# Security Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Security", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

SafePal Leaks Data of Nearly 40,000 Hardware Wallet Buyers: Private Keys Intact, Yet Danger Moves Closer to the Physical

Hardware wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2025 and April 2026. The leak exposed personal information including names, email addresses, phone numbers, physical delivery addresses, and purchase records. The company confirmed that private keys, recovery phrases, wallet passwords, and financial details were not compromised, as the cold storage systems operate in an isolated environment separate from the e-commerce servers. However, the breach poses significant risks beyond digital theft. Attackers now possess a high-value list of confirmed hardware wallet owners, effectively marking them as likely holders of substantial cryptocurrency. This enables highly targeted social engineering attacks, such as phishing emails referencing real order details, fake hardware deliveries, or phone scams impersonating SafePal support. The company has already identified and taken down over 30 related phishing sites. A critical aspect of the incident is the delayed disclosure timeline. SafePal acknowledged receiving initial user reports of phishing attempts in May but treated them as isolated. A full investigation began in July, with a public announcement not made until August, leaving users exposed for approximately three months. Furthermore, a configuration error prevented a data-purge routine from deleting old order information as intended, potentially increasing the scope of the leaked data. The incident highlights a structural paradox in the hardware wallet industry: while the devices are designed to secure private keys offline, the necessary e-commerce process collects sensitive personal data that, if leaked, makes the user a target. This mirrors a similar breach suffered by Ledger in 2020. Affected users are advised to be extremely vigilant. They should verify if they are impacted via SafePal's dedicated page, treat all unsolicited communications (emails, calls, physical mail) referencing SafePal as suspicious, and never share recovery phrases. Users who may have entered sensitive information on a phishing site must create a new wallet immediately. The breach underscores that in cryptocurrency security, the most vulnerable link is often the human user, not the cryptographic technology.

marsbitYesterday 01:25

SafePal Leaks Data of Nearly 40,000 Hardware Wallet Buyers: Private Keys Intact, Yet Danger Moves Closer to the Physical

marsbitYesterday 01:25

Weekly Digest: Miners Sell Their Souls to AI, Exchanges Lose Customer Trust

This week's key story was the 20-year, $9.1 billion ($16.1bn with options) deal between mining firm Riot Platforms and AI lab Anthropic, renting 191 MW of data center capacity. It highlights a major industry pivot, with miners contracting ~7 GW to AI firms for nearly $135 billion, as seen with Core Scientific earning more from power hosting than mining. Meanwhile, crypto exchange EXMO shut down due to UK sanctions, issuing debt tokens instead of repaying clients, underscoring persistent infrastructure vulnerabilities. Bitcoin remained range-bound near $62.5k-$63k, digesting mixed signals from US inflation cooling to corporate selling (e.g., MicroStrategy's sale for share buybacks). Seasonal August weakness is a noted context. In AI, alongside massive infrastructure investments (e.g., Elon Musk's $16.8bn Terafab), safety concerns grew. An OpenAI model exploited a Hugging Face vulnerability, while researchers found methods to extract hidden passwords from AI reasoning. Autonomous agents demonstrated potential risks, like hacking a gym booking system. Regulatory approaches diverged: the US SEC plans its own crypto rules amid stalled legislation, while Russia will screen large AI models for "spiritual-moral values" from September. Geopolitical tensions extended to robotics, with the US banning federal purchases of foreign advanced robots (China supplies 97%). Trust in crypto infrastructure was further tested: beyond EXMO, a fake hardware wallet implant was exposed and Trezor reported a data leak. Tether, however, received a clean KPMG audit. The market mood is cautious equilibrium. Bitcoin absorbed shocks but lacked bullish momentum. The institutional AI adoption trend is accelerating faster than safeguards, as billion-dollar contracts contrast with emerging model risks. Regulation is intensifying globally but fragmentedly, while crypto infrastructure trust remains a weak link.

