TAPS

Coldcard
2026-08-05 11:34:27

Coldcard RNG flaw tied to four suspected attack waves as scrutiny grows over Bitcoin self-custody risks

A years-old randomness flaw in Coldcard hardware wallet firmware has come under intense scrutiny after several waves of suspicious Bitcoin sweeps were linked by researchers to seeds created under affected software versions. Investigations by Block and Coinkite traced the issue to a 2021 code migration that routed seed generation through a software pseudorandom number generator instead of the intended hardware RNG on some firmware paths, reducing the effective search space of wallet seeds below the design target. Galaxy Research said three suspected attack waves it identified covered 4,585 addresses and 1,367.05 BTC, and on Aug. 3 its researchers flagged a fourth wave that was later updated to about 448.7 BTC across 709 potential victim addresses. Those figures come from on-chain pattern analysis and are not a wallet-by-wallet confirmation of Coldcard victims or final losses. The incident has also reopened debate over custody models. Researchers and market observers pointed to higher address activity, movements from older UTXOs, and inflows to centralized venues after the disclosure, while cautioning that on-chain data alone cannot prove those moves were caused by the Coldcard bug. Coinkite has said users with affected seeds need to generate a new seed in patched firmware or another trusted environment and move funds, because updating firmware alone does not restore the missing entropy in an already created mnemonic.

1400
Coldcard RNG flaw tied to four suspected attack waves as scrutiny grows over Bitcoin self-custody risks
Coldcard
2026-07-31 07:43:46

Coldcard seed-generation flaw linked to 594 BTC drained in 25 minutes

Coinkite has confirmed a seed-generation flaw affecting parts of the Coldcard hardware-wallet line, after on-chain analysts tracked the theft of 594.48 BTC in a burst of transactions completed within roughly 25 minutes. The incident involved 1,324 UTXOs swept through 500 transactions across a three-block window, with the funds taken from about 500 single-signature addresses. Security researchers said the issue traces back to firmware changes introduced in March 2021 that accidentally disabled the secure chip’s hardware random-number generator, leaving key generation to rely on predictable inputs such as a chip serial number and clock registers. Coinkite first focused its warning on the Mk3, then later expanded the affected scope to include older firmware on the Mk4, Mk5 and Q. The company said users should not wait for a firmware update and should move funds by creating a new seed on an unaffected device, verifying backups, testing with a small transaction and then transferring the full balance. Devices including TAPSIGNER, OPENDIME and SATSCARD were said to be outside the affected codebase.

1140
Coldcard seed-generation flaw linked to 594 BTC drained in 25 minutes
Telegram Game
2026-07-08 12:46:14

Top 5 Telegram Tap-to-Earn Crypto Games to Watch in 2025

Telegram tap-to-earn games are gaining momentum in 2025. This article reviews five standout titles—TapSwap, Notcoin, Blum, Hamster Kombat, and Yescoin—while outlining how the model works, its appeal, and key risks.

260
Top 5 Telegram Tap-to-Earn Crypto Games to Watch in 2025
Telegram Game
2026-07-08 12:46:14

Top Telegram Tap-to-Earn Crypto Games to Watch in 2025

Telegram tap-to-earn games are gaining traction in 2025, offering lightweight gameplay and small crypto rewards. Here are five notable titles, how they work, and what users should know about benefits, earnings strategies, and risks.

230
Top Telegram Tap-to-Earn Crypto Games to Watch in 2025