Audit

Squid
2026-08-07 11:03:38

Squid’s token launch turned dramatic: funding, a hack three days later, and a Binance Alpha debut 74 days after

Cross-chain routing protocol Squid took an unusual path to token issuance. The project had already been running on mainnet for three and a half years, routing more than $6 billion in volume, before introducing its native token, QUID, in 2026. On May 22, Squid announced a $6 million strategic funding round led by North Island Ventures with participation from Ripple, bringing total funding to $13.5 million. Three days later, on May 25, a third-party Gnosis Safe module tied to the Squid name was exploited, with losses reported at roughly $3 million in the article’s headline framing and about $3.2 million to $4 million in the detailed account. The core routing contracts, according to Squid, were not affected. QUID’s public sale opened from June 30 to July 3 on Legion and Kraken at $0.045 per token, with a $2.25 million hard cap. The sale drew about $26.66 million in subscriptions, or around 11.9 times oversubscribed, from 3,542 participants across 78 countries. On Aug. 4 at 13:00 UTC, QUID held its token generation event and debuted first on Binance Alpha, followed by Kraken, Bitget, Upbit, Bithumb, MEXC, and later LBank, BingX, and XT. The token rose from its public sale price to a peak of $0.14 and was trading around $0.09 to $0.11 as of Aug. 7.

1260
Squid’s token launch turned dramatic: funding, a hack three days later, and a Binance Alpha debut 74 days after
Coinkite
2026-08-07 08:51:47

Coinkite Says It Will Publish Technical Post-Mortem on Coldcard Firmware Bug

Coinkite said it will release a detailed technical post-mortem on the Coldcard firmware vulnerability once security conditions allow. The company said the bug has already led to more than $100 million in confirmed losses, with about 1,596 bitcoin stolen from 7,300 addresses. It also said it cannot independently verify a separate estimate of roughly $130 million because of Coldcard’s privacy-first design, and that it is focused on helping affected customers while posting updates on its blog. Coinkite also said industry-wide AI-assisted security audits have uncovered multiple critical vulnerabilities in crypto software systems, according to Bloomberg.

900
Coinkite Says It Will Publish Technical Post-Mortem on Coldcard Firmware Bug
Bitcoin Red T
2026-08-06 01:16:58

Bitcoin Red Team Flags Nearly 5,000 Potential Issues in 390 Projects Within 29.8 Hours

Bitcoin Red Team, an all-volunteer security group, said it found nearly 5,000 potential issues during a rapid AI-assisted audit of Bitcoin ecosystem projects. The team consists of 16 volunteers, and its ranks include AnchorWatch CEO Rob Hamilton as well as bitcoin developer Calle. Calle explained that the group pairs AI tools with manual review to scan Bitcoin-related open-source codebases for vulnerabilities. That workflow produced an average of about one critical vulnerability per person per hour. Within 29.8 hours of the audit beginning, the team had reviewed 390 projects and logged 4,962 potential issues. Of those, 720 were classified as high severity or critical, and 21.4% of the findings have been reproduced so far. The remaining 78.6% have not yet been reproduced. The audit started a few days after the Coldcard hardware wallet incident, a security event in which more than $100 million in bitcoin was stolen. The numbers were relayed by Calle in his disclosure.

1000
Bitcoin Red Team Flags Nearly 5,000 Potential Issues in 390 Projects Within 29.8 Hours
ZEUS
2026-08-05 23:09:38

ZEUS Takes Infrastructure Offline After Cyber Incident, Says No Customer Funds Lost

ZEUS said it temporarily took its infrastructure offline after a cybersecurity incident in the past few hours, according to a statement relayed by Bitcoin News on X. The attack has been mitigated, but services will remain offline until the company completes a full security audit and resumes operations. ZEUS said no customer funds were lost and none are currently at risk. Customers whose Lightning Service Provider channels were closed will receive replacement channels after service is restored. The investigation so far indicates the incident appears limited to ZEUS's own infrastructure, with no evidence of a Lightning node software vulnerability. ZEUS also noted it has been using a trusted execution environment and the Validating Lightning Signer project to strengthen its infrastructure, with the project aimed at mitigating such attacks in its upcoming architecture. ZEUS said it would provide further updates as the investigation continues.

