GCP Exclusive Reporting

10/cate3/GCP Exclusive Reporting

Featured Startups

5/cate1/icos

exchanges

6/cate2/exchanges

videos

6/cate3/videos

regulations

5/cate1/regulations

Now Playing:

3/cate6/videos

Recent post

The Sandbox Bridge Was Exploited, Creating More SAND Than Was Ever Supposed to Exist...

Sandbox Bridge SAND Exploit

The Sandbox has contained a cross-chain bridge exploit that allowed an attacker to create unbacked SAND tokens on Base and BNB Smart Chain, producing one of those crypto headlines that sounds physically impossible at first glance: security researchers counted billions of newly minted SAND, with one estimate putting their nominal value near $49 billion.

No, an attacker did not steal $49 billion from The Sandbox. There was never $49 billion of real value sitting there waiting to be withdrawn. The number came from applying SAND's normal market price to an absurd quantity of tokens that had been created without collateral behind them.

That distinction is the center of this story.

What the Attacker Actually Found

The affected infrastructure was the cross-chain version of SAND used on Base and BNB Smart Chain. In a normal bridge setup, SAND is locked on Ethereum and a corresponding amount can then exist on another supported network. The supply on the destination chain is supposed to remain backed by the original tokens.

According to blockchain security firm Blockaid, the attacker hijacked LayerZero delegate permissions tied to SAND's omnichain fungible token contract and used the approveAndCall function to mint tokens that had no corresponding SAND locked behind them. Blockaid flagged roughly $49 billion in face-value minting across more than 400 transactions while the attack was still underway.

PeckShield later counted roughly 14.9 billion SAND minted across two attacker addresses. For perspective, SAND's stated maximum supply is only 3 billion tokens. The forged amount identified by PeckShield was therefore close to five times the maximum supply the token was ever supposed to have.

Crypto has found many creative ways to make token supply charts look strange. Creating several extra lifetimes' worth of supply in one exploit is certainly one of them.

Why $49 Billion Was Never Really $49 Billion

At the time of the incident, SAND's entire market capitalization was only around $140 million. There was obviously nowhere near enough liquidity on Base, BNB Chain, centralized exchanges, or anywhere else to turn tens of billions of newly created tokens into tens of billions of dollars.

If someone creates 10 billion unbacked tokens and the legitimate token trades at five cents, a block explorer can display a theoretical value of $500 million. That does not mean there are buyers willing to hand over $500 million. In an exploit like this, the displayed value becomes increasingly fictional as the unauthorized supply grows.

The economically important questions are how much legitimate liquidity the attacker could reach, whether any backed tokens or other assets escaped before containment, and who was left holding affected liquidity positions. The Sandbox has not yet published a full technical post-mortem or a final audited loss figure.

The Sandbox Shut the Doors on Base and BNB Chain

The Sandbox said it identified and contained the vulnerability, disabled bridging to and from Base and BNB Smart Chain, and isolated SAND on those networks so the affected tokens cannot be moved or redeemed through the official bridge.

The company also said SAND on Ethereum and Polygon was unaffected, no user wallets were compromised, and the Ethereum-held SAND backing legitimate bridged tokens remains intact. It warned users not to buy, sell or trade SAND on Base or BNB Smart Chain while liquidity on those networks is compromised. CoinDesk's report also noted that Upbit and Bithumb suspended SAND deposits and withdrawals after the incident.

The team is taking a pre-incident snapshot and says it is preparing compensation for eligible users of the affected liquidity pools. A full incident report and technical post-mortem are still expected.

There Is One Number That Still Needs Clarification

The Sandbox described the impact as less than 0.01% of total SAND supply. Taken literally against a 3 billion-token maximum supply, 0.01% would be fewer than 300,000 SAND.

That clearly does not describe the total number of unauthorized tokens minted, because independent security firms observed billions. The most reasonable reading is that The Sandbox is using "impact" to describe the amount of legitimate value affected rather than the quantity of fake tokens created. The company has not yet fully reconciled those figures publicly, so investors should avoid treating the 0.01% statement as a measurement of the exploit's minting activity.

That distinction matters because headlines can easily swing from one bad interpretation to another. Calling this a $49 billion theft would be wrong. Calling it a trivial exploit because the project says the impact was under 0.01% would also skip over what actually happened.

