Web3

Home Web3

Scammers Pose as EU Regulators to Prey on MiCA Deadline Fallout – Decrypt

0
Scammers Pose as EU Regulators to Prey on MiCA Deadline Fallout – Decrypt



In brief

French regulator ESMA said its logo and identity are being misused in falsified documents to promote scams, following the passing of the MiCA registration deadline.
More than 1,700 unlicensed firms must wind down EU operations, against 323 that have secured a MiCA license.
Chainalysis puts crypto scam and fraud losses at $17 billion last year, against $6 billion in 2020.

Fraudsters are impersonating European regulators and crypto exchanges to steal from customers caught in the shutdown of unlicensed firms, watchdogs across the bloc have told the Financial Times.

Companies that missed the July 1 deadline to obtain a license under the EU’s Markets in Crypto-Assets Regulation are now operating illegally and must tell customers to withdraw or move their holdings. Only 323 firms appear on the register that the European Securities and Markets Authority (ESMA), the EU’s markets watchdog, updated at the end of July, while data provider VASPnet estimated last month that more than 1,700 unlicensed companies would have to cease operating.

That has put a large number of people in the position of hurriedly moving funds to an unfamiliar provider, which is precisely the moment criminals want. “This moment is an opportunity for scammers more than usual,” Stéphane Pontoizeau, an executive director at France’s markets regulator the Autorité des Marchés Financiers (AMF) told the FT.

The AMF has recorded cases of fraudsters posing as its own staff, telling customers of unlicensed firms to transfer assets to a fake website. ESMA said it is aware of “fraudulent practices involving the misuse of ESMA’s logo and identity,” including falsified documents used to promote scams. Dutch regulator the Autoriteit Financiële Markten said traders should treat any third-party request to move funds with caution and verify it against the provider’s official website and app.

The AMF has declined to set an aggressive wind-down date for unlicensed firms operating in France, reasoning that manufactured urgency is what pushes people into scams, and has urged customers to take their time choosing a replacement provider. Pontoizeau said the regulator will refer cases to law enforcement where criminals impersonate it or licensed companies.



How the deadline landed

MiCA replaced a patchwork of national regimes with a single authorization that passports across all 27 member states, and its transition period ended on July 1. Coinbase, Kraken and OKX are among those licensed.

Binance is the largest firm without one. It withdrew its application in Greece in June after reports that the regulator would reject it, and said it would seek approval elsewhere. Spain’s securities regulator ruled out any extension days before the cut-off.

Chainalysis puts losses to crypto scams and fraud at $17 billion last year, a projection based on historical trends, against $6 billion five years earlier. Impersonation is among the fastest-growing categories it tracks.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Meta Debuts AI Coding Agent Muse: Here’s How It Compares to Claude Code and Codex – Decrypt

0
Meta Debuts AI Coding Agent Muse: Here’s How It Compares to Claude Code and Codex – Decrypt


In brief

Meta released Muse Code (beta), a terminal coding agent powered by Muse Spark 1.2, its updated coding model. It’s available now via the Meta Model API and a curl install script.
The agent coordinates persistent background subagents and keeps a replay-exact event log, so a crash resumes exactly where it stopped.
On Meta’s own charts, Muse Spark 1.2 trails Anthropic’s Opus 5 on every coding benchmark shown, while beating OpenAI’s Codex and Google’s Antigravity on most.

Meta is the latest tech giant to ship a coding agent, racing to compete with leading AI behemoths Anthropic and OpenAI.

“We’re excited to release Muse Code (beta), a terminal coding agent powered by Muse Spark 1.2, our newest model,” the company wrote in an official announcement. “This marks our next step toward the frontier, with larger and much more capable models on the way.”



As an agentic coding tool, Muse Code is built for software engineering across large repositories. Per Meta, it “takes on complex software engineering tasks across large repositories: planning changes, writing code, and validating the results. It can coordinate multiple persistent subagents for each task, solving difficult problems faster, more accurately, and with less intervention.”

The detail that stands out is the runtime. Muse Code logs every model call, tool run, approval, and edit to a local event log that acts as a single source of truth. “This single source of truth makes the runtime replay-exact and restart-safe: after a crash, the agent can resume precisely where it stopped,” Meta said. For long-running jobs, that’s the feature that matters more than raw speed—and it’s the part competitors haven’t made a selling point.

