Connect with us

Crypto World

BitMEX, Hayes Sued Over 623 BTC Liquidation Claims as Exchange Winds Down

Published

on

BitMEX, Hayes Sued Over 623 BTC Liquidation Claims as Exchange Winds Down


BitMEX and its co-founders, including Arthur Hayes, were sued in a proposed class action accusing the exchange of keeping customer collateral seized in liquidations and running an internal trading desk with access to confidential position data. The complaint was filed July 23 in the Southern… Read the full story at The Defiant

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Ethereum price clears key averages in push toward $2,000

Published

on

Ethereum daily chart shows ETH holding above $1,900 and testing the 100-day moving average near $1,911.

Ethereum price traded near $1,918 on Friday after reclaiming $1,900, as spot ETF inflows and improving short-term momentum supported another test of overhead resistance.

Summary

  • Ethereum price held above $1,900, turning the psychological threshold into near-term support.
  • US spot Ethereum ETFs attracted $92.15 million in net inflows on Aug. 6.
  • The 4-hour RSI rose to 61.74, showing bullish momentum without reaching overbought territory.
  • Liquidity clusters near $1,925 and $1,950 could draw price higher, while $1,850 remains key support.

Ethereum price action today

According to data from crypto.news, Ethereum (ETH) price traded at $1,918.26 at the time of writing, up 0.74% during the daily session. The token reached an intraday high of $1,918.88 after opening near $1,904.

The move extended ETH’s recovery from the $1,850 area and kept its weekly gain above 4%. Buyers have repeatedly defended the $1,840–$1,850 region since the start of August, preventing a deeper correction toward the July lows.

Advertisement
Ethereum daily chart shows ETH holding above $1,900 and testing the 100-day moving average near $1,911.
Ethereum price daily chart — Aug. 7 | Source: crypto.news

Price has now moved above three closely watched daily averages. ETH is trading over its 20-day moving average at $1,895.45, its 100-day average at $1,911.42, and its 50-day average at $1,796.09.

That alignment improves the short-term outlook, but Ethereum remains below its 200-day moving average at $2,061.80. The gap shows that the latest recovery has not yet reversed the broader downtrend that began after ETH traded above $2,400 in April.

The daily Bull Bear Power reading has returned to positive territory at 32.07. The indicator suggests buyers have regained a modest advantage after bearish pressure briefly returned at the beginning of August.

ETF inflows and US jobs data support ETH

Renewed demand for US-listed spot Ethereum exchange-traded funds has provided one catalyst for the move.

Advertisement

The funds recorded about $92.15 million in net inflows on Aug. 6, equal to roughly 48,327 ETH at the reported market price. The latest intake followed net inflows of $60.86 million on Aug. 5, with BlackRock’s ETHA accounting for $50.34 million of that session’s total.

Cumulative net inflows into US spot Ethereum ETFs have now moved above $11.4 billion. The products give US investors regulated ETH exposure through conventional brokerage accounts, although their flows do not always produce an immediate or proportional price response.

A softer US employment reading also helped the wider risk-asset backdrop. Private employers added 44,000 jobs in July, below forecasts of about 70,000 and down from a revised 95,000 in June, according to ADP.

The weaker hiring figure pointed to some cooling in the labor market. However, annual pay still rose 4.4%, and jobless claims remained historically low, leaving uncertainty around the Federal Reserve’s next rate decision. Any renewed increase in rate-hike expectations could weigh on ETH and other risk assets.

Advertisement

Ethereum liquidation map points to $1,950

Ethereum’s 4-hour chart shows price moving above the Supertrend threshold near $1,907.42. Holding that level would preserve the immediate bullish structure and give buyers another opportunity to attack the recent highs.

Ethereum 4-hour chart shows ETH above $1,900 with RSI at 61.74 and Supertrend support near $1,851.
Ethereum price 4-hour chart — Aug. 7 | Source: crypto.news

The 4-hour Relative Strength Index stood at 61.74, above its signal average of 57.76. Momentum therefore favors buyers, but the reading remains below the overbought threshold of 70.

The 3-day liquidation heatmap shows a concentration of leveraged positions immediately above the market near $1,925. A larger liquidity band sits around $1,945–$1,955.

Ethereum 3-day liquidation heatmap shows major liquidity clusters near $1,950 and between $1,850 and $1,870.
Ethereum liquidation heatmap | Source: CoinGlass

These pools could act as short-term price magnets. A push through $1,925 may trigger forced buying from short sellers and accelerate a move toward $1,950.

Above that level, the psychological $2,000 mark becomes the next target. Ethereum would still need to overcome the daily 200-day average near $2,062 before the broader technical structure turns decisively bullish.

Liquidity is also building below the current price. The nearest downside zones appear around $1,890, $1,870 and $1,850–$1,860. Losing $1,900 could therefore expose ETH to a sweep of leveraged long positions in those areas.

