# Vulnerability Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Vulnerability", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

Cryptocurrency Wallet Manufacturers Warn of Phishing Attacks

Hardware cryptocurrency wallet manufacturers Trezor and Foundation have warned users of a surge in phishing attacks following the disclosure of a vulnerability in Coldcard wallets. Trezor and Foundation both issued alerts via social media, stating they have observed an increase in phishing attempts where attackers impersonate the companies. They emphasized that they will never ask users for their wallet recovery seed or request the download of unknown software. Cybersecurity firm Proofpoint detailed the phishing scheme targeting Coldcard users. Attackers send emails pretending to be from the manufacturer, prompting users to perform a "hardware audit." This leads to a fake website where victims download a file that installs a legitimate remote access tool, potentially giving attackers control. This phishing wave coincides with a critical vulnerability in Coldcard devices, involving a flawed random number generator (RNG) in the firmware. This weakness could allow attackers to brute-force wallet seed phrases. Manufacturer Coinkite has released firmware patches but stressed that users with seed phrases generated on vulnerable versions must create new ones and transfer funds. According to Galaxy Research, confirmed losses from the Coldcard exploit are at least 1,596 BTC (~$100M) from about 7,300 addresses, with potential total losses reaching $130 million. The company warns at least 15 different attackers are actively exploiting the flaw.

cryptonews.ru08/04 14:58

Cryptocurrency Wallet Manufacturers Warn of Phishing Attacks

cryptonews.ru08/04 14:58

Being at the Front Lines of the Coldcard Theft Case Made Me Realize Why the Impact is Far Greater Than the Numbers Suggest

Even 5 years after a vulnerability was discovered, no one expected it to fuel the largest Bitcoin theft of the year. On July 30, anomalies were detected: hundreds of Bitcoin were aggregated from numerous addresses in a short timeframe, followed by a rapid expansion of the attack. The perpetrator scanned thousands of addresses, stealing nearly 2,000 BTC worth over $100 million. The cause was quickly identified: a bug in the mnemonic generation process of the Coldcard hardware wallet, specifically a weak random number issue that made the entropy predictable. While initially less noticed in China due to Coldcard's smaller user base, the incident caused an uproar overseas, where Coldcard is highly respected among Bitcoin OGs and maximalists. Panic peaked by July 31, with small transactions (under 1 BTC) reaching a daily volume of 39,600 BTC, the highest since FTX's collapse in 2022. The attack is believed to have been discovered and executed by an AI model, similar to a prior incident that halved Zcash's value, but with potentially more severe psychological impact. The breach shook the core belief system of Bitcoin's most dedicated community. According to Yu Xian, founder of SlowMist, who is assisting some victims, the profound impact lies in undermining trust in a historically reputable, open-source, "perfect" hardware wallet. This erodes confidence in self-custody solutions, leading some users to reconsider the perceived safety of centralized exchanges with robust security measures. For ordinary users, Yu Xian recommends: always use a passphrase with your mnemonic seed; maintain a small amount in a non-passphrase wallet as a canary; and for non-technical users, relying on reputable centralized services might be a simpler option. General advice includes auditing your asset storage methods, staying calm to avoid phishing, and isolating questionable assets. The incident underscores a critical security asymmetry: attackers, unrestricted and highly motivated, can leverage AI far more aggressively than defenders, who face various constraints. This dynamic could lead to even larger-scale breaches in the future, potentially involving core protocols like Bitcoin itself. The industry's challenge is to continuously evolve and strengthen its defenses in this ongoing arms race.

marsbit08/04 06:56

Being at the Front Lines of the Coldcard Theft Case Made Me Realize Why the Impact is Far Greater Than the Numbers Suggest

marsbit08/04 06:56

July Security Report: Total Losses Approximately $97 Million, Cross-Chain Bridge Attacks Concentrated with Over $35 Million

In July 2026, the cryptocurrency sector suffered total losses of approximately $97 million, with hacker attacks and contract vulnerabilities accounting for about $94 million. A significant trend was the shift in attack vectors from smart contract code to off-chain infrastructure, signature key leaks, and governance manipulation. Major incidents included: * **Ostium ($23.75M loss):** An attacker gained access to its off-chain price oracle signing system, manipulated BTC prices, and drained funds. * **AFX Trade Bridge ($24.15M loss):** The private validator key for its cross-chain bridge was compromised, allowing unauthorized withdrawals. * **BonkDAO ($20M loss):** An attacker acquired enough tokens to pass a malicious governance proposal and drain the treasury, exploiting low voting thresholds. * **Bonzo Lend ($9.05M loss):** A third-party oracle provider's signature verification was exploited to inject manipulated token prices. * **Verus Bridge ($7.55M loss):** A repeat attack exploiting the same unpatched bridge vulnerability. * **B2 Network ($3.86M loss):** An attacker seized the upgrade authority for a staking contract. Cross-chain bridges remained a prime target, with concentrated attacks causing over $35 million in losses. Phishing scams resulted in roughly $3 million in losses, employing sophisticated methods like fake mobile apps and physical counterfeit letters targeting Ledger users. Key takeaways are the acceleration of attacks on off-chain infrastructure, the persistent vulnerability of cross-chain bridges, and the rising prominence of governance-layer exploits. Recommendations include enhancing off-chain key management with multi-sig security, implementing stricter governance controls, and increasing user vigilance against phishing.

marsbit08/04 02:21

July Security Report: Total Losses Approximately $97 Million, Cross-Chain Bridge Attacks Concentrated with Over $35 Million

marsbit08/04 02:21

AI Bulk Bombards Apple Bug Bounty Program, Review Team Has Gone Offline

Apple has temporarily suspended and limited submissions to its Bug Bounty Program due to a flood of AI-generated vulnerability reports. The program, launched in 2016 and offering rewards up to $5 million, has been overwhelmed by reports from amateur researchers using tools like ChatGPT, many containing false positives or "AI hallucinations." This AI-driven surge in bug reports is straining Apple's security review team, leading the company to impose a 30-day "cooling-off" period and submission caps. The trend highlights a broader industry challenge, with other major firms like Google and GitHub also adjusting their vulnerability disclosure programs. Paradoxically, while AI is creating a reporting bottleneck, it's also accelerating defense. Apple's recent macOS Tahoe 26.6 security update, which patched 194 vulnerabilities, included its first-ever acknowledgments to AI tools (Claude, Codex Security, etc.) for helping discover flaws. This forces Apple into faster, more frequent security updates, a departure from its traditionally controlled release cadence. A key example involves Apple's advanced "Memory Integrity Enforcement" (MIE) security feature, touted as a major breakthrough. However, researchers using an AI model bypassed its protections in just five days, demonstrating both the power and disruptive pace of AI in cybersecurity. The incident underscores a critical shift: as AI compresses the vulnerability discovery cycle to days, traditional monthly security update cycles may become dangerously long exposure windows.

marsbit08/04 01:46

AI Bulk Bombards Apple Bug Bounty Program, Review Team Has Gone Offline

marsbit08/04 01:46

活动图片