The Weak Link Was the Cross-Chain Layer

Ethereum SAND itself was not reported compromised. The exploit targeted the machinery that lets representations of SAND exist on other networks. That is a familiar pattern in crypto security: the underlying chain or token can work exactly as designed while permissions in a bridge create a completely separate attack surface.

The technical issue is particularly important because the attack involved LayerZero-related delegate permissions. That does not automatically mean LayerZero itself was compromised. The available reports point to permissions associated with The Sandbox's SAND OFT deployment. The final post-mortem will need to explain precisely where control failed, how the delegate authority was obtained, and why the minting path accepted it.

Until that report arrives, traders should focus on the facts that can be established: unbacked SAND was minted on Base and BNB Smart Chain, the affected bridge routes have been disabled, Ethereum and Polygon SAND were reported safe, and the eye-popping $49 billion figure measures theoretical face value rather than money stolen.

The exploit may ultimately prove modest in direct financial losses, but the permission failure was anything but modest. When a bridge can create several times a token's maximum supply before someone hits the stop button, the post-mortem matters almost as much as the reimbursement plan.

---------------

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News

Strategy Makes $334 Million in New Investments... None of it Bitcoin.

Strategy investmenrts

For years, Strategy had one of the easiest corporate capital allocation stories in America to explain: sell securities, buy Bitcoin, repeat. That story is now getting more complicated.

Strategy sold 3,458,866 shares of MSTR between August 10 and August 16 and raised $333.7 million in net proceeds. It bought no Bitcoin. It also sold no Bitcoin during the week. Instead, the entire haul went toward preferred-stock dividends, repurchasing STRC preferred shares and adding cash to the company's growing U.S. dollar reserve.

The breakdown in Strategy's latest SEC filing is unusually revealing. Of the $333.7 million raised, $52.4 million went to STRC dividends, $132.2 million funded the repurchase of 1,388,720 STRC shares, and $149.1 million went into the dollar reserve. In percentage terms, roughly 16% funded dividends, 40% funded preferred-stock buybacks and 45% went to cash.

The Bitcoin Machine Has Become a Capital Structure Machine

Strategy still owns an enormous amount of Bitcoin: 840,447 BTC acquired for an aggregate $63.36 billion, or an average of $75,385 per coin. But its behavior since late June shows that management is now actively balancing Bitcoin exposure against the obligations created by its increasingly elaborate stack of common stock, preferred stock and debt.

The change did not begin this week. Strategy's last Bitcoin purchase was 520 BTC reported on June 22. Since then, its own Bitcoin ledger shows four rounds of sales totaling 6,916 BTC: 1,363 BTC around the end of June, 2,225 BTC in early July, 1,638 BTC reported in early August and another 1,690 BTC reported last week. Add the small 32 BTC sale from earlier in June and Strategy has sold 6,948 BTC during 2026.

That is tiny next to an 840,447 BTC treasury, so calling this an exit from Bitcoin would be absurd. It is not. What has changed is the old assumption that every fresh dollar raised by Strategy is destined to become another satoshi on the balance sheet.

Why Strategy Is Building So Much Cash

Strategy created its U.S. dollar reserve to cover preferred-stock dividends and interest on outstanding debt. The reserve stood at $4.80 billion as of August 16, up from $4.65 billion a week earlier and $2.55 billion in early July.

That cash pile matters because Strategy now has recurring obligations that do not disappear when Bitcoin has a bad quarter. Preferred shareholders expect dividends. Debt holders expect interest. Bitcoin, famously, does not care about either one.

In late June, Strategy's board formally approved a Bitcoin monetization program that allows the company to sell BTC to replenish the dollar reserve, cover preferred dividends and interest, or fund repurchases of its securities. The company also authorized up to $1 billion of preferred-stock repurchases and up to $1 billion of MSTR repurchases.

Last week's transactions show the other side of that framework. Strategy did not need to sell BTC because it could issue common stock instead. In effect, the company sold new MSTR shares, used part of the proceeds to buy back STRC, paid STRC dividends and banked the rest.

