wallet securi2026-08-19 08:31:25Wallet security incidents put AI-driven crypto defense under the spotlightA string of wallet-related security incidents over the past month has sharpened attention on a wider shift in crypto security: the attack surface is expanding well beyond private keys, and AI is making every stage of the attack chain cheaper to run. The article links three separate cases — Coldcard’s random number generation flaw, Trezor’s exposure tied to a third-party logistics service, and SafePal’s risks involving order systems and plugin permissions — to a broader pattern in which code review, phishing generation, target selection and social engineering can all be automated at a much larger scale. It argues that wallet security can no longer be reduced to whether a seed phrase was stolen. Risks now span key generation, hardware, supply chains, user identity data, dApp connections, approvals, support channels and even AI agents. The piece also revisits earlier discussions from imToken on “AI × Web3 security,” outlining a more active defense model in which wallets use AI to review code dependencies, analyze suspicious dApps, simulate transaction outcomes before signing and build dynamic risk models around user behavior. Even so, it stresses that critical actions such as large transfers, new approvals and sensitive contract interactions still need clear user confirmation, least-privilege controls and explainable warnings.560
AI security2026-08-13 00:14:20Researchers say hidden reasoning traces from major AI models were once recoverable through smaller sibling modelsA research team from MATS Research, the University of Tübingen, the Max Planck Institute for Intelligent Systems and other institutions says proprietary large language model APIs previously exposed a way to recover hidden reasoning traces without breaking encryption or compromising servers. In a paper titled “Stealing Reasoning Traces from Proprietary LLM APIs,” the authors describe how encrypted reasoning blobs returned by flagship models could be fed back into smaller models from the same vendor, which then reproduced the hidden content. The paper names three examples: Anthropic’s Claude Opus 4.8 with Haiku 4.5, OpenAI’s GPT-5.6 Sol with GPT-5.6 Luna, and Google’s Gemini 3.1 Pro with Gemini Robotics 1.6. The researchers also examined 6,708 public agent trajectories gathered from GitHub and Hugging Face and said they recovered 315,320 hidden reasoning segments, including API keys, passwords, personal email addresses, access tokens and private keys. The paper estimates that, at Haiku 4.5 pricing at the time, decoding 10,000 reasoning traces with 12,000-token input and output windows would carry a nominal cost of about $720. The team says it reported the issue to Anthropic, OpenAI, Google, Microsoft and Hugging Face through responsible disclosure, and that the original attack method could no longer be reproduced by the time the paper was released.1710