Coldcard2026-09-20 05:41:35Coldcard firmware flaw from 2021 linked to more than $100 million in stolen BitcoinA 2021 firmware flaw in hardware wallet maker Coldcard has been tied to a large Bitcoin theft, according to the report cited by Odaily. The issue allegedly reduced randomness in some recovery seeds, and attackers have moved roughly 1,600 to 1,800 BTC from affected wallets since July 30, spanning thousands of addresses and valued at more than $100 million. Coinkite, the company behind Coldcard, said it has to consider the possibility that someone used AI to review its public firmware, though there is still no confirmation that AI played a role in the attack. The report also pointed to a separate disclosure from Shielded Labs researcher Taylor Hornby, who said an audit agent powered by Claude Opus 4.8 found a vulnerability in the Zcash Orchard shielded pool circuit dating back to 2022. In testing, the flaw could create unlimited counterfeit ZEC without leaving traces. Developers fixed the issue within days, and no theft has been confirmed. Separately, Chainalysis said daily on-chain inscriptions carrying malware instructions and command-and-control information rose from about 2.06 to 11.1, a 440% increase.350
Coldcard2026-09-20 05:41:52Coldcard firmware flaw tied to theft of roughly 1,600 to 1,800 BTC, report saysA 2021 firmware flaw in hardware wallet maker Coldcard left some recovery seeds with insufficient randomness, and attackers have drained roughly 1,600 to 1,800 Bitcoin from affected wallets since July 30, according to ChainCatcher. The stolen funds span thousands of addresses and are valued at more than $100 million. Coldcard manufacturer Coinkite said it must assume someone used AI to review its public firmware, though there is still no confirmation that AI was involved in the attack itself. The report also cited a separate finding from Shielded Labs researcher Taylor Hornby, who used a Claude Opus 4.8 auditing agent to identify a Zcash Orchard shielded pool circuit flaw dating back to 2022. In testing, the bug could generate unlimited counterfeit ZEC without leaving traces. Developers fixed that issue within days, and no theft has been confirmed. Chainalysis data in the same report showed that on-chain insertions carrying malware instructions and command-and-control information rose from about 2.06 per day to 11.1 per day, a 440% increase.360
Chainalysis2026-09-19 15:27:20Chainalysis says malware operators are storing instructions on blockchains as on-chain malicious writes jump 440%Blockchain analytics firm Chainalysis said in a new report that cyber attackers are increasingly storing malware instructions on public blockchains, a technique it described as "dead drops" on-chain. The company said the attackers are not compromising blockchain protocols themselves. Instead, they are using the public and persistent data layer of blockchains as infrastructure. According to the report, malicious on-chain write activity tied to this technique has surged by about 440% since mid-2025. Chainalysis also linked different forms of the activity to actors associated with North Korea and Iran, as well as Russian-speaking cybercrime groups motivated by financial gain. The firm said the trend should change how defenders look at blockchain activity. For wallet providers and security teams, monitoring can no longer focus only on stolen funds or suspicious transfers. Public blockchain data may also be used to host operational instructions for malware.280
Chainalysis2026-09-18 16:59:38Chainalysis Says Blockchain Dead Drop Attacks Rose 420% as State-Linked Groups Took a Larger ShareBlockchain dead drop attacks, a technique that uses public blockchains to hide malware instructions or pointers to command-and-control systems, climbed 420% over the past 12 months, according to Chainalysis. The firm said the increase was measured on a year-over-year basis, and that by the second quarter of 2026, state-linked groups were responsible for roughly two-thirds of new activity each quarter and half of all activity it tracked. Chainalysis also reported a separate rise in malicious blockchain writes, from 2.06 per day before the arrival of high-capacity, open-weight Chinese AI models in mid-2025 to 11.1 per day in less than a year, a 440% increase. The report described campaigns tied to North Korea, suspected operators linked to Iran’s Ministry of Intelligence, and Russian-language criminal groups using chains including Tron, Aptos, BNB Smart Chain, Bitcoin, and Polygon. The firm said the technique does not make malware inherently more destructive, but it removes the central server defenders would usually seize or shut down. As long as the underlying chain stays online, the stored code or pointer remains accessible.450
