BTC $65,039.00 +0.14%
ETH $1,921.82 +0.05%
BNB $605.77 +2.14%
XRP $1.04 +1.80%
SOL $76.31 +3.13%
TRX $0.3287 +0.31%
DOGE $0.0713 +1.78%
ADA $0.2000 -0.26%
BCH $217.45 +0.73%
LINK $8.36 +0.61%
HYPE $54.81 -1.62%
AAVE $91.37 +1.48%
SUI $0.6992 +3.81%
XLM $0.1660 +3.28%
ZEC $504.74 -2.20%
BTC $65,039.00 +0.14%
ETH $1,921.82 +0.05%
BNB $605.77 +2.14%
XRP $1.04 +1.80%
SOL $76.31 +3.13%
TRX $0.3287 +0.31%
DOGE $0.0713 +1.78%
ADA $0.2000 -0.26%
BCH $217.45 +0.73%
LINK $8.36 +0.61%
HYPE $54.81 -1.62%
AAVE $91.37 +1.48%
SUI $0.6992 +3.81%
XLM $0.1660 +3.28%
ZEC $504.74 -2.20%

security

All
Article
Flash

Coldcard has suspended the automatic deletion of customer data due to a security incident and will retain relevant records in accordance with the law

The cryptocurrency hardware wallet manufacturer Coldcard has released an update on its customer data retention policy. Due to legal compliance requirements arising from the security incident disclosed on July 30, the company has temporarily suspended its original automatic customer data deletion mechanism.Previously, Coldcard's standard practice was to automatically clear customer records after 120 days, retaining only the user's email address and country information, while allowing customers to request early deletion of data at any time after product delivery. Coldcard stated that due to the security incident involving ongoing and potential legal proceedings, the company is obligated to retain records that may be relevant to litigation. Therefore, customer data that was originally scheduled for deletion will be temporarily retained until the law permits the resumption of normal processes.However, users can still request Coldcard to handle their personal information according to the original data retention policy. If users wish for their data not to be included in this legal retention scope, they can contact official customer service to make a request. Coldcard emphasizes that the retained data will be strictly protected, accessible only to authorized personnel, and will not be used for any purposes other than fulfilling legal obligations. The company will restore the previous automatic data deletion mechanism once legally permissible.

hot_img Expected direction of South Korea's secondary regulations on security tokens: allowing asset pooling and setting trading limits for general investors

According to the expected plan compiled by the Korea Digital Convergence Industry Association, the secondary regulations for Security Token Offerings (STO) in South Korea may include: allowing "pooling" issuance of similar types of underlying assets, setting over-the-counter trading limits for general investors, clarifying the licensing conditions and business scope for non-standard securities over-the-counter exchanges, and developing a phased roadmap for the tokenization of standard securities. In addition, the technical and financial requirements for issuer account management institutions are also expected to be included in the regulations.This expected plan is based on publicly available policy directions and industry discussions and is not an official version. Specific standards still need to be determined through legislative announcements, regulatory reviews, and other procedures. Previously, the STO market was primarily focused on single assets; if pooling is allowed, it could promote the issuance of multi-asset composite products such as music copyrights and real estate. The over-the-counter trading limits for general investors are expected to be higher than existing sandbox cases, but the final limits still need to balance investor protection and market liquidity. The status of non-standard securities over-the-counter trading platforms and existing operators, as well as the future path for the tokenization of standard securities (stocks, bonds), will be key focuses moving forward. The industry warns that after the regulations are implemented, the preparation time for related companies' systems and internal controls may be quite urgent.