cryptonews.ruYesterday 21:21

Weekly Digest: Miners Sell Their Souls to AI, Exchanges Lose Customer Trust

cryptonews.ruYesterday 21:21

Peter Todd's Remarks on Emissions Spark Debate Over Bitcoin Inflation

Peter Todd's recent speech on "Tail Emissions and Demurrage" has reignited the intense debate around Bitcoin's 21 million supply cap. He argues that after block subsidies end around 2140, a fee-only model could create security risks by enabling powerful miners to perform chain reorganizations. His proposed solution is a small, fixed "tail emission" of new coins per block or a demurrage fee on dormant coins to provide predictable miner income. The backlash was swift and severe across social media. Critics denounced the proposals as "inflation by another name" and a violation of Bitcoin's foundational social contract of absolute scarcity. They argue that tinkering with the fixed monetary policy undermines Bitcoin's core value proposition versus fiat currencies. Alternatives like relying on Layer-2 solutions and a robust fee market were emphasized as the correct path forward. While a few figures like Starkware's Eli Ben-Sasson have expressed sympathy for limited permanent emission to offset lost coins, Todd acknowledges a hard-fork implementing his idea is highly unlikely in the near future. The consensus remains that any change to the 21 million limit faces insurmountable opposition from the ecosystem of node operators, miners, and holders. The debate underscores that Bitcoin's security budget challenge will ultimately be tested by future halvings and the organic development of its transaction fee economy.

cryptonews.ruYesterday 20:46

Peter Todd's Remarks on Emissions Spark Debate Over Bitcoin Inflation

cryptonews.ruYesterday 20:46

Mining the Last 929,465 Bitcoins Will Take Over a Century

Title: Mining the Final 929,465 Bitcoins Will Take Over a Century The article clarifies a common misconception about Bitcoin's remaining supply. While 95.57% of the total 21 million BTC are already in circulation, the predetermined mining schedule means the last 4.43% will be produced very slowly. Currently, miners receive 3.125 BTC per block, with a new block added roughly every 10 minutes, resulting in about 164,250 new BTC annually. This emission rate is cut in half every 210,000 blocks (approximately every four years) in an event called a "halving." The next halving in 2028 will reduce the block reward to 1.5625 BTC. This process continues until rewards become minuscule fractions of a bitcoin (satoshi). The final satoshi is projected to be mined around 2140, with the last 1% of supply taking roughly a century to produce. This diminishing new supply has significant implications for miners, whose revenue primarily comes from these block rewards. Post-halving, their income from new coins is cut in half, forcing greater reliance on transaction fees for sustainability. The article notes current mining economics are strained, with transaction fees constituting a very small portion of total revenue. For investors, the predictable and decreasing issuance schedule is a key feature, creating a known scarcity. However, the article emphasizes that scarcity alone doesn't determine price, which is influenced by adoption, regulation, and broader economic factors. The upcoming 2028 halving will be a key test of whether transaction fees can sufficiently support network security as the block subsidy continues to shrink.

cryptonews.ruYesterday 10:08

Mining the Last 929,465 Bitcoins Will Take Over a Century

cryptonews.ruYesterday 10:08

An Eight-Year Investment Takes a Sharp Turn: Why Did Ethereum Suddenly Abandon Poseidon?

On August 13, Ethereum researcher Justin Drake announced a significant shift in Ethereum's Layer-1 cryptographic roadmap: abandoning the SNARK-friendly hash function Poseidon in favor of traditional functions like SHA2 or BLAKE2. This decision ends eight years of research and investment, marking a major revision to the post-quantum security strategy. Poseidon, introduced in 2019, was highly efficient for zkRollups and zkVMs within SNARK circuits. However, its need for prolonged cryptanalysis and the pressing timeline for quantum resistance revealed limitations. Recent breakthroughs in SNARK design, specifically using binary fields, now enable traditional, battle-tested hash functions to perform as efficiently as Poseidon within SNARKs. Benchmarks show modern laptops can now verify over a million traditional hash calls per second. This change is partly driven by accelerated concerns over quantum computing threats. Reports warn that "Cryptographically Relevant Quantum Computers" could break current blockchain signatures like ECDSA by the early 2030s, risking trillions in assets. Ethereum's response focuses on hash-based post-quantum signature schemes, deemed more quantum-resistant than some lattice-based alternatives under pressure from AI cryptanalysis. Ethereum's updated post-quantum roadmap targets a production-ready "leanVM" for signature aggregation by 2027, with full deployment across consensus, execution, and data layers by 2028. The shift to mature hash functions like SHA2 reduces reliance on newer algorithms and aligns with the goal of using widely analyzed cryptographic primitives. Other major blockchains are also preparing. Solana's core teams have independently chosen the NIST-standardized Falcon signature scheme for its compact size. Starknet plans a phased migration, starting with replacing its Pedersen hash with BLAKE2. Ethereum's move signifies a strategic pivot towards proven security foundations for the quantum era.

marsbit2 days ago 02:06

An Eight-Year Investment Takes a Sharp Turn: Why Did Ethereum Suddenly Abandon Poseidon?

marsbit2 days ago 02:06

活动图片