Aggregator
When Does The New Season of ‘Tulsa King’ Start? ‘Tulsa King’ Season 4 Release Date Info
‘Punisher’ star Jon Bernthal says pit bulls are victims of ‘dog racism’: ‘A lot of bulls–t’
Rand Paul’s ‘Vendetta’: Letters to the Editor — Aug. 3, 2026
"Nothing Is 100%": CZ Warns Bitcoin Holders After $89 Million Coldcard Wallet Exploit
Update (1030ET): A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,367 BTC - close to $89 million - drained from 4,585 addresses since Thursday.
As Cyberkendra.com reports, the size is not the interesting part. The third wave is the first one designed to be hard to follow, and that shift tells self-custody holders more about what happens next than any dollar figure does.
Galaxy Research published the wave-three findings early Sunday. Between 12:23 UTC on July 31 and 06:42 UTC on August 1, across blocks 960,396 to 960,471, another 207.73 BTC left 1,912 addresses. That is roughly a tenth of a coin per victim.
Wave one, which opened at 01:10 UTC on July 30 and closed 41 minutes later, took 1,082.65 BTC from 1,195 addresses — nearly a full coin each.
Wave two, on July 31, collected just 76.16 BTC from 1,478 addresses.
Median losses tell the same story more bluntly: 0.270 BTC in wave one, 0.010 in wave two, 0.013 in wave three. The operator is now emptying wallets worth a few thousand dollars apiece and still finding enough of them to spend ten hours sweeping.
Waves one and two were easy to map because the attacker made them easy.
Both funneled coins through a handful of shared collector addresses into P2WPKH holding wallets (pay-to-witness-public-key-hash — plain single-key SegWit outputs, fully visible on chain).
Wave three abandoned that.
Each victim's coins went to their own destination, and the proceeds now sit in 293 separate P2WSH vaults (pay-to-witness-script-hash, a format that keeps its spending conditions hidden until the first time the coins move). The sweeper also batched an average of 6.37 victims per transaction, where wave one took exactly one at a time, and scanned only the default derivation path instead of testing several branches per seed. Even the fee constant changed — 30 sat/vB in wave one, 50 and 10 in wave two, roughly 200 then exactly 10 in wave three.
That is either the same crew rebuilding after being enumerated in public, or a second crew grinding the same broken key space on its own.
The falling average haul suggests the profitable end of the vulnerable key space is picked over. That is cold comfort. Wave three's median take of 0.013 BTC is the clearest evidence yet that no balance is now small enough to be beneath the scanner's notice — and the sweeping had not stopped three days in.
* * *
As Decrypt.co detailed earlier, Binance founder Changpeng "CZ" Zhao is warning crypto owners not to place blind faith in hardware wallets, following an exploit that drained tens of millions of dollars in Bitcoin from Coldcard devices.
In a Saturday post on X, Zhao cautioned that even hardware wallets can carry bugs, and that older wallets with long histories are not immune.
“Nothing is 100%,” he posted.
He suggested holders consider spreading their funds across several wallets as one way to reduce exposure, while acknowledging the approach carries its own trade-offs and that no setup is entirely foolproof.
CZ closed with his familiar refrain urging users to stay informed and keep their funds safe: “Stay SAFU!”
His comments followed the discovery of a flaw in Coldcard devices made by manufacturer Coinkite.
As Decrypt reported, a build error caused seeds on affected units to be drawn from a software fallback rather than the device's hardware random-number generator, leaving the private keys far easier to guess than intended.
The problem traced back to firmware shipped in March 2021, and updating the firmware does not fix a seed already created on a compromised device.
The scope of the theft has grown considerably since the first estimates.
Early reporting pegged losses at roughly 594 BTC, or about $38 million, drained from around 500 wallets.
According to a report from Galaxy Research, which mapped the flow of funds based on a pattern identified by engineers at Jack Dorsey’s Block, the toll is now put at 1,196 addresses drained for about 1,082.65 BTC, or roughly $70.2 million, in a 41-minute window on July 30.
That is nearly double the initial figure.
Galaxy said every sweep paid an identical hardcoded fee and left no change output, a signature it described as consistent with an automated tool spending keys it already held rather than owners moving their own funds.
“The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins,” Galaxy Research said, adding that Bitcoiners should move funds out of single-signature Coldcard addresses and into secure custody.
The victims spanned native SegWit and older address types, pointing to multi-path key scanning.
The stolen Bitcoin was consolidated within minutes into a handful of addresses and, per Galaxy, has not moved since.
Coinkite co-founder Rodolfo Novak said in an X post on Friday that the company takes responsibility for the firmware bug and has shipped emergency hotfixes.
Novak also warned that the update does not protect seeds generated on vulnerable firmware.
He advised users who generated seeds on vulnerable firmware to move their funds to a new seed.
Tyler Durden Sun, 08/02/2026 - 10:30‘Marshals’ Season 2 Release Date: When Does Luke Grimes’ ‘Yellowstone’ Spin-off Return With New Episodes?
