Coldcard Users Must Move Funds After Seed Flaw
The bug was structural rather than random: a feature flag treated as present let attackers reconstruct private keys from a single button press, and Coinkite says severe losses have occurred even…
Every Zipp story tagged #Security, newest first.
The bug was structural rather than random: a feature flag treated as present let attackers reconstruct private keys from a single button press, and Coinkite says severe losses have occurred even…
Coldcard losses alone climbed past $100M as investigators widened the scope, proving a vendor-level flaw can drain thousands of cold wallets at once.
AI-assisted cryptanalysis hit a long-trusted digital signature scheme and a well-known symmetric cipher, signalling the model's research utility is widening beyond code and prose.
The $31.7M drained from two bridges is the headline; the third protocol pulling staking is the broader signal that DeFi is treating post-exploit contagion as the real threat.
Polosukhin argues formal verification is the only path left as AI collapses the timeline from vulnerability discovery to exploit, and from manual audit to proof generation.
The onchain investigator argues current hardware wallets aren't fit for signing critical transactions or storing large balances, and floated a dedicated iPhone as a stronger alternative.
Incidents are up but median loss per hack keeps falling, signalling attackers are shifting toward smaller or abandoned protocols while larger venues harden against AI-enabled exploits.
The Foundation frames AI-driven auditing as a force multiplier for human reviewers, not a replacement, and the false-positive ratio is the reason that distinction still matters.
The platform's wallet-to-wallet model sidesteps the pooled-custody attack surface that drained KelpDAO, Drift, and Grinex in a single quarter.
Treasury's $10B scam warning and a new DeFi coalition show the industry is finally treating social engineering and state-linked hackers as the primary attack surface, not smart-contract bugs.
The builder cannot trace the perpetrator, and recovery work is still running through parallel approaches two weeks after the breach first surfaced.
The flaw sat in SecondFi's address-generation layer, so moving a seed phrase to a new wallet offers zero protection, and SlowMist's wider loss estimate is the number every ADA holder is reading now.
A US criminal case built around a Bitcoin-funded Lamborghini has put physical attacks on crypto holders back in the courtroom, as cumulative losses from wrench attacks top $100M this year.
Bridges, flash-loans and key compromises have been engineered out. The remaining risk is bespoke protocol logic — and a single flaw now lands on Ethereum, Base, Arbitrum, Polygon, OP Mainnet and…
April logged breaches on 27 of 30 days and North Korea drained nearly $600M from Drift and Kelp — the executives on stage in Paris said the bridge problem alone is keeping institutional capital on…
Solstice Labs' CEO frames the gap as cultural, not technical: DeFi's growth is being undercut by a $2B+ exploit cycle that proves capital management, not code, is the missing layer.
OpenZeppelin's CEO says coding agents have flipped the asymmetry on smart contract security — and $1.1B in 12-month hack losses plus a $20B+ TVL drop make the warning impossible to wave off.
Cross-chain liquidity router Squid has moved to distance itself from a $3.2 million exploit tied to a third-party…
A four-chain drain hitting BTC, ETH, BNB and Base layers puts THORChain back on incident-watch — the fourth or fifth security event on a protocol that has been here before.
Ronghui Gu says the cost gap is structural: attackers lean on AI to scan operational and supply-chain gaps faster than white-hat budgets can keep up, while the Arbitrum freeze fallout threatens…