daily cyber × ai intelligence

index

August 2, 2026

Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves

61 of 68 sources 399 gathered 399 triaged 38 clustered 38 written

An ongoing exploit against Coldcard hardware wallets is the story of the day, with losses now estimated above $88M across at least three attack waves. The rest was steady: a Russian captive-portal campaign, a fresh Rails patch, and a deep reverse-engineering teardown of CrowdStrike Falcon.

Threat Activity

  • The Coldcard drain is still live and growing. What began earlier this week as reporting on a COLDCARD firmware/entropy weakness (earlier coverage) has escalated into one of the largest self-custody thefts on record — The Hacker News reports attackers drained roughly $70M in 41 minutes from addresses generated with weak entropy (The Hacker News). Trackers logged a second wave of 1,158 BTC from 2,673 addresses and a third wave pushing estimated losses past $88M (@DarkWebInformer). Galaxy researchers say the campaign is continuing and that ~600 attacker-linked addresses have been reported to investigators, urging Coldcard single-sig holders to move funds immediately (@glxyresearch). Note that the surrounding “timed to a chain fork / Clarity Act” theories circulating on X are unsubstantiated speculation.

Detection & Reverse Engineering

  • A full teardown of CrowdStrike Falcon maps how the sensor actually catches you. The write-up reverse-engineers the Windows sensor end to end — kernel callbacks, Windows Filtering Platform hooks, minifilter, and the detection-engine architecture — and turns up a (low-severity) bug along the way. It’s a rare, detailed look at commercial EDR internals directly useful for evasion research and detection engineering alike (0xdbgman).

Cloud & Identity

  • Microsoft attributes worldwide hotel Wi-Fi hijacking to Midnight Blizzard (Storm-2945). In its CaptiveCrunch report, Microsoft ties the Russian SVR actor to manipulation of captive-portal management infrastructure since May 2026, redirecting guest traffic through actor infrastructure to push fake OS updates and steal credentials — an evolution of the hotel-network abuse tracked earlier (earlier coverage). Since February the group has also run AI-augmented device-code and OAuth phishing leading to rogue Entra device registration and M365 data theft (Microsoft, The Hacker News).
  • Device-code phishing has gone industrial in under six months. The abuse of the OAuth 2.0 device authorization grant — originally a niche red-team trick — is now a mainstream token-theft technique because it sidesteps MFA and leans on legitimate login flows, per a breakdown of why it’s scaling so fast (The Hacker News).
  • Kyndryl Azure/Entra tenant data is being offered for sale. A forum actor claims 170,000+ records — employee and service accounts, admin roles, display names, emails — allegedly pulled directly from Kyndryl’s Azure/Entra environment using compromised credentials, with a 2,200-record sample posted (@DarkWebInformer).

Vulnerabilities & Exploits

  • macOS Screen Sharing pre-auth RCE (macOS ≤ 26.5). An SRP frame-length validation bypass in screensharingd enables remote root code execution — arbitrary file access and reverse shells before authentication. Fixed in macOS 26.6 (warez.sl0p.foo).
  • Joomla Content Editor RCE is under active exploitation. CVE-2026-48907, a critical RCE in JCE, was added to CISA’s KEV catalog after in-the-wild exploitation — watchTowr flagged client exposure six days ahead of the KEV listing (@watchtowrcyber).
  • Rails ships the fix for the Active Storage RCE. The KindaRails2Shell flaw (arbitrary file read escalating to RCE via libvips) now has an official patch and a full technical write-up (earlier coverage); unauthenticated attackers can read arbitrary files and potentially reach code execution (BleepingComputer, Ethiack).
  • Backdoor planted in the ARVE WordPress plugin. Wordfence found a hardcoded-token backdoor in ARVE v10.8.7 (CVE-2026-18072) granting full admin access; the plugin was pulled from WordPress.org after detection (Hackread).
  • 84 flaws disclosed across 4G and 5G cores. NTU researchers describe a “widespread class” of vulnerabilities in cellular core networks enabling DoS and full session hijacking of a user’s network session (The Hacker News).
  • SolarWinds Web Help Desk SAML auth bypass. A flaw in SAML 2.0 assertion handling lets an attacker bypass authentication and reach administrative functions on SAML-enabled deployments (NCSC-NL).
  • Chrome’s recent releases fixed a staggering number of bugs. Google resolved 1,072 security issues across Chrome 149 and 150 — more than the prior 23 milestones combined — followed by another 370 in Chrome 151 (The Hacker News).

AI & Model Security

  • DeepSeek’s new V4 Flash update draws rapid jailbreaks. The “0731” refresh jumps ten points on the Artificial Analysis index, landing near GPT-5.6 Luna at ~60% lower cost (The Decoder). Researchers immediately reported it as trivially jailbroken, with claims of cracking 6 of 8 refusal classes via a single system prompt and eliciting malware and hazardous-synthesis content — one tester calling it “extremely easy to jailbreak” (@elshayib_). (discussion)
  • EU AI Act transparency obligations kick in August 2. From that date, providers must label or watermark AI-generated chatbots and synthetic media as authentic-looking content, alongside a new Brussels enforcement team targeting deepfakes and illicit imagery (Engadget, SecurityWeek). (discussion)

Supply Chain

  • DPRK actor “PolinRider” behind dozens of npm, Go, and PHP compromises. New analysis extends the North Korean campaign already linked to the axios/debug/chalk incidents (earlier coverage), detailing how developer machines are hijacked via social engineering to silently push malicious releases; recommended mitigations include token rotation, dependency scanning, and access hardening (opensourcemalware.com).
  • Two Joyfill npm beta releases were compromised to drop a RAT. The @joyfill beta packages execute malicious import-time code that installs a remote-access trojan and fetches further payloads; Socket advises immediate removal, host isolation, and credential rotation (Socket).

Threat Intelligence

  • ShinyHunters resurfaces with new infrastructure and fresh victim claims. After announcing a “we’re back” statement with new Telegram/X channels and a PGP key, the group has listed several new victims including Questel SAS (claiming 21M Salesforce records / 147 GB) and Lumenis (@DailyDarkWeb).
  • South Korean state-sponsored campaign abuses AnySign4PC via compromised sites. Authorities and four security firms detailed a watering-hole operation exploiting locally installed financial-security software to silently deploy SIGNBT and COPPERHEDGE backdoors with no user prompt (The Hacker News). A parallel “Operation Double Barrel” abuses WebSocket buffer overflows in two Korean financial-security products, with one intrusion chain delivering Gunra ransomware (blackorbird).
  • DPRK macOS malvertising revives Contagious Interview. A new iteration redirects victims to full-screen fake update sequences to deliver crypto-stealing malware on macOS (The Hacker News).

Data Breaches

  • CareCloud breach hits 350,000+. Attackers exfiltrated personal, financial, and medical data from the healthcare IT firm’s AWS environment back in March 2026 (SecurityWeek).