hardware wall2026-08-26 18:16:05BitBox says card-payment sales rose roughly 10x after Coldcard incident; Trezor and OneKey also report gainsHardware wallet maker BitBox said its credit-card payment sales in August rose by about 10 times versus a baseline from the previous several weeks, with most of the increase coming from North America. Trezor and OneKey also confirmed higher sales over the same period, though neither company disclosed exact figures. After the Coldcard incident, Trezor, BitBox, and OneKey said they re-examined processes tied to mnemonic generation, random number generators, entropy, and firmware verification. Trezor plans penetration testing for core firmware functions and said it will publish the related security audit report. OneKey said it will step up reviews of security-critical code paths and transaction-signing procedures. Ledger CTO Charles Guillemet said AI-assisted attacks mean patch releases, vulnerability disclosure, and user education need to move faster. Blockstream Jade has already released a firmware update with multiple fixes and advised users to update their apps, operating systems, devices, routers, and home appliances as well.940
SafePal2026-08-23 12:53:24SafePal says it is selecting anti-phishing firms and independent security auditors after order system data leakSafePal has shared a fresh update on its response to a previous data leak involving its order system. The Web3 wallet brand said it is tracking phishing websites and impersonation accounts on a daily basis and submitting takedown requests, while narrowing down a final choice from four professional anti-phishing companies to speed up removals. The company also said it is monitoring dark web forums and other channels for any signs that affected data is being sold or made public, and plans to alert impacted users immediately if such activity is detected. On the audit side, SafePal said it is choosing from three independent security firms for a full review of the order system. It added that its order and logistics processes are being reviewed at the same time to reduce the scope of retained data. Impacted users can continue to receive one-on-one help through official support channels, while updates, FAQs and scam cases will be posted on the company’s scam-protection page. SafePal also reminded users that it will never ask for seed phrases.1130
SafePal2026-08-23 12:55:51SafePal says it is vetting anti-phishing and audit firms after security incidentSafePal has released a follow-up update on its recent security incident, saying it is continuing to track phishing websites and impersonation accounts while moving to speed up takedowns of malicious content. The wallet project said it is making a final selection from four specialized anti-phishing security firms and expects the chosen partner to improve its response to fake websites and scam accounts. The team also said it is monitoring whether affected data is being sold or disclosed, including on dark web forums and trading marketplaces. If signs of related data exposure are found, impacted users will be alerted immediately. On the audit side, SafePal said it is choosing from three established independent security firms to carry out a full review of its order system. At the same time, the company is reassessing its order and logistics processes to reduce the amount of data stored at the initial stage of the system, aiming to lower risk at the source. For affected users, SafePal said it will keep offering one-on-one assistance through official support channels and continue updating its scam protection page with incident updates, FAQs and scam case analysis. The company again reminded users that official staff will never ask for a seed phrase.1190
Sherlock2026-08-18 15:50:00Sherlock launches Audit Engine for coordinated AI security reviewsBlockchain security audit platform Sherlock said it has launched Sherlock Audit Engine, a system it describes as combining its strongest AI security methods into a coordinated review workflow. The company said the goal is to open a new stage of AI-native security auditing. Sherlock added that its team spent several months building the engine in a non-public environment and tested it against high-risk code. The Audit Engine is now live and can conduct coordinated AI security reviews for smart contracts and other code.1020
Bitcoin minin2026-08-14 14:02:46256 Foundation flags 41 issues in ASIC firmware audit, with risks centered on third-party builds256 Foundation has launched its 256 Red Team security effort to audit ASIC miner firmware, according to a post shared by Bitcoin News on X. The group said it used reverse engineering, live traffic capture, and share-level reconciliation in its review process. The team reported that it has filed 41 issue reports covering stock Bitmain firmware as well as third-party options including LuxOS, VNISH, and Braiins OS. The issues identified include unauthenticated factory APIs, paths that can grant root access, default credentials, embedded vendor SSH keys, and update tools that cannot verify what is being installed. After decompiling Bitmain miner daemons and examining live connections, the researchers said they found no evidence of hashpower skimming, remote kill switches, or covert beacons in Bitmain’s stock firmware. They said the main concerns were concentrated in third-party “optimization” firmware instead. The researchers have sent three responsible disclosures to VNISH, Luxor, and Braiins, giving each party 30 days to respond before public disclosure. Future audits are planned for MicroBT, Canaan, Auradine, Bitdeer, and ePIC.1300
Zilliqa2026-08-12 09:51:53Zilliqa's Address Detection Tool Goes Live as Migration Audit NearsZilliqa has issued the latest update on the random number generation vulnerability that was previously disclosed in its Ledger application. According to the project, the address detection tool has now gone live, while an audit of the migration tool is about to begin. Once the audit results are confirmed, Zilliqa will announce the specific launch date for the migration tool, the team confirmed in its announcement. On the migration front, several exchanges have already confirmed that they will take part in the process, and the first batch of exchange migrations is being targeted for completion by the end of August. Zilliqa also said that the work of tracing stolen funds is continuing, and that this effort is being carried out together with law enforcement, exchange partners and other relevant parties. Because the investigation is still in progress, the project cannot disclose further details at this stage, according to a statement from Zilliqa.1520
Babylon2026-08-10 14:19:15Babylon says TBV audit is complete ahead of native Bitcoin collateral launch on Aave v4Babylon said its Trustless Bitcoin Vaults, or TBV, protocol has completed a security audit by Runtime Verification as it prepares native Bitcoin for collateralized lending on the Aave v4 mainnet. The audit, according to Runtime Verification, lasted seven weeks and was completed in May 2026. The review combined design analysis, manual code review, and formal verification based on Kontrol, the firm’s symbolic execution engine. Runtime Verification said the work covered the full vault lifecycle, atomic cross-chain mint and redemption flows, and the settlement, borrowing, and liquidation logic tied to the Aave v4 integration. It also said every issue identified during the audit was either resolved during the remediation period or otherwise confirmed. The disclosure came from a post by Babylon on X, where the project framed the completed review as a step toward bringing native Bitcoin-backed lending to Aave v4.2150
Coinkite2026-08-07 08:51:47Coinkite Says It Will Publish Technical Post-Mortem on Coldcard Firmware BugCoinkite said it will release a detailed technical post-mortem on the Coldcard firmware vulnerability once security conditions allow. The company said the bug has already led to more than $100 million in confirmed losses, with about 1,596 bitcoin stolen from 7,300 addresses. It also said it cannot independently verify a separate estimate of roughly $130 million because of Coldcard’s privacy-first design, and that it is focused on helping affected customers while posting updates on its blog. Coinkite also said industry-wide AI-assisted security audits have uncovered multiple critical vulnerabilities in crypto software systems, according to Bloomberg.1750