Policy and Re2026-08-31 10:55:47AI-driven impersonation scams are overtaking code exploits as a core crypto security threatImpersonation and AI-assisted fraud are becoming one of the most serious security problems in crypto, shifting attention away from code bugs alone and toward identity, access control, and accountability. Chainalysis said at least $14 billion in on-chain funds flowed into crypto scams in 2025, though not all of that activity was tied to AI. Within a subset of cases linked on-chain to AI vendors, the average scam operation was about $3.2 million, compared with roughly $719,000 for scams without those links, a correlation the company did not describe as causal. Executives interviewed across the sector pointed to a broad change in attack methods. Binance Chief Security Officer Jimmy Su said smart-contract security has improved enough that attackers now focus more on people around protocols, credentials, and governance systems, citing Binance security team assistance in stopping a $1.2 million governance attack on BrainTrust. Binance Research also said access control failures accounted for about two-thirds of the $621 million lost to DeFi exploits in April 2026 alone. The report also highlights unresolved attribution issues, mixer-related tracing gaps, and a new frontier in AI agents that can pay, register for services, and potentially transact on users’ behalf. Several executives argued that the missing layer is not transaction verification itself, but trustworthy identity and responsibility behind those actions.900
Coldcard2026-08-31 00:12:42Coldcard entropy flaw shakes self-custody confidence, but experts still favor holding your own keysA flaw tied to entropy handling in Coldcard hardware wallets has triggered Bitcoin losses and reignited a core debate in crypto: whether users are still better off keeping assets in self-custody after a wallet failure of this scale. According to the report, the issue stemmed from a deep firmware bug that remained hidden for five years and affected private-key generation on Coldcard Mk3 devices. During a code migration from Python to C, developers unintentionally disabled the built-in secure random number generator, causing the device to fall back to a highly insecure algorithm and reducing cryptographic entropy from 256 bits to just 22 bits. Speakers at Bitcoin Asia said the incident exposed weak spots in vendor maintenance, including code review, bug bounty design, and broader management practices. Even so, they argued that centralized exchanges still carry greater counterparty risk than hardware defects. The discussion centered on multi-vendor multisig setups using devices from different manufacturers, along with passphrase protections and modern coordination tools such as Liana, Unchained, and Casa. The report also said development teams are increasingly turning to AI-assisted code auditing to scan large legacy codebases and catch logic errors earlier. In that view, the Coldcard incident has damaged trust, but it has also pushed the ecosystem toward stricter security practices rather than away from self-custody.860
Sparrow Walle2026-08-27 12:55:54Sparrow Wallet rolls out v2.5.4 security update with broader independent verificationSparrow Wallet has released version 2.5.4 after what it described as extensive AI-assisted review, adding a set of security-focused changes aimed at cutting users’ reliance on external servers such as Electrum. The release strengthens handling for Ledger, Keycard, Trezor, Payjoin, PSBTs, and multisig workflows, while also removing Bitcoin Core credentials and other sensitive information from debug logs. In addition, the update restricts permissions on existing wallet and backup directories so they are accessible only to the owner. Another fix addresses lingering local DNS resolution leaks when Tor is in use. The release also tightens validation around wallet imports, signing, downloads, and server responses. According to Bitcoin News, the main thrust of the update is a wider scope for independent verification of transaction data, hardware devices, and other inputs, reducing dependence on data supplied by external servers.900
Tron2026-08-27 11:57:59Tron address poisoning attacks cost 15 victims about $9.4 million over four weeksOn-chain analyst Specter said a series of address poisoning attacks on the Tron network over the past four weeks has led to losses of about $9.4 million across 15 victims. Two victims each lost $2.5 million, while another lost $2 million. According to Specter, the attacker quickly swapped all stolen assets into the stablecoin USDD after each theft and moved the funds to a collection address, where the money remains. Specter urged wallet service providers in the Tron ecosystem to put blocking measures in place as soon as possible and advised users to carefully verify recipient addresses before making transfers. The disclosure points to a sustained attack pattern on Tron rather than a single isolated incident.920
1inch2026-08-27 09:26:231inch received 1,055 bug bounty reports in the first half, with 32 rewarded1inch has released its first-half bug bounty report in partnership with security platform HackenProof, outlining activity across six core bounty programs. The report said the programs received a combined 1,055 submissions, with 32 reports qualifying for rewards. By category, 1inch smart contracts received 267 reports and three rewards were issued. The wallet segment logged 85 reports, including six rewarded submissions, while the web segment received 68 reports and one report earned a bounty. In other areas, the Business segment received 111 reports, nine of which were rewarded. Infrastructure recorded 52 reports with four rewards. Aqua, the shared liquidity layer, had the highest submission count at 472 reports, with nine receiving payouts. According to the report, all issues covered by the rewarded and reviewed submissions have already been fixed.1020
Bitcoin2026-08-26 23:39:32Coldcard entropy flaw pushes multi-vendor multisig to the forefront of Bitcoin custodyBitcoin Magazine argues that the fallout from Coinkite’s Coldcard entropy bug has forced a broad rethink of Bitcoin self-custody practices, especially for users relying on single-signature setups. The article says the flaw, which reportedly went unnoticed since at least 2021, exposed how much trust single-seed users place in one hardware wallet maker’s key generation process. In response, self-custody advocates and industry participants are increasingly treating multi-vendor multisignature setups as a stronger default, because they spread signing authority across devices and manufacturers rather than concentrating it in one place. The report walks through the threat-modeling framework behind that shift. It highlights backup failures, forgotten passwords and theft as recurring causes of fund loss, then places bad entropy attacks alongside incidents involving Trust Wallet and fake wallet apps. It also explains how 2-of-3 and 3-of-5 multisig arrangements work, why providers such as Casa, Nunchuck, Sparrow and Unchained Capital are part of the discussion, and how advanced multisig designs can add resistance to coercion, phishing and social engineering. At the same time, the article notes a key tradeoff: users must preserve not only threshold signing access, but also a copy of the multisig script or template needed to reconstruct spending conditions independently.930
Bitcoin2026-08-26 20:01:23BTC Sessions says tens of millions in Bitcoin were moved to safety after Coldcard flawBTC Sessions said his team spent weeks helping Bitcoin holders affected by the Coldcard vulnerability move funds to safer storage, with an estimated tens of millions of dollars in BTC protected during the process. The update was shared by Bitcoin News on X. He said the response still came too late for some users. One member of his local Bitcoin community reportedly lost 90% of their Bitcoin, while a woman he spoke with lost all of hers. BTC Sessions described the incident as possibly the most serious self-custody event in Bitcoin’s history. He added that the episode forced him to rethink how assets should be held, saying the main lesson was the need to diversify security measures rather than rely on a single setup.870
Bitcoin2026-08-26 20:01:51BTC Sessions says Coldcard flaw may rank as Bitcoin’s worst self-custody incidentBitcoin News said in a post on X that BTC Sessions described a weeks-long effort by his team to help Bitcoin holders affected by the Coldcard vulnerability move funds to safety. He estimated that the work protected tens of millions of dollars worth of BTC during that period. Even so, he said the response came too late for many users. According to his account, one member of his local Bitcoin community lost 90% of their Bitcoin, while another woman he spoke with lost all of hers. BTC Sessions said the episode could be the most severe self-custody incident in Bitcoin’s history. He added that the experience pushed him to rethink asset custody, with diversified security measures standing out as the main lesson.880