The Ethereum Foundation provides security funding to WEBCAT to assist in wallet verification front-end code to prevent phishing attacks

According to official news, the Ethereum Foundation's "Trillion Dollar Security" (1TS) has announced a special grant to the Freedom of the Press Foundation (FPF) to support the ongoing development of the open-source tool WEBCAT, aimed at addressing the long-standing front-end code verification security gap in Ethereum wallets and decentralized applications (DApps).WEBCAT (Web-based Code Assurance and Transparency) is an open-source tool designed to help browsers verify whether the code loaded by a website matches the version publicly released by the developer.This funding will promote the expansion of WEBCAT to Ethereum wallets and application scenarios, enabling users to verify whether the front-end pages they access have been tampered with.The Ethereum Foundation stated that while HTTPS can verify the website a user is connected to and encrypt communication, it cannot prove that the front-end code actually running on the website is the same version released by the developer. If an attacker controls the website's front-end code, they may modify the transaction receiving address without the user's knowledge or induce the user to sign transactions that do not match the content displayed on the page.The Ethereum Foundation noted that front-end attacks have become a significant security risk for blockchain infrastructure, with malicious modifications to web interfaces potentially leading to supply chain attacks, DNS hijacking subsequent attacks, and user interface deception.WEBCAT was initially developed by the Freedom of the Press Foundation to enhance the code credibility of secure communication systems like SecureDrop.With this expansion into the Ethereum ecosystem, it will complement security measures such as "Clear Signing" in the 1TS program: the former helps wallets confirm that the application front-end has not been tampered with, while the latter helps users understand the transaction content they are approving.

Jim Cramer said he will liquidate his Bitcoin holdings, concerned about the threat of quantum computing to its security

Former hedge fund manager and CNBC host Jim Cramer stated that due to concerns about quantum computing threatening Bitcoin's security, he plans to sell all of his BTC holdings. His statement stems from an interview with IBM Chairman and CEO Arvind Krishna, who said that investors should be wary of the challenges quantum computing may pose to modern cryptography in the next 3 to 4 years. Cramer believes that quantum computing could threaten the Bitcoin network in a similar timeframe. However, no one has independently confirmed how much BTC he holds or whether he has completed the sale.After his statement, Bitcoin continued to trade normally around $63,764, with some market participants viewing his comments as a "reverse Cramer" signal. Bitcoin uses the ECDSA signature mechanism based on the secp256k1 curve, and theoretically, a sufficiently powerful quantum computer could use Shor's algorithm to derive the private key from the public key. The risk is mainly concentrated on addresses with exposed public keys, including reused addresses, early wallet formats, and the brief time window after a transaction is broadcast but not yet confirmed. Researchers estimate that about 6 to 7 million BTC, accounting for approximately 30% of the supply, may fall into this category. Google Quantum AI estimated in March this year that breaking the relevant cryptographic mechanisms could require fewer than 500,000 physical qubits, reducing the previous estimate by about 20 times. However, current quantum systems typically only have hundreds to thousands of physical qubits, with even fewer logical qubits that have higher reliability. Most researchers expect that truly capable quantum computers for cryptographic breaking may not appear until the 2030s or even 2040s, making Cramer's 3-year prediction significantly earlier than most technological expectations.

Researchers at the Chinese People's Public Security University have developed an AI algorithm to track Bitcoin money laundering, achieving an overall accuracy rate of about 90%

Researchers at the Chinese People's Public Security University have developed an AI framework capable of detecting illegal cryptocurrency transactions with an overall accuracy rate close to 90%. The study was published in the Chinese peer-reviewed journal "Journal of Intelligence," and the corresponding author, Dr. Sun Jingchao (specializing in criminal investigation and cybersecurity), noted that the research "provides an accurate, scalable, and interpretable solution for detecting illegal cryptocurrency transactions," and offers "an innovative technical path" for regulatory agencies to combat illegal cryptocurrency transactions and economic crimes.This AI framework utilizes memory modules and large language models, specifically targeting the anonymity and cross-border characteristics of cryptocurrencies to track illegal activities such as money laundering. The release of this research coincides with China's ongoing efforts to intensify the crackdown on financial crimes related to cryptocurrencies. In March of this year, the Supreme People's Procuratorate of China disclosed that by 2025, procuratorial authorities had prosecuted 3,259 individuals for money laundering crimes involving virtual currencies and underground banks.As the trading volume of cryptocurrencies rapidly increases, their anonymity and cross-border characteristics provide a channel for illegal fund flows. This police-developed AI detection tool marks a shift in regulatory technology from passive tracking to proactive intelligent identification.
app_icon
ChainCatcher Building the Web3 world with innovations.