For common shareholders, that is a much more nuanced equation than the old "issue stock and buy Bitcoin" model. Selling MSTR creates dilution. Buying back preferred shares can reduce financing costs or improve the capital structure. Building the dollar reserve lowers the risk that a prolonged Bitcoin downturn forces unpleasant choices later. Whether the trade is attractive depends heavily on the price at which each security is issued or repurchased.

There Is Still a Lot More MSTR That Can Be Sold

Strategy reported about $21.7 billion of remaining capacity under its MSTR at-the-market programs. That does not mean the company will issue all of it, but it gives management a very large financing lever if market conditions allow.

The company also had $653 million of authorization remaining for preferred-stock repurchases after last week's STRC purchases. Its separate $1 billion MSTR repurchase authorization remained untouched.

This is the part of Strategy that is becoming easy to miss if every update is reduced to one question about how much Bitcoin Michael Saylor bought. Strategy is now managing several securities that interact with each other, with Bitcoin and with a multibillion-dollar cash reserve. The Bitcoin treasury remains the center of gravity, but it is no longer the only moving part.

The latest week is therefore notable precisely because nothing happened to the Bitcoin count. Strategy raised $333.7 million and found three other uses for it. For investors who still model MSTR as a simple machine that converts equity issuance directly into Bitcoin, the machine has clearly acquired a few more gears.

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News

Harmony Exploit Forged 3.01 Trillion Tokens, They Want to Fix it By Reverting Blockchain to Pre-Hack Date...

Harmony Exploit

Harmony's latest security incident has gone from bad to surreal. What initially looked like an unauthorized mint of about 4 billion ONE has turned into a reconstructed total of roughly 3.01 trillion forged tokens, and the network's chosen fix is equally dramatic: roll the blockchain back to a point before the exploit and throw away everything recorded after it.

Harmony says the forged supply was created through six cross-shard transactions and sent to four attacker-controlled wallets. One wallet alone moved 2.385 trillion ONE through 477 successful transfers in just 106 seconds. At pre-attack prices, that quantity had a notional value measured in billions of dollars, although no attacker could realistically sell trillions of ONE anywhere near the pre-attack market price.

The Original 4 Billion Figure Was Only the Beginning

Harmony first acknowledged the incident on August 12 after researchers spotted unauthorized ONE appearing through empty blocks. The early analysis identified two records that created 1 billion and 3 billion ONE. That 4 billion figure was alarming on its own because it represented a large chunk of the legitimate token supply.

A deeper reconstruction changed the scale completely. Harmony's later incident update said investigators found a flaw in cross-shard receipt verification that allowed valid receipts to be processed more than once.

In plain English, a cross-shard receipt is evidence that something happened on one part of Harmony's sharded network and should be credited on another. If that receipt can be reused, the receiving side can credit value repeatedly without a matching debit happening again on the sending side. That turns a bookkeeping proof into a printing press, which is generally not a feature anyone wants in a monetary system.

Harmony patched the vulnerability on August 12 with Mainnet v2026.1.1 and suspended bridge services while it worked with validators, exchanges and infrastructure providers to contain the damage. The project has said it traced more than 99.9% of the forged ONE pathways to wallets or service clusters. Tracing a path, however, is not the same thing as recovering the money or identifying the person behind the wallet.

Why Harmony Chose a Full Rollback

The team considered less disruptive options. Those included blacklisting wallets, trying to burn forged tokens, selectively replaying legitimate transactions and even migrating ONE to a new token. Harmony concluded that each option created its own problems, especially because forged tokens had already moved through exchanges, decentralized pools, bridges and other wallets.

If an innocent user received ONE that had passed through an attacker-linked pool, a blunt blacklist or burn could punish the wrong person. Selectively restoring transactions sounds cleaner until smart contracts, balances, transaction nonces and dependent transactions no longer line up with the altered history.

Harmony's answer is a fixed rollback window. Its rollback plan keeps Shard 0 at block 92,730,034 and Shard 1 at block 94,978,278, both timestamped August 11 at 23:25:37 UTC. New blocks would then be produced from replacement databases built around those checkpoints.

The cost is real. Harmony says the discarded window contains 141,628 consecutive blocks, 109,126 regular transactions and 315 staking transactions. Those are not all attacker transactions. Legitimate activity after the checkpoint disappears too.