It also ships with default skills. The “/plan” command turns a task into an approval-gated plan, while “/grill” stress-tests that plan until it holds up and “/goal” works toward successful completion of the objective similar to what Hermes does. Meta said it co-trained Muse Spark 1.2 with Muse Code so the core LLM and the agent work together in synergy.

The benchmarks, and the catch

Muse Spark 1.2 is a coding-focused update to Muse Spark 1.1. Meta said it “significantly scaled up training compute on coding tasks while expanding training environment diversity, delivering improvements in code generation, complex debugging, and end-to-end developer workflows.” The charts tell a clear story.

On Terminal-Bench 2.1, Muse Spark 1.2 with Muse Code scored 82.9%, behind Claude Code on Opus 5 at 86.7% but ahead of GPT-5.6 Terra on Codex (81.8%) and Grok Build (81.6%).

DeepSWE 1.1, which measures agentic coding capabilities, was closer: 59.3% for Muse versus 65.0% for Opus 5 and 64.8% for Codex. On Meta’s internal coding bench, Muse hit 70.6% to Opus 5’s 79.4%.

The speedup charts flip the order. Over 1,000-plus tool calls, Opus 5 posted the biggest gain versus baseline (about 74–75%), with Muse Spark 1.2 mid-pack at roughly 61–69% depending on the run. Meta’s point is that the agent keeps improving as tool calls accumulate, the behavior you want from a long-horizon coder.

The most interesting demos are long-horizon and multimodal. In stress testing, Meta said Muse Code “iteratively optimized GPU kernels over 1,000+ tool calls (up to 24 hours) on Nvidia Hopper GPUs.” That means it was able to improve over time.

There’s also a visual-coding angle. In one demo, a user drops a fly-through video of a house into the terminal as an mp4, and Muse Code “interprets the video and produces a visually rich website with booking capabilities.” Reading raw video into a working web app is the multimodal pitch Meta has been making across the Muse line.

See the launch thread:

The field is already crowded

That said, Meta is late to the fight. OpenAI’s Codex already runs parallel cloud agents; DeepSeek has built its own rival to Claude Code and agentic tools like Hermes or OpenClaw are already good substitutes with more capabilities. Muse Code’s edge is the crash-safe runtime and the subagent design, not benchmark supremacy.

The risk is the usual one for agentic coding: an agent that resumes after a crash and keeps calling tools for 24 hours is powerful and unpredictable. Meta is betting developers want that autonomy, and it’s shipping now.

Muse Code is available for testing upon installation entering this command:curl -fsSL https://dev.meta.ai/install.sh | bash

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





Source link

Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI – Decrypt

0
Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI – Decrypt



In brief

The UK’s AI Security Institute found 19 unsanctioned actions across 10 of 122 evaluation runs, 17 of them from Anthropic’s Mythos 5 and two from OpenAI’s GPT-5.6 Sol.
One agent opened a malicious pull request on a real repository, then used accounts it controlled to endorse it and pressure the maintainer.
Separate agents found a GitHub token one of them had leaked publicly and used a shared repository to coordinate.

The UK AI Security Institute has disclosed that AI agents took “sustained, unsanctioned action” on the live internet during a cyber evaluation in late July, including cases that “targeted real people and organisations.”

Across 122 runs of two cyber ranges on seven models, AISI catalogued 19 actions that reached outside the test environment, in 10 runs. Seventeen came from Anthropic’s Claude Mythos 5 and two from OpenAI’s GPT-5.6 Sol. Internet access was deliberately enabled and the providers’ cyber classifiers switched off, conditions that do not apply to public deployments.

In the most serious run, an agent decided to solve its challenge with a supply-chain attack, picking its target by mistake: it searched GitHub for keywords from the exercise, landed on two unaffiliated developers, and wrongly concluded they were in scope. It registered accounts over Tor to get past sign-up checks, opened a pull request carrying a hidden malware dropper wrapped in a genuine bug fix, and posted from a second account it controlled to manufacture support. It also planted prompt injections aimed at AI coding assistants and sent malware to the maintainers.

