BTC $65,048.15 +0.24%
ETH $1,917.36 +0.07%
BNB $604.35 +0.17%
XRP $1.03 -0.21%
SOL $76.88 +0.59%
TRX $0.3313 +0.50%
DOGE $0.0699 -0.18%
ADA $0.1966 +0.31%
BCH $215.63 -0.32%
LINK $8.32 +0.51%
HYPE $55.07 +1.53%
AAVE $91.53 +0.50%
SUI $0.6956 +0.70%
XLM $0.1636 +0.46%
ZEC $507.12 -2.75%
BTC $65,048.15 +0.24%
ETH $1,917.36 +0.07%
BNB $604.35 +0.17%
XRP $1.03 -0.21%
SOL $76.88 +0.59%
TRX $0.3313 +0.50%
DOGE $0.0699 -0.18%
ADA $0.1966 +0.31%
BCH $215.63 -0.32%
LINK $8.32 +0.51%
HYPE $55.07 +1.53%
AAVE $91.53 +0.50%
SUI $0.6956 +0.70%
XLM $0.1636 +0.46%
ZEC $507.12 -2.75%

theft

All
Article
Flash

The cryptocurrency industry is once again debating "who should hold the private keys" due to the $130 million theft case involving the Coldcard wallet

A wallet security incident involving approximately $130 million in Bitcoin losses is reigniting discussions in the crypto industry about asset custody models: should Bitcoin holders rely on personal self-custody or turn to institutional custody? Hardware wallet manufacturer Coldcard had a vulnerability in its firmware in 2021 that led to some mnemonic phrases generated by the device being predictably risky. This vulnerability was discovered years later, and approximately 5,200 addresses and about 2,000 BTC have been stolen, with losses amounting to around $130 million.After the incident, some investors began to turn to Wall Street custody products. Data shows that the U.S. spot Bitcoin ETF saw a net inflow of about $626 million within days of the incident. Bloomberg ETF analyst Eric Balchunas stated that such security incidents could further drive funds into ETFs. However, the Bitcoin core community still insists on the self-custody concept. Casa co-founder Jameson Lopp stated that recent events should not undermine users' confidence in self-custody and pointed out that third-party custody also carries risks. Bitcoin Core early developer Peter Todd also believes that self-custody has a better long-term safety record than centralized institutions.Onramp co-founder Michael Tanguma believes that both options have flaws. He stated that concentrating a large amount of assets in a single institution creates a "honey pot," while hardware wallets face risks related to supply chains, firmware, and random number generation. Tanguma proposed a "multi-institution custody" solution, where multiple regulated institutions hold keys through a multi-signature mechanism, requiring multiple institutions to jointly sign any transaction to reduce single points of failure. However, this model has also sparked controversy. Critics argue that while multi-institution custody enhances security, it also introduces permissioned management, conflicting with the decentralized ideals originally pursued by Bitcoin. As Bitcoin gradually enters the fields of pensions, trusts, and institutional asset allocation, the industry is seeking new custody solutions suitable for long-term wealth management. The Coldcard vulnerability incident once again highlights that achieving a balance between security, decentralization, and usability remains a core challenge facing the Bitcoin ecosystem.

Security Alert: 30 malicious npm packages disguised as trading bot repositories, targeting the theft of developer keys and mnemonic phrases

SlowMist issued a security alert, detecting a coordinated malicious npm supply chain attack. The attackers utilized fake trading bot repositories and DeFi-themed npm packages to deploy JavaScript information stealers, targeting npm users, DeFi developers, and trading bot users.This attack involved 30 malicious npm packages, among which stake-math@3.5.4 appeared as a locked dependency in the donoaccestag/forex-mt5-trading-bot repository. This repository presented approximately 2300 highly homogeneous bulk-generated forks, mostly concentrated under the poly-stocks account, with signals being exceptionally clear. The sensitive data that attackers could steal is extensive, including cryptocurrency wallet libraries, browser cookies and saved passwords, browsing history, developer credentials, shell history, password manager libraries, private keys, mnemonic phrases, and API tokens exposed in source code.SlowMist recommends that developers immediately remove the affected npm packages, audit package.json and package-lock.json, and check CI logs for any of the 30 malicious packages; consider any system that has executed npm install as potentially compromised, rotate all exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens, and rebuild the affected environment from a clean image.
app_icon
ChainCatcher Building the Web3 world with innovations.