Advertisement

The 4-hour Supertrend support near $1,850.62 provides the main bullish invalidation level. A sustained break below it would weaken the recovery and could open a move toward $1,800 or the 50-day average near $1,796.

Analysts see $2,000 as the next Ethereum test

Analyst Michaël van de Poppe said Ethereum could outperform Bitcoin if the broader market leader begins another upward move.

“Honestly, if BTC breaks upwards, I’d assume we’re seeing a significantly stronger breakout on ETH rather than Bitcoin.”

His chart placed a broader Ethereum target near $2,400, although ETH would first need to clear resistance around $2,000 and the 200-day moving average.

Analyst Ted Pillows also focused on the reclaimed psychological level and the potential for a short-term continuation.

Advertisement

“ETH is still holding above the $1,900 level. Clarity Act voting has been delayed, but still Ethereum looks good. If ETH manages to hold above this level, a rally to $2,000 could happen next.”

For now, $1,900 separates the bullish and bearish short-term scenarios. A daily close above $1,925 would strengthen the case for $1,950 and $2,000, while a reversal below $1,900 would shift attention back to $1,850.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Advertisement

Source link

Continue Reading

Crypto World

Crypto crime has moved beyond online hacks, Chainalysis says

Published

on

Crypto crime has moved beyond online hacks, Chainalysis says

Chainalysis has warned that cryptocurrency crime has increasingly extended into kidnappings, home invasions and other violent incidents as criminals pursue holders who can transfer digital assets immediately under coercion.

Summary

  • Chainalysis said violent attacks against crypto holders have become more common as criminals target self custody wallets and instantly transferable assets.
  • The report estimated more than $30 million has been stolen through successful physical attacks during the first half of 2026.
  • Investigators found attackers leave blockchain trails that help trace stolen funds even after violent thefts succeed.
  • France has recorded the highest number of publicly known crypto related violent incidents since 2023 as authorities expand organized crime investigations.
  • Family members have increasingly been targeted to pressure crypto holders into transferring digital assets.

According to the blockchain analytics firm’s latest report shared with crypto.news, cybercrime still accounts for most illicit crypto activity, including an estimated $3.4 billion stolen through hacks, $17 billion lost to scams and about $820 million linked to ransomware in 2025. 

At the same time, physical attacks have become more common because crypto holders often control large amounts of wealth through self-custody wallets without the institutional safeguards associated with traditional financial assets.

Advertisement

The report estimates that violent criminals have extracted more than $30 million from crypto holders during the first half of 2026 through successful kidnappings, hostage situations, and home invasions. If the current pace continues, 2026 would surpass the $58 million stolen during 2025, although the estimate only covers publicly reported incidents and likely understates the full scale of the problem.

Earlier this week, Galaxy Research estimated that confirmed losses from the Coldcard hardware wallet vulnerability had reached 1,596 Bitcoin across three attack waves, with a suspected fourth wave potentially lifting total losses to about 2,055 BTC if verified. 

While the Coldcard incident involved a software flaw rather than physical violence, it underscored the value of cryptocurrency that criminals continue targeting through both digital exploits and real-world attacks.

Chainalysis says on-chain trails still expose violent attackers

Although the number of attacks has increased, the report said criminals are succeeding less often. Only 12 of 46 documented violent theft attempts resulted in victims surrendering funds through late June, producing a 26% success rate compared with 49% in 2025 and 67% in 2024. 

Advertisement

When failed extortion attempts, blocked transfers and recovered assets are included, the value connected to violent incidents rises to roughly $107 million during the first half of 2026.

According to the report, every successful forced transfer also creates a blockchain record that investigators can examine. Analysts grouped attackers into three categories based on how they handled stolen assets after the theft.

The least experienced offenders typically sent funds directly to centralized exchanges, making compliance teams and law enforcement more likely to identify them. More capable operators used decentralized exchanges, bridges and intermediary wallets to complicate tracing before eventually cashing out.

Advertisement

The report identified a third category consisting of attackers who appeared connected to established criminal networks. 

In one investigated case, stolen funds passed through an instant exchange before reaching what analysts described as a suspected over-the-counter laundering service that had previous blockchain links to cartel-related laundering services, wallets associated with alleged cocaine trafficker Ryan Wedding, terrorist financing clusters and Southeast Asian money laundering networks. 

The report presented those links as blockchain exposure rather than proof that every connected entity participated in the original violent crime.

Home invasions have become more common

As investigators documented more incidents, the nature of the attacks also changed. Kidnappings continued to account for most documented wrench attacks, while home invasions climbed from 14% of incidents in 2025 to 37% through mid-2026. According to the report, criminals increasingly use homes because they can pressure victims in familiar surroundings without moving them elsewhere.

Advertisement

Regional patterns also differed. The United States remained an outlier for home invasions, while France experienced a much higher share of kidnapping attempts than other countries tracked in the dataset.

