze, CEO of Ether.Fi. 

“It will essentially guarantee that the only ones staking are large centralized entities with zero cost of capital where users passively hold their ETH.”

De Tychey disputed this point, saying on the Ethereum Magicians forum that users of large staking providers must pay fees, making those services less attractive as rewards fall, though he acknowledged the research on this is still contested. 

The proposed network update will lower ETH issuance and inflation. Source: Zach Pandl

Others pointed to the seemingly rushed timeline to consider the proposal, though this appears to be due to confusion over the upcoming deadline on Aug. 6. 

“This clearly doesn’t leave adequate time for community review of a monetary policy change of this magnitude,” said Greg Koumoutsos, a co-author of EIP-8148 and EIP-8205.

Where the proposal currently stands

The Tapered Issuance Burn proposal has not been approved, scheduled or included in Hegotá.

While there is an Aug. 6 deadline relating to this proposal, the deadline is for pull requests proposing additional EIPs for Hegotá, not a deadline for deciding which proposals will be included. 

Ethereum community organizer Trent Van Epps said the selection process could continue until Nov. 8, and that Hegotá is likely to reach mainnet in the second quarter of 2027.

Magazine: The 100x obsession: Fundamentals grow in importance as crypto matures

COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns

0

  • Galaxy Research has linked at least 1,596 BTC, worth over $102 million, to a flaw in COLDCARD wallet seed generation.
  • Investigators are tracking at least 15 attacker patterns, while a larger suspected set approaches 2,055 BTC.

A vulnerability in COLDCARD hardware wallets has been linked to the theft of at least 1,596 Bitcoin, pushing the estimated value of confirmed losses above $102 million (at current bitcoin price of $64,203).

Galaxy Research’s latest investigation, published on Aug. 3, traced the high-confidence theft set across roughly 7,300 Bitcoin addresses. The activity includes three major theft waves and at least 14 smaller incidents reported or confirmed by affected owners.

Bitcoin was trading near $64,027 on Aug. 4, valuing the confirmed total at approximately $102.2 million.

A broader pool of suspected activity reaches approximately 2,054.9 BTC, worth around $131.6 million at the same price. However, that figure includes pattern-matched transactions and a possible fourth wave that had not been confirmed by affected owners.

It should not be described as 2,055 BTC of confirmed COLDCARD theft.

Galaxy’s category-level chart accounted for approximately 1,590.9 BTC, around 5 BTC below its latest headline figure. The difference appears to reflect new victim reports and continued classification while the investigation was being assembled.

The cleanest current estimate is therefore Galaxy’s high-confidence total of 1,596 BTC.

More From AlexaBlockchain

At least 15 attacker patterns identified

Alex Thorn, Galaxy’s head of firmwide research, said investigators have identified at least 15 distinct transaction patterns associated with exploitation of the COLDCARD weakness.

That does not necessarily mean 15 individual hackers have been identified.

Galaxy is separating attackers through their onchain behavior, including how funds are consolidated, divided, routed and held. One operator could use several patterns. A single pattern could also represent a coordinated group.

The number is important because the incident no longer resembles one attacker discovering a weakness and sweeping a narrow group of wallets.

It increasingly resembles an expanding race to identify and drain vulnerable seeds before their owners can move the funds.

One victim who reported losing less than one bitcoin helped investigators identify what Galaxy calls “Footprint O.” Thorn said the previously unidentified pattern had drained approximately 12 BTC from 126 addresses.

Small victim reports are therefore helping investigators uncover larger clusters.

Galaxy reportedly has direct contact with around 80 victims. Those reports are central to the investigation because the affected addresses are dispersed across Bitcoin’s blockchain.

Unlike an exchange hack, the thefts do not originate from one known treasury address.

Galaxy maintains a broader triage list containing possible victims and suspicious transactions. Activity is only added to its headline estimate when investigators consider the supporting evidence sufficiently strong, often after an owner confirms that specific addresses were generated using an affected device.

Three large waves moved 1,367 BTC

The three largest known theft waves moved approximately 1,367.05 BTC.

The first wave was detected on July 30. An attacker swept 1,196 Bitcoin addresses in around 41 minutes, taking 1,082.65 BTC worth approximately $70.2 million at the time.

Two additional waves subsequently raised the observed large-wave total to 1,367.05 BTC across 4,585 addresses.

Galaxy said the coins associated with those three waves remained parked at tracked holding addresses as of its latest investigation.

The movement patterns differed considerably.

Wave 1 consolidated the stolen bitcoin through a relatively small number of funnel addresses. That produced a more concentrated and readable transaction graph.

Wave 3 divided the bitcoin among hundreds of staging and holding addresses.

That fragmentation makes the flow harder to monitor. It may also give the attacker more options for moving smaller amounts through bridges, exchanges, gambling platforms or informal liquidity networks.

The smaller suspected operators have already shown different laundering behavior.

According to Thorn, some stolen funds have moved through peel chains, THORChain and offshore gambling platforms. A peel chain repeatedly removes smaller amounts from a larger balance, leaving the remainder in a newly created address.

