Connect with us

Crypto World

Coldcard Flaw Exposes Hardware Wallet Testing Blind Spot: Kraken

Published

on

Coldcard Flaw Exposes Hardware Wallet Testing Blind Spot: Kraken

Coldcard’s five-year seed-generation flaw has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco. 

In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware. 

“Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco. 

His comments follow an ongoing attack that is believed to exploit weak seed phrases generated by affected Coldcard devices. As of Sunday, over 4,500 addresses have been impacted, draining nearly $90 million in Bitcoin

Advertisement

Coldcard RNG flaw remained undetected for five years

On Thursday, Coinkite disclosed a software flaw that has existed since March 2021, when Coldcard changed its seed-generation process as it integrated a new cryptographic library. 

The migration inadvertently routed wallet creation to a weaker MicroPython generator that existed in the codebase, rather than Coldcard’s intended true random number generator (TRNG). 

“The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base,” Coinkite said in its postmortem. “At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.”

The presence of the intended random number generator allowed the vulnerability to slip through undetected. Code reviews would confirm the existence and functioning of Coldcard’s TRNG code, but there was no check to ensure this was the RNG actually being called. 

Advertisement

Such checks are already standard across the rest of the security industry, said Percoco, referencing NIST SP 800-90B, a US government standard specifying requirements for designing, testing and validating physical true random number generators for cryptographic security and BSI AIS-31, a similar standard created by the German Federal Office for Information Security.

“Hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls,” he said. 

“The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception,” said Percoco. 

Related: Suspected 4th Coldcard attack wave sweeps 389 Bitcoin: Galaxy’s Thorn

Advertisement

Coldcard said Sunday it has halted all device shipments since confirming the vulnerability on Thursday, and has destroyed all remaining units at its facilities containing the affected firmware

However, Coinkite has advised users with affected devices not to dispose of them as “it may become essential if funds are recovered.”

“Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.” 

Related: Coldcard exploit sparks Bitcoin flight, ‘bullish’ crypto consolidation: Hodler’s Digest, August 2

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Bitcoin Is Now Calmer Than South Korea’s AI-Driven Stock Market

Published

on

Sk Hynix has seen a massive rally this year, but has also fallen over 20% in the last month alone.

Bitcoin (BTC) posted lower return volatility than South Korea’s benchmark stock index this year, Bloomberg data shows. A national stock gauge just out-swung crypto’s most-watched asset.

By comparison, the KOSPI’s daily returns swung 63% from their average pace this year. Bitcoin’s swung just 48%. Two chipmakers integral to the South Korean market are driving the gap.

Two Stocks Steer an Entire Index

Samsung Electronics and SK Hynix supply the memory chips powering the AI boom. Their shares have surged so fast that the pair now make up more than half the KOSPI’s weight. Listed affiliates push that share even higher.

Sk Hynix has seen a massive rally this year, but has also fallen over 20% in the last month alone.
Sk Hynix has seen a massive rally this year, but has also fallen over 20% in the last month alone. Image Source: Trading View

That concentration turns Korea’s benchmark into a leveraged AI bet. In turn, it ties the market’s mood to Wall Street sentiment. When the KOSPI closed at a record high in June, more than 650 of its 831 stocks fell, Bloomberg reported.

SK Hynix later lost 27% of its value over three trading days amid concerns about data center spending. It then jumped by Korea’s 30% daily limit once sentiment reversed. That mirrors an earlier AI memory stock selloff that hit the chipmaker this month.

Advertisement

Retail Leverage Fuels the Swings

Individual investors hold most of the leveraged exchange-traded funds (ETFs) that track Samsung and SK Hynix. Those funds amplified the swings further. At their peak, the ETFs and underlying stocks made up more than 70% of daily trading value. Korea’s stock market totals $3.4 trillion.

Meanwhile, the volatility forced the Korea Exchange to halt trading nine times this year. That compares with just once in 2024. That said, the pace follows a historic stock market crash that already ranks among Korea’s worst on record.