France’s attack surge has coincided with alleged data exposure

France has recorded the highest number of publicly known violent crypto incidents since 2023, with 30 cases reported through mid-2026 after recording 19 during all of 2025, according to the report. Interior Minister Laurent Nuñez has said authorities documented more than 70 crypto-related violent incidents and announced a rapid identification and alert system for people considered at risk.

The report pointed to an alleged 2024 theft and sale of tax records belonging to high-net-worth crypto holders as the most likely explanation for the rise in French cases. According to the report, the dossiers allegedly contained names, addresses, holdings, phone numbers and tax information that could help criminals identify potential victims. 

It also cited Waltio’s January 2026 disclosure that unauthorized access affected data connected to about 50,000 users, while stopping short of establishing a direct causal link between the breach and individual attacks.

Advertisement

French authorities have treated the attacks as organized crime investigations. By mid-2026, the crackdown had resulted in around 200 arrests, 88 indictments, 75 suspects held in pretrial detention and more than a dozen investigations, according to the report.

Family members have increasingly become leverage

Beyond targeting crypto holders themselves, attackers have increasingly turned to relatives and acquaintances to force victims into handing over digital assets. According to the report, family members or close relations accounted for roughly 25% to 30% of documented incidents by early 2026 after being almost absent from recorded cases in 2021. In France, more than 40% of incidents involved someone connected to the holder rather than the holder directly.

The report also found that most victims were local residents instead of visitors. Known residency data showed locals accounted for all documented victims in Sweden, 93% in France, 82% in Brazil and 77% in the United States, a pattern that the firm said points to advance reconnaissance using leaked information, blockchain activity, social media or insider knowledge.

Advertisement

Source link

Continue Reading

Crypto World

Spindex’s Real-Time Data Pipeline Surpasses 150 Million Tracked Gaming Events

Published

on

[PRESS RELEASE – Los Angeles, United States, August 7th, 2026]

Spindex, a real-time data analytics platform for the iGaming industry, has surpassed 150 million tracked gaming events across its monitoring infrastructure, ingesting more than 2,000 new data points per minute from over 700 slot titles. The milestone highlights the scale of live data now flowing through independent, third-party tracking layers built on top of the online gaming industry — infrastructure that exists separately from any single operator’s own reporting.

Built for Scale: A High-Throughput Data Pipeline

Spindex’s infrastructure ingests activity directly from a network of major online gaming platforms, including Stake, Stake.us, Rainbet, Roobet, Gamdom, Shuffle, and Duelbits, among others. Rather than depending on any one platform’s self-reported numbers, every event is captured independently and fed into public dashboards, giving a continuously updating, cross-platform view of activity across the wider industry.

Advertisement

The platform maintains dedicated data suites for its most closely monitored sources — Stake, Stake.us, Rainbet, and Roobet — alongside broader ingestion from the wider market.

Turning Raw Activity Into Rankings

Rather than surfacing whatever a platform chooses to promote, Spindex’s Hot Slots rankings use actual tracked activity volume over rolling 7-day and 30-day windows to identify which games are trending up or down in real usage. Each ranked title is paired with live stats — total tracked events, average and maximum hit multiplier, and win rate — computed directly from the incoming data stream.

Spindex also runs a live “Big Wins” feed, surfacing notable outcomes (20x multiplier and $100 or higher) as they occur across its monitored network, alongside independent verification tools that let users check the cryptographic fairness of individual outcomes for themselves.

Advertisement

Beyond Data: A Free Content Library

Alongside its live data products, Spindex offers a free library of more than 7,000 playable slot titles — sourced from studios including Pragmatic Play, Hacksaw Gaming, and NoLimit City — that users can try without signing up or wagering real funds. The platform also offers free utilities such as VIP-tier calculators, bonus estimators, and sports betting calculators.

“We built Spindex because there wasn’t an independent layer of data sitting on top of this industry,” Josh Newman, CEO of Spindex said. “Crossing 150 million tracked events is a sign that people want a data source that isn’t controlled by the platforms it’s reporting on.”

Spindex plans to continue expanding its data coverage and tracked title library throughout the rest of 2026, alongside further development of its analytics and verification tooling.

About Spindex

Advertisement

Spindex is a real-time data analytics platform for the iGaming industry. The platform independently tracks activity across major online gaming platforms to surface trending-title rankings, live big-win activity, and per-title performance stats, and pairs that data with a free library of 7,000+ playable slot titles and a suite of free utilities, including VIP calculators, bonus estimators, and outcome-verification tools. More information is available at spindex.net.

The post Spindex’s Real-Time Data Pipeline Surpasses 150 Million Tracked Gaming Events appeared first on CryptoPotato.

Source link

Advertisement
Continue Reading

Crypto World

Bitcoin price stalls below $65K despite ETF inflows

Published

on

U.S. spot Bitcoin ETFs, source: Farside

Bitcoin held near $64,206 on Aug. 7, according to crypto.news market data, slipping 0.5% over 24 hours and 0.6% over seven days. 

