address poiso2026-08-11 13:44:56Address Poisoning Attack Drains $100K in USDT, Attacker Converts Funds to ETHCyvers Alert has detected an address poisoning attack that cost a victim approximately $100,000 in USDT. The attacker planted a spoofed address in the victim's transaction history 66 days ago, and the victim transferred funds without fully verifying the wallet address. The stolen USDT has since been swapped into roughly 52.8 ETH to evade potential freezing. Cyvers urges users to always verify full wallet addresses and suggests AI-powered on-chain security tools for real-time anomaly detection.1730
crypto shutdo2026-08-09 13:52:54More Than 100 Crypto Projects Have Shut Down in 2026 as Industry Consolidation Picks UpMore than 100 crypto projects have shut down, filed for bankruptcy, or permanently ceased operations so far in 2026, according to an Odaily report citing CoinDesk. The pace has been speeding up, with BitMEX, BitMart, Movement Labs, and Storj Labs all announcing closures or related filings in a single week in late July. The list of exits spans trading platforms, wallets, DeFi lending protocols, NFT marketplaces, and layer-1 blockchains. The report points to a mix of pressures behind the wave of shutdowns. Ethereum general-purpose layer-2 networks expanded quickly in 2023, but lower deployment barriers later crowded the market and left some projects without clear differentiation. Many teams had usage but no conventional revenue, while also paying engineers in native tokens, subsidizing liquidity, and covering security audit costs. Recent declines of 70% to 90% across many altcoins also undermined token-denominated treasury assumptions and runway estimates. Security losses added to the pressure. Blockaid estimated on-chain attack losses reached $1.1 billion in the first half of 2026, above the total for all of 2025, while TRM Labs said North Korea-linked attackers accounted for 66% of crypto attack losses in the same period. By contrast, projects still growing through the bear market tended to rely on dollar-based revenue, with Hyperliquid and Aave cited as examples.1820
Policy and Re2026-08-07 07:36:26AI tools are being used to flag sham token projects and on-chain pyramid schemesRegulators and security teams are increasingly using artificial intelligence to spot suspicious crypto projects before they scale. The article outlines how AI can scan white papers, marketing copy, team backgrounds, social media activity, fundraising claims, smart contract structures, and on-chain fund flows to detect patterns often linked to fake token offerings, multi-level referral schemes, and other illicit activity. It points to several concrete examples and policy signals. A June 2026 warning from Shenzhen’s financial regulator said bad actors were using labels such as “AI agents,” “AI quantitative investment,” and “Web3.0” to conduct illegal fundraising. The piece also cites the “Fun Coffee” virtual currency investment case in Hong Kong, which had drawn 225 reports involving HK$94 million as of early August 2026. Lawmaker Johnny Ng said the case involved a Ponzi scheme and a layered person-to-person recruitment structure. The article argues that AI can help by identifying templated white papers, fake community traction, fabricated investment claims, pyramid-style capital structures, rapid fund aggregation, abnormal rebate models, and wallet links to blacklists or mixers such as Tornado Cash. At the same time, it stresses that AI is not a final judge. False positives remain possible, decentralization does not equal illegality, and human review is still needed alongside data analysis and on-chain evidence.1850
Bitcoin2026-08-06 10:48:54Community honeypot test suggests attackers still favor easiest Coldcard Mk3 RNG targetsA new community honeypot test indicates that attackers are still focusing on the easiest wallets exposed by the Coldcard Mk3 RNG flaw, according to a post by Bitcoin News on X. Researcher @ColeTU funded five affected Mk3 wallets for the test: one used only the vulnerable mnemonic, three were protected by BIP39 passphrases of one, two, and three words respectively, and one used a random account number. After 14 hours, only the unprotected wallet that relied solely on the vulnerable mnemonic had been drained. Separately, @jamesob’s live tripwire dashboard showed that only 2 out of 17 honeypot wallets had been emptied so far. The wallets confirmed as drained did not include extra entropy, while wallets protected with dice rolls, passphrases, multisig, or other added complexity had not been touched. The test suggests attackers are currently spending their effort on wallets that are easiest to brute force rather than trying to crack hardened setups. Even so, affected users are still urged to move funds immediately instead of depending on temporary safeguards.1870
