Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (3 August 2026)
Published: Loading…
At a Glance
- A COLDCARD firmware RNG flaw enabled theft of an estimated $88.6 million in Bitcoin from thousands of wallets.
- Attackers drained 1,196 Coldcard Bitcoin addresses worth $70.2 million in 41 minutes on 30 July 2026.
- A critical Adobe Campaign Classic flaw, CVE-2026-48449, scores 10.0 on CVSS and allows unauthenticated code execution.
- Attackers modified Adform's trackpoint-async.js script to rewrite cryptocurrency wallet addresses on visiting customer sites.
- DPRK-linked npm packages bianira-ui and fluid-type-ui hide C2 IP addresses inside blank Ethereum transfer recipient addresses.
- A critical Rails Active Storage vulnerability allows unauthenticated attackers to read arbitrary files and potentially achieve remote code execution.
Editorial Analysis
A years-old firmware flaw in COLDCARD hardware wallets, which silently routed seed generation to a deterministic software generator instead of hardware randomness, has now been tied to an estimated $88.6 million in stolen Bitcoin — including a single 41-minute sweep of nearly 1,200 addresses worth $70.2 million. COLDCARD's security advisory was published only after the theft was already underway, making the disclosure reactive rather than preventive.
Two smaller incidents targeted cryptocurrency transfers rather than custody: the compromised Adform ad script silently swapped wallet addresses copied to visitors' clipboards across thousands of sites, while DPRK-linked npm packages hid C2 infrastructure inside blank Ethereum transfers. Across all three cases, the compromised component was part of the infrastructure surrounding cryptocurrency transactions rather than the blockchain itself.
Highlights of the Day
COLDCARD Wallet Firmware Flaw Left Bitcoin Seeds Predictable
A macro-check error in COLDCARD firmware caused its random number generator to fall back to MicroPython's deterministic Yasmarang generator instead of the STM32 hardware RNG. Mk2 and Mk3 devices running firmware v4.0.0–v4.1.9 produced fully deterministic wallet seeds, while Mk4, Q and Mk5 devices retain only 32 bits of secure-element entropy after reseeding. Block disclosed the issue alongside Coinkite after reports of active fund theft from affected devices.
Rails Active Storage Flaw Enables Arbitrary File Read and RCE
A vulnerability in Rails Active Storage allows unauthenticated attackers to read arbitrary server files by uploading crafted images processed through libvips. Exposed data can include environment variables containing secret_key_base and external service credentials, potentially enabling remote code execution. The issue affects applications using the vips variant processor with untrusted image uploads and is fixed in updated activestorage releases alongside a required libvips upgrade to version 8.13 or later.
Advertising company Adform, used by around 14,000 websites, had its trackpoint-async.js script compromised to serve clipboard-hijacking malware. The malicious code detects copied Bitcoin, Ethereum and Tron wallet addresses and silently replaces them with attacker-controlled addresses every three seconds. The script also beaconed visitor IP addresses and referring sites to an external server, and the files involved were flagged as clean by all Virustotal vendors.
DPRK Hackers Hide C2 Servers in Blank Crypto Transfers
Researchers identified a new command-and-control technique, NullReceiver, used by DPRK-linked malware in two trojanized npm packages, bianira-ui and fluid-type-ui. The malware encodes a C2 server's IP address directly within the recipient address bytes of a zero-value, zero-data Ethereum transfer, avoiding smart contracts or transaction data fields entirely. This builds on the earlier EtherHiding technique by removing its fixed, publicly known destination address, making detection significantly harder.
Daily Coverage