Bitcoin2026-10-03 14:25:37EntropyLab releases candidate build of offline Bitcoin key and wallet calculatorEntropyLab has released v1.0.0rc1, the first candidate version of its self-contained Bitcoin key and wallet calculator, according to a post by Bitcoin News on X. The tool runs as a single HTML file, does not require an internet connection, and does not generate entropy on its own. Instead, users can supply their own entropy and calculate keys and wallets in a fully offline environment. The application supports multisig, PSBT, BIP-85, Silent Payments, vanity addresses, watch-only wallet export, and randomness analysis. The release is reproducible and can be verified through signatures from four independent signers. The team said users should download and verify the file before moving it to an air-gapped computer. A full v1.0.0 release will come after testing of the candidate version is completed.70
Crypto Securi2026-09-30 03:00:58Crypto security’s center of gravity is shifting from code bugs to permissions and trust chainsA TechFlowPost article argues that the biggest security failures in crypto are no longer centered on undiscovered smart contract bugs. Instead, recent losses have clustered around permissions, signing flows, RPC dependencies, supply chains, backend approval systems, and the people trusted to operate them. The piece points to four major incidents — Bybit, Bitget, KelpDAO, and Drift — as evidence that attackers are increasingly bypassing code and going after the trust assumptions wrapped around it. In the article’s framing, the industry has spent years hardening contracts, adding multisigs, separating cold wallets, and expanding audits, yet funds still disappeared because the systems approving transactions were fed false data or because authorized signers were manipulated into approving malicious actions. It also argues that AI is changing the economics of attacks by making social engineering, malware delivery, identity fabrication, and large-scale contract scanning cheaper and easier to automate. The article does not say audits are useless. Its point is narrower: audits cover a shrinking share of the places where money is actually lost. As attack surfaces move outward, the proposed response shifts as well — toward permission governance, infrastructure diversity, runtime controls, continuous monitoring, and insurance structures that price security architecture directly.180
Web3 Security2026-09-30 00:49:03Web3 security is shifting from code exploits to trust and permission failures, Foresight saysA long-form analysis published by Foresight argues that the center of gravity in Web3 security has moved away from smart contract bugs and toward permissions, signing flows, RPC dependencies, supply chains, and operational trust. The piece points to four major incidents — Bybit, KelpDAO, Drift, and Bitget — to show that some of the largest recent losses did not come from undiscovered contract 0days. Instead, attackers targeted the systems and people around the code: compromised signing interfaces, poisoned backend approval flows, manipulated RPC responses, and social engineering aimed at privileged operators. The article says the pattern has become clearer over the past three years. In 2024, phishing overtook private key leaks as the biggest threat. In 2025, the Bybit theft pushed front-end supply chain risk and signing interfaces into focus. In 2026, the KelpDAO, Drift, and Bitget cases turned RPC trust, multisig design, and permission configuration into the main battleground. It also argues that AI is changing the economics of attacks by making phishing, fake identities, malware delivery, and old-contract scanning cheaper to run at scale, while forcing defenders to secure every entry point. Foresight’s conclusion is blunt: Web3 has not become safe or unsafe in a simple sense. The most valuable attack surface has moved outside the contract itself and into the broader trust chain that surrounds it.190
Cosmos Hub2026-09-26 01:26:38Cosmos Hub recovers 1.227 million ATOM from Neutron exploit, moves funds to 4-of-6 multisigCosmos Labs said roughly 1.73 million ATOM was moved to Cosmos Hub after a governance attack on Neutron on Sept. 22 led to stolen liquidity from protocols including Astroport. Cosmos Hub itself was not compromised, and user funds were not affected. To stop further movement of the stolen tokens, Hub validators halted the network for about 24.5 hours and resumed block production on Sept. 23 using the patched Gaia v28.3.0 release. During the halt, 1.227 million ATOM remained in the attacker’s Hub address and was transferred, through a one-time state change at restart, into a 4-of-6 multisig controlled by Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu. Cosmos Labs added that about 500,000 ATOM had already been swapped for ETH through THORChain and could not be recovered, while another 169,000 ATOM entered the attacker’s address after the network resumed because of a THORChain refund, then was moved to Osmosis and sold. The recovered ATOM will stay in the multisig and can only be returned with authorization from a Cosmos Hub governance proposal.350
