‹ BackNewsWallet Security

Wallet Security

Policy and Re
2026-08-31 10:55:47

AI-driven impersonation scams are overtaking code exploits as a core crypto security threat

Impersonation and AI-assisted fraud are becoming one of the most serious security problems in crypto, shifting attention away from code bugs alone and toward identity, access control, and accountability. Chainalysis said at least $14 billion in on-chain funds flowed into crypto scams in 2025, though not all of that activity was tied to AI. Within a subset of cases linked on-chain to AI vendors, the average scam operation was about $3.2 million, compared with roughly $719,000 for scams without those links, a correlation the company did not describe as causal. Executives interviewed across the sector pointed to a broad change in attack methods. Binance Chief Security Officer Jimmy Su said smart-contract security has improved enough that attackers now focus more on people around protocols, credentials, and governance systems, citing Binance security team assistance in stopping a $1.2 million governance attack on BrainTrust. Binance Research also said access control failures accounted for about two-thirds of the $621 million lost to DeFi exploits in April 2026 alone. The report also highlights unresolved attribution issues, mixer-related tracing gaps, and a new frontier in AI agents that can pay, register for services, and potentially transact on users’ behalf. Several executives argued that the missing layer is not transaction verification itself, but trustworthy identity and responsibility behind those actions.

900
AI-driven impersonation scams are overtaking code exploits as a core crypto security threat
Coldcard
2026-08-31 00:12:42

Coldcard entropy flaw shakes self-custody confidence, but experts still favor holding your own keys

A flaw tied to entropy handling in Coldcard hardware wallets has triggered Bitcoin losses and reignited a core debate in crypto: whether users are still better off keeping assets in self-custody after a wallet failure of this scale. According to the report, the issue stemmed from a deep firmware bug that remained hidden for five years and affected private-key generation on Coldcard Mk3 devices. During a code migration from Python to C, developers unintentionally disabled the built-in secure random number generator, causing the device to fall back to a highly insecure algorithm and reducing cryptographic entropy from 256 bits to just 22 bits. Speakers at Bitcoin Asia said the incident exposed weak spots in vendor maintenance, including code review, bug bounty design, and broader management practices. Even so, they argued that centralized exchanges still carry greater counterparty risk than hardware defects. The discussion centered on multi-vendor multisig setups using devices from different manufacturers, along with passphrase protections and modern coordination tools such as Liana, Unchained, and Casa. The report also said development teams are increasingly turning to AI-assisted code auditing to scan large legacy codebases and catch logic errors earlier. In that view, the Coldcard incident has damaged trust, but it has also pushed the ecosystem toward stricter security practices rather than away from self-custody.

860
Coldcard entropy flaw shakes self-custody confidence, but experts still favor holding your own keys
Sparrow Wallet rolls out v2.5.4 security update with broader independent verification
Tron address poisoning attacks cost 15 victims about $9.4 million over four weeks
1inch received 1,055 bug bounty reports in the first half, with 32 rewarded
Coldcard entropy flaw pushes multi-vendor multisig to the forefront of Bitcoin custody
BTC Sessions says tens of millions in Bitcoin were moved to safety after Coldcard flaw
BTC Sessions says Coldcard flaw may rank as Bitcoin’s worst self-custody incident