Summary

  • Bitcoin trades near $64K, down 0.5% daily, while four straight ETF inflow sessions support demand.
  • U.S. spot Bitcoin ETFs attracted $137.6 million Thursday, lifting four-day net inflows to $763.6 million.
  • Senate leaders delayed the CLARITY Act vote until September, removing an expected August regulatory catalyst.
  • Bitcoin derivatives open interest is rebuilding, but remains below levels seen near October’s price peak.
  • July employment data arrives Friday before inflation Wednesday, keeping Federal Reserve expectations central for markets.

The asset traded between $64,114 and $64,916, showing that the market remains compressed after failing to reclaim resistance above $66,000.

The price action comes as U.S. spot Bitcoin ETFs extend a four-session inflow streak, while the Senate delays the CLARITY Act vote until September and traders wait for fresh U.S. employment data. Those factors leave Bitcoin supported by institutional demand but without a breakout from its range.

Advertisement

Bitcoin ETF inflows continue supporting the $64K area

Farside’s recorded $137.6 million in net inflows into U.S. spot Bitcoin ETFs on Aug. 6. That followed $170.1 million on Aug. 3, $211.5 million on Aug. 4 and $244.4 million on Aug. 5, bringing the four-day total to about $763.6 million.

BlackRock’s IBIT led Thursday’s flows with $128.3 million, while Fidelity’s FBTC added $11.2 million. VanEck’s HODL recorded $32.8 million in outflows. The positive aggregate flow has provided a steady source of spot demand even though Bitcoin has not cleared nearby resistance.

U.S. spot Bitcoin ETFs, source: Farside
U.S. spot Bitcoin ETFs, source: Farside

As previously reported, renewed inflows have helped stabilize Bitcoin during weak trading periods. However, ETF buying does not guarantee immediate price appreciation when other holders sell into the same demand.

The $62,000 to $65,000 region has contained much of Bitcoin’s recent trading. Analyst Daan Crypto Trades said a move above $67,000 would make the structure more constructive, with $69,000 to $72,000 containing several higher-timeframe resistance levels. Until that breakout occurs, he described BTC as remaining in sideways trade.

Advertisement

CLARITY Act delay removes an August policy catalyst

The Senate will leave Washington without voting on the CLARITY Act before its August work period. Senate Majority Leader John Thune said the legislation would be queued when lawmakers return. The Senate lists Aug. 10 through Sept. 11 as a state work period.

The legislation would establish a federal digital asset market structure and clarify regulatory responsibilities between the SEC and CFTC. Earlier CLARITY Act showed that Republican leaders need Democratic support to overcome a filibuster. The often-cited 60-vote figure applies to cloture, rather than the simple-majority threshold normally required for final passage.

Advertisement

For BTC, the delay removes an expected August policy event but does not change the asset’s legal status. Market reaction also cannot be attributed solely to the bill because ETF flows, interest-rate expectations, positioning and broader risk appetite are moving simultaneously.

Derivatives leverage is rebuilding from lower levels

CryptoQuant analyst Amr Taha reported that Bitcoin open interest is recovering across Binance, Bybit and Gate.io. Binance open interest reached about $3.9 billion on Aug. 7, while Bybit stood near $2.14 billion and Gate.io around $2.09 billion. Deribit diverged, falling to roughly $725 million.

Combined open interest across those four exchanges was about $8.86 billion, according to Taha, nearly 54% below the $19.21 billion recorded around BTC’s October 2025 peak. That suggests leverage is returning gradually rather than approaching the crowded conditions seen near the previous high.

Ali Charts offered a bullish long-term reading, pointing to a TD Sequential buy signal on BTC’s monthly chart, proximity to the 50-month simple moving average and a Chande Momentum Oscillator reading near negative 71. Those signals are technical interpretations, not confirmation that a new bull market has begun.

Advertisement

On the daily chart, BTC remains in a broader downtrend but has stabilized above the $60,000 to $62,000 support zone. Accumulation and Distribution has recovered since late June, while Bull Bear Power is slightly positive. A sustained move through $66,000 to $70,000 would provide stronger evidence of a trend change.

Bitcoin price chart, source: crypto.new
Bitcoin price chart, source: crypto.new

U.S. jobs and inflation data become the next test

The Fed’s kept its target rate at 3.50% to 3.75% on July 29 in a 9-3 vote. Beth Hammack, Neel Kashkari and Lorie Logan dissented because they preferred a 25-basis-point increase.

The next immediate catalyst is the July employment report, for Aug. 7 at 8:30 a.m. ET. July CPI follows on Aug. 12. Stronger employment or persistent inflation could reinforce expectations for tighter monetary policy, while softer data could reduce pressure on risk assets.

