搜索
全部
文章
快讯
专题
活动
专栏作者
文章
查看更多
快讯
Coldcard 2021 Firmware Vulnerability Led to Over $100 Million in Bitcoin Theft
Odaily News: A 2021 firmware vulnerability in the hardware wallet Coldcard resulted in insufficient randomness in some recovered seeds. Since July 30, attackers have transferred approximately 1,600 to 1,800 BTC from affected wallets, involving thousands of addresses, with an estimated value exceeding $100 million.Coldcard manufacturer Coinkite stated that it must be assumed that someone used AI to review its public firmware. The vulnerability has existed for about five years, and whether AI was involved in the related attacks has not yet been confirmed.Shielded Labs researcher Taylor Hornby used a Claude Opus 4.8 audit agent and discovered a vulnerability in the Zcash Orchard shielded pool circuit dating back to 2022, which in testing could generate unlimited counterfeit ZEC without a trace. Developers completed the fix within days, and no theft of coins has been confirmed.Statistics from blockchain analytics firm Chainalysis show that on-chain writes carrying malware instructions and command-and-control information rose from about 2.06 per day to 11.1 per day, an increase of 440%. (Bitcoin.com News)
Chainalysis: Global Crypto Taxable Activity Hits $457 Billion, Stablecoin Payment Flows Account for Largest Share
Odaily reports that Chainalysis has released its "Crypto Tax Report: Select Country Data," estimating global crypto-related taxable activity at approximately $457 billion, covering trading gains, on-chain income, and digital payments.The report states that it uses on-chain data to map these activities by region and country, providing tax authorities with a geolocated view of potential taxable activity within their jurisdictions. Among these, stablecoin payment flows represent the largest and most globally distributed category. The report also analyzes cross-border channels and their impact on direct and indirect tax obligations, and demonstrates how on-chain intelligence can help tax authorities identify high-value, high-risk wallets to determine enforcement priorities.
Data: Cases of hackers using open-source AI to implant malicious on-chain instructions increased by 440% in a year
Odaily reports: Blockchain analytics firm Chainalysis has released a report stating that hackers are increasingly leveraging open-source artificial intelligence (AI) to implant malware control instructions into on-chain transactions and smart contracts, with such cases surging approximately 440% in less than a year. Data shows that these incidents have risen from roughly 2 per day to approximately 11 per day. Attackers write malicious instructions on-chain to manipulate infected devices into stealing passwords and funds, and redirect assets to designated wallets; since on-chain records cannot be deleted, defense and interception are becoming increasingly difficult.The report notes that state-sponsored hackers from countries such as North Korea and Iran have become the primary drivers of such activity. Open-source models support local independent operation and modification, allowing them to directly bypass cloud-based defenses. However, the public and transparent nature of blockchain also leaves critical evidence for tracing attack infrastructure. (Bloomberg)
Four people killed in Mexico, suspects accused of stealing a cold wallet holding millions of dollars in Bitcoin
Odaily News: The State Attorney General's Office of Mexico (FGJEM) stated that two suspects are accused of killing four people in search of a cold wallet believed to contain millions of dollars in Bitcoin. The two are scheduled to appear in court on Wednesday, where a judge will determine whether there is sufficient evidence to continue criminal proceedings.The surnames of suspects Diego Sebastián and Gerardo have not been disclosed. Prosecutors allege that the pair killed Jonathan Meléndez, keyboardist for the rock band Camilo Séptimo, his pregnant wife, their daughter, and an employee at a residence in the city of Atizapán de Zaragoza. The family's golden retriever was also killed.Mexico's Secretary of Security, Omar García Harfuch, stated that one of the suspects was a business partner of the victim and allegedly used that relationship to gain entry into the residence. If convicted, the two could face sentences ranging from 25 to 70 years in prison for each victim.Blockchain security firm CertiK reported that 52 violent coercion attacks against cryptocurrency holders were recorded globally in the first half of 2026, a 33.3% increase from 39 during the same period in 2025. Blockchain analysis company Chainalysis estimates that the value of stolen cryptocurrency from related attacks exceeded $30 million. (Cointelegraph)
France Over 90% of Crypto Gains Unreported, Taxable On-Chain Activity Reaches $9.4 Billion in 2025
Odaily News According to blockchain analysis firm Chainalysis, France's potential taxable cryptocurrency activity in 2025 is estimated at $9.4 billion, comprising $5.2 billion in payments, $2.5 billion in capital gains, and $1.7 billion in mining and staking income.French taxpayers declared only €368 million in net gains for the 2024 tax year, involving approximately 24,000 individuals—up from about 7,700 people and €150.8 million the previous year. Chainalysis noted that in some countries, the rate of non-compliance with crypto tax obligations may exceed 90%.The EU's Eighth Administrative Cooperation Directive (DAC8) took effect on January 1, 2026, requiring crypto service providers to collect user identity and transaction data. Member state tax authorities will begin cross-border exchanges of relevant records from September 30, 2027. The CARF currently covers approximately 14% of potentially taxable on-chain activity globally. (Bitcoin.com News)
1:1 compensation for legitimate holders prior to the vulnerability incident; The Sandbox will reimburse cross-chain SAND using treasury funds
Odaily News, The Sandbox has released a post-mortem report on the August 22 vulnerability incident. The report shows that attackers exploited vulnerabilities in contracts related to cross-chain configurations on Base and BNB Smart Chain (BSC), stealing 14,742,341.84 SAND from the Ethereum treasury, accounting for approximately 0.5% of the maximum supply, with an estimated economic impact of approximately $1.4968 million, of which about $987,000 was actually retained by the attackers. The Ethereum mainnet and Polygon network were not affected. Until further notice, please do not purchase or send SAND on Base or BNB Smart Chain. Contracts deployed on Base and BNB Smart Chain have been permanently deactivated and will not be reopened. The Sandbox stated that the team has reported the attacker's wallet address to blockchain analysis firms TRM Labs and Chainalysis, and has communicated directly with relevant exchanges. The Sandbox also announced a compensation plan, which will compensate wallets that legitimately held cross-chain SAND on Base or BSC prior to the incident at a 1:1 ratio in Ethereum SAND. Compensation funds will come from The Sandbox treasury, with no new tokens issued. The claim process will open within the next two weeks and remain open for two weeks.