Neutron2026-09-25 16:59:041.227 Million ATOM Moved to 4-of-6 Multisig After Neutron Governance AttackCosmos Labs said Neutron suffered a governance attack on Sept. 22 that led to liquidity being drained from protocols including Astroport, with roughly 1.73 million ATOM later moved by the attacker to Cosmos Hub. Cosmos Hub itself was not compromised, and user funds on the Hub were not affected. To stop further outbound transfers of the stolen ATOM, Hub validators halted the network for about 24.5 hours and resumed block production on Sept. 23 using the patched Gaia v28.3.0 release. According to Cosmos Labs, 1.227 million ATOM remained in the attacker’s Hub address during the halt and was moved, through a one-time state change at restart, into a 4-of-6 multisig controlled by Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu. Cosmos Labs also said about 500,000 ATOM had already been swapped into ETH via THORChain and could not be recovered, while another 169,000 ATOM was refunded through THORChain after the network restart, returned to the attacker address, then moved to Osmosis and sold. The funds now held in the multisig cannot be returned unless authorized by a Cosmos Hub governance proposal, and they will not be staked, lent, or traded. Neutron said it expects to submit a recovery plan and related governance proposal next week.230
Liquid Networ2026-09-15 05:39:19How 4,000 BTC Left Liquid Network’s Vault Without a Stolen KeyOn Sept. 6, roughly 4,000 BTC, worth about $320 million at the time, left Liquid Network’s federation wallet in what the article describes as the largest crypto theft of 2026 so far. What made the incident unusual was not just the size. No private key was reported stolen, no hardware security module was broken, and no insider compromise was identified. The 11-of-15 multisig process still worked exactly as designed. The reported failure point was lower in the stack: the software logic used to verify whether newly issued L-BTC was valid. According to the reconstruction cited in the source article, an attacker abused a range-proof cache issue in Elements, the open-source node software used by Liquid, allowing 3,996 unsupported L-BTC to be accepted and later redeemed for real BTC through the normal peg-out path. The article notes that Blockstream has not formally confirmed that this exact bug caused the theft, but says external researchers linked the timeline to a patch that had already been written before the attack and was merged too late for the federation nodes running in production. The attacker later returned 3,400 BTC and kept 598.5 BTC while calling themselves white hats and demanding an additional payout. Blockstream publicly rejected that demand, said it would not pay ransom, and maintained that L-BTC holders would not be haircut to cover the loss.690
CoinCorner2026-09-08 20:16:20CoinCorner rolls out Lloyd’s-insured multisig Bitcoin vault with AnchorWatchCoinCorner, a British bitcoin exchange based in the Isle of Man, has launched a new multisignature BTC custody product called Vault in partnership with U.S. firm AnchorWatch. Under the setup, control of customer keys is split between the two companies, and the holdings are insured by Lloyd’s of London. CoinCorner said the service carries a 1.5% annual fee and is aimed at bitcoin owners seeking cold-storage security without having to manage hardware devices on their own. The company said customers can open a Vault account and deposit any amount of bitcoin, though assets do not move into the insured wallet right away. Transfers are typically processed on the first working day of the following month, and customers can verify holdings on-chain through a wallet address provided by CoinCorner. The firms also said users may add funds at any time and can set their own identity-verification rules before assets are allowed to move. The launch follows the Coldcard wallet hack referenced in the report, in which single-signature bitcoin wallet users lost funds after attackers exploited a firmware bug that led to weak seed generation. About $115 million was lost, according to the article. Bitcoin Magazine said the new service was first reported in a piece written by Mathew Di Salvo.780
LAPTOP2026-09-09 12:12:17Ai Yi says about 23 million LAPTOP tokens are allocated for market making, with GSR, G20 and Wintermute involvedMonitoring data cited by Ai Yi indicates that Wintermute has joined GSR Markets and G20 as a market maker for LAPTOP. Around 21 hours before the post, Wintermute received 2.5 million LAPTOP tokens from the project’s multisig address and has since distributed them to multiple exchange deposit addresses. The other two market makers had already received their allocations several days earlier, suggesting Wintermute may be the most recent firm to reach a cooperation agreement with the project. Based on those observed allocations, the actual pool of LAPTOP tokens used for market making is estimated at about 23 million. Of that amount, GSR Markets holds 15.5 million tokens, G20 holds 5 million, and Wintermute holds 2.5 million. The post added that Wintermute’s share accounts for about 2.3% of the token’s total supply.1180