Advertisement

The crypto enters the data window with conflicting signals. ETF demand remains positive and leverage is rebuilding from depressed levels, while price is still below the resistance needed to confirm a stronger recovery. Holding $62,000 to $64,000 keeps current stabilization intact, but traders are likely to look toward $67,000 and then $69,000 to $72,000 for clearer evidence that buyers have regained control.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

US Court Upholds Bybit’s Request to Trace Funds From $1.5B Hack

Published

on

Crypto Breaking News

Newly unsealed court records show a US judge granted Bybit expedited discovery in the exchange’s ongoing legal push to identify assets tied to a $1.5 billion North Korea-linked attack. The ruling is aimed at helping Bybit move from broad allegations toward practical, court-backed tracing—an approach that can matter when large portions of stolen crypto have already been obfuscated.

According to the filings, Bybit brought the case under seal on June 18, naming North Korea, the Reconnaissance General Bureau, the Lazarus Group and 20 unnamed defendants. The court granted the expedited discovery request the following day, giving Bybit a faster route to request information that could pinpoint alleged intermediaries and determine what—if any—stolen funds remain recoverable through identifiable on-chain or account-linked activity.

Key takeaways

  • Unsealed records confirm a federal judge granted Bybit expedited discovery tied to the June 18 lawsuit over the $1.5 billion 2025 North Korea-linked hack.
  • Bybit claims 90.2% of stolen assets became untraceable after moves through mixers, cross-chain bridges, and OTC trading channels.
  • The company reports 9.8% of the funds were traceable to identifiable wallets, including 5.3% (about $75.5 million) that were frozen or recovered.
  • Bybit obtained a temporary restraining order that the court renewed and partially supported with a preliminary injunction decision later in July.
  • The complaint seeks relief that includes compensatory, punitive and treble damages under the US RICO statute.

Expedited discovery: turning allegations into targeted asset recovery

The court documents describe Bybit’s strategy as an attempt to identify alleged actors and intermediaries that may have handled stolen funds after the hack. Expedited discovery typically shortens the timeline for obtaining information from counterparties or other relevant parties—particularly important in high-stakes crypto cases where defendants may move assets quickly or hide trail details behind complex transaction structures.

In the complaint, Bybit alleges that some traceable assets ended up on or through platforms that operate in the United States or maintain US-based infrastructure. Bybit sought account-holder identities, balances and transaction histories, arguing that certain platforms indicated they would cooperate once a court order was issued.

From an investor and market-structure standpoint, this matters because court-ordered discovery can bridge a gap that often exists in crypto investigations: even when chain analytics suggest where funds may have gone, legal access to counterparties’ records is often what enables meaningful recovery efforts.

Advertisement

How much of the stolen crypto was still traceable?

Bybit’s filing includes a key metric about how the attackers allegedly laundered the stolen assets. As of the June 18 submission, the exchange said 90.2% of the funds had become untraceable after passing through mixers, cross-chain bridges, and over-the-counter dealers. The remaining 9.8% it said could be tied to identifiable wallets.

Within that smaller traceable portion, Bybit reported that 5.3% of the total theft—about $75.5 million—had been frozen or recovered. The rest of the traceable amount was described as still linked to identifiable wallets, implying it may be recoverable if the legal process can connect those wallets to accountable parties.

Bybit’s numbers also suggest a significant shift compared with more than a year earlier. The exchange previously reported that 68.57% of the stolen funds remained traceable, a claim attributed to Bybit CEO Ben Zhou at the time. In this newer filing, the traceability figure has dropped materially, underscoring how quickly stolen crypto can become harder to recover as it moves through layered obfuscation techniques.

Restraining orders and injunction steps in July

Alongside expedited discovery, Bybit secured legal measures designed to prevent alleged defendants from moving certain traceable assets while the case progresses. The company obtained a temporary restraining order on June 19 against the unnamed defendants, aimed at halting transfers of specific traceable funds.

Advertisement

That restraining order was renewed on July 16. The court also partially granted Bybit’s request for a preliminary injunction on July 30. While the records indicate that some exhibits and related materials remain sealed, the sequence reflects a court willingness to support Bybit’s attempt to preserve at least part of the identifiable asset set while discovery and claims move forward.

Background of the Feb. 21, 2025 hack and FBI attribution

The underlying incident dates to Feb. 21, 2025. Bybit said the attackers compromised the Safe Wallet infrastructure after gaining access through compromised credentials associated with a Safe developer. Forensic investigations cited in earlier coverage described malicious code being injected into Safe’s cloud infrastructure.

The FBI attributed the theft to North Korea on Feb. 26, 2025, according to its public notice on the incident. That attribution has been central to how regulatory and law enforcement narratives have framed the event, and it helps explain why a civil lawsuit targeting North Korea-linked entities would be pursued alongside asset-tracing and recovery measures.