2025 global potentially taxable on-chain crypto activity reaches $457 billion, CARF coverage only 14%
Odaily News Blockchain analysis firm Chainalysis stated that the scale of potentially taxable on-chain crypto activity globally in 2025 amounts to at least $457 billion, with approximately $112.6 billion in the US, $134.6 billion in North America, and $125.1 billion in the EU. The estimates cover realized gains, mining, staking, lending income, and crypto payments, but do not include activities such as trading on centralized exchanges.Chainalysis noted that of the on-chain taxable activities it identified, only 14% fall within the scope of the Organisation for Economic Co-operation and Development (OECD) Crypto-Asset Reporting Framework (CARF), while the remaining 86% involve decentralized exchanges, peer-to-peer transfers, on-chain income streams, and payment activities.CARF was established by the OECD in 2022 and requires eligible crypto service providers to report customer transaction data to tax authorities. CARF data collection commenced on January 1, 2026, in 48 jurisdictions, including the UK and EU member states. Platforms are required to collect customer and tax residency information and report transaction data. (Cointelegraph)
Iranian Rial Hits Record Low, US Sanctions Target Digital Assets for First Time
According to Odaily, the Iranian rial hit a record low this week, with the open market exchange rate falling to approximately 2.02 million rials per US dollar on August 24, compared to around 1.53 million rials in the first quarter. During the same period, the US government launched "Operation Economic Exodus," adding more than 60 entities to the Treasury Department's blacklist and, for the first time, designating digital assets as a sanctionable category.State-controlled farms linked to Iran's Islamic Revolutionary Guard Corps (IRGC) control approximately 65% of Iran's Bitcoin mining capacity. Iranian miners have accounted for roughly 3% to 7% of global Bitcoin hashrate since 2019, with the mined Bitcoin valued at an estimated $1.35 billion to $3.15 billion at various stages.Iran legalized Bitcoin mining in 2019, allowing licensed operators to use industrial electricity at approximately $0.004 per kilowatt-hour and sell the mined tokens to the Central Bank of Iran. Chainalysis estimates that IRGC-affiliated wallets received over $3 billion in Q4 2025; Elliptic states that the Central Bank of Iran holds at least $507 million in USDT.The US Treasury sanctioned Nobitex, Wallex, Bitpin, and Ramzinex in June. Nobitex had processed more than half of Iran's digital asset inflows; in April, the US Treasury seized nearly $500 million in Iran-linked crypto assets. (Bitcoin.com News)
Chainalysis's Operation Lighthouse investigation tracked 29,000 crypto addresses and uncovered over 7,700 suspicious accounts
Odaily News: Chainalysis announced that its Operation Lighthouse investigation has examined 29,120 crypto addresses and digital identity markers, generating 14,300 investigative leads. The operation targets cryptocurrency activities related to child sexual abuse material, covering over 100 clearnet and darknet platforms, forums, and distribution networks. Chainalysis stated that the operation also identified more than 7,700 suspicious accounts and flagged suspects across 125 countries. The operation was organized by the U.S. National Cyber Forensics and Training Alliance, with participation from multiple law enforcement agencies, crypto industry firms, and nonprofit organizations.
专用链新增可选合规筛选与优先费功能,Arbitrum激活Elara升级
Odaily Planet Daily News: On August 20, Arbitrum activated the ArbOS 61 "Elara" upgrade, adding optional protocol-level transaction filtering, priority fee support, and an alternative data availability interface for dedicated chains, while adjusting Arbitrum One's base fee management and expanding Stylus contract capacity. The compliance filtering feature is disabled by default, and chain owners must proactively configure external compliance service providers such as TRM Labs or Chainalysis and set rules, which are enforced through transaction simulation and on-chain guardian mechanisms. The priority fee feature is also disabled by default, requiring chain owners to enable it via precompiles; the collection of priority fees on Arbitrum One still requires a separate DAO vote.
查看更多