The technique complicates attribution by generating a long series of transactions.

In one case involving gambling platform Duel, the platform reportedly identified a depositor linked to the incident. The bitcoin had already been withdrawn before the funds could be frozen.

Traced does not mean recovered

Galaxy has shared roughly 600 suspected attacker addresses with federal investigators, exchanges, compliance companies, cyber investigators and the Security Alliance, commonly known as SEAL.

No public seizure, arrest, return of funds or successful freeze has been announced.

That distinction matters.

Bitcoin’s public ledger allows investigators to follow transactions after a theft. However, visibility does not provide control over the coins.

The large-wave funds that remain stationary are traceable, but they have not been recovered. The attackers still control the private keys.

Recovery becomes more difficult when bitcoin reaches a service that does not cooperate with investigators, operates in a loosely regulated jurisdiction or allows funds to be exchanged without robust identity checks.

Cross-chain conversion also creates additional complications.

Moving BTC through THORChain, for example, may allow an attacker to obtain an asset on another blockchain without depositing the bitcoin directly at a centralized exchange.

Investigators can still follow the transaction trail, but the process requires coordination across networks, analytics providers and service operators.

A deterministic fallback weakened wallet seeds

The underlying failure was not a break in Bitcoin’s cryptography.

It was a failure in the process used by affected COLDCARD firmware to create private keys.

Hardware wallets normally generate wallet seeds using highly unpredictable information supplied by a hardware random-number generator. The resulting recovery words control the private keys and therefore the bitcoin.

In the affected COLDCARD firmware, a configuration and software interaction caused seed generation to enter a deterministic MicroPython pseudorandom-number-generator fallback rather than using the expected hardware randomness.

Block’s Bitcoin Engineering and Security teams independently traced the problem after reports of active theft began appearing on July 30. Block said the vulnerability could allow an attacker to recreate candidate output streams under certain assumptions about a device’s identifier, timer state and earlier random-number-generator calls.

An attacker could generate possible seeds offline, derive the corresponding Bitcoin addresses and compare them with publicly visible addresses holding funds.

No physical access to the victim’s hardware wallet would necessarily be required.

The vulnerability was introduced after COLDCARD moved wallet-generation operations to a library called libNgU in March 2021. Block’s technical timeline shows that the vulnerable path was present in firmware version 4.0.0, while additional reseeding behavior was introduced for the Mk4 in 2022.

Coinkite described the cause as a complex chain of bugs that prevented the hardware random-number generator from contributing the intended randomness.

In simple terms, Bitcoin’s private-key system remained intact.

Some private keys were simply created from a much smaller range of possibilities than their owners expected.

Mk2 and Mk3 seeds face the highest risk

The most severely exposed seeds were generated on COLDCARD Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9.

Coinkite estimates that the affected Mk3 process may provide roughly 40 bits of effective search space under its assumptions. That is drastically weaker than the 128-bit target associated with a properly generated 12-word BIP-39 seed.

Later models received additional entropy from secure elements, reducing the severity but not eliminating the problem.

Coinkite said seeds generated on the Mk4 and Mk5 before firmware version 5.6.0, or on the COLDCARD Q before version 1.5.0Q, may contain approximately 72 bits of entropy rather than the intended 128 bits.

The affected firmware version is the version used when the seed was created.

Installing safe firmware today does not retroactively strengthen an old seed.

Restoring the same recovery words on a new COLDCARD, another hardware wallet or a software wallet also does not solve the problem. The vulnerability follows the seed words because those words encode the weakly generated private-key material.

Coinkite has released fixed firmware for each affected product line. However, the company says owners must generate an entirely new seed after installing the corrected firmware and transfer their funds to addresses controlled by that new seed.

Does this undermine the hardware-wallet safety narrative?

The incident will test one of the crypto industry’s most persistent security messages: that hardware wallets are safer than exchanges or internet-connected software wallets.

That message remains broadly defensible, but it needs qualification.

A hardware wallet isolates private keys from everyday laptops, browsers and smartphones. This can reduce exposure to malware, remote-access tools, phishing sites and compromised wallet extensions.

However, a hardware wallet is not automatically secure simply because the key is stored offline.

Its security also depends on firmware quality, random-number generation, supply-chain integrity, signing-screen accuracy, update procedures and how the owner creates and backs up the seed.

The COLDCARD incident exposes a particularly damaging failure because it affected the point at which the wallet’s core secret was born.

Air-gapped signing, secure elements and offline storage cannot protect a key that an attacker can recreate through a reduced search space.

The case therefore does not prove that software wallets or exchanges are safer.

It shows that “hardware wallet” is a product category, not a security guarantee.

The Bybit theft in February 2025 provided another warning about that distinction. Attackers stole $1.5 billion in Ether during a transfer involving an exchange cold wallet, making it the largest publicly reported crypto theft at the time. Investigators said the compromise manipulated the signing process rather than breaking Ethereum’s underlying cryptography.