In the complaint, Bybit seeks recovery related to approximately $1.5 billion, including compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act. In practical terms, the damages claim indicates Bybit is not only seeking to preserve and identify assets but also to establish broader liability if the court finds actionable wrongdoing and causation.

Advertisement

What to watch next

The immediate question is whether expedited discovery turns the “traceable” wallet subset into actionable, court-backed targets—especially given Bybit’s claim that most of the stolen crypto has already become untraceable. Readers should watch how the case develops as sealed exhibits are gradually revealed and as the court’s preliminary injunction posture evolves, because those steps can determine how much of the remaining identifiable funds can realistically be recovered.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Crypto World

Coldcard temporarily halts customer data deletion over July exploit

Published

on

Coldcard MK5 ships with 5 major wallet upgrades

Coldcard has temporarily suspended its automatic customer data deletion process because of legal obligations tied to the security incident disclosed on July 30, preserving records that would otherwise have been erased after 120 days.

Summary

  • Coldcard has suspended its automatic customer data deletion policy because of legal obligations tied to its July security incident.
  • Customers can still request their records be handled under the company’s original data retention policy by contacting support.
  • The policy change follows a wallet flaw that Galaxy Research linked to 1,596 confirmed stolen Bitcoin across three attack waves.
  • Coldcard said retained customer records will remain restricted to authorized personnel and used only to meet legal requirements.

Coldcard announced the policy change in a post on X, saying it must retain customer records that could be relevant to ongoing and anticipated legal proceedings arising from the wallet security incident.

The company said the temporary measure overrides its published data-retention schedule but added that customers who do not want their information preserved under the legal protocol can still request the application of its existing retention policy by contacting customer support.

Coldcard has paused automatic data deletion

Explaining the change, the company said its standard practice has been to “automatically blank customer records after 120 days,” keeping only customers’ email addresses and country of residence. It also noted that buyers have long been able to request accelerated deletion after their orders were delivered.

Advertisement

The company said the July 30 security incident has changed those procedures because it is now legally required to preserve records that may become relevant during litigation.

As a result, customer records that were scheduled for deletion under the normal 120-day policy will now be retained until further notice.

Coldcard said customers who prefer not to have their records included in that legal preservation process can contact its support team to request that their information be handled under the original retention policy instead.

Advertisement

Addressing privacy concerns, the company wrote that it understood the decision “is a departure from our published practices” and acknowledged that customers value the privacy protections it previously committed to maintaining.

It added that retained customer information will remain securely stored, access will be limited to authorized personnel, and the data “will not be used for any purpose other than compliance with legal obligations.” 

According to the company, the previous automated deletion system will return once legal requirements no longer require record preservation.

Security incident has already triggered investigations

The revised retention policy follows one of the largest known hardware wallet security incidents affecting Bitcoin users.

Advertisement

As previously reported by Galaxy Research, attackers have stolen 1,596 BTC from about 7,300 wallet addresses across three confirmed attack waves linked to the Coldcard vulnerability. The research firm said a fourth suspected wave could increase total losses to about 2,055 BTC, although it has not yet received enough victim confirmations to classify those additional thefts as confirmed.

Galaxy has distinguished its confirmed figures from blockchain-only observations. While earlier on-chain analysis identified approximately 1,815.75 BTC moving across four observed waves, the firm’s latest estimate is based on confirmed reports from affected wallet owners.

Separately, Galaxy’s head of firmwide research, Alex Thorn, said blockchain activity indicates the suspected fourth wave was “substantially comprised of” a single attacker. Even so, the firm has continued treating the additional addresses as unconfirmed until more victims come forward.

Investigators have also shared confirmed attacker and victim addresses with U.S. federal law enforcement agencies, cryptocurrency exchanges and cyber-investigation groups so the stolen funds can be monitored if they move through regulated platforms.

Advertisement

Firmware flaw reduced wallet seed randomness

According to Coinkite’s earlier technical disclosure, the vulnerability originated in March 2021 during the integration of a new cryptographic library into Coldcard firmware.

Instead of generating wallet seeds through the intended hardware-backed random-number generator, affected firmware accidentally relied on MicroPython’s deterministic pseudo-random generator during wallet creation.

Block’s Bitcoin engineering and security team independently reviewed the firmware and reached the same conclusion, stating that vulnerable versions called the deterministic MicroPython fallback instead of the STM32 hardware random-number generator while generating seed phrases.

Coinkite estimated that affected Mk2 and Mk3 devices provided roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q devices generated about 72 bits rather than the intended 128 bits.

Advertisement

Because of that weakness, attackers were able to reproduce possible wallet seeds offline, derive Bitcoin addresses from those seeds and compare them with publicly visible blockchain data. The attack did not require physical possession of affected devices, users’ PINs or any weakness in the Bitcoin protocol itself.

Most stolen Bitcoin remains untouched

Although the investigation has expanded, most of the stolen cryptocurrency has not yet moved.