A third developer spotted the injected code, ran it in an isolated container to confirm it was malicious, and warned the maintainer, who closed the pull request citing malware.

The agent repeatedly weighed whether its surroundings were simulated, at one point ruling out an attack on the real PyPI because “causing real-world harm — that’s completely off the table.” Elsewhere it concluded “it seems more likely that we’re actually in 2026 and GitHub is genuinely real,” and continued anyway.

After being caught it force-pushed to erase the payload, edited earlier posts, and presented the code as an accidental commit. Its reasoning describes timing a sockpuppet comment so it would read “as independent feedback rather than coordinated.”



AISI sees only summarised reasoning from the model APIs. In one case the summarising model appears to have refused the job, replying that it would not engage with content about deceiving maintainers and evading detection.

One agent published a GitHub access token in a public gist. Agents in other runs found it, took over the account, and used a shared repository to coordinate, one leaving instructions so the others would not exhaust the shared API quota.

Commercial monitoring flagged the Tor traffic on the morning of July 28. AISI declared an incident, terminated the runs and quarantined the machines within about 90 minutes, then cut internal access to Mythos 5, Mythos Preview, Opus 5 and GPT-5.6 Sol. No agent tried to escape its sandbox.

Third disclosure in a fortnight

The news is the latest in a string of incidents where AI agents have exceeded their parameters in testing. On July 21, OpenAI said GPT-5.6 Sol and an unreleased model found a zero-day in an internal package proxy, escaped a sandbox with no internet access and reached Hugging Face’s production database to steal benchmark answers. The same run reached four more companies, OpenAI disclosed a week later.

Anthropic followed on July 30, disclosing three incidents found in a review of more than 141,000 evaluation runs. Opus 4.7 pulled several hundred rows from a real production database, and Mythos 5 uploaded a malicious Python package to the real PyPI, where it was installed on 15 systems. In AISI’s evaluation, the same model ruled out attacking PyPI as real-world harm.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





Source link

This Bitcoin Bridge Shut Itself Down Because AI Was Finding Bugs Too Fast – Decrypt

0
This Bitcoin Bridge Shut Itself Down Because AI Was Finding Bugs Too Fast – Decrypt



In brief

Bitcoin bridge Boltz has suspended its Bitcoin swap service indefinitely.
The company says AI-assisted attacks are outpacing its ability to patch vulnerabilities.
Boltz says no user funds were at risk because the platform is non-custodial.

Boltz has suspended its Bitcoin swap service indefinitely, saying a surge in AI-assisted attacks has left it unable to continue operating safely.

In a series of posts on X on Monday, the company said swaps are disabled “until further notice” and that it cannot provide an estimate for when the service will return.



“We can’t give an ETA as of this time, but will provide an update once we know more,” Boltz wrote.

Boltz is a non-custodial Bitcoin swap service that lets users move Bitcoin between the Lightning Network and the blockchain’s base layer without giving the company custody of their funds. Boltz has not published transaction volume figures. Boltz currently holds around $262,000 in total value locked, according to DeFiLlama.

Because users retain control of their assets throughout the process, Boltz said “no user funds were ever at risk.”

“To be clear: this is not a response to a single incident,” the company wrote. “Over the past months we have seen a steady rise in automated, AI-assisted probing of our infrastructure, and we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch.”

Boltz said the pace of attacks accelerated over the past few days, leading it to conclude it could no longer safely operate its swap service.

“After reviewing the results of our own recent security scans, we cannot responsibly re-enable Boltz swaps, especially as we are being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes,” the company wrote.

The company said its API remains available to process cooperative refunds, unilateral refunds continue to work because they do not depend on Boltz’s infrastructure, and customer support remains available.

Boltz argued the attacks reflect a broader change facing Bitcoin infrastructure operators.

“What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis,” the company wrote. “Do not expect swap services to resume shortly.”

The announcement comes as the cryptocurrency industry grapples with how AI is changing cyberattacks.

