
Swiss hardware Bitcoin wallet maker BitBox discovered two critical vulnerabilities and a bootloader issue in its firmware through an internal AI audit, prompting the release of the Dixence security update. Exploiting these flaws would require a successful phishing attack and user interaction with a compromised device. BitBox stated that no user funds were stolen and seed phrases were never at risk. The company disclosed the issues voluntarily, with no evidence of exploitation. This incident serves as a reminder that hardware wallets are not infallible, and users should promptly update firmware to mitigate risks.
1 hour ago

BitBox has released firmware updates to fix two critical vulnerabilities that could allow malicious firmware installation or lock bitcoins to unintended addresses. The first flaw affects unconfigured BitBox02 and BitBox02 Nova Multi versions, potentially enabling arbitrary code execution; the second affects the Silent Payments implementation. BitBox stated that no exploits have been detected and no user funds have been reported lost. This follows a previous Coldcard firmware vulnerability that led to the theft of over $112 million in bitcoins.
9 hours ago

In August 2026, SafePal, Trezor, and Bits of Gold disclosed data breaches within four days, exposing the names, phone numbers, addresses, and purchase histories of approximately 253,000 customers. The Trezor and Bits of Gold breaches stemmed from the same vulnerability, CVE-2026-72898, a critical SQL injection flaw in Metabase. This data was used to target cryptocurrency holders in physical attacks (wrench attacks), which surged 33% in the first half of 2026, causing $124.1 million in financial losses. The article analyzes the common technical root cause and highlights the structural inadequacies of hardware wallet manufacturers and brokers in addressing such threats.
10 hours ago

U.S. prosecutors announced that Edward Zimbardi, accused of running a $165 million cryptocurrency Ponzi scheme, returned to the U.S. on August 14 after being deported from Fiji, facing 25 federal charges including 12 counts of wire fraud, 12 counts of money laundering, and one count of conspiracy to launder money. He allegedly operated 'The Crypto Program' from June 2022 to August 2023, promising guaranteed monthly returns of 25% through investments in digital advertising packages, attracting thousands of investors and raising over $165 million. Over $34 million was used for forex trading, and $10 million for personal expenses. Zimbardi is presumed innocent, and the case will be tried in Georgia.
13 hours ago

Payward, the parent company of Kraken, has joined Anthropic's Project Glasswing to gain restricted access to Claude Mythos 5 for defensive cybersecurity work. The company plans to scan all its software environments for vulnerabilities in the coming weeks and share verified third-party findings with relevant open-source project maintainers. Anthropic limits access to Mythos 5 due to potential misuse of its cybersecurity capabilities and requires customers to accept thirty-day data retention for security monitoring.
15 hours ago

Kraken's parent company, Payward, has joined Anthropic's Project Glasswing, gaining access to its cybersecurity AI model, Claude Mythos 5, to scan for vulnerabilities and strengthen security. This move responds to a call from over 40 Bitcoin and crypto companies urging AI labs to open frontier AI to security defenders. Payward is the first crypto company to join the project, and its security team will use the AI to identify and fix vulnerabilities, as well as report third-party software flaws to open-source maintainers, protecting millions of customers globally and the crypto industry's infrastructure.
20 hours ago

This article reviews Insight Guard, examining how it differs from recovery scams as a fraud investigation service. It notes that many recovery services promising to retrieve funds are themselves scams, while Insight Guard focuses on structured investigations and case documentation, without guaranteeing results or proactively contacting victims, and provides clear deliverables. The article emphasizes the importance of transparency and realistic expectations, and warns victims to be wary of secondary scams.
2026-08-17

Dutch prosecutors have sold cryptocurrencies seized from the bankrupt platform Knaken, raising $2.5 million to repay creditors. The trustee estimates customers invested between $12 million and $14 million, but the sale proceeds are currently the only funds in the bankruptcy estate. A lawyer for affected customers questions whether prosecutors had the authority to sell these assets. Knaken, which operated without regulatory permission, went offline in early June and was declared bankrupt by a court on July 16. This follows a 2020 incident where 23 BTC were stolen. The trustee stated that customers actually hold euro-denominated claims, not ownership of the cryptocurrencies.
2026-08-17

Apple has patched a critical vulnerability in macOS Screen Sharing (CVE-2026-65400) that was exploited by attackers to gain root access on internet-exposed Macs and install Monero mining software. The Dutch National Cyber Security Centre confirmed active exploitation, and Huntress discovered tens of thousands of Macs potentially exposed. The flaw affects Secure Remote Password authentication; changing passwords won't help, so users must install the security update.
2026-08-17

After the MiCA grace period ended, over 1,000 unauthorized crypto service providers were forced to halt operations, prompting a mass user migration. Regulators warn that scammers are exploiting this transition by impersonating authorities or licensed exchanges to lure users to fake websites or wallets and steal cryptocurrencies. ESMA advises users to verify providers via official registries. TRM Labs data shows 1,062 EEA companies lacked MiCA authorization as of July 1.
2026-08-17