Yankees vs. Cubs prediction: MLB Sunday player props, picks, odds
Massive debate sparked after customer asked to tip kitchen staff: ‘Fear something’s going to be messed with our food’
James Madison knew the antidote for Dr. Fauci’s COVID tyranny
Jamie-Lynn Sigler sings national anthem at Mets game on same day ‘Sopranos’ star Vincent Pastore dies
Iran signaled it would allow Hormuz to reopen before Trump called off attacks: report
Yankees’ Jasson Dominguez takes responsibility for Wrigley Field misplay: ‘Not an excuse’
When Does ‘House of the Dragon’ Season 3 Episode 7 Come Out?
America’s terrifying, secret plan to deal with biological-weapon attacks
Demetric Felton Jr., former UCLA, NFL star, has solution to playbook dilemma
Hero sheepdog takes charge of SoCal rescue — with unexpected move to aid first responders
Kalshi promo code NYPMAX: Trade $25, get up to $500 for MLB trade deadline markets
Water-System Hacks Hit 7 States This Week, FBI Warns, As Trump Shoots Down Iran Theory
Cyberattacks on municipal water systems were reported in at least seven states this week, according to a joint public service announcement from the FBI and the Environmental Protection Agency - and in some cases, the agencies say, the malicious activity actually degraded water operations. The feds declined to name the states.
A water tower in Plymouth, Minnesota, on Thursday after a cyberattack targeted the operating technology at more than 30 water systems across the state. (Ellen Schmidt/AP Photo/Ellen Schmidt)The warning lands just days after we reported that a "coordinated cyberattack" struck more than 30 community water systems in Minnesota over July 26-27 - knocking the water plant in tiny Braham offline for a stretch, pushing Plymouth and South St. Paul onto manual operations, and prompting Maple Plain to declare a local state of emergency, according to Just The News.
The playbook, per federal officials, was crude but effective: attackers remotely accessed internet-facing operational technology, changed device IP addresses and passwords, and locked utility operators out of their own monitoring and control systems, NBC News reported. The PSA is now pleading with utilities to do the bare minimum - pull programmable logic controllers off the open internet and put them behind gateways and firewalls, use actual passwords, and restrict which devices are allowed to talk to one another.
(Yes - in the year 2026, a nontrivial share of the machines controlling America's drinking water are still sitting on the public internet, some with absurdly simple passwords.)
CISA followed Thursday with an advisory warning that Iranian-affiliated actors are going after U.S. critical infrastructure, water and wastewater systems included - an update to guidance the agency first pushed out in April, which we flagged in our earlier coverage. Some of the larger water-sector intrusions, the advisory notes, have produced boil-water notices and left plants grinding along in manual mode for extended stretches. CISA's top-line fix is the same one it has been repeating for years: cut direct internet access to control systems.
Except - Washington can't agree on who did it.
Multiple U.S. officials have told ABC News the Minnesota attacks may be linked to Iran, and investigators' preliminary assessment reportedly leans the same way - with the caveat that it could change. Meanwhile President Trump denied it. Speaking to reporters at Camp David on Friday, Trump dismissed the Iran theory - "Iran should be so lucky," he said - and instead pinned the blame on what he called Minnesota's grossly incompetent and corrupt leadership under Gov. Tim Walz, arguing Tehran has bigger problems than the Gopher State's pump stations.
Trump:
They like to say, "Ohh, it's Iran. Iran should be so lucky."
Iran's got bigger problems than worrying about Minnesota. https://t.co/4FnVLLzSmY pic.twitter.com/9HMP4RTcii
Cybersecurity veteran Morgan Wright, founder of the National Center for Open and Unsolved Cases, told The Hill that Iran is the likely culprit, pointing to the CISA advisory as one tell. The U.S. may dominate on land and at sea, Wright argued, but cyberspace is the one domain where Tehran gets to punch above its weight class. Federal officials, for their part, caution that attribution requires careful technical analysis alongside broader threat intelligence - because otherwise it looks like the same nakedly transparent propaganda we've been fed for decades (duh).
That said - there is precedent as we detailed in our Minnesota coverage, if we're to believe the official stories. In November 2023, the IRGC-linked CyberAv3ngers seized control of a device at the Municipal Water Authority of Aliquippa, Pennsylvania. In early 2024, the Cyber Army of Russia Reborn claimed attacks on water facilities in the U.S. and Poland, including a breach in Muleshoe, Texas that dumped tens of thousands of gallons of water. In October 2024, American Water - the largest regulated water utility in the country, serving more than 14 million people across 14 states and 18 military installations - shut down computer systems after a cyberattack. Beijing's Volt Typhoon has spent years quietly pre-positioning inside U.S. critical-infrastructure networks, per CISA. And just weeks ago, the Iranian MOIS-linked Handala persona claimed to have compromised California Water Service - which serves roughly 2 million customers - leaking 5 gigabytes of data, then vowed via Tehran's Press TV to keep hitting U.S. industrial control systems.
Tyler Durden Sun, 08/02/2026 - 09:45