Bitcoin2026-08-22 15:32:52Bitcoin software faces AI-driven security pressure as Bitcoin Red Team races to find flawsArtificial intelligence is lowering the barrier to offensive cyber capabilities, and Bitcoin developers say that shift is turning wallets, apps, exchanges, Lightning software, and other tools around Bitcoin into more attractive targets. In an interview with Decrypt, pseudonymous developer Calle said the Bitcoin Red Team was formed as an emergency effort to identify AI-assisted threats across the broader Bitcoin ecosystem before attackers can use them. According to Calle, the volunteer group has about 20 to 25 members, including pseudonymous contributors such as Stu, Talip, and thesimplekid, along with developers Ben Carmen, Daniela Brozzoni, James O'Beirne, and Vinteum Bitcoin R&D Center board member Bruno Garcia. Calle said the group has not found issues in the Bitcoin protocol itself. The concern is centered on surrounding software that users rely on to transact with Bitcoin. Calle also said the team uses Chinese AI models far more often than U.S. models because guardrails on American systems can block security research. He argued that AI has weakened the information advantage that once kept some vulnerabilities out of reach for less-skilled attackers, and said crypto may be feeling that pressure earlier than other sectors because internet money presents a direct financial target.1230
Bitcoin2026-08-22 05:21:00Analyst Rob says Bitcoin’s 200-week average remains a buy zone, while self-custody risks call for diversificationCrypto market analyst Rob, host of the Digital Asset News YouTube channel, used a recent appearance on The Milk Road Show to lay out how he is navigating Bitcoin near the 200-week moving average, why he does not try to call an exact bottom, and how he adjusts weekly purchases using a risk model. He said Bitcoin around the 200-week line still looks attractive for dollar-cost averaging, and added that his current risk reading is roughly 0.3, which puts him in a 4x buying phase under his framework. Rob also discussed how he handles exits in bull markets, saying he prefers scaling out instead of trying to sell the top. He compared that with his growing concern over wallet security, recent incidents involving cold-wallet brands, and the limits of self-custody for ordinary users. Rather than relying on a single storage method, he said he spreads funds across Ledger, Tangem, iTrust Capital and spot Bitcoin ETFs. On altcoins, he said his focus stays narrow, with a core basket tied to four major stablecoin rails: BNB, ETH, SOL and TRX.1410
IRS2026-08-22 00:58:05IRS warns crypto holders about phishing letters posing as tax noticesThe U.S. Internal Revenue Service (IRS) has issued a security alert over a sophisticated phishing campaign targeting cryptocurrency holders. According to Techub News, attackers are mailing paper letters that impersonate the IRS and contain fake tax notices with QR codes designed to steal wallet credentials and private keys. The IRS has not disclosed how many victims there are or the amount of losses. It says recipients should not scan suspicious QR codes and should verify any tax notice through the official website or by phone. Law enforcement is investigating the source of the campaign.1250
Ethereum2026-08-21 15:21:01Security study says 63% of sampled EIP-7702 wallet authorizations were tied to malicious contractsA security paper presented at the USENIX Security Symposium found that 63% of the sampled Ethereum EIP-7702 wallet authorization transactions were linked to malicious contracts controlled by attackers, according to a Techub News report citing NewsBTC. The study said those malicious authorization activities have already resulted in more than $2.3 million in confirmed asset theft. The report said the main issue is not an inherent flaw in Ethereum itself. Instead, it centers on malicious authorizations and a broader wallet attack surface created around the way users approve permissions. EIP-7702, as part of account abstraction, lets externally owned accounts gain more flexible functionality through authorized code execution, but that same flexibility can leave users exposed if they sign harmful authorizations. Researchers said wallet interface design has become a critical layer of defense. They suggested wallets may need clearer warnings, stronger authorization displays, and better simulation tools so users can better understand the risks before signing.1080
Coldcard2026-08-21 12:10:55Coldcard ships firmware after bitcoin theft, says AI helped find more bugsColdcard has shipped a firmware update after a three-week review that followed a bitcoin theft. The company said the review uncovered problems unrelated to the flaw that cost users $114 million. It also said the update does not make a compromised wallet safe again, and that AI helped surface additional bugs during the process.1050
Policy Regula2026-08-20 13:36:19Fake AML check sites impersonate crypto services to trick users into wallet approvalsCybersecurity firm Malwarebytes has identified multiple fake cryptocurrency anti-money laundering, or AML, screening websites that imitate legitimate services such as AMLBot and try to get users to connect their wallets and approve transactions. The company said a real AML screening process only requires a public wallet address and does not require users to connect a wallet, approve permissions, or sign transactions. The fraudulent sites mimic a normal service flow with fake progress bars and fabricated screening results. One of the sites also asks users to deposit a small amount of funds as a supposed screening fee, then shows a result marked “clean, low risk” regardless of whether any actual check has taken place. Malwarebytes said connecting a wallet does not by itself steal funds, but it can expose wallet addresses and asset holdings, giving scammers the information they need to build transactions for users to approve later. Users who have granted suspicious token permissions should revoke them. Anyone who entered a seed phrase or private key should treat the wallet as compromised and move assets to a new wallet, according to the report cited by Decrypt.1720
crypto scams2026-08-20 13:34:04Fake Crypto AML Checkers Try to Trick Users Into Exposing WalletsCybersecurity firm Malwarebytes has warned that scammers are setting up fake anti-money laundering, or AML, checking services aimed at crypto users. The sites claim to assess whether a wallet has touched stolen funds, sanctioned entities, scams, or other suspicious activity, but instead push visitors to connect wallets and approve actions they should never need to authorize for a basic check. Some pages imitate the legitimate service AMLBot, while others use generic branding such as “AML Check.” Malwarebytes said the scam pages often display fabricated progress messages and bogus results to make the process look real, and at least one site asked for a small top-up fee before returning a “Clean, Low Risk” label. The firm stressed that a standard AML wallet screening only requires a public wallet address, not wallet connection, permission approvals, or transaction signatures. Malwarebytes also said the same layout and workflow appeared under multiple names and logos, pointing to a reusable scam kit. The warning comes as crypto phishing campaigns keep surfacing, including cloned sites tied to Coldcard, Pudgy World, and more than 1,200 fake CoinDCX domains identified over a period running from April 2024 to January 2026.490
Rapid72026-08-20 12:35:32Rapid7 says Operation Asterix targeted 885,000 phone numbers in crypto phishing pushCybersecurity firm Rapid7 has identified a cryptocurrency phishing operation, dubbed Operation Asterix, that targeted about 885,000 phone numbers across several jurisdictions in an attempt to steal investors’ assets. According to Rapid7, the campaign redirected victims to spoofed wallet provider sites and fake wallet apps, while recovered logs also showed fraudulent emails impersonating Crypto.com. The firm said 5,576 accounts matched to Binance users were queued for attack, and the largest dataset in the campaign contained 316,002 German mobile numbers. Additional directories covered Hong Kong, Bulgaria, the UK, the US, Canadian fintech companies and Ledger-linked lists. Rapid7 analysts Anna Sirokova and Jan Recinsky said the attackers impersonated Ledger, Trezor and Exodus and used fake support emails and phone calls to trick users into handing over seed phrases. From the German dataset alone, 43,066 accounts were matched to exchange users, implying a 13.6% hit rate. Rapid7 also found a Kraken checker used to bulk-validate phone numbers against exchange accounts and said AI tools played a major part in the campaign.560