Finance Minister Koo Yun Cheol acknowledged regulators approved the leveraged products too quickly. Officials have since pledged exposure caps and higher trading costs to curb retail risk.

Bitcoin’s Year Hasn’t Been Calm, Just Steadier

Bitcoin opened 2026 near $88,000 and now trades around $63,000, a decline of roughly 29% year to date. Measured against its October 2025 all-time high of $126,000, the drop widens to nearly 50%.

Advertisement

The slide has not been a single sharp shock. Bitcoin fell to lows near $60,000 in February, recovered briefly, then broke down again to roughly $57,000 in June. Traders have tied the pressure to slowing ETF inflows and capital rotating into AI-linked stocks instead.

Bitcoin’s price has generally trended downward this past year. Image Source: BeInCrypto

That grinding, one-directional decline is likely why Bitcoin’s volatility reading looks tame next to the KOSPI’s. Bloomberg’s measure captures how sharply daily returns swing from their own average, not the size of the overall move.

A steady downward drift can produce a lower reading than a market that lurches both up and down, even when the total loss is larger.

Crypto audiences usually treat Bitcoin as the erratic asset. Whether Korea’s AI rally cools before its leverage does may decide which market earns that reputation next.

The post Bitcoin Is Now Calmer Than South Korea’s AI-Driven Stock Market appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Crypto World

Morgan Stanley Upgrades South Korea Stocks After 30% KOSPI Crash

Published

on

KOSPI Index Performance

South Korea’s “leverage washout” has created a fresh entry point into the AI trade, according to Morgan Stanley, which lifted its rating on the country’s equities to overweight. The bank now sees the KOSPI climbing 36% to its 9,000 target.

Strategists led by Daniel K Blake described the selloff as mainly technical. The bank previously rated the country as an equal weight.

Samsung and SK Hynix Underpin Morgan Stanley’s KOSPI Call

The KOSPI has exhibited notable volatility. The index tumbled more than 30% from its June peak. A boom in single-stock leveraged exchange-traded funds and concentrated index weightings deepened the rout.  

However, according to the analysts,

Advertisement

“We are past the midpoint of unwinding leveraged ETFs, hedge fund leverage, and retail margin.”

Morgan Stanley sees the index trading in a near-term range of 5,500 to 10,500. It expects Samsung Electronics and SK Hynix to provide valuation support, with tailwinds for industrials, defense, and financials.

The bank also upgraded Thai equities to overweight, citing cheap valuations, AI capex, and energy security themes. Meanwhile, it cut Australia to underweight, seeing limited upside after rate hikes and property tax reforms.

Follow us on X to get the latest news as it happens

AI Stocks Whipsaw as KOSPI Extends Losses

Meanwhile, this comes as Korean stocks swing down again. The KOSPI posted a sharp 18% rally on Friday before reversing on Monday.

Advertisement

At press time on Monday, the KOSPI traded at 6,304.80, down 4.41%, or 290.65 points, from Friday’s close of 6,595.45. Samsung Electronics fell 7.43% to 243,000 won, while SK Hynix dropped 7.51% to 1,589,000 won.

KOSPI Index Performance
KOSPI Index Performance. Source: Google Finance

The weakness spread to Japan. The Nikkei 225 slipped 2.09% to 63,018.33, with chip equipment makers Advantest and Tokyo Electron down 2.86% and 2.34%.

However, US stock futures moved in the opposite direction. They rose modestly after President Donald Trump said he had canceled planned strikes on Iran.

Whether the deleveraging Morgan Stanley describes has truly run its course may become clearer in the coming weeks.

Advertisement

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

The post Morgan Stanley Upgrades South Korea Stocks After 30% KOSPI Crash appeared first on BeInCrypto.

