# Theft Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Theft", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru08/02 15:26

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru08/02 15:26

AFX Bizarre Theft Case: Audit Report Full of Holes, Suspected Parent Company is Crypto Exchange Phemex

The decentralized perpetual exchange AFX suffered a hack on its cross-chain bridge, resulting in the theft of over $24 million, effectively draining the protocol's TVL. Following the incident, scrutiny fell on a security audit report released in early June by firm Zellic. The report itself raised significant red flags, stating it only covered part of the bridge's components, lacked testing of critical security paths, and was conducted without access to a live or local environment for proper validation. Prominent figures, including MetaMask's Taylor Monahan, criticized the report as alarming, noting numerous confirmed issues were left unaddressed and suggesting the team exhibited negligent security practices, potentially with a single point of control. Further investigation reveals strong ties between AFX and the centralized exchange Phemex. Key evidence includes a core AFX team member's previous role as Phemex's Head of Listing, overlapping social connections, Phemex's now-deleted blog posts actively promoting AFX, and nearly identical brand aesthetics. Notably, Phemex itself experienced a major $70+ million hack in January 2025, attributed at the time to North Korean hackers. The close association between the two entities, coupled with AFX's deeply flawed audit and subsequent major breach, raises serious questions about security standards and potential internal risks, leaving the true nature of the incident—whether another external attack or an internal scheme—unclear.

链捕手07/24 07:14

AFX Bizarre Theft Case: Audit Report Full of Holes, Suspected Parent Company is Crypto Exchange Phemex

链捕手07/24 07:14

活动图片