Harmony says about 95.8% of the affected regular transactions were automated activity, much of it associated with decentralized exchange bots. The network also said only 22 of the 109,126 regular transactions were simple native transfers with no obvious dependency in its data. Even those cannot simply be dropped back into the replacement chain with complete confidence because the state around them may have changed.

This Is What Blockchain Finality Looks Like Under Stress

Rollback debates tend to become philosophical very quickly because blockchains market themselves around immutability. In practice, public chains are software systems run by human communities, validators and developers. When the ledger itself has accepted a catastrophic amount of forged supply, every available choice damages something.

Do nothing, and trillions of unauthorized tokens remain part of the ledger. Blacklist aggressively, and innocent holders can get caught in the blast radius. Attempt a surgical reconstruction, and subtle state mismatches can create a second disaster. Roll back the chain, and valid transactions that users reasonably believed were final are erased.

Harmony chose the last option because it believes one audited cutoff applied to everyone creates the lowest risk of another exploit or consensus failure. Whether validators, exchanges, bridges and users can coordinate the restart cleanly is now the practical test.

Harmony Has Been Here Before, but This Attack Is Different

The incident also lands on a network with painful security history. In 2022, Harmony's Horizon bridge lost about $100 million in crypto. The FBI later attributed that theft to North Korea's Lazarus Group. That attack targeted bridge infrastructure. This one is more fundamental because the vulnerability involved the network's own cross-shard verification logic and the creation of native ONE.

There is no public evidence at this point linking the current exploit to Lazarus Group, and it would be irresponsible to imply otherwise. The relevant comparison is technical and reputational: Harmony is once again asking users and counterparties to trust its recovery process after a major security failure.

The patch may have closed the bug, but the harder part is restoring a coherent ledger, reconciling exchange and bridge balances, and convincing users that the replacement history can be treated as final. A blockchain can survive a rollback. Restoring confidence after trillions of tokens appeared from nowhere is the more difficult job.
---------------

Author: Dorian Fenwick
Silicon Valley Newsroom
Breaking Crypto News

Bitcoin ETFs Bleed $300+ Million, While Solana Funds Quietly Pull In Fresh Cash...

Bitcoin ETFs, Solana

Bitcoin started the week with a modest rebound, but the money moving through U.S. crypto ETFs is sending a less comfortable message. Spot Bitcoin funds saw roughly $390 million in net withdrawals during the trading week of August 10 through August 14, reversing the strong inflows from the week before. At the same time, Solana ETFs attracted fresh money and posted their strongest weekly inflow since mid-May.

That split is more interesting than another day of Bitcoin moving a percent or two. ETF flows have become one of the clearest public windows into demand from investors who want crypto exposure through traditional brokerage accounts, retirement accounts and institutional portfolios. They do not tell us what every large investor is doing, but when hundreds of millions of dollars reverse direction in a week, it is worth paying attention.

A $1.2 Billion Swing in Bitcoin ETF Demand

The reversal was sharp. U.S. spot Bitcoin ETFs had pulled in about $853.5 million during the previous week, their best weekly showing since April. One week later, the same category finished roughly $390 million in the red. That is a swing of more than $1.2 billion in weekly net flows.

The daily numbers show that this was not one giant redemption distorting an otherwise normal week. According to flow data from Farside Investors, the funds were negative on four of the five trading days. Monday lost about $145 million, Wednesday about $61 million, Thursday about $131 million and Friday another $56 million. Tuesday was the lone positive session.

Fidelity's FBTC took the biggest weekly hit in Farside's table, losing about $153 million. Grayscale's GBTC lost roughly $88 million, BlackRock's IBIT about $79 million and ARK 21Shares' ARKB about $70 million. Grayscale's lower-fee Bitcoin Mini Trust moved the other way, taking in about $76 million during the week, which softened the total damage.

There is an important distinction here. ETF redemptions do not automatically mean a wave of institutions has suddenly decided Bitcoin is doomed. Some flows come from short-term positioning, basis trades, portfolio rebalancing and investors moving between products. Still, the broad pattern matters because Bitcoin has spent much of the summer struggling to build sustained momentum. A market can rally without ETF inflows, of course. It is simply easier when one of its largest regulated demand channels is buying instead of redeeming.