Source link

Advertisement
Continue Reading

Crypto World

Here’s why Michael Saylor’s Strategy (MSTR) is tracking BTC’s 200-week moving average

Published

on

Here's why Michael Saylor’s Strategy (MSTR) is tracking BTC's 200-week moving average

If you’ve been tracking crypto markets, you’ve likely seen analysts flag bitcoin’s 200-week moving average (200W MA) as a key inflection line where the broader trend can turn decisively higher. This line represents bitcoin’s average closing price over roughly four years.

Strategy is now tracking the same indicator, along with bitcoin’s premium (or discount) to that average. The firm’s Founder, Michael Saylor, announced it on X on Sunday, reinforcing the long-term average as a pivotal level for traders and investors alike.

“We’re now tracking Bitcoin’s 200-week moving average and its premium to that level on http://Strategy.com. Since the 200W MA became available, Bitcoin has traded above it 92% of the time. Today, it sits almost exactly on the line,” Saylor said Sunday on X.

However, in the hours since the post, prices have come under pressure, likely over concerns about a delay in the passage of the long-awaited Clarity Act, which is expected to unlock a significant institutional bid for digital assets. According to reports, the Senate did not list the Clarity Act in Monday’s agenda.

Advertisement

Source link

Continue Reading

Crypto World

Weak June Jobs Data Lifted Bitcoin to $62,000. Will Friday Send BTC Tumbling?

Published

on

Weak June Jobs Data Lifted Bitcoin to $62,000. Will Friday Send BTC Tumbling?

Bitcoin’s last brush with a nonfarm payrolls report ended in a rally. Friday’s edition of the same report may not treat traders as kindly.

Back on July 2, June’s jobs data missed forecasts badly. The US economy added just 57,000 payrolls, far below the roughly 115,000 economists expected. Bitcoin jumped 4% to near $62,000 that day, then kept climbing toward $64,000 over the following weekend as traders bet the miss would keep the Federal Reserve from hiking rates.

Why This Time Looks Different

Friday’s July payrolls report carries a much higher bar. Economists expect payrolls to rise by roughly 85,000 to 88,000, nearly double June’s print, according to a Bloomberg survey of forecasters. Employers likely kept hiring at a steady pace in July even as geopolitical tension and elevated inflation weighed on the broader outlook.

Bitcoin has faced some volatility this week, but the last payroll report helped push things in a positive direction. Image Source: BeInCrypto

A beat would argue against any rate cut. Fed officials have already floated another hike, and three policymakers dissented in favor of one at last week’s meeting. That combination puts more weight on Friday’s print than markets have placed on a single jobs report in months.

Bitcoin has already felt that pressure. The asset slipped roughly 3% on July 31 and traded near $63,080. Thirty-year Treasury yields climbed to their highest level since 2007 that same week, a sign bond markets are pricing in tighter policy, not easier.

Advertisement

What Would Change the Outcome

The mechanism cuts both ways. A weak print, like June’s, would revive rate-cut bets and likely lift Bitcoin the way it did last time. That June report added just 57,000 jobs versus forecasts near 110,000, and Bitcoin rose as rate-cut bets built back up.

A hot print would harden the case for a hike, and strong wage growth would only add to that pressure. Average hourly earnings carry extra weight this cycle, since persistent wage growth feeds the inflation the Fed is still fighting.

Friday’s report, due August 7, lands five weeks before the Fed’s September 16 meeting. That gives policymakers time to weigh it alongside the August 12 inflation data before they decide.

Friday’s data, more than any headline this week, will likely decide which direction that base case breaks.

Advertisement

The post Weak June Jobs Data Lifted Bitcoin to $62,000. Will Friday Send BTC Tumbling? appeared first on BeInCrypto.

Source link

Continue Reading

Crypto World

BitGo CEO puts 100 BTC behind Claude challenge

Published

on

BTC breaks $80k for the first time since January as Fox DeFi explains the capital driving the rally

BitGo CEO Mike Belshe challenged Anthropic’s Claude models on Aug. 1 by publishing a Bitcoin address holding 100 BTC and inviting the AI system to move the funds. 