900
ZEUS Takes Infrastructure Offline After Cyber Incident, Says No Customer Funds Lost
ZEUS
2026-08-05 23:09:51

ZEUS Takes Lightning Infrastructure Offline After Security Incident

ZEUS said in a post published by Bitcoin News on X that a cybersecurity incident over the past few hours had led it to temporarily take its infrastructure offline. ZEUS said the attack has been mitigated, but services will remain offline until a full security audit is completed and operations are restored. According to ZEUS, no customer funds were lost and none are currently at risk. Customers whose Lightning Service Provider (LSP) channels were closed will receive replacement channels after services are restored. ZEUS noted that, based on the current investigation, the incident seems to be limited to its own infrastructure and there is no evidence that it was caused by a vulnerability in Lightning node software. ZEUS also said it has been using trusted execution environments and the Validating Lightning Signer project to strengthen its infrastructure, describing that project as aimed at mitigating such attacks in its upcoming architecture. ZEUS said it will continue to provide updates as the investigation progresses.

840
ZEUS Takes Lightning Infrastructure Offline After Security Incident
Trustworthy A
2026-08-04 12:25:36

Trustworthy AI Hackathon in Taipei sets Aug. 29 start, centers on agent identity and authorization

Taiwan Blockchain Enthusiasts Association chairman Taka Kao said the Trustworthy AI Hackathon was built around industry problems gathered from three closed-door expert sessions held on June 7, rather than topics drafted internally by organizers. Those meetings ran for a combined 24 hours and produced about 22 problem statements drawn from discussions with industry representatives and technical specialists. The event will run from Aug. 29 to Aug. 31 at N24 Taipei Ark in Nangang, Taipei, with Demo Day scheduled for Aug. 31. Registration closes on Aug. 5. Speaking at an Aug. 4 media tea session for the “2026 Trendy Taipei” technology festival, Kao said nearly 20 teams had already signed up at that point and final entrants would be selected afterward. Kao framed the challenge around a shift from “Responsible AI” to “Trustworthy AI” as agents move beyond code generation and content creation into autonomous actions such as signing legal documents, acting as digital twins, and coordinating across institutions. He said the association’s proposed direction is a credential-based model that combines digital identity, data governance, ownership, authorization, and accountability, so agents can act with verifiable permission on behalf of their owners. Organizers previously said the hackathon will offer prize money starting at $12,000, accept up to 20 teams, and, for the first time, allow individual registration.

960
Trustworthy AI Hackathon in Taipei sets Aug. 29 start, centers on agent identity and authorization
Texas
2026-08-04 11:25:49

Texas Orders Audit of Queued Data Center Projects, Pausing ERCOT Power Approval Track

Texas Governor Greg Abbott on Monday directed the Public Utility Commission of Texas and grid operator ERCOT to audit all data center projects currently in the state’s interconnection queue. ERCOT then paused its “Batch Zero” large-load approval process, which had been scheduled to release results this month. Data center applications now account for about 90% of ERCOT’s 474 GW interconnection queue, according to the report cited by ChainCatcher. In a client note published Tuesday, Bernstein analysts said the review is likely to curb speculative development and tighten incremental power capacity supply, increasing the scarcity value of already approved capacity. The firm said that dynamic could favor existing bitcoin miners and AI operators with secured access to power. Bernstein highlighted Cipher Digital, CleanSpark and Core Scientific as more exposed because their near-term expansion plans rely on Texas grid access, while Terawulf was described as more resilient due to power assets spread across Kentucky, Maryland and New York. Riot Platforms and IREN, which already hold large approved operating assets in ERCOT, were identified as potential beneficiaries.

1040
Texas Orders Audit of Queued Data Center Projects, Pausing ERCOT Power Approval Track
Coldcard
2026-08-04 10:52:57

Coldcard exploit sparks phishing wave as potential losses approach $130 million

Phishing activity aimed at hardware wallet users is picking up after disclosure of the Coldcard firmware flaw, with Trezor, Foundation and security firm Proofpoint all flagging new scams tied to the incident. Trezor said it has already seen more phishing attempts and reminded users that wallet backups should only ever be entered on the device itself, while stressing that its own hardware is not affected. Foundation reported emails impersonating the company and pushing victims to fake websites and malicious downloads, adding that it will never ask for a recovery phrase or tell users to install software to secure a wallet. Proofpoint said attackers are leaning on a “hardware audit” narrative lifted from the Coldcard incident. In the campaign it tracked on Monday, spoofed Coldcard emails directed recipients to a cloned site with a “Start Hardware Audit” button. Clicking it downloaded a GitHub-hosted batch file that installed ScreenConnect, a legitimate remote-access tool that can open the door to data theft, financial theft or follow-on malware, including ransomware. The fake site also featured a live chat operated by a human who guided victims through installation. Galaxy Research said the underlying flaw traces back to a March 2021 firmware build and has already been used in three confirmed theft waves since July 30, with high-confidence losses of 1,596 BTC, or more than $100 million. Including a suspected but unconfirmed fourth wave, total losses could reach $130 million.

210
Coldcard exploit sparks phishing wave as potential losses approach $130 million