wallet securi2026-08-19 08:31:25Wallet security incidents put AI-driven crypto defense under the spotlightA string of wallet-related security incidents over the past month has sharpened attention on a wider shift in crypto security: the attack surface is expanding well beyond private keys, and AI is making every stage of the attack chain cheaper to run. The article links three separate cases — Coldcard’s random number generation flaw, Trezor’s exposure tied to a third-party logistics service, and SafePal’s risks involving order systems and plugin permissions — to a broader pattern in which code review, phishing generation, target selection and social engineering can all be automated at a much larger scale. It argues that wallet security can no longer be reduced to whether a seed phrase was stolen. Risks now span key generation, hardware, supply chains, user identity data, dApp connections, approvals, support channels and even AI agents. The piece also revisits earlier discussions from imToken on “AI × Web3 security,” outlining a more active defense model in which wallets use AI to review code dependencies, analyze suspicious dApps, simulate transaction outcomes before signing and build dynamic risk models around user behavior. Even so, it stresses that critical actions such as large transfers, new approvals and sensitive contract interactions still need clear user confirmation, least-privilege controls and explainable warnings.550
SafePal2026-08-16 14:37:20Specter questions SafePal over timing of data leak disclosure after phishing reportsOn-chain analyst Specter has challenged SafePal’s handling of a disclosed data leak, arguing the company waited too long to go public. According to Specter, the leaked data spans from March 2, 2025, to April 11, 2026, suggesting the vulnerability had occurred by April or early May at the latest. Specter said SafePal did not disclose the issue until recently, after Trezor announced its own data leak. Specter also said some users had already received phishing emails before SafePal acknowledged the incident, and that some people suffered losses as a result. In Specter’s view, SafePal failed to issue an early warning and had denied the problem earlier, leaving customers’ personal data exposed to risk. The remarks add to scrutiny around how wallet providers communicate security incidents and user data exposure.1240
SafePal2026-08-16 12:49:52SafePal says order-tracking plugin flaw exposed data of about 39,798 customersSafePal said on Aug. 16 that a security flaw in its order-tracking plugin allowed unauthorized access to some customer order records. The company said around 39,798 users were affected, all of whom placed orders between March 2, 2025, and April 11, 2026. The exposed information included names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal said wallet data remained secure throughout the incident. The company added that mnemonic phrases, private keys, wallet passwords, bank account information, payment card numbers, and government-issued identity documents were not involved. According to the announcement, the issue has been fixed and additional security measures have been added. All affected customers have already been notified individually by email. SafePal also launched an official verification page that lets users check whether they were affected by entering their order number and shipping country. The company apologized for the incident and urged users not to share mnemonic phrases, private keys, or passwords with anyone, while staying alert to phishing attempts and impersonation scams. SafePal said follow-up updates will continue to be posted on its official blog.1050
Neutrl2026-08-14 02:59:27Foresight corrects Neutrl recovery vote claim, says post came from suspected impersonatorForesight has issued a correction on earlier claims that Neutrl had proposed a protocol recovery plan and put it to a community vote. After review, the outlet said the message came from a suspected impersonation account, @NeutrlFnd, rather than from Neutrl’s official account. As of publication, Neutrl’s official account had not posted any announcement about a recovery plan or a vote. The suspected fake account showed several warning signs. Its display name was written as "NeutrI Foundation," using an uppercase "I" to mimic a lowercase "l." Foresight also noted that the account was registered in April 2012, had posted only 11 times in its history, used a purchasable organization verification badge, and had replies restricted on its posts. Foresight added that wording in the post about offering proportional compensation and recovery allocations to users holding positions at the time of suspension matched common phishing language. The voting link may have been designed to lure users into connecting wallets and signing malicious approvals.1540
DeFi2026-08-13 06:41:13DeFi whale loses another $25 million as stolen funds move through CCTP to HyperliquidA DeFi whale lost roughly $25 million to $26 million after multiple wallets were drained within 15 minutes early on Aug. 13, according to Scam Sniffer and on-chain tracking cited by Foresight News. The stolen assets included DAI, WBTC, aUSDC, LDO, sUSDe, and native ETH. Analyst Ember said three wallets were affected, including one address with no prior token approval history, a detail that suggests the incident may have involved direct private key compromise rather than a standard approval-phishing attack. On-chain records show the victim’s main wallet and a related address moved assets to a newly created recipient wallet around 5:05 on Aug. 13. Within about an hour, tokens including WBTC, cbBTC, LDO, USDS, CRV, and sUSDe were swapped into DAI and ETH. Of that amount, 20 million DAI was sent to a downstream address labeled by Arkham as a separate entity and had not moved again as of publication. Other ETH was split into batches, routed through smart contracts, swapped to USDC on Uniswap, sent to Circle’s Token Minter, bridged to Arbitrum through CCTP, and then deposited into Hyperliquid. The same victim had already suffered a phishing loss of about $24.23 million in September 2023 after signing a malicious increaseAllowance transaction.1590
SlowMist2026-08-12 07:26:48SlowMist says ColdCard private key flaw may trace back to build setting that disabled hardware RNGSlowMist said ColdCard, a hardware wallet maker, was hit by a major private key vulnerability that led to losses of about 1,719 BTC. Using Mk3 firmware version 4.1.9 as an example, the security team said it fully reproduced the attack chain and traced the issue to a build configuration error. According to SlowMist, the setting "MICROPY_HW_ENABLE_RNG" was set to 0, which disabled the STM32 hardware true random number generator. That forced the random number path to fall back to the Yasmarang software pseudo-random number generator, which SlowMist described as not cryptographically secure. The team said its state was almost entirely predictable, cutting effective entropy to about 40 bits on Mk2 and Mk3 devices, or about 72 bits on Mk4, Mk5, and Q models. SlowMist said attackers could model keypress consumption patterns, use GPU clusters to brute-force the candidate space, derive private keys, and then match single-signature P2WPKH addresses across the network to steal funds. The firm urged affected users to upgrade to fixed firmware, create a new mnemonic, and move funds only after confirming the new address works properly.1750
BTCPay Server2026-08-11 21:16:03BTCPay backers offer up to 3 BTC bounty after wallet exploitBTCPay Server supporters are offering a recovery bounty after a recent exploit exposed connected wallets to theft. In a post on X on Monday, the project said it would pay 10% of any recovered funds, capped at 3 BTC, if all stolen Bitcoin is returned. The offer applies to anyone who provides useful information, including the attacker. The project had first warned users on Friday to upgrade to version 2.4.2 or take servers offline. BTCPay later said the flaw allowed attackers to obtain LND admin macaroons, credentials that grant broad control over a Lightning Network node, and then use them to access linked wallets. It has not disclosed the amount of Bitcoin stolen, the number of affected users, or whether any funds have already been recovered. BTCPay also said the BTCPay Server Foundation will donate 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for responsibly disclosing the bug. The company added that it is tightening code review and putting security patches ahead of new features as AI makes vulnerability discovery easier for attackers.1770
Coldcard2026-08-11 20:02:55Coldcard Mk3 Vulnerability Could Generate Identical Mnemonics; ~4.5M Seed States Scannable in 3 SecondsBitcoin News shared on X a technical analysis by @KLoaec finding that some vulnerable Coldcard Mk3 wallets may derive from only ~4.5 million RNG starting states, searchable in about 3 seconds on a single RTX 4090. Even with extra per-wallet uncertainty, an attacker could finish the search on a high-end GPU in ~50 minutes. The flaw could cause different devices to generate identical mnemonics; assuming 30,000 Mk3 units, roughly 120 pairs may produce the same random stream.1850