Bitcoin2026-08-27 06:44:32Frostsnap rolls out v0.4.0 to patch two security issues, urges users to updateBitcoin multisig hardware wallet maker Frostsnap released version 0.4.0 on Aug. 27, fixing two disclosed security issues and urging users to update both the app and device firmware. The team said it has not found any user fund losses so far. The first issue, tracked as FSA-2026-001, involved malicious signing requests that could mark an output as belonging to the user’s wallet. Because the device did not verify that claim and did not show it on the confirmation screen, funds could potentially be sent to an address the user had never seen. The second issue, FSA-2026-002, affected change addresses that could fall outside the wallet recovery scan range. After a backup restore, users might see funds shown as missing even though the assets remained in the wallet. Following the update, the app will prompt users to upgrade device firmware and now includes downgrade protection for firmware.970
Bitcoin2026-08-26 23:39:32Coldcard entropy flaw pushes multi-vendor multisig to the forefront of Bitcoin custodyBitcoin Magazine argues that the fallout from Coinkite’s Coldcard entropy bug has forced a broad rethink of Bitcoin self-custody practices, especially for users relying on single-signature setups. The article says the flaw, which reportedly went unnoticed since at least 2021, exposed how much trust single-seed users place in one hardware wallet maker’s key generation process. In response, self-custody advocates and industry participants are increasingly treating multi-vendor multisignature setups as a stronger default, because they spread signing authority across devices and manufacturers rather than concentrating it in one place. The report walks through the threat-modeling framework behind that shift. It highlights backup failures, forgotten passwords and theft as recurring causes of fund loss, then places bad entropy attacks alongside incidents involving Trust Wallet and fake wallet apps. It also explains how 2-of-3 and 3-of-5 multisig arrangements work, why providers such as Casa, Nunchuck, Sparrow and Unchained Capital are part of the discussion, and how advanced multisig designs can add resistance to coercion, phishing and social engineering. At the same time, the article notes a key tradeoff: users must preserve not only threshold signing access, but also a copy of the multisig script or template needed to reconstruct spending conditions independently.930
Coldcard2026-08-26 23:44:03Coldcard entropy flaw tied to over $100 million in stolen Bitcoin as multisig gains attentionColdcard, the hardware wallet brand owned by Coinkite, has been linked to a serious entropy flaw that reportedly went undetected since 2021 and led to more than $100 million worth of Bitcoin being stolen. According to the report, most victims were users relying on single-seed-phrase wallets, where weak entropy made it possible for attackers to guess private keys through customized methods. The incident has pushed the Bitcoin community to revisit the reliability of single-signature self-custody setups. In that context, multi-vendor multisignature arrangements are being presented as a new baseline for long-term holders. The model uses keys from different wallet makers to reduce dependence on any one hardware provider, with one example combining Trezor Safe 7, Ledger Nano and a Casa recovery key in a 2-of-3 setup. The report also notes that multisig can help defend against wrench attacks and has supported services such as BTC-denominated Bitcoin insurance from firms including AnchorWatch. At the same time, it adds operational overhead because users must keep threshold keys safe and also retain a copy of the multisig script or template for independent recovery if wallet services go offline.930
Galaxy Resear2026-08-14 16:52:41Galaxy Research says Coldcard incident is reshaping Bitcoin self-custody thinkingGalaxy Research head Alex Thorn said on X that attack activity tied to the Coldcard hardware wallet vulnerability has slowed sharply, but total losses are still rising as more victim reports come in. According to Galaxy, the firm has directly contacted 190 victims and has high confidence that 1,778.84 BTC, worth about $112.7 million, was stolen across more than 8,600 addresses. That figure does not include some medium-confidence suspicious activity, including an unconfirmed 「Wave 4」. If those cases are included, losses could reach 2,417.35 BTC, or roughly $153 million. Thorn said the incident has hit the Bitcoin community hard because the victims were mainly long-term BTC holders committed to self-custody and cold storage, rather than users exposed through high-risk trading or DeFi activity. Using a $112 million benchmark, he said the case would rank among the 20 largest hacks in crypto history and stands as one of the most serious security failures yet in hardware-wallet self-custody. Galaxy also said the episode is shifting views on wallet security, with multisig emerging as the clear relative beneficiary. So far, it said, none of the stolen transactions came from multisig wallets, while providers including Casa, Unchained, Nunchuk and Anchorwatch have reported clear increases in user sign-ups and BTC inflows.1310