Summary

  • 100 BTC remained in the published address after Mike Belshe challenged Claude to move it.
  • Three Claude models accessed real systems after evaluation environments mistakenly retained internet connectivity during tests.
  • BitGo says its Bitcoin multisignature wallets require two of three keys to authorize transactions onchain.

BitGo’s official website identifies Belshe as its co-founder and chief executive.

Belshe framed the wager as a response to Anthropic’s July 30 disclosure that Claude models accessed three real organizations during cybersecurity evaluations. He wrote that there had been “enough with the ‘we created a hacking monster’ games” and called for a real-world demonstration.

Advertisement

BitGo’s 100 BTC wallet remains untouched

The address received 100 BTC on July 31, according to publicly indexed blockchain reports. On-chain checks cited through Aug. 2 showed the full balance remained at the address with no outgoing transaction.

The absence of movement does not establish that Claude tried and failed. Belshe’s post did not describe an evaluation setup, grant access to BitGo systems or identify which Claude model should participate. It instead created a public, observable target whose balance can be monitored through the Bitcoin network.

Advertisement

Meanwhile, Anthropic said it found three incidents after reviewing 141,006 evaluation runs. The cases involved Claude Opus 4.7, Mythos 5 and an internal research model. A misunderstanding with evaluation partner Irregular left test machines connected to the internet, even though prompts told the models they were inside sealed simulations.

The models then used basic techniques, including weak passwords and unauthenticated endpoints, against real infrastructure they treated as part of capture-the-flag exercises. Anthropic said the models did not deliberately escape or pursue independent goals. It described the episodes as closer to an “operational failure” than a model alignment failure. The models also lacked the standard classifiers and monitoring used in Anthropic’s publicly available products.

In the most serious case, Opus 4.7 obtained credentials and reached a database containing several hundred production records. Mythos 5 separately published a malicious package to the public PyPI registry. Anthropic said the package remained available for about one hour and ran on 15 real systems before its removal.

The Claude challenge is not a like-for-like test

Publishing a Bitcoin address does not provide the credentials needed to spend its funds. Bitcoin transactions require valid cryptographic signatures produced with the relevant private keys. BitGo’s technical documentation says its Bitcoin multisignature wallets generally require two of three independent keys to authorize a transaction.

Advertisement

Claude would therefore need access to a signing environment, key material or an exploitable operational weakness. The address alone supplies none of those. Moreover, the exact signing policy behind this particular unspent output cannot be confirmed from Belshe’s post alone, even though he identified it as a BitGo wallet.

That makes Belshe’s challenge a test of whether an AI-enabled attacker could breach BitGo’s wider controls, rather than whether Claude can derive private keys from public blockchain data. A controlled comparison would also require agreed rules, authorized access, activity logs and independent verification of any attempted attack.

As previously reported, BitGo has tested post-quantum MPC signing for institutional custody. In related coverage, crypto.news examined how Claude Mythos 5 could accelerate attacks against exposed keys, weak signing flows and misconfigured systems without creating a universal ability to defeat cryptography.

U.S. scrutiny now shifts toward testing controls

The dispute arrives as U.S. officials review how advanced AI systems should undergo cybersecurity testing. President Donald Trump directed advisers in June to develop a voluntary testing framework for leading models, according to Reuters. Anthropic’s disclosure may add pressure for clearer containment standards and incident reporting across AI laboratories and external evaluators.

Advertisement

Anthropic stopped its cyber evaluations on July 23, identified all three incidents the following day and notified affected organizations on July 27. It said METR would conduct an independent review and that it planned to release a redacted transcript of the malicious-package incident within one week. Irregular is conducting its own investigation.

Those disclosures, rather than movement from Belshe’s wallet, are the next formal checkpoints. Any transaction from the address would be visible onchain. However, investigators would still need to establish who authorized it, how the signing requirements were satisfied and whether a Claude model played any role.