Solana Went the Other Direction

Solana's ETF market is much smaller, which makes direct dollar comparisons with Bitcoin misleading. The direction of travel is still notable. Solana spot ETFs took in about $10.26 million for the week, their strongest weekly inflow since May.

Bitwise's BSOL accounted for most of the buying with roughly $8.83 million in weekly inflows. Morgan Stanley's MSOL added about $1.43 million. SoSoValue data put total Solana ETF assets at roughly $894 million at the end of the period, with cumulative net inflows of about $1.16 billion. The detailed fund lineup can also be seen in Farside's Solana table.

Those are not giant numbers by Bitcoin standards, but that is precisely why traders may want to watch the trend rather than the absolute amount. Bitcoin products are already huge. Solana's regulated ETF market is still relatively young, so a persistent flow advantage can become meaningful faster if it continues.

Bitcoin Is Still Trading Like a Macro Asset

Bitcoin was holding above the low $63,000 area early Monday and recovering alongside U.S. equity futures. Nasdaq 100 futures were also higher, reinforcing a pattern that has become familiar over the last year: when there is no major crypto-specific catalyst, Bitcoin frequently behaves like a high-beta macro asset with a 24-hour trading schedule.

That leaves traders with mixed signals. Equity markets are providing some support. Bitcoin ETF demand weakened sharply. Solana ETF demand improved. Derivatives positioning is not screaming conviction in either direction, and the broader U.S. crypto market structure bill remains stuck in Washington.

None of that produces a clean "Bitcoin down, Solana up" trade. Markets are rarely considerate enough to make it that easy. What it does show is that crypto ETF demand is becoming more selective. Investors are no longer moving through the entire asset class as one trade.

For Bitcoin, the next useful signal is whether the ETF outflows fade as quickly as they appeared or develop into another multiweek streak. For Solana, the question is whether its strongest week since May becomes the start of sustained demand or simply one good week in a small market. Right now, the money is giving traders a reason to watch both.

Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News

Senate Pushes CLARITY Act Vote to September, Extending Crypto's Regulatory Wait...

CLARITY Act Vote

Washington has given the crypto industry a familiar product update: the Digital Asset Market Clarity Act is not dead, but the launch date has slipped. The U.S. Senate will not vote on the market-structure bill before the August recess, moving its next real chance of action to September.

Senate Majority Leader John Thune said there would be no August vote, with a possible vote in September. The delay follows unresolved disagreements between the parties, including demands for stronger ethics rules, enforcement provisions and market safeguards. The result is straightforward for traders and companies: the regulatory map remains unfinished for at least another month.

What the bill is trying to settle

The bill, H.R. 3633, is designed to create a clearer U.S. framework for digital-asset markets. At its core, it aims to define responsibilities across the Securities and Exchange Commission and Commodity Futures Trading Commission, while setting rules that would matter to token issuers, exchanges, brokers and customers. That may sound like Capitol Hill furniture-moving, but the practical stakes are substantial: classification and registration rules help determine which products can be offered, by whom, and under what compliance burden.

The House has already passed the measure, and its official Congress record lists it on the Senate Legislative Calendar. The Senate, however, is not a conveyor belt. A calendar placement means the bill is available for consideration, not that the chamber has solved its political and procedural problems.

Why the August miss matters

The Senate is scheduled to return on Sept. 14, leaving a relatively short working window before other legislative deadlines and election-season pressures crowd the agenda. Industry participants had hoped senators would remain in session long enough to resolve final disputes. That did not happen, and the bill now arrives in September with the same complicated questions still waiting for it.

For exchanges and U.S.-based crypto businesses, delay has a cost even without a new ban or enforcement action. Companies must still make product, custody, listing and compliance decisions under overlapping claims of authority. Investors also have to price the chance that a rulebook appears, changes materially, or remains stuck in the legislative queue. Regulatory uncertainty is not exciting, unless your hobby is modeling downside cases in a spreadsheet.

What has to happen next

A September vote is possible, not guaranteed. Senators will need to settle whether the bill has sufficient guardrails around consumer protection, enforcement and conflicts of interest, then navigate the usual Senate procedural gauntlet. Reporting on the delay indicated that unresolved bipartisan issues, rather than a simple lack of floor time, kept the measure from moving before recess.

