SafePal flaw exposes data of nearly 40K customers
The incident separates wallet-control risk from privacy risk: private keys and seed phrases were not compromised, but customer-data protection is under scrutiny.
Every Zipp story tagged #WalletSecurity, newest first.
The incident separates wallet-control risk from privacy risk: private keys and seed phrases were not compromised, but customer-data protection is under scrutiny.
Private keys and seed phrases are untouched, but names, physical addresses and contact details are now in the wild, giving attackers a clean phishing dataset that will linger well past the patch.
The unresolved cause broadens the security question beyond one dormant wallet, putting old keys and wallet tooling under scrutiny for Ethereum users.
The $190K cap is the headline, but the real story is LND as a single-vendor credential risk now that attackers have demonstrated a working drain against the dominant Lightning node stack.
The bounty is set at 10% of recovered funds, capped at 3 BTC, while the flaw puts connected wallets and LND nodes at risk.
Half the value stolen since 2022 came from key theft, phishing, and governance, not contract bugs. The 'audited' badges never claimed to cover those layers.
Coldcard's migration guidance adds an immediate wallet-security issue to the fund movement, with specific device versions and seed setups requiring action.
The 55% surge in on-chain activity is the cleanest real-time signal that the Coldcard breach is forcing users to move funds, not just talk about it.
The figure is roughly twice the early read on the incident and lands Coldcard inside a growing supply-chain risk tier no Bitcoin custodian can ignore.
Galaxy mapped the July 30 sweep to 1,196 wallets and 1,082 BTC drained in 41 minutes via a seed-generation bug that collapsed the keyspace to a few billion options.
The campaign weaponises USB shortcuts, clipboard monitoring, and Tor to drain wallets, with an Uber Eats delivery breadcrumb hinting at how far the operators are willing to mass-pollute endpoints.
Project Eleven's zero-knowledge proof makes BIP-361's freeze recoverable for any post-2012 wallet with a seed phrase, but the 1.1 million BTC Satoshi mined before BIP-32 had no derivation tree to…
The Trezor executive agreed firmware updates can disrupt urgent transactions, but framed the critique as overbroad for the entire self-custody category.
The offering lands as Bitcoin's transition to post-quantum cryptography remains a theoretical debate, but institutions holding UTXO-based balances now get tooling to measure their exposure today.
Roughly 1 in 24 contracts scanned since the platform's launch carried a scam flag, with 80% of those hits landing in just the last 30 days, a pace that points to industrialised wallet-drain…
Microsoft's threat team linked the campaign to a hacking group it tracks as CryptoBandits, which uses poisoned USB sticks to seed malware that rewrites browser extensions for wallet theft.
The drainer did not exploit a contract bug — it exploited user signing habits. The reminder list is unsexy, which is exactly why it keeps working.
The stolen USDC was swapped into ETH inside two transactions within minutes — a drain pattern consistent with automated kits rather than a targeted attack on a high-value holder.
Web3 Antivirus has built a wallet risk scanner that lets users paste any Ethereum address, contract, or ENS name and…
The Ethereum Foundation has rolled out Clear Signing, an open standard designed to replace blind signing across the…