# Security Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Security", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

The article discusses using dice rolls to generate secure Bitcoin wallet seeds, providing entropy independent of potentially flawed hardware random number generators. It explains that each fair dice roll offers about 2.585 bits of entropy, with around 50 rolls needed for a standard 12-word seed phrase and 99+ recommended for higher security. This method gained attention after a vulnerability was revealed in some Coldcard hardware wallets, where a faulty firmware RNG (dating back to 2021) compromised generated keys. The analysis notes that while a dice-generated main seed was safe from this specific flaw, other Coldcard functions (like creating paper wallets, backup keys, or passwords) could still be vulnerable if they used the defective RNG. The piece argues that while dice-based entropy is technically robust, the manual process is error-prone, tedious, and unrealistic for most new users, who might make mistakes in recording or inputting rolls. It concludes that while manual entropy generation should remain an option for advanced users, the long-term goal is to develop reliable, user-friendly hardware and software that securely generates randomness without requiring specialized knowledge. Coldcard users are advised to check their firmware version and replace any secondary secrets (like paper wallet keys) created with vulnerable devices, while also considering multi-signature setups with devices from different manufacturers for added security.

cryptonews.ru08/01 21:37

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

cryptonews.ru08/01 21:37

U.S. Tax Service Details New Cryptocurrency Fraud Scheme

The U.S. Internal Revenue Service (IRS) has warned of a new cryptocurrency fraud scheme. Scammers are sending paper letters impersonating official U.S. Department of the Treasury and IRS correspondence. These letters urge Americans to urgently register on a non-existent platform called the "Digital Asset Compliance Portal." The fraudulent letters contain QR codes linking to a phishing website disguised as the official IRS site. Victims are prompted to disclose their cryptocurrency exchange or wallet provider (examples given include Coinbase, Kraken, and Ledger) and the amount of crypto assets they hold. Jarod Koopman, Chief of the IRS Criminal Investigation Division, stated that criminals are exploiting public trust in government institutions by creating convincing fake websites and official-looking correspondence. According to the investigation, the infrastructure for this scam was set up just days before the mailing campaign began, using a domain registered through a Hong Kong-based registrar. The IRS assured taxpayers that it does not require them to provide wallet information via third-party sites or to click links from suspicious messages. The agency advised Americans to verify the authenticity of any notifications through official channels, such as making a phone call. This alert follows a recent FBI warning about a separate fraudulent scheme targeting cryptocurrency wallet holders on the Tron network.

cryptonews.ru07/31 20:30

U.S. Tax Service Details New Cryptocurrency Fraud Scheme

cryptonews.ru07/31 20:30

AFX Trade Promises to Present "Goodwill Plan" on August 3 Following $24 Million Loss Incident

AFX Trade, a cryptocurrency platform, announced it will present a "goodwill plan" on August 3rd, following a security incident on July 22nd that resulted in a loss of $24.15 million. The company's brief update offered no specific details on compensation for affected users, investors, and employees, only urging calm while the team formulates next steps. The theft occurred from a USDC custody account on Arbitrum, with the stolen funds converted to Ethereum. Blockchain analysts traced the funds to a single wallet. AFX Trade and Arbitrum clarified the exploit targeted a third-party bridge, not Arbitrum's native bridge. An investigation revealed the attack began on July 9th with a social engineering scheme targeting a developer. The attacker then deployed malicious code within AFX's internal JFrog repository and infrastructure, eventually compromising bridge validators to authorize the fraudulent withdrawal. The company stated the exploit leveraged a "trust vulnerability," not a smart contract bug. AFX Trade's head of business development made an offer to the attacker, proposing they keep 30% of the funds as a white hat bounty if 70% is returned. The incident fits a 2026 trend identified by TRM Labs: while the number of crypto hacks hit a record, total losses decreased. However, infrastructure and operational breaches, though fewer, accounted for the majority of financial losses. The AFX breach is classified as an infrastructure incident involving private key compromise.

cryptonews.ru07/31 12:41

AFX Trade Promises to Present "Goodwill Plan" on August 3 Following $24 Million Loss Incident

cryptonews.ru07/31 12:41

活动图片