Skip to main content
The FYCKL Project
No AI. No Bull.

Main navigation

  • Home
User account menu
  • Log in

Breadcrumb

  1. Home

Aggregator

See the inappropriate messages Modest Mouse guitarist Simon O’Connor sent to underage fan

NY Post
2 months 1 week ago
In a shocking Reddit post, an anonymous person shared Instagram DMs the guitarist allegedly sent her days before her 17th birthday.
Tamantha Ryan

When Does The New Season of ‘Tulsa King’ Start? ‘Tulsa King’ Season 4 Release Date Info

NY Post
2 months 1 week ago
It's good to be the king.
mliss1578

‘Punisher’ star Jon Bernthal says pit bulls are victims of ‘dog racism’: ‘A lot of bulls–t’

NY Post
2 months 1 week ago
"It's just racism. It's just dog racism," Bernthal said.
Anthony Blair

Rand Paul’s ‘Vendetta’: Letters to the Editor — Aug. 3, 2026

NY Post
2 months 1 week ago
New York Post readers weigh in on Sen. Rand Paul’s efforts to prosecute Dr. Anthony Fauci for invoking the Fifth Amendment during his testimony on the US' response to the COVID-19 pandemic,
Post readers

"Nothing Is 100%": CZ Warns Bitcoin Holders After $89 Million Coldcard Wallet Exploit

Zero Rss
2 months 1 week ago
"Nothing Is 100%": CZ Warns Bitcoin Holders After $89 Million Coldcard Wallet Exploit

Update (1030ET): A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,367 BTC - close to $89 million - drained from 4,585 addresses since Thursday.

As Cyberkendra.com reports, the size is not the interesting part. The third wave is the first one designed to be hard to follow, and that shift tells self-custody holders more about what happens next than any dollar figure does.

Galaxy Research published the wave-three findings early Sunday. Between 12:23 UTC on July 31 and 06:42 UTC on August 1, across blocks 960,396 to 960,471, another 207.73 BTC left 1,912 addresses. That is roughly a tenth of a coin per victim.

Wave one, which opened at 01:10 UTC on July 30 and closed 41 minutes later, took 1,082.65 BTC from 1,195 addresses — nearly a full coin each.

Wave two, on July 31, collected just 76.16 BTC from 1,478 addresses.

Median losses tell the same story more bluntly: 0.270 BTC in wave one, 0.010 in wave two, 0.013 in wave three. The operator is now emptying wallets worth a few thousand dollars apiece and still finding enough of them to spend ten hours sweeping.

Waves one and two were easy to map because the attacker made them easy.

Both funneled coins through a handful of shared collector addresses into P2WPKH holding wallets (pay-to-witness-public-key-hash — plain single-key SegWit outputs, fully visible on chain).

Wave three abandoned that.

Each victim's coins went to their own destination, and the proceeds now sit in 293 separate P2WSH vaults (pay-to-witness-script-hash, a format that keeps its spending conditions hidden until the first time the coins move). The sweeper also batched an average of 6.37 victims per transaction, where wave one took exactly one at a time, and scanned only the default derivation path instead of testing several branches per seed. Even the fee constant changed — 30 sat/vB in wave one, 50 and 10 in wave two, roughly 200 then exactly 10 in wave three.

That is either the same crew rebuilding after being enumerated in public, or a second crew grinding the same broken key space on its own.

The falling average haul suggests the profitable end of the vulnerable key space is picked over. That is cold comfort. Wave three's median take of 0.013 BTC is the clearest evidence yet that no balance is now small enough to be beneath the scanner's notice — and the sweeping had not stopped three days in.

* * *

As Decrypt.co detailed earlier, Binance founder Changpeng "CZ" Zhao is warning crypto owners not to place blind faith in hardware wallets, following an exploit that drained tens of millions of dollars in Bitcoin from Coldcard devices.

In a Saturday post on X, Zhao cautioned that even hardware wallets can carry bugs, and that older wallets with long histories are not immune.

“Nothing is 100%,” he posted.

He suggested holders consider spreading their funds across several wallets as one way to reduce exposure, while acknowledging the approach carries its own trade-offs and that no setup is entirely foolproof.

CZ closed with his familiar refrain urging users to stay informed and keep their funds safe: “Stay SAFU!”

His comments followed the discovery of a flaw in Coldcard devices made by manufacturer Coinkite.

As Decrypt reported, a build error caused seeds on affected units to be drawn from a software fallback rather than the device's hardware random-number generator, leaving the private keys far easier to guess than intended.

The problem traced back to firmware shipped in March 2021, and updating the firmware does not fix a seed already created on a compromised device.

The scope of the theft has grown considerably since the first estimates.

Early reporting pegged losses at roughly 594 BTC, or about $38 million, drained from around 500 wallets.

According to a report from Galaxy Research, which mapped the flow of funds based on a pattern identified by engineers at Jack Dorsey’s Block, the toll is now put at 1,196 addresses drained for about 1,082.65 BTC, or roughly $70.2 million, in a 41-minute window on July 30.

That is nearly double the initial figure.