Traders should avoid treating a September date as an automatic bullish or bearish catalyst. A credible path toward market-structure rules could improve confidence for institutions and U.S. platforms, but the final text and the timing of any vote matter more than the calendar headline. It is also possible the debate produces amendments that shift the bill's impact for particular categories of tokens or intermediaries.

For now, the CLARITY Act remains one of crypto's most consequential U.S. policy files, just delayed rather than decided. September will show whether the Senate can turn broad support for clearer rules into actual legislation, or whether the industry gets another reminder that “soon” is Washington's most flexible unit of time.

---------------

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News

Bitcoin Reclaims $65,000 After Payrolls Miss - is it a Breakout or a Fake-out?

Bitcoin price

Bitcoin got the macro catalyst traders had been waiting for on Friday: a U.S. jobs report soft enough to restart the argument over how much room the Federal Reserve has to ease. BTC pushed as high as $65,340 on Bitstamp, up roughly 1.3% on the day, after July nonfarm payrolls showed the economy lost 23,000 jobs instead of adding the roughly 80,000 economists expected.

That is a meaningful miss, not a rounding error. The Bureau of Labor Statistics also revised May and June employment lower by a combined 103,000 jobs. July unemployment came in at 4.1%, little changed from the prior month, but the larger message was clear: the labor market is no longer giving the Fed the same comfortable cushion it appeared to have a few months ago. The full payroll release gave risk markets exactly the kind of ambiguity they enjoy turning into a bid.

Why Bitcoin cared

A cooler labor market can reduce the case for keeping monetary policy tight, assuming inflation does not decide to become difficult again. Lower expected rates generally help long-duration and liquidity-sensitive assets, and crypto has spent years proving it belongs in that unruly group. Traders swiftly repriced the rate discussion after the data, helping bitcoin take another run at a zone that had repeatedly capped it near $65,000.

The setup was especially notable because the prior session had pointed the other way. Stronger-than-expected jobless-claims data had helped push BTC down to about $64,384, while $64,800 to $65,000 remained a stubborn resistance band. In other words, bitcoin did not suddenly discover a new narrative. It got a fresh macro datapoint that challenged the one from a day earlier. Markets, in their eternal quest for efficiency, can now argue with themselves using two labor reports instead of one.

The number to watch is still $65,000

Friday's intraday high matters, but it is not the same as a clean break and hold. Bitcoin had been hovering near $64,350 before the payrolls release and remains in a range where quick moves above $65,000 have not yet turned into durable acceptance. For traders, the useful question is less whether BTC printed a satisfying headline number and more whether spot demand can keep it above the former ceiling when the initial macro reaction fades.

Near-term support remains clustered around the low-$64,000 area, based on this week's price action. A sustained move above the Friday high would put the next nearby round-number zone near $67,000 on more desks, while a return below $65,000 would make this another familiar range trade rather than the start of a clean trend. Current price feeds put BTC near $65,000, reinforcing just how close the market remains to that decision point.

What changes next

The next major test is whether incoming inflation data agrees with the rate-friendly reading investors drew from payrolls. Weak employment can support risk appetite, but it does not automatically produce easier policy. If inflation stays sticky, the Fed could remain cautious and leave crypto with a very expensive false start.

For now, the report gave bitcoin a lift and returned $65,000 to center stage. That is progress, but not a coronation. A breakout needs follow-through, and BTC has seen enough dramatic intraday reversals to know that one cheerful Friday candle is not a binding contract.

Bitcoin has regained a key psychological level on softer labor data; the next few sessions will show whether that level becomes support or merely another well-photographed ceiling.

---------------

Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News

$70 Million in Bitcoin Vanished From Coldcard Wallets - Make Sure YOUR Crypto is Safe...

For years the whole pitch behind a Coldcard was that nobody could reach your Bitcoin unless they were physically holding the device in their hands.