On Tuesday, Ledger CTO Charles Guillemet warned that AI allows attackers to scan code and uncover vulnerabilities “at machine speed,” while defenders are increasingly relying on AI to find the same flaws first. The comments came as fallout from the Coldcard exploit continued to grow, with losses nearing $130 million.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M – Decrypt

0
Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near 0M – Decrypt



In brief

Trezor and Foundation both reported a surge in phishing attempts targeting hardware wallet owners following the Coldcard exploit.
Proofpoint identified a phishing campaign targeting Coldcard holders with a cloned site and “Hardware Audit” that installs remote-access software.
A person, rather than a bot, staffs the fake site’s customer service chat and talks victims through the install.

Hardware wallet manufacturers Trezor and Foundation have warned of a surge in phishing attempts trading on the Coldcard firmware exploit, with scammers chasing users’ recovery phrases and pushing malicious downloads.

Trezor said it was already seeing an increase in phishing attempts following the disclosure, telling users to enter a wallet backup only on the device itself and reiterating that its own hardware is unaffected. Foundation said it had been made aware of emails impersonating the firm that push recipients toward fake websites and malicious downloads, adding that it will never ask for a recovery phrase or tell users to install software to secure a wallet.

Security firm Proofpoint documented a phishing campaign targeting Coldcard users on Monday. Emails sent from a spoofed Coldcard address invite recipients to complete a “coordinated hardware audit,” a theme lifted from the security incident itself, and link to a cloned Coldcard site carrying a “Start Hardware Audit” button.

Clicking it pulls a batch file hosted on GitHub, which installs ScreenConnect, a legitimate remote-access tool. Proofpoint said that gives attackers a route to data and financial theft, or to follow-on malware such as ransomware.

The fake site also runs a customer service chat window. Proofpoint said a real person, not a bot, answers it and walks victims through the installation, assessing the breach as an effective social engineering lure because it “preys on the fear and concern” holders now have about their crypto security.

The exploit behind the lure

The Coldcard exploit stems from a March 2021 firmware build that drew wallet seeds from a software fallback instead of the device’s hardware random number generator, leaving private keys guessable.

Galaxy Research has confirmed three waves of thefts since July 30 and puts high-confidence losses at 1,596 BTC, above $100 million. Including a fourth wave it suspects but has not confirmed with victims, it said the total could reach $130 million.

The firm’s Head of Research Alex Thorn said Tuesday that at least 15 separate attackers are now exploiting the flaw, noting that every wave but the first was identified through victim reports. Coldcard manufacturer Coinkite has issued patched firmware and  told affected users to move funds to newly generated seeds.

A familiar playbook

Phishing campaigns have used an array of methods to target hardware wallet owners. In February, Trezor and Ledger users were hit by a physical mail campaign impersonating the firms, complete with holograms and forged executive signatures, built around the same manufactured deadline. A counterfeit Ledger app drained millions from holders in April, and a March campaign used fake GitHub issues to lure developers onto a spoofed site.

Galaxy Research said the Coldcard exploit is ongoing and urged holders to move funds to a fresh seed or a custodian—giving the phishing lure a long potential shelf life.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





Source link

Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too – Decrypt

0
Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too – Decrypt



In brief

UCLA researchers launched an OnlyFans account called OnlyMarms after traditional research funding became harder to secure.
More than 10 OnlyMarms-inspired meme coins have appeared on Solana, though it’s unclear who created them or whether they’re connected to the research team.
The project has become an unlikely example of how internet culture and crypto can converge around scientific research.

Scientists behind one of the world’s longest-running wildlife studies have turned to one corner of internet culture for funding—and found another waiting for them.

Researchers at UCLA launched an OnlyFans account called OnlyMarms to help support a project that has tracked yellow-bellied marmots in Colorado since 1962 after traditional research funding became harder to secure.



The idea came to professor Daniel Blumstein as research funding dwindled. A graduate student dubbed the account “OnlyMarms,” and the team leaned into the joke by promising subscribers “uncensored marmot content.” Blumstein said it has also become a way to reach new audiences.

“Maybe this is a different audience than, you know, most of our science communication reaches,” Blumstein told NPR in an interview. “That’s great. Turns out, it’s even bigger than this.”

The account has generated about $4,000 so far. Blumstein said the project ultimately needs between $75,000 and $100,000 a year to support graduate students and fieldwork, funding that federal grants once provided.