Galaxy previously said about 90% of the stolen Bitcoin remained untouched, giving investigators additional time to monitor attacker-controlled addresses. Later on-chain analysis found that the largest identified attacker still holds 1,159 BTC spread across seven addresses without moving the funds.

Separate blockchain monitoring has identified activity from another attacker, however. According to analysts tracking the transactions, 64 BTC entered a transaction flow associated with a cryptocurrency mixer. Roughly 10 BTC was initially mixed, while approximately 54 BTC returned as change before being split into outputs of about 7 BTC each.

Advertisement

Researchers said the activity appears unrelated to the seven-address cluster holding the 1,159 BTC, indicating that multiple attackers likely exploited the same wallet weakness.

At the same time, Coinkite has continued urging affected users to replace vulnerable wallet seeds even after installing updated firmware. The company has already released patched firmware for all affected Coldcard models and destroyed remaining inventory containing vulnerable versions.

According to Coinkite, firmware updates protect only wallets created after the fix. Users whose seed phrases were generated with vulnerable firmware are advised to create entirely new seeds, verify a receiving address, send a small test transaction and move the remaining balance only after confirming the transfer works. Existing wallets created with at least 50 fair private dice rolls are not affected by this specific random-number-generation flaw.

Advertisement

Source link

Continue Reading

Crypto World

Uniswap Adds Permissioned Pools to Bring Regulated Assets to v4

Published

on

Uniswap Adds Permissioned Pools to Bring Regulated Assets to v4


Uniswap introduced Permissioned Pools, a new hook standard for its v4 protocol that lets regulated assets trade through automated market makers while enforcing compliance rules directly onchain, the company said in a blog post published Thursday. Rather than relying on a frontend gate or an… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

Ondo's Oasis Pro Markets Cleared to Offer Tokenized Stocks in US

Published

on

Ondo's Oasis Pro Markets Cleared to Offer Tokenized Stocks in US


Ondo Finance said its broker-dealer subsidiary, Oasis Pro Markets, secured regulatory authorization to offer tokenized equities and funds to U.S. investors under SEC and FINRA oversight, according to a post from the company's official X account on Thursday. Ondo described Oasis Pro Markets as an… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

Bitcoin Telegram accounts targeted by North Korean hackers

Published

on

Telegram accounts under attack, source: X

Bitcoiners are facing a renewed warning over an active social-engineering campaign that hijacks trusted Telegram accounts and funnels cryptocurrency professionals into fake Zoom or Microsoft Teams meetings. 

Summary

  • BlueNoroff is hijacking Telegram accounts and using fake Zoom or Teams meetings against crypto professionals.
  • JUMPSEC found the phishing kit profiles cryptocurrency wallets before operators selectively deliver malware to victims.
  • Security Alliance attributed 164 blocked domains to UNC1069 between February and early April 2026 alone.
  • Mandiant observed compromised Telegram accounts, fake Zoom calls, ClickFix commands and malware targeting crypto organizations.
  • FBI guidance recommends independent identity verification and keeping wallet secrets off internet-connected devices whenever possible.

Lightning News raised the alarm on Aug. 7, citing recent accounts from Bitcoin community members. Independent security research confirms the core attack chain, though not every claim has been verified.

JUMPSEC said in July that it obtained source code from an active BlueNoroff phishing kit after exposed JavaScript source maps. The researchers found a victim-acquisition platform that abuses compromised Telegram contacts, profiles cryptocurrency wallets and delivers malware to selected targets on Windows and macOS systems. JUMPSEC said identified campaign infrastructure remained active as of July 22.

Advertisement
Telegram accounts under attack, source: X
Telegram accounts under attack, source: X

BlueNoroff turns trusted Telegram contacts into lures

The attack begins with trust rather than a blockchain vulnerability. JUMPSEC found operators using compromised Telegram accounts belonging to real industry contacts to invite targets to fake video meetings. Because messages arrive from genuine accounts and can reference existing relationships, sender recognition alone provides limited protection.

Google Mandiant independently documented a similar UNC1069 intrusion in February. A victim received messages from a compromised crypto executive’s Telegram account, scheduled a meeting and was redirected to a spoofed Zoom domain. The victim reported seeing what appeared to be an AI-generated video of another crypto executive during the staged call.

Attribution needs precision. Mandiant tracks the actor as UNC1069 and says it overlaps with BlueNoroff. U.S. Treasury has formally designated BlueNoroff, also known as APT38, as a North Korean state-sponsored group controlled by the Reconnaissance General Bureau. Security Alliance likewise attributes the fake-meeting campaign to UNC1069, or BlueNoroff.

Fake meetings push ClickFix commands and malware

JUMPSEC’s reconstructed kit shows a staged meeting interface asking for webcam access before an operator joins with prerecorded video. The victim then sees a supposed audio problem and a fake software update. The displayed troubleshooting text is deceptive: copying it places an attacker-controlled ClickFix command onto the clipboard.