That promise came apart this week, when an attacker quietly swept around 1,082 BTC, worth roughly $70 million, out of more than a thousand wallets in under an hour. The unsettling part is that the thief never touched a single device, never phished anyone, and never needed a PIN or a password. These coins were sitting in cold storage, offline, kept exactly the way every self-custody guide tells you to keep them. And they walked out anyway. For a corner of crypto that treats hardware wallets as the gold standard of safety, this is a genuinely rough moment.

Blockchain analysts at Galaxy Digital, who have been tracking the drain, first put the losses near $38 million before revising the number upward as more addresses turned up in the sweep. Hardware wallet maker Coinkite has confirmed the flaw and rushed out patched firmware, but by then the money was long gone. According to Coinkite's own security advisory, the theft happened roughly a day before the company managed to warn users publicly, so plenty of people watched their balances drop to zero before they had any idea anything was wrong. When your entire brand is built on paranoid, belt-and-suspenders security, a delay like that is about as bad as it gets. The company says it is still working to pin down the full scope of the damage.

A five-year-old bug in how the wallet made its keys

The root cause here is boring and alarming at the same time. When you set up a hardware wallet, it is supposed to build your seed phrase from true randomness, the kind that makes guessing it mathematically hopeless. Somewhere in a firmware build shipped back in March 2021, Coldcard's software started skipping its dedicated hardware random number generator and quietly fell back to predictable values pulled from the chip itself. Instead of the expected 128 bits of entropy, affected Mk3 devices were producing seeds with only about 40 bits, and later Mk4, Mk5 and Q models landed somewhere around 72 bits. In plain English, the recovery phrase that was meant to be unguessable became something a determined attacker with modern hardware could grind through.

What makes it worse is that this sat undetected for more than five years. Every wallet created on the affected builds carried the same weakness baked in from the very start, whether or not the owner ever did a single thing wrong. Some researchers have suggested that automated or AI-assisted tooling may have helped the attacker chew through the reduced keyspace fast enough to clear so many wallets in one sitting, though that claim has not been confirmed. Coinkite says the fixed firmware restores proper randomness, but a patch cannot rewrite history. Any seed generated on the old software still exists in its weakened form, which is exactly why the advice coming out now has been so blunt.

The people who got hit did everything "right"

This one stings because it landed on the folks who followed the standard advice to the letter. The drained wallets largely belonged to long-term holders who pulled their coins off exchanges years ago and left them sitting untouched in cold storage, which is supposed to be the responsible move. Their reward for being careful was watching those balances vanish while newer and less disciplined traders on custodial platforms were completely unaffected. There is a bitter twist buried in here too. Users who bothered to add their own dice rolls during setup, or who layered on a passphrase or a multisig arrangement, appear to have been protected, because that extra input put back the randomness the firmware had thrown away, and the people most exposed were the ones who simply trusted the device to handle its single most important job.

What to do if you own one

If you have a Coldcard, the guidance from Coinkite is direct: treat your seed as compromised and move your funds. That means updating to the patched firmware, generating a brand new seed on that updated hardware, and then sending everything over to the fresh wallet, because a firmware update on its own fixes nothing when the weak seed already exists. Annoyingly, there is no self-test that tells you whether your particular seed falls inside the guessable range, so the only safe assumption is that it might. You can check your firmware version under the Advanced menu on the device, and anything generated on the vulnerable builds between 2021 and the recent fix should be treated as suspect. Bitcoin slipped about 3% as the scale of the mess sank in, and the timing hands an easy talking point to everyone who has been pushing regulated custodians and spot ETFs over do-it-yourself storage.

The uncomfortable lesson is that "not your keys, not your coins" was always sold as the safer road, and for the most part it still is, but your keys only protect you if they were actually random to begin with. A single quiet build error hid for half a decade inside one of the most trusted names in Bitcoin self-custody, and it took a $70 million heist for anyone to catch it. None of this means hardware wallets are a scam or that cold storage is suddenly dead. It does mean the unglamorous stuff, the firmware updates and the extra entropy and the passphrases and the multisig setups, is the part that quietly saves you, right up until the day it turns out to be the only thing standing between you and an empty wallet.

---------------

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News

Samsung Is Putting Stablecoins on 240 Million Phones... It Just Won't Say Which Ones, or When.

Samsung crypto wallet


Samsung just told hundreds of millions of phone owners they'll soon be able to hold digital dollars right next to their boarding passes and coffee loyalty cards.

