๐จ ACTIVE EXPLOITATION
-
Coldcard Hardware Wallet Flaw Linked to $70M Bitcoin Theft in 41 Minutes
A firmware flaw in Coldcard hardware wallets enabled theft of over $70 million in Bitcoin.- Applies to Coldcard Bitcoin-only hardware wallets by Coinkite, including Mk2, Mk3 (4.0.0-4.1.9), Mk4, Mk5 (pre-5.6.0), and Q (pre-1.5.0Q) models
- Vulnerability caused by March 2021 firmware error routing seed generation to deterministic software PRNG instead of hardware RNG
- Attackers can reproduce seed outputs offline by constraining device UID, timer state, and RNG call history to derive victim addresses
- Galaxy Research mapped theft of 1,196 Bitcoin addresses totaling 1,082.65 BTC (~$70.2M) drained in 41 minutes on July 30, 2026
- Coinkite released emergency firmware July 31 but it does not repair existing compromised seeds; affected users must generate new seeds
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Hackers Target 30+ Minnesota Water Systems in 48-Hour Cyberattack
Over 30 Minnesota water systems were hit by a coordinated cyberattack in 48 hours.- Targets: More than 30 Minnesota community water systems including Braham, Maple Plain, Plymouth, South St. Paul
- Vulnerabilities: Water treatment control systems managing chemical dosing, pressure, and distribution
- Attack impact: At least one plant shut down; emergency statewide response activated
- Attack nature: Disruption-focused, no confirmed financial gain or direct public health impact yet
- Technical context: SCADA networks with legacy software and limited cybersecurity in smaller utilities
๐ Coverage: worldwaterreserve.com ยท ๐ via r/cybersecurity
๐ CVEs & KEV
- CVE-2026-55734 โ CVSS โ โ guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1Allocat...
- CVE-2026-55733 โ CVSS โ โ Atom-table exhaustion denial of service in Guardian permissions AtomEncoding ...
- CVE-2026-54894 โ CVSS โ โ Atom-table exhaustion denial of service in Guardian via unbounded atom creati...
- CVE-2026-55735 โ CVSS โ โ Guardian.revoke/3 acts on unverified token claims, allowing forged-token sess...