August 2, 2026
Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves
61 of 68 sources → 399 gathered → 399 triaged → 38 clustered → 38 written
An ongoing exploit against Coldcard hardware wallets is the story of the day, with losses now estimated above $88M across at least three attack waves. The rest was steady: a Russian captive-portal campaign, a fresh Rails patch, and a deep reverse-engineering teardown of CrowdStrike Falcon.
Threat Activity
- The Coldcard drain is still live and growing. What began earlier this week as reporting on a COLDCARD firmware/entropy weakness (earlier coverage) has escalated into one of the largest self-custody thefts on record — The Hacker News reports attackers drained roughly $70M in 41 minutes from addresses generated with weak entropy (The Hacker News). Trackers logged a second wave of 1,158 BTC from 2,673 addresses and a third wave pushing estimated losses past $88M (@DarkWebInformer). Galaxy researchers say the campaign is continuing and that ~600 attacker-linked addresses have been reported to investigators, urging Coldcard single-sig holders to move funds immediately (@glxyresearch). Note that the surrounding “timed to a chain fork / Clarity Act” theories circulating on X are unsubstantiated speculation.
Detection & Reverse Engineering
- A full teardown of CrowdStrike Falcon maps how the sensor actually catches you. The write-up reverse-engineers the Windows sensor end to end — kernel callbacks, Windows Filtering Platform hooks, minifilter, and the detection-engine architecture — and turns up a (low-severity) bug along the way. It’s a rare, detailed look at commercial EDR internals directly useful for evasion research and detection engineering alike (0xdbgman).
Cloud & Identity
- Microsoft attributes worldwide hotel Wi-Fi hijacking to Midnight Blizzard (Storm-2945). In its CaptiveCrunch report, Microsoft ties the Russian SVR actor to manipulation of captive-portal management infrastructure since May 2026, redirecting guest traffic through actor infrastructure to push fake OS updates and steal credentials — an evolution of the hotel-network abuse tracked earlier (earlier coverage). Since February the group has also run AI-augmented device-code and OAuth phishing leading to rogue Entra device registration and M365 data theft (Microsoft, The Hacker News).
- Device-code phishing has gone industrial in under six months. The abuse of the OAuth 2.0 device authorization grant — originally a niche red-team trick — is now a mainstream token-theft technique because it sidesteps MFA and leans on legitimate login flows, per a breakdown of why it’s scaling so fast (The Hacker News).
- Kyndryl Azure/Entra tenant data is being offered for sale. A forum actor claims 170,000+ records — employee and service accounts, admin roles, display names, emails — allegedly pulled directly from Kyndryl’s Azure/Entra environment using compromised credentials, with a 2,200-record sample posted (@DarkWebInformer).
Vulnerabilities & Exploits
- macOS Screen Sharing pre-auth RCE (macOS ≤ 26.5). An SRP frame-length validation bypass in
screensharingdenables remote root code execution — arbitrary file access and reverse shells before authentication. Fixed in macOS 26.6 (warez.sl0p.foo). - Joomla Content Editor RCE is under active exploitation. CVE-2026-48907, a critical RCE in JCE, was added to CISA’s KEV catalog after in-the-wild exploitation — watchTowr flagged client exposure six days ahead of the KEV listing (@watchtowrcyber).
- Rails ships the fix for the Active Storage RCE. The KindaRails2Shell flaw (arbitrary file read escalating to RCE via libvips) now has an official patch and a full technical write-up (earlier coverage); unauthenticated attackers can read arbitrary files and potentially reach code execution (BleepingComputer, Ethiack).
- Backdoor planted in the ARVE WordPress plugin. Wordfence found a hardcoded-token backdoor in ARVE v10.8.7 (CVE-2026-18072) granting full admin access; the plugin was pulled from WordPress.org after detection (Hackread).
- 84 flaws disclosed across 4G and 5G cores. NTU researchers describe a “widespread class” of vulnerabilities in cellular core networks enabling DoS and full session hijacking of a user’s network session (The Hacker News).
- SolarWinds Web Help Desk SAML auth bypass. A flaw in SAML 2.0 assertion handling lets an attacker bypass authentication and reach administrative functions on SAML-enabled deployments (NCSC-NL).
- Chrome’s recent releases fixed a staggering number of bugs. Google resolved 1,072 security issues across Chrome 149 and 150 — more than the prior 23 milestones combined — followed by another 370 in Chrome 151 (The Hacker News).
AI & Model Security
- DeepSeek’s new V4 Flash update draws rapid jailbreaks. The “0731” refresh jumps ten points on the Artificial Analysis index, landing near GPT-5.6 Luna at ~60% lower cost (The Decoder). Researchers immediately reported it as trivially jailbroken, with claims of cracking 6 of 8 refusal classes via a single system prompt and eliciting malware and hazardous-synthesis content — one tester calling it “extremely easy to jailbreak” (@elshayib_). (discussion)
- EU AI Act transparency obligations kick in August 2. From that date, providers must label or watermark AI-generated chatbots and synthetic media as authentic-looking content, alongside a new Brussels enforcement team targeting deepfakes and illicit imagery (Engadget, SecurityWeek). (discussion)
Supply Chain
- DPRK actor “PolinRider” behind dozens of npm, Go, and PHP compromises. New analysis extends the North Korean campaign already linked to the axios/debug/chalk incidents (earlier coverage), detailing how developer machines are hijacked via social engineering to silently push malicious releases; recommended mitigations include token rotation, dependency scanning, and access hardening (opensourcemalware.com).
- Two Joyfill npm beta releases were compromised to drop a RAT. The
@joyfillbeta packages execute malicious import-time code that installs a remote-access trojan and fetches further payloads; Socket advises immediate removal, host isolation, and credential rotation (Socket).
Threat Intelligence
- ShinyHunters resurfaces with new infrastructure and fresh victim claims. After announcing a “we’re back” statement with new Telegram/X channels and a PGP key, the group has listed several new victims including Questel SAS (claiming 21M Salesforce records / 147 GB) and Lumenis (@DailyDarkWeb).
- South Korean state-sponsored campaign abuses AnySign4PC via compromised sites. Authorities and four security firms detailed a watering-hole operation exploiting locally installed financial-security software to silently deploy SIGNBT and COPPERHEDGE backdoors with no user prompt (The Hacker News). A parallel “Operation Double Barrel” abuses WebSocket buffer overflows in two Korean financial-security products, with one intrusion chain delivering Gunra ransomware (blackorbird).
- DPRK macOS malvertising revives Contagious Interview. A new iteration redirects victims to full-screen fake update sequences to deliver crypto-stealing malware on macOS (The Hacker News).
Data Breaches
- CareCloud breach hits 350,000+. Attackers exfiltrated personal, financial, and medical data from the healthcare IT firm’s AWS environment back in March 2026 (SecurityWeek).
Topics
Vendors
Threat actors
Malware
Models