The marmot project has also attracted attention from the crypto community.

Over on Pump.fun, several OnlyMarms-inspired meme coins have appeared, though it’s unclear who created them or whether any are connected to the UCLA research team. Blumstein told NPR that the researchers did not create the tokens.

“People have independently created a meme coin and told us to grab the transaction—to register it, and then we get the transaction fees. And that is blowing up,” he said. “Apparently, this is a meme coin for good that people like.”

It wouldn’t be the first time an internet-famous animal inspired a cryptocurrency.

In 2024, the Solana token Moo Deng, based on the viral pygmy hippo, launched on Pump.fun and briefly reached a market capitalization of about $680 million before landing listings on major exchanges, including Coinbase.

The researchers have also partnered with a Colorado brewery on a “Marmot Tears” IPA and launched a public “Fat Marmot Week” competition.

Blumstein said the situation reflects the state of scientific funding in the United States, noting that raising money through platforms like OnlyFans is a far cry from how research projects were funded when he was in graduate school.

“No. It’s appalling,” he said. “What we’re doing is destroying the scientific structure and the university-federal partnerships that made us great, made us rich, made us the scientific leaders of the world. It’s being taken apart, and that’s really sad.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Coldcard Losses Near $114M as Small Bitcoin Transfers Spike – Decrypt

0
Coldcard Losses Near 4M as Small Bitcoin Transfers Spike – Decrypt



In brief

Transfers of less than 1 BTC reached 39,600 BTC on July 31, close to the 39,900 moved days after FTX failed, per CryptoQuant.
Daily active addresses jumped from 645,000 to almost a million, the highest since December 2024.
Galaxy Research has flagged a likely fourth wave of thefts, which would take losses to about 1,816 BTC.

Small Bitcoin holders moved coins on July 31 at a rate not seen since the collapse of FTX, according to CryptoQuant, as news spread that Coldcard hardware wallets had been generating guessable keys for five years.

Transfers of less than 1 BTC totaled 39,600 BTC (around $2.5 billion) that day, the firm’s Head of Research Julio Moreno tweeted. The last comparable figure was 39,900 BTC on November 16, 2022, days after FTX failed. Daily active addresses rose from 645,000 on July 30 to almost a million on July 31, the highest since December 2024, with the jump concentrated in sending addresses rather than receiving ones.

Some of it went to exchanges. Deposits made up of sub-10 BTC transfers hit 7,300 BTC ($459 million) on July 31, the most since February 6, CryptoQuant said. Moreno linked the move to the Coldcard breach, saying people appeared to be shifting holdings “looking for safety,” while noting the connection was not certain.

Notably, Bitcoin’s price barely moved amid the wave of exchange deposits, suggesting that users were moving their coins to secure them rather than sell. Bitcoin is currently trading at $62,724, down 0.7% over the past day, per CoinGecko data.



The ColdCard exploit

The Coldcard flaw dates to a March 2021 firmware build error that left seed phrases drawn from far too small a pool. Galaxy Research logged three waves of thefts by Saturday, totaling 1,367 BTC across 4,585 addresses, up from $38 million when the flaw was disclosed and $70 million when Binance founder Changpeng Zhao warned holders.

A fourth is likely under way. Galaxy Research’s Alex Thorn flagged sweeps across 15 consecutive blocks on Monday, running at roughly 45 times the normal rate, and after correcting a set that had wrongly included multisig addresses put the wave at 709 addresses and 448.73 BTC ($28 million). That would take the running total to about 1,816 BTC, near $114 million. Thorn added a caveat that no victim has yet confirmed the fourth wave, which rests on pattern matching.

Some sweeps were still sitting unconfirmed in the mempool and had opted into replace-by-fee, he said, meaning holders who act quickly and pay a high fee may be able to outbid the attacker. None of the addresses hit in the first three waves were multisig.

‘A wake-up call’

Kraken chief security officer Nick Percoco called the incident a “wake-up call for the entire hardware wallet industry.” ColdCard’s Mk4, Mk5 and Q ship with certified secure elements, he noted, and their seeds still came out around 72 bits, because the certification covered the component while nobody verified which code path actually ran.