Both incidents involved systems generally described as offline or cold storage.

The weaknesses were different. Bybit faced an institutional signing and operational-security compromise, while COLDCARD users were exposed through defective seed generation.

In each case, the protective label concealed a more complicated security stack.

Crypto exploits remained large in 2025 and 2026

The COLDCARD losses add to two years of major infrastructure, wallet and protocol compromises.

Bybit’s $1.5 billion theft dominated 2025. The incident also showed how one compromised workflow could bypass multiple institutional controls attached to a cold-wallet transfer.

Cetus, a decentralized exchange on the Sui network, suffered an exploit of approximately $220 million in May 2025. The incident contributed to $2.5 billion in crypto hack and scam losses during the first half of that year, according to CertiK.

Indian exchange CoinDCX disclosed the theft of approximately $44 million from an internal operational account in July 2025. The exchange said the stolen USDT was routed through several hops before reaching two principal wallets.

The attacks continued in 2026.

In April, an exploit involving KelpDAO and LayerZero infrastructure drained approximately $290 million in rsETH. Galaxy described it as the largest DeFi exploit of 2026 at the time, with knock-on effects across Aave lending markets.

Ostium subsequently lost around $24 million in a July exploit, according to Galaxy’s research index.

The incidents span different failure modes: compromised institutional signing, faulty smart contracts, operational-account breaches, bridge vulnerabilities and weak private-key generation.

The common theme is that attackers increasingly target the infrastructure surrounding cryptography rather than attempting to break the cryptographic algorithms themselves.

What COLDCARD owners should do

Users who generated a seed on an affected COLDCARD should not assume that installing an update is sufficient.

Coinkite recommends installing the fixed firmware for the applicable device before generating any replacement seed. The corrected versions include 4.2.0 or later for Mk2 and Mk3, 5.6.0 or later for standard Mk4 and Mk5 devices, and 1.5.0Q or later for the standard Q release. Separate fixed versions apply to the Edge firmware track.

Owners should then create a completely new seed.

They should record and verify the new backup, confirm the wallet fingerprint and verify a receiving address directly on the hardware-wallet screen.

A small test transaction should be sent first. The remaining balance should only be moved after the test transaction has arrived and the new wallet can be restored successfully.

The old seed backup should not be destroyed until the entire migration has been confirmed.

Users should never enter their recovery words into a website claiming to test whether a seed is vulnerable. Attackers are likely to exploit the public warning through fake migration tools, support accounts and phishing pages.

The COLDCARD PIN is also not the same as a BIP-39 passphrase.

Coinkite says a strong, unique and separately stored BIP-39 passphrase can create an additional barrier. However, a weak, reused or predictable passphrase may be guessed, and even a strong passphrase does not repair the affected seed.

Seeds created with at least 50 fair, independent and private dice rolls may not be exposed to this specific randomness failure alone. Users who do not clearly remember how the seed was created should treat it as potentially affected and migrate.

Larger holders should also reconsider reliance on one seed and one manufacturer.

A properly configured multisignature wallet can reduce the risk that one defective seed-generation process compromises all funds. However, Block warned that multisignature setups composed entirely of vulnerable COLDCARD devices may remain exposed. A secure quorum must include independently generated keys that are not affected by the flaw.

An ongoing security incident

The COLDCARD theft has already crossed nine figures, but the final loss may take weeks or months to establish.

More vulnerable wallets may remain funded. Additional attackers may be scanning the blockchain for addresses derived from weak seeds. Some victims may never contact investigators or may not yet know why their coins disappeared.

The difference between Galaxy’s confirmed and suspected sets is therefore likely to remain important.

A transparent accounting should distinguish victim-confirmed thefts from transactions that merely resemble the known attacker patterns.

The investigation also leaves broader organizational questions for Coinkite and the hardware-wallet industry.

The vulnerable path existed in publicly available firmware for years. It was not detected before attackers apparently began using it at scale, despite open-source review and growing use of artificial intelligence for code auditing.

Coinkite said an AI model it used to review the firmware before the disclosure did not find the bug. The company has suggested that attackers may have used similar tools to inspect older code, although no public evidence has established exactly how the weakness was discovered.

The episode is therefore not only a warning about one wallet.

It is a warning about security claims built around individual features.

Offline storage, secure elements and open-source firmware can all improve safety. None of them replaces verified randomness, independent audits, cautious key generation and a migration plan when a foundational assumption fails.

The coins still sitting in attacker-controlled addresses remain visible.

They are not yet recovered, and the theft may not be over.

The above article “COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns” was first published on AlexaBlockchain. Read the complete article here: https://alexablockchain.com/coldcard-bitcoin-theft-tops-102m-as-investigators-track-at-least-15-attacker-patterns/

Read Also: This is the First U.S.-Chartered Depository Bank to Offer Stablecoin Invoicing

Disclaimer: The information provided on AlexaBlockchain is for informational purposes only and does not constitute financial advice. Read complete disclaimer here.