At Galaxy Unpacked in London on July 22, the company confirmed that Samsung Wallet will get native stablecoin support, putting dollar-pegged tokens into the same app people already use to tap their phone at the checkout. For an industry that has spent years arguing stablecoins are the killer app for crypto, having one of the biggest hardware makers on earth agree out loud is a big deal. Samsung says the feature would make it one of the first major smartphone brands to support stablecoins natively on its devices, and that reach is the whole story here. This is a company that ships phones by the hundreds of millions every year, so the potential distribution dwarfs anything a standalone crypto wallet could ever dream of building on its own.

And yet, for an announcement this large, Samsung was strangely quiet on the details that actually matter. It showed a mockup with Circle's USDC on stage, then declined to name USDC, Tether, or any other issuer as a confirmed partner. There is no launch date, no word on which blockchains will be supported, no list of eligible countries, and no answer to the single most important question for anyone who cares about their money: will Samsung hold your funds, or will you? That last point, custodial versus non-custodial, is the difference between a real crypto wallet and a glorified balance display, and so far Samsung has said nothing about it. For a feature meant to inspire trust, that is a lot of blanks left unfilled.

The credit card is the part that's actually shipping

Buried under the stablecoin headlines was the thing Samsung actually launched that same day: the Samsung Galaxy Card. It's a credit card issued by Barclays and running on the Visa network, and it went live in the United States on July 22 with no "coming soon" asterisk attached. The rewards structure is aimed squarely at keeping you inside Samsung's world, with 5% back on Samsung purchases, 3% on anything you buy through Samsung Wallet, and 2% on streaming services. On its own that's a fairly ordinary co-branded card, the kind every big brand eventually launches to lock in loyal customers. What makes it interesting is the context, because Samsung is clearly trying to turn Wallet from a place you store a plane ticket into a full financial hub, and stablecoins are meant to be the piece that makes it all feel modern.

Read together, the card and the stablecoin tease point at the same ambition. Samsung wants Wallet to be where you keep money, spend money, and eventually move money, all without opening a separate banking or crypto app. The card handles the spending side today, and it works right now. The stablecoin support, whenever it actually arrives, is supposed to handle the moving-money-around side, letting people send digital dollars roughly as easily as they send a photo. It's a coherent plan on paper, but plans on paper have a habit of slipping, and Samsung gave itself plenty of room to slip by refusing to commit to any date at all.

Wider implications

Even if you never personally plan to keep a single dime of USDC in your phone, if you trade crypto this is good news. Retail crypto adoption has historically gone stablecoins first and speculation second. Someone who already holds a stablecoin balance in an app they trust is a much shorter walk away from buying bitcoin or ether than someone who holds nothing at all and has to sign up for an exchange from scratch. If Samsung genuinely puts even a basic stablecoin feature in front of a big chunk of its user base, it quietly widens the top of the funnel for the entire market. That's a slow-burn effect rather than an overnight one, and it won't show up on a candlestick chart next week no matter how much anyone wants it to.

Which is exactly why you shouldn't expect this to move prices in any immediate way. The crypto industry has a long and unimpressive record of "major partnership" and "mainstream adoption" headlines that felt enormous in the moment and then did absolutely nothing to the charts over the following month. Infrastructure announcements tend to work like that. They matter over years, not days, and this one is especially soft because so much of it is still a mockup and a promise rather than shipping code. Treat it as a directional signal about where consumer fintech is heading, which is clearly toward digital dollars living inside apps you already have, and not as a reason to reposition your portfolio today.

The small print

So where does all this leave things? Samsung has made a loud and credible commitment to putting stablecoins in front of an enormous audience, and that commitment is genuinely meaningful for the long arc of adoption. But a commitment with no named partner, no date, no chain, and no custody model is still mostly a statement of intent, and intent has always been cheap in this industry. The Galaxy Card is real and available now, the stablecoin wallet is a slide and a mockup, and the gap between those two things is worth remembering the next time someone tells you crypto just went mainstream overnight. Watch for the follow-up details in the months ahead, because that's when we'll actually find out whether Samsung is building a real crypto wallet or just a nicer place to stare at a number.

---------------

Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News