Percoco wants independent lab validation of entropy sources, bound to specific firmware versions and listed in a public registry, as payment terminals already require. He added that Coinkite’s hotfix now fails the build unless the correct generator is linked in, a control he said took about 48 hours to write once the company knew what to look for.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





Source link

Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets – Decrypt

0
Coldcard Bitcoin Exploit Balloons to  Million as Attackers Keep Draining Wallets – Decrypt



In brief

The Coldcard exploit is ongoing, with Galaxy Research now tracking about $88.6 million stolen across 4,585 addresses in three waves.
Galaxy’s Alex Thorn described the sweeps as deliberate and likely LLM-orchestrated, warning that every single-sig Coldcard address created after the March 2021 firmware flaw will eventually be drained.
The breach has spurred an unusual reversal of the “not your keys, not your coins” ethos as users move Bitcoin back to exchanges.

The theft of Bitcoin from compromised Coldcard hardware wallets is still underway, with researchers now tracking losses of roughly $88 million and warning that every vulnerable device will eventually be emptied.

Galaxy Research said Saturday it has identified a third wave of thefts, in which 207.73 BTC was drained, lifting its observed tally to about 1,367 BTC—around $88.6 million—across 4,585 addresses. The firm called the exploit ongoing and urged anyone holding single-signature funds on a Coldcard to move them at once. Galaxy said it has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms and cross-industry cyber investigators, crediting victims who shared transaction details for helping map the on-chain patterns.



“I continue to investigate and add new Coldcard victim and attacker addresses to our investigation database,” Galaxy’s head of research Alex Thorn posted to X. “The attack is ongoing—move your funds off Coldcard-generated addresses immediately if you have not done so.”

The flaw, as Decrypt previously reported, stems from a March 2021 firmware build error on Coinkite’s devices that caused seed phrases to be generated with far too little randomness, leaving private keys guessable. Thorn wrote that the sweeps look deliberate and programmatic, probably orchestrated with a large language model, and cautioned that every single-sig Coldcard address created after that 2021 update will eventually be drained, saying it is only a matter of time.

Thorn noted the stolen coins had sat untouched for years before being taken—an average dormancy of 3.18 years—underscoring that the victims were long-term holders. The funds from the three documented waves remain parked in attacker addresses and have not moved.

The fallout has driven a panicked response from affected users, with security experts urging caution when moving funds to new addresses. Many of the affected users are racing to move Bitcoin off self-custody and back onto centralized crypto exchanges, such as Coinbase or Binance, or freshly generated addresses—an inversion of the industry’s usual “not your keys, not your coins” ethos.

For some, the warnings came too late. Canadian coach Jonathan Goodman said in a post on X that 18.25 BTC, worth about $1.6 million Canadian, was swept from his wallets in a seven-minute span on July 29, despite his keys sitting in a safety deposit box that never touched the internet. “Perhaps the hardest part about this is that I did everything right,” he wrote, adding that he is filing reports with police and the Ontario Securities Commission.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





Source link

CZ Warns Bitcoin Holders After $70 Million Wallet Exploit: ‘Nothing Is 100%’ – Decrypt

0
CZ Warns Bitcoin Holders After  Million Wallet Exploit: ‘Nothing Is 100%’ – Decrypt



In brief

CZ warned on X that even hardware wallets and long-established wallets can have bugs, suggesting holders split their funds across several wallets to mitigate risk while noting no setup is fully foolproof.
The warning follows a Coldcard exploit stemming from a March 2021 firmware build error that drew seeds from a software fallback instead of the hardware generator, making private keys far easier to guess.
Galaxy Research, mapping the fund flows from a pattern identified by Block engineers, now pegs losses at about 1,082.65 BTC (~$70.2 million) across 1,196 addresses—nearly double the original $38 million estimate.

Binance founder Changpeng “CZ” Zhao is warning crypto owners not to place blind faith in hardware wallets, following an exploit that drained tens of millions of dollars in Bitcoin from Coldcard devices.

In a Saturday post on X, Zhao cautioned that even hardware wallets can carry bugs, and that older wallets with long histories are not immune. “Nothing is 100%,” he posted.