Coldcard2026-08-12 18:22:54Coldcard Firmware Exploit Leads to Theft of 2,100 BTC, Nearly $130M LossAccording to a report from ChainCatcher, a firmware vulnerability in Coldcard hardware wallets has been exploited, leading to the theft of roughly 2,100 Bitcoin and causing losses that approach $130 million. Data from the blockchain indicates that in the days around the exploit, wallets associated with long-term holders sent out approximately 233,000 Bitcoin, worth around $15 billion. Nick Neuman, the chief executive officer of Casa, stated that a portion of these outgoing transfers came from Coldcard users who were moving their holdings into multisignature wallets. He also noted that users of Ledger and Trezor devices adopted similar measures after the security incident. During the same period, close to 22,000 Bitcoin were shifted into exchange platforms. In response, Coinkite, the company behind the Coldcard product line, has instructed customers who generated their mnemonic phrases using firmware versions 4.1 through 4.1.9 to regard their wallets as compromised and to migrate to new seed phrases without delay. These firmware versions correspond to the timeframe spanning March 2021 to July 2026.1530
Bitcoin2026-08-11 19:10:11Casa CEO says 233,000 BTC shifted to safer setups after Coldcard exploitCasa CEO Nick Neuman said onchain activity following the recent Coldcard firmware exploit shows how self-custody can reduce systemic damage even when individual wallets are compromised. In an Aug. 9 post on X, Neuman cited Checkonchain data showing that in the days after the incident, about 22,000 BTC moved to exchanges and 233,000 BTC left long-term holder wallets, while roughly 2,100 BTC was stolen. Galaxy Research has tracked confirmed losses tied to the Coldcard entropy flaw from as low as 1,700 BTC to more than 2,000 BTC, with the theft unfolding in multiple attack waves beginning July 30 and higher-end estimates nearing $130 million. According to Neuman, conversations with Casa customers suggest some holders moved from non-Coldcard single-key setups, including Ledger and Trezor, into multisig wallets after rethinking single-key risk, while other users removed Coldcard devices from existing multisig keysets. He argued that this pattern highlights a core strength of self-custody: losses were fragmented across individual wallets rather than concentrated in one custodian. The episode has also renewed debate around single-signature hardware wallets, seed generation practices, multisig, and covenant-based vault designs.1800
BitGo2026-08-04 02:56:49BitGo CEO Mike Belshe Dares Anthropic to Take 100 BTC From a Public WalletBitGo co-founder and CEO Mike Belshe has publicly challenged Anthropic by depositing 100 BTC into a BitGo wallet and posting the address on X, saying the company should try to take the funds if Claude is truly capable of breaking into systems. The stash was described as being worth about $6.3 million at the time. Belshe’s post directly mocked claims around a supposed “hacking monster,” arguing that if Anthropic’s technology is as formidable as suggested, it should prove it on a real target rather than in controlled demonstrations. The funds, however, were not placed in a simple wallet. According to the source, they sit inside BitGo’s institutional custody platform using a multisignature or MPC setup, meaning any successful theft would require breaching layered key management, approval policies, hardware protections and operational controls. Public on-chain data currently shows both spent_txo_count and spent_txo_sum at zero for the address, with no unconfirmed transactions in the mempool. Anthropic has not publicly responded so far, while online reactions have also framed the exchange as a form of marketing theater.1840
MARA2026-08-03 16:53:00MARA opens Slipstream as a permissionless public service without client softwareMARA’s Bitcoin transaction relay service, Slipstream, is now available as a permissionless public service and no longer requires client software, according to a post from Bitcoin News on X cited by Odaily. The change matters in particular for users moving funds out of vulnerable COLDCARD wallets. In those cases, a multisig spend can reveal all public keys and spending conditions. If that transaction reaches the public mempool, an attacker can immediately compare the exposed keys against a precomputed database of weak COLDCARD private keys and, if a majority of keys is under control, broadcast a higher-fee double-spend before the original transaction confirms. Slipstream is designed to avoid that path by sending transactions directly to miners so they do not enter the public mempool before being mined. MARA also advised users to choose conservative fees to reduce the risk of transactions getting stuck. The service is currently free aside from standard Bitcoin network fees.1940