Galaxy said every sweep paid an identical hardcoded fee and left no change output, a signature it described as consistent with an automated tool spending keys it already held rather than owners moving their own funds.

“The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins,” Galaxy Research said, adding that Bitcoiners should move funds out of single-signature Coldcard addresses and into secure custody.

The victims spanned native SegWit and older address types, pointing to multi-path key scanning.

The stolen Bitcoin was consolidated within minutes into a handful of addresses and, per Galaxy, has not moved since.

Coinkite co-founder Rodolfo Novak said in an X post on Friday that the company takes responsibility for the firmware bug and has shipped emergency hotfixes.

Novak also warned that the update does not protect seeds generated on vulnerable firmware.

He advised users who generated seeds on vulnerable firmware to move their funds to a new seed.

Tyler Durden Sun, 08/02/2026 - 10:30
Tyler Durden

‘Marshals’ Season 2 Release Date: When Does Luke Grimes’ ‘Yellowstone’ Spin-off Return With New Episodes?

NY Post
2 months 1 week ago
Sundays aren't the same without new episodes of Marshals.
mliss1578

Yankees vs. Cubs prediction: MLB Sunday player props, picks, odds

NY Post
2 months 1 week ago
Gerrit Cole appears to be finding his stride at the right time.
Dylan Svoboda

Massive debate sparked after customer asked to tip kitchen staff: ‘Fear something’s going to be messed with our food’

NY Post
2 months 1 week ago
Enough is enough!
Fabiana Buontempo

James Madison knew the antidote for Dr. Fauci’s COVID tyranny

NY Post
2 months 1 week ago
Anthony Fauci, the public health bureaucrat who became the face of America’s botched COVID-19 response, testified last week on Capitol Hill. Except Fauci actually didn’t testify: In an astonishing act of hubris and disdain for the countless Americans who bore the brunt of tyrannical COVID-era “Faucism,” the mad doctor invoked the Fifth Amendment well over...
Josh Hammer

Jamie-Lynn Sigler sings national anthem at Mets game on same day ‘Sopranos’ star Vincent Pastore dies

NY Post
2 months 1 week ago
The Mets invited a mob daughter to sing the national anthem on Saturday.
Thomas Gamba-Ellis

Iran signaled it would allow Hormuz to reopen before Trump called off attacks: report

NY Post
2 months 1 week ago
Iran's negotiators signaled to the US that they could reopen the Strait of Hormuz before President Trump called off massive strikes on the country this weekend, according to reports — but the IRGC is already denying any deal.
Ryan King

Yankees’ Jasson Dominguez takes responsibility for Wrigley Field misplay: ‘Not an excuse’

NY Post
2 months 1 week ago
The Yankees right fielder made a costly misplay on a ball down the line Saturday night, as it kicked off the wall and got past him, ensuring the go-ahead run scored all the way from first in what became a 5-2 loss to the Cubs.
Greg Joyce

When Does ‘House of the Dragon’ Season 3 Episode 7 Come Out?

NY Post
2 months 1 week ago
Wait, is Alicent really going to murder her own son at Harrenhal?
mliss1578

America’s terrifying, secret plan to deal with biological-weapon attacks

NY Post
2 months 1 week ago
The United States is under biological attack from a genetically modified plague. There is chaos in the streets, bloody corpses strewn on sidewalks, people killing neighbors they believe have the contagious bug for fear of it spreading. In the White House, the country’s Secretary of Defense is informing the president of the nature of the...
Larry Getlen

Demetric Felton Jr., former UCLA, NFL star, has solution to playbook dilemma

NY Post
2 months 1 week ago
Demetric Felton Jr. knows what it’s like to drown in a playbook.
Ben Bolch

Hero sheepdog takes charge of SoCal rescue — with unexpected move to aid first responders

NY Post
2 months 1 week ago
A little white sheepdog unexpectedly became the hero of the day, stepping in to help first responders land a helicopter during an emergency in Orange County.
Katie Jerkovich

Kalshi promo code NYPMAX: Trade $25, get up to $500 for MLB trade deadline markets

NY Post
2 months 1 week ago
Trade $25, get up to $500 for MLB trade deadline markets with Kalshi promo code NYPMAX.
Malik Smith

Water-System Hacks Hit 7 States This Week, FBI Warns, As Trump Shoots Down Iran Theory

Zero Rss
2 months 1 week ago
Water-System Hacks Hit 7 States This Week, FBI Warns, As Trump Shoots Down Iran Theory

Cyberattacks on municipal water systems were reported in at least seven states this week, according to a joint public service announcement from the FBI and the Environmental Protection Agency - and in some cases, the agencies say, the malicious activity actually degraded water operations. The feds declined to name the states.

A water tower in Plymouth, Minnesota, on Thursday after a cyberattack targeted the operating technology at more than 30 water systems across the state. (Ellen Schmidt/AP Photo/Ellen Schmidt)

The warning lands just days after we reported that a "coordinated cyberattack" struck more than 30 community water systems in Minnesota over July 26-27 - knocking the water plant in tiny Braham offline for a stretch, pushing Plymouth and South St. Paul onto manual operations, and prompting Maple Plain to declare a local state of emergency, according to Just The News.