He suggested holders consider spreading their funds across several wallets as one way to reduce exposure, while acknowledging the approach carries its own trade-offs and that no setup is entirely foolproof. CZ closed with his familiar refrain urging users to stay informed and keep their funds safe: “Stay SAFU!”

His comments followed the discovery of a flaw in Coldcard devices made by manufacturer Coinkite. As Decrypt reported, a build error caused seeds on affected units to be drawn from a software fallback rather than the device’s hardware random-number generator, leaving the private keys far easier to guess than intended. The problem traced back to firmware shipped in March 2021, and updating the firmware does not fix a seed already created on a compromised device.

The scope of the theft has grown considerably since the first estimates. Early reporting pegged losses at roughly 594 BTC, or about $38 million, drained from around 500 wallets. According to a report from Galaxy Research, which mapped the flow of funds based on a pattern identified by engineers at Jack Dorsey’s Block, the toll is now put at 1,196 addresses drained for about 1,082.65 BTC, or roughly $70.2 million, in a 41-minute window on July 30. That is nearly double the initial figure.

Galaxy said every sweep paid an identical hardcoded fee and left no change output, a signature it described as consistent with an automated tool spending keys it already held rather than owners moving their own funds. The victims spanned native SegWit and older address types, pointing to multi-path key scanning. The stolen Bitcoin was consolidated within minutes into a handful of addresses and, per Galaxy, has not moved since.

Coinkite has shipped emergency hotfixes and urged exposed users to migrate to newly generated seeds.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





Source link

The More Americans Know About AI, the Less They Like It: Gallup – Decrypt

0
The More Americans Know About AI, the Less They Like It: Gallup – Decrypt



In brief

Gallup says Americans have become more skeptical of AI after two years of improving attitudes.
More Americans believe AI does more harm than good and will reduce U.S. jobs.
Trust in businesses to use AI responsibly has declined, especially among younger adults.

In a report published Tuesday, polling company Gallup said Americans are cooling toward artificial intelligence after two years of growing more comfortable with the technology.

According to Gallup, seven in 10 Americans now say they are somewhat or extremely knowledgeable about AI, up from 64% in 2024. But as familiarity has grown, so has skepticism. More Americans now believe AI does more harm than good, expect it to reduce the number of U.S. jobs over the next decade, and are less likely to trust businesses to use the technology responsibly.



Thirty-nine percent of Americans now say AI does more harm than good, up from 31% in 2025. Just 9% say AI does more good than harm, while 52% believe it does equal amounts of harm and good.

The shift was most pronounced among adults ages 18 to 29. Nearly half now say AI does more harm than good, up from 36% last year. Gallup said younger adults also became more skeptical of AI’s overall impact, businesses’ use of the technology, and its effect on jobs.

Trust in businesses to use AI responsibly also declined.

Twenty-seven percent of Americans said they trust businesses at least “some” to use AI responsibly, down from 31% in 2025. Among adults ages 18 to 29, trust dropped from 30% to 20%, while those with no trust at all increased from 29% to 41%.

Nearly eight in 10 Americans said AI will reduce the number of U.S. jobs over the next decade, up from 73% in 2025 to 79% this year. The biggest increase came among adults ages 18 to 29, where the share expecting job losses rose from 62% to 75%. Among adults ages 45 to 59, it increased from 75% to 84%.

Gallup also found Americans increasingly view AI as performing about as well as people on tasks such as driving, providing financial advice, and providing medical advice. Even so, respondents continued to rate people higher than AI across every category measured, including hiring decisions, creative work, and helping students with schoolwork.

The report follows several other surveys that have found Americans remain uneasy about AI despite using it more often.

In March, an NBC News poll found 56% of Americans had recently used AI tools such as ChatGPT, Microsoft Copilot, or Google Gemini, yet 57% said the technology’s risks outweigh its benefits. In June, an Anthropic survey of nearly 52,000 Americans found job losses were the public’s top concern across every state and political party, while just 15% said they trust AI companies to make decisions about how the technology is developed and used.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Popular Posts

My Favorites

Deepseek OCR: AI Doesn’t Just Read Texts, It “Sees” Them

0
Deepseek’s new OCR system processes texts as images and compresses them up to 10 times. This technology, capable of analyzing 33 million pages...