Category archive

Crypto

Bitcoin, Ethereum and digital assets

3 stories loaded

Crypto
CoinDesk · 3 days ago

XRP Ledger upgrade brings back features once pulled over critical bugs

Ripple's xrpld 3.3.0 release, expected next week, will propose five amendments to validators including revised versions of Batch and Permission Delegation—features that were pulled in 2025–2026 after critical bugs were found that could enable unauthorized transactions and fee draining. The amendments require 80% validator approval over two consecutive weeks; new features include Confidential MPT (privacy via zero-knowledge proofs), Sponsored Fees (letting institutions cover user costs), and Dynamic MPT (adjustable token properties). This upgrade positions XRPL to support institutional tokenized-asset activity at scale.

Crypto
CoinDesk · 3 days ago

How bitcoin cold wallets lost $70 million in an attack that never touched the devices

A firmware vulnerability in Coldcard hardware wallets (Mk2–Mk5 models) allowed attackers to computationally enumerate seed phrases offline by exploiting weak randomness generation tied to device serial numbers and clock values, rather than a dedicated hardware RNG. Over 1,082 BTC (~$70M) were drained from 1,196 wallets in 41 minutes on July 30; the attacker derived private keys entirely on their own hardware and checked them against the public blockchain, never requiring network access to the victims' devices. The exploit is significant because it breaks the core security assumption of cold storage—that an air-gapped device is unreachable—by attacking the generation mechanism itself rather than the device's connectivity.

Crypto
CoinDesk · 4 days ago

Major bitcoin wallet flaw drains $38 million worth of BTC in 25-minute sweep

A randomness generation flaw in Coldcard firmware 4.0.0 (March 2021) caused the wallet to use predictable, non-secret chip data instead of its hardware random number generator when creating seed phrases. An attacker exploited this to derive private keys and sweep approximately 594 BTC (~$38M) from around 500 single-signature wallets in under 30 minutes on Friday. The vulnerability affects Mk3 devices running firmware 4.0.1 or later; Mk4, Q, and Mk5 models appear unaffected. The stolen coins have largely been consolidated into a single address and remain stationary, and Bitcoin's price showed little reaction to the incident.