Coldcard2026-08-13 21:39:51New Research Details How Coldcard Attackers Prioritized Rich WalletsAccording to Bitcoin News, new research by @PraveenPerera details how Coldcard attackers operated: they first identified vulnerable addresses, then sorted them by bitcoin holdings and began transferring funds from the highest-balance addresses. The tool used was rough — in one address with 225 spendable UTXOs, it pulled exactly the 200 newest records, matching a blockchain API's default 200-record limit and suggesting the attacker may not have loaded the next page. The software also spent a 294-satoshi UTXO, increasing transaction fees by around 2,040 satoshis. The researchers conclude the builder understood balance systems better than Bitcoin's UTXO model. Despite the attacker seemingly obtaining full seeds, at least 75 BTC remain in other addresses derived from those seeds; 132.95 BTC still sit in 153 stolen addresses, and the seeds cannot be reproduced, leaving open the possibility of undisclosed private device data.1600
Bitcoin2026-08-04 22:02:50Bitcoin Red Team says it scanned 150 repositories and plans to open-source AI audit toolsBitcoin Red Team, a volunteer group focused on security work around Bitcoin-related software, said it has scanned 150 code repositories and privately disclosed more than a dozen vulnerabilities, according to a post shared by Bitcoin News on X. The group said it uncovered key issues while helping harden wallets, cryptographic libraries, and infrastructure after the COLDCARD vulnerability incident. That effort has used about $20,000 in AI compute, a cost covered by OpenSats. Researchers involved in the work are using multiple AI tools, and many of them said open-source models such as Kimi K3 have become the main tools for security research. By contrast, frontier closed-source models from OpenAI and Anthropic were described as more restricted for this type of analysis. The team said it plans to release its AI security tools as open source so projects can keep auditing their own repositories. Researchers also warned that Bitcoin may be only the first sector to face a wave of AI-assisted vulnerability discovery, with similar work later spreading across open-source software more broadly.2070
Kraken2026-07-08 20:34:15Kraken Accuses Security Research Firm of Theft and Extortion; Certik Slams Threats Against EmployeesKraken CSO claims a security research firm stole $3 million and attempted to extort more; Certik identifies itself as the firm, accusing Kraken of threatening employees and demanding a mismatched crypto return.480