Advertisement

On Windows, JUMPSEC observed PowerShell and VBScript components capable of disabling defenses, conducting reconnaissance and supporting follow-on access. On macOS, researchers found shell scripts and Mach-O payloads designed to steal credentials and other sensitive data. The kit also scans for browser wallet providers before malware delivery, helping operators identify valuable targets.

That means the claim that merely opening a meeting link automatically drains a wallet is too broad. In the documented chains, compromise requires another action, such as running a copied command or malicious update. However, once malware executes, Mandiant found tooling capable of stealing browser data, Keychain credentials and Telegram user data.

As previously reported, Martin Kuchař said his Telegram account was compromised and used in a similar attack. Earlier victim coverage also documented crypto executives being approached through trusted contacts before fake meeting prompts attempted to install malware.

Security researchers say the campaign remains broad

Security Alliance reported that it attributed 164 blocked domains to UNC1069 between Feb. 6 and April 7. Its advisory described multi-week social engineering through Telegram, LinkedIn and Slack before fraudulent Zoom or Teams links were delivered. JUMPSEC later expanded the infrastructure picture and said high- and medium-confidence infrastructure remained active in late July.

Advertisement

The FBI has warned separately that North Korean actors conduct highly tailored social engineering against cryptocurrency and DeFi employees. Its guidance specifically flags requests to execute code, install unfamiliar applications, run scripts to fix video calls or move conversations between communication platforms.

The FBI recommends verifying identities through an independent channel and keeping wallet credentials, seed phrases and private keys off internet-connected devices. Two-factor authentication remains useful, but infected devices can expose session data, so compromised sessions should also be revoked from a clean device.

What Bitcoin and crypto users should watch next

The most important correction to the Aug. 7 warning is that researchers have not established one universal method for the initial Telegram takeover. Claims that expired or temporary phone numbers are the main cause remain unverified in the material reviewed. Researchers confirm compromised accounts, but the takeover mechanism can vary.

In separate Telegram platform coverage, Apple briefly removed the messaging app from its App Store over a CSAM policy review before restoring it after Telegram removed the flagged content and banned the responsible user.

Advertisement

Users should treat unexpected meeting requests, domain changes, audio-fix prompts and requests to paste commands as high-risk signals. If suspicious code has already run, the FBI advises disconnecting the affected device from the internet while leaving it powered on for potential forensic recovery, then contacting incident-response specialists and law enforcement.

The campaign is therefore best described as an ongoing, North Korea-linked social-engineering operation targeting the human layer around crypto custody. Its effectiveness comes from exploiting trusted identities and familiar workplace tools, not from breaking Bitcoin itself.

Source link

Advertisement
Continue Reading

Crypto World

Bybit Wins Court Support to Trace $1.5B North Korea Hack Funds

Published

on

Bybit Wins Court Support to Trace $1.5B North Korea Hack Funds

United States court records unsealed on Thursday show that a federal judge backed crypto exchange Bybit’s effort to trace assets stolen in the $1.5 billion North Korea-linked hack by granting the company expedited discovery. 

According to the records,  Bybit filed the lawsuit under seal on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants. The court granted Bybit’s request for expedited discovery on June 19.

The discovery authority gives Bybit a practical route to identify alleged intermediaries and pursue a small portion of stolen assets that remains traceable, rather than relying solely on a judgment against North Korea. 

In its complaint, Bybit alleged that some traceable assets reached exchanges operating or maintaining infrastructure in the US. The company sought account-holder identities, balances and transaction histories, saying certain platforms had indicated they would cooperate after receiving a court order.

Advertisement

Bybit says 90% of stolen funds became untraceable

Bybit also obtained a temporary restraining order on June 19 preventing the unidentified defendants from transferring certain traceable assets. The court renewed the order on July 16 and partially granted Bybit’s request for a preliminary injunction on July 30. Some exhibits and other records remain sealed.

As of the June 18 filing, Bybit said 90.2% of the stolen assets had become untraceable after passing through mixers, cross-chain bridges and over-the-counter dealers. The remaining 9.8% had been traced to identifiable wallets, including 5.3% of the total, about $75.5 million, that had been frozen or recovered.

The figures mark a sharp drop from more than a year ago, when Bybit CEO Ben Zhou said at the time that 68.57% of the funds remained traceable

Related: Bybit made ‘slow but steady comeback’ in 2025 after massive hack: CoinGecko

Advertisement

The hack occured on Feb. 21, 2025, after attackers compromised Safe Wallet’s infrastructure. Forensic investigators said compromised credentials belonging to a Safe developer allowed the attackers to inject malicious code into its cloud infrastructure. The FBI attributed the theft to North Korea on Feb. 26, 2025. 

The lawsuit shows that Bybit is seeking the return of the stolen assets, approximately $1.5 billion in compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act.

Magazine: 10 weirdest things ever tokenized… including farts

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025