Coldcard2026-08-03 09:18:00Coldcard wallet exploit may have entered a fourth sweep, with losses nearing $114 millionA security incident tied to Coldcard hardware wallets appears to be widening, with total losses potentially nearing $114 million, according to CoinDesk and on-chain analysis cited by Galaxy Research head Alex Thorn. Thorn said a new Bitcoin sweep attack targeting Coldcard-derived addresses appears to be underway and that the latest transactions are using Replace-by-Fee, or RBF. That gives affected users a limited chance to outbid an attacker and redirect funds to a safe address if they spot their transaction in the mempool before confirmation. The attack was first observed on July 30. The first wave moved about 1,083 BTC from 1,196 addresses in 41 minutes. Two later waves pushed confirmed losses to roughly 1,367 BTC across 4,585 addresses. If the fourth wave estimate holds, around 1,816 BTC has been moved since July 30, affecting more than 5,200 addresses. Researchers believe the issue traces back to a March 2021 Coldcard firmware version that used a predictable software random number generator during seed creation instead of the chip’s hardware entropy source. Manufacturer Coinkite has released an emergency firmware update and advised users to move assets to wallets created from entirely new seeds. Current research indicates the incident mainly affects single-signature wallets, with no multisig impact identified so far.1850
Coldcard2026-08-03 02:03:42Coldcard fallout drives on-chain BTC movement as DeepSeek Harness opens closed testingA newly surfaced Coldcard wallet flaw remained at the center of crypto discussions on Aug. 2 after community developers said AI tools identified the issue in minutes. A Reddit developer used Claude Code to scan Coldcard’s open-source firmware and said the core flaw was found within eight minutes: the firmware generated private keys with a software pseudo-random number generator instead of a hardware true random number generator. The input states that this bug led to the theft of roughly $70 million in BTC across 1,196 wallets. Another community user said Zhipu GLM 5.2, trained on June 16 and used without internet access, independently found the same issue. The bug had reportedly existed in the open-source wallet code for more than five years. As the security incident spread, sub-1 BTC transfers rose to their highest level since November 2022, according to CryptoQuant’s Julio Moreno. Elsewhere, BNB Chain said it had launched legal action after a former employee allegedly used unauthorized access to an old test wallet to deploy a meme token, while DeepSeek began recruiting developers for the closed test of DeepSeek Harness.660
Coldcard2026-08-03 00:52:28Galaxy research head flags suspected fourth organized Coldcard attack affecting 462 addressesGalaxy’s head of research said monitoring points to what appears to be a fourth organized attack tied to Coldcard, with similar transactions still sitting in the mempool awaiting confirmation. Previously confirmed transactions showed Replace-By-Fee, or RBF, enabled. During blocks 960,778 through 960,792, roughly a 2.5-hour span, 218 transactions were recorded. Those transactions involved 462 victim addresses, 216 new destination addresses, and 388.92748828 BTC. The monitoring also found that none of the transactions used inputs older than the Coldcard firmware boundary. The sweep rate during that window reached 13.8 per block, compared with 0.3 per block in the pre-incident comparison window, about 45 times higher. In terms of topology, the transactions followed a 1:1 pattern, with each victim address mapped to a new destination address. Only one destination address received two sweeps, and no consolidation address appeared. Some of the funds have already moved on to second-hop addresses.1740
Galaxy Resear2026-08-01 01:27:18Galaxy Research says more than $70 million in BTC was stolen through the Coldcard flawGalaxy Research said on X that its review of the Coldcard hacking incident found 1,196 affected addresses and total losses of 1,082.65 BTC, with the stolen bitcoin valued at more than $70 million. The firm also said the attack was carried out within a 41-minute window and took place 30 hours before Coldcard publicly issued its warning. The figures add a clearer picture to the scale and timing of the incident, based on Galaxy Research’s published findings.1770