The playbook, per federal officials, was crude but effective: attackers remotely accessed internet-facing operational technology, changed device IP addresses and passwords, and locked utility operators out of their own monitoring and control systems, NBC News reported. The PSA is now pleading with utilities to do the bare minimum - pull programmable logic controllers off the open internet and put them behind gateways and firewalls, use actual passwords, and restrict which devices are allowed to talk to one another.

(Yes - in the year 2026, a nontrivial share of the machines controlling America's drinking water are still sitting on the public internet, some with absurdly simple passwords.)

CISA followed Thursday with an advisory warning that Iranian-affiliated actors are going after U.S. critical infrastructure, water and wastewater systems included - an update to guidance the agency first pushed out in April, which we flagged in our earlier coverage. Some of the larger water-sector intrusions, the advisory notes, have produced boil-water notices and left plants grinding along in manual mode for extended stretches. CISA's top-line fix is the same one it has been repeating for years: cut direct internet access to control systems.

Except - Washington can't agree on who did it.

Multiple U.S. officials have told ABC News the Minnesota attacks may be linked to Iran, and investigators' preliminary assessment reportedly leans the same way - with the caveat that it could change. Meanwhile President Trump denied it. Speaking to reporters at Camp David on Friday, Trump dismissed the Iran theory - "Iran should be so lucky," he said - and instead pinned the blame on what he called Minnesota's grossly incompetent and corrupt leadership under Gov. Tim Walz, arguing Tehran has bigger problems than the Gopher State's pump stations.

Trump:

They like to say, "Ohh, it's Iran. Iran should be so lucky."

Iran's got bigger problems than worrying about Minnesota. https://t.co/4FnVLLzSmY pic.twitter.com/9HMP4RTcii

— Adam Scott (@chefcascottccc) July 31, 2026

Cybersecurity veteran Morgan Wright, founder of the National Center for Open and Unsolved Cases, told The Hill that Iran is the likely culprit, pointing to the CISA advisory as one tell. The U.S. may dominate on land and at sea, Wright argued, but cyberspace is the one domain where Tehran gets to punch above its weight class. Federal officials, for their part, caution that attribution requires careful technical analysis alongside broader threat intelligence - because otherwise it looks like the same nakedly transparent propaganda we've been fed for decades (duh).

That said - there is precedent as we detailed in our Minnesota coverage, if we're to believe the official stories. In November 2023, the IRGC-linked CyberAv3ngers seized control of a device at the Municipal Water Authority of Aliquippa, Pennsylvania. In early 2024, the Cyber Army of Russia Reborn claimed attacks on water facilities in the U.S. and Poland, including a breach in Muleshoe, Texas that dumped tens of thousands of gallons of water. In October 2024, American Water - the largest regulated water utility in the country, serving more than 14 million people across 14 states and 18 military installations - shut down computer systems after a cyberattack. Beijing's Volt Typhoon has spent years quietly pre-positioning inside U.S. critical-infrastructure networks, per CISA. And just weeks ago, the Iranian MOIS-linked Handala persona claimed to have compromised California Water Service - which serves roughly 2 million customers - leaking 5 gigabytes of data, then vowed via Tehran's Press TV to keep hitting U.S. industrial control systems.

Tyler Durden Sun, 08/02/2026 - 09:45
Tyler Durden

Giants’ Odell Beckham Jr. shows off vintage form as Jaxson Dart deals tough day

NY Post
2 months 1 week ago
Observations from Saturday's Giants training camp practice.
Ryan Dunleavy

Jamie-Lynn Sigler pays tribute to ‘kind and loving’ ‘Sopranos’ co-star Vincent Pastore after his death

NY Post
2 months 1 week ago
As Page Six previously reported, the actor best known for his role as Salvatore “Big P--y” Bonpensiero in “The Sopranos," passed away on Saturday.
mliss1578

Pagination

  • First page
  • Previous page
  • …
  • Page 1248
  • Page 1249
  • Page 1250
  • Page 1251
  • Page 1252
  • Page 1253
  • Page 1254
  • Page 1255
  • Page 1256
  • …
  • Next page
  • Last page

zero rss

News feeds

  • Is America Winning The AI Race?
  • "Interplanetary Shockwave" Detected?
  • Paramount-Warner Reveals The Extent Of California's Control
  • Houthi Missile Attack On Busy Terminal At Riyadh Airport Kills 12, Injures 309
  • High School Wrestler Asks Supreme Court To Allow Her To Avoid Competing With Boys
  • Chinese Workers Return From Holiday To Find Factories Emptied, Owners Gone
  • Ukraine's Drones Reach Russia's Arctic "Gas Capital"; Is Nornickel's Palladium Next?
  • Trump Says "Time For Ukraine To Get A New Leader" After Zelensky Ignored Six Pleas To Stop Refinery Strikes
  • Moraes Orders Eduardo Bolsonaro Jailed For Lobbying Washington On Sanctions As His Brother Heads Into Brazil Runoff
  • Some Safety Protections In ChatGPT For Teens Don't Work, Watchdog Finds
More

zero rss

Copyright (c) 2026 FYCKL Project