SlowMist2026-09-22 03:10:39SlowMist and OKX say App Store-listed FomoPeek versions 1.1 and 1.2 carried an iOS exploit frameworkSlowMist and the OKX security team said their joint analysis found that FomoPeek, an on-chain whale-tracking app distributed through Apple’s App Store, included a full iOS kernel attack framework in versions 1.1 and 1.2. According to the report, users did not provide mnemonic phrases and did not sign any transactions, yet their assets could still be stolen. SlowMist’s MistTrack data showed a main hacker address active since Sept. 15 that had received 579,984.34 USDT as of publication, with funds still flowing in. The researchers said the malicious components were shipped inside the official App Store builds rather than spread through re-signing or sideloading, and that the framework could communicate with attacker-controlled servers, exploit kernel flaws, escape the sandbox, decrypt Keychain data and collect information across apps. The report also said the command-and-control server targeted 19 wallet and note-taking apps, including Gate Web3, SafePal, OKX Wallet, MetaMask, Trust Wallet, imToken, TokenPocket, TronLink and Apple Notes. SlowMist advised users who installed versions 1.1 or 1.2 to treat old mnemonic phrases and private keys as compromised and move assets to a newly created wallet on a clean device.790
Coldcard2026-08-20 15:28:53Coldcard rolls out new firmware after mnemonic generation security reviewColdcard has released firmware 5.6.1 for Mk4 and Mk5 devices and version 1.5.1Q for the Q model, following a three-week security review after an emergency fix. The update is aimed at reducing the risk tied to a previously disclosed mnemonic-generation attack. Under the new rules, every newly generated seed phrase must include at least one source of user-provided entropy, either through at least 65 irregular key presses, 50 physical dice rolls, or 128 physical coin flips. That input is then combined with fresh entropy from STM32 TRNG, SE1, and SE2. The firmware also adds staged PSBT verification immediately before signing, tightens USB connection and firmware-update boundaries, improves Delta Mode isolation, fixes an active wallet backup issue, strengthens random number generator initialization and fault checks, and changes the default SIGHASH setting. Coldcard said the release is meant to cut the risk of device compromise. The company also warned that updating firmware does not repair seed phrases created by affected older firmware. Users covered by the security notice are advised to update first, generate and verify a new mnemonic, then move funds to a new wallet. Coldcard recommended that all Mk4, Mk5, and Q users update promptly and verify firmware signatures before installation.1290
Binance2026-08-11 05:06:57Binance Wallet Extension Adds Support for Creating Mnemonic Phrase WalletBinance Wallet Extension now supports creating a mnemonic phrase wallet directly inside the extension. The update also lets users import an existing mnemonic phrase wallet. This feature was reported via Foresight newsflash.1750
Changpeng Zha2026-08-03 06:20:57CZ shares mnemonic backup guide first written in 2020 and updated in 2025Changpeng Zhao, known on X as @cz_binance, said he has shared an article on how to back up wallet mnemonic phrases, a guide he originally wrote in 2020 and updated in 2025. Zhao said the piece goes through several backup methods in detail and, despite its length, is worth reading. The guide focuses on one of the most important security elements in crypto wallets: the mnemonic phrase, whose storage and recovery setup can directly affect asset safety. According to the Techub News item, the article also offers specific backup recommendations for different usage scenarios, aiming to help users strengthen how they protect their crypto holdings. The update puts renewed attention on self-custody practices and the practical steps users can take to reduce the risk tied to losing or exposing wallet recovery information.370
Coldcard2026-08-01 16:41:01Coldcard features may remain exposed to Yasmarang PRNG flaw even if seed phrase is safeBitcoin News said in a post on X that several Coldcard functions may still be vulnerable because of a flaw in the Yasmarang pseudo-random number generator, even when the seed phrase itself remains secure. The post said mnemonic phrases generated by rolling dice enough times, or seed phrases imported from an existing source, are still safe on their own. The issue instead affects other secrets created through the device’s flawed randomness. Functions named in the post include paper wallets, device cloning, USB sessions, Secret Teleport, multisig keys, the password generator, and HSM mode. The warning suggests that protecting a mnemonic phrase through manual dice rolls does not fully shield every feature on the hardware wallet if those features depend on the affected random number generator.1980
BNB Chain2026-08-01 10:16:49BNB Chain says former employee used previously created wallet in new token incidentBNB Chain said on X that a wallet address at the center of a new token controversy had originally been created by a former employee and used in a video tutorial to generate tokens. The company said that individual is no longer employed there because of the incident. According to BNB Chain, after leaving the company, the former employee still had unauthorized access to the mnemonic phrase tied to the wallet and used it to generate a new private key. BNB Chain said it later learned that the same address was being used independently for a new meme token. The company said it did not create, authorize, promote, or participate in the creation of that token, and that it has no control over either the token or the wallet address. BNB Chain added that neither the token nor the wallet is associated with or endorsed by the company. It also said it is taking legal action against the former employee and cooperating with relevant authorities. Separately, community estimates cited in the update said the developer made more than $1 million from a bundled token launch.1940
OneKey2026-07-20 03:17:39OneKey founder warns third-party keyboards may keep reading clipboard dataOneKey founder Wang Yishi said in a post on X that the risk of sensitive data exposure may extend beyond screenshots being captured on screen recordings. He warned that third-party keyboard apps may also continuously read clipboard contents, creating another path for mnemonic phrases and other private information to leak. The post drew follow-up comments from several users, who said that after opening Pinduoduo without saving an image, or after only copying related content, the app’s recommendation feed showed products highly related to what had previously appeared on their screens or in their clipboards. Those users questioned whether the app might be reading screen content or clipboard data. For now, the claims are based mainly on user tests and feedback shared on social platforms. Pinduoduo has not publicly responded, according to the ChainCatcher newsflash.2040
Bitcoin2026-07-08 18:08:15Mnemonic Phrases Are Not a Magic Key: A Practical Guide to Bitcoin Wallet Recovery and SecurityMnemonic phrases are central to crypto wallet backup, but recovery is not always straightforward. Differences in BIP39 implementations and derivation paths can affect whether funds appear in another wallet.420