North Korea h2026-09-17 23:49:23Asia Express: North Korea-linked onchain malware jumps, CoinEx to shut after nine yearsNorth Korea- and Iran-linked hackers were behind most of this year’s 420% rise in malware activity on public blockchains, according to Chainalysis, which said state-backed actors made up roughly two-thirds of new activity and tied the previously unattributed UNC5342 cluster to activity on Tron, Aptos and BNB Smart Chain. In a separate report, NBC said North Korea is using remote workers from third countries, including Iran and Lebanon, to pass job interviews before DPRK operatives take over the roles. Elsewhere in Asia, South Korean police referred 18 Polymarket users to prosecutors after identifying 26 users through public blockchain data, with total wagers of about 17.6 billion won, or $12.7 million. CoinEx said it will cease operations after nine years, citing weak trading volumes, lower liquidity in the bear market, and rising regulatory and compliance costs, while withdrawals will remain open until Dec. 22. The roundup also includes India’s tokenized corporate bond pilot with 10.25 billion rupees issued by three companies, Metaplanet’s cut to its Series 10 stock pool, policy developments in Hong Kong, Vietnam and Thailand, and new guidance from Singapore’s High Court on crypto asset valuation.520
Chainalysis2026-09-18 00:26:57Chainalysis says blockchain “dead drop” abuse jumped about 420% over the past 12 monthsA new Chainalysis report says the use of so-called blockchain “dead drops” — a technique that stores malicious payloads or command-and-control, or C2, configurations in on-chain transactions and smart contracts — rose about 420% over the past 12 months. The report says average daily malicious writes increased from 2.06 to 11.1, with more than 15 operations identified across five major public blockchains. Chainalysis also said that, as of the second quarter of 2026, state-backed actors accounted for roughly two-thirds of newly observed activity. The report names North Korea’s UNC5342, which it said had targeted crypto developers with fake job offers since February 2025 and repeatedly used TRON, Aptos and BSC. It also said parties linked to Iran’s Ministry of Intelligence had encoded data through Bitcoin OP_RETURN since late 2024, while Russian-speaking criminal groups were operating on Polygon under a malware-as-a-service model.390
Chainalysis2026-09-17 23:58:57Chainalysis Says State-Linked Hackers Now Account for Half of Malware Instructions Hidden on BlockchainsMalware instructions written directly to public blockchains have surged more than fivefold over the past year, and state-linked operators now account for roughly half of the attributed activity, according to a Thursday report from Chainalysis. The firm said daily writes carrying malware instructions rose from 2.06 to 11.1 after open-weight Chinese AI models were released in mid-2025, spanning more than a dozen malware strains across five blockchains. Chainalysis described the method as a "blockchain dead drop," where attackers place the address of a command server inside a smart contract or transaction instead of embedding it in malware. Infected machines then query the chain to learn where to connect, making domain blocking far less effective. The report said instructions written to public chains are extremely difficult to seize or remove through traditional means. The company outlined three operating models: a North Korean group tracked by Google as UNC5342 using TRON, Aptos, and BNB Chain; operators suspected of links to Iran’s Ministry of Intelligence writing instructions into Bitcoin transactions; and a Russian-language criminal service model renting resolver contracts on Polygon. Chainalysis said state-linked groups began appearing in meaningful numbers in mid-2024 and were responsible for 51% of attributed writes by the second quarter of 2026.410
Mexico2026-09-12 13:17:59Mexican authorities uncover illegal crypto mining site in Puebla with 300 GPUsMexican authorities have uncovered an illegal cryptocurrency mining operation in a remote mountain building in Tlacuilotepec, Puebla state, according to Reuters as cited by ChainCatcher. Officials found 300 GPUs, 80 medium-voltage terminals, and eight satellite dishes at the site, and are now investigating whether the operation stole electricity from a nearby hydroelectric plant. The case is the fourth similar crypto mining farm discovered in the area since the beginning of last year. Three other sites were previously found near a hydroelectric facility in northern Puebla. Local residents said the noise from the equipment could be heard from as far as one kilometer away. Security analyst David Saucedo said the setup suggests a new level of sophistication from drug trafficking groups, given the technical expertise and financial backing required. Chainalysis Latin America specialist Caio Motta said such sites are often located in areas with very low power costs or within territory controlled by organized crime, making power theft and large-scale mining infrastructure easier to establish.780