Source link

Advertisement
Continue Reading

Crypto World

The ‘Huge’ Macro Week Is Here: Will This Data Finally Spark a Crypto Breakout?

Published

on

Bitcoin, the altcoins, and the broader financial markets face another eventful week, with geopolitical developments, key US labor data, major earnings reports, and fresh economic indicators all capable of influencing investor sentiment.

The cryptocurrency market is in a fragile place once again. The weekend moves on the war front in the Middle East did little to boost BTC and the alts higher, and Trump’s reassuring words about an upcoming deal for the Strait of Hormuz are taken with a grain of salt.

Key Events in Focus

The first market reaction was expected to be a larger one, after US President Donald Trump canceled the planned military strikes against Iran over the weekend. Moreover, he claimed on a couple of occasions that there’s a Hormuz deal in the making, but Iranian officials denied it.

Admittedly, the US stock futures markets indeed rose after Trump’s promises, while oil prices plunged. The impact in the crypto space, though, was limited to a brief surge from BTC to $63,500 yesterday, only to be halted and driven below $63,000 on Monday morning.

Advertisement

The next big thing in focus would be the manufacturing and labor data. The July ISM Manufacturing PMI, one of the first major indicators of the US economy’s health, will be announced later today. Tuesday will see the release of the June JOLTS Job Openings report, which, aligned with Wednesday’s ADP Nonfarm Employment Change, will provide a glimpse into employment conditions ahead of Friday’s official jobs report.

Friday’s July Nonfarm Payrolls report is considered one of the Fed’s most closely watched economic releases. A stronger labor market could reduce expectations for policy easing, and vice versa.

Earnings Season Is Here

Nearly 20% of S&P 500 companies are scheduled to report quarterly results this week, providing additional insight into corporate profitability and investor sentiment. Some of the most anticipated names this week are SpaceX and AMD on Tuesday, followed by SanDisk on Wednesday.

Although these companies do not have a direct connection to the crypto market (aside from SpaceX’s BTC holdings), strong earnings from major tech firms have frequently boosted appetite for higher-risk assets.

This week, described as ‘huge’ by the analysts at the Kobeissi Letter, combines geopolitical developments, labor-market data, manufacturing activity, and corporate earnings, and it comes shortly after the Fed delivered one of its most closely watched monetary policy decisions in years.

A slowing economy, paired with contained geopolitical risks, could benefit BTC and the rest of the market. However, stronger-than-expected data or another major escalation in the Middle East could push the market leader toward $60,000 again.

Advertisement

The post The ‘Huge’ Macro Week Is Here: Will This Data Finally Spark a Crypto Breakout? appeared first on CryptoPotato.

Source link

Continue Reading

Crypto World

Binance to delist 6 tokens on Aug. 17

Published

on

Binance to delist 6 tokens on Aug. 17

Binance will remove Across Protocol, Hashflow, PIVX, Vulcan Forged PYR, Vanar and Viction from spot trading on Aug. 17, 2026, at 03:00 UTC after completing its latest asset review.

Summary

  • Six tokens will leave Binance spot trading on August 17 after the exchange’s periodic review.
  • Futures positions will settle August 7, while token withdrawals remain available through October 17, 2026.
  • Binance will not support VANRY’s Base migration, requiring holders to use Vanar’s migration portal themselves.

The exchange said every spot pair tied to ACX, HFT, PIVX, PYR, VANRY and VIC will close. Outstanding spot orders will be canceled. Binance did not identify a separate reason for each asset. Instead, it cited its broader review framework, which covers liquidity, development activity, network safety, team conduct, transparency, tokenomics and regulatory changes.

Binance delisting begins with an Aug. 7 futures cutoff

The first major deadline arrives before the spot removal. The company Futures will prevent users from opening new positions at 08:30 UTC on Aug. 7. It will close and automatically settle remaining contracts at 09:00 UTC. The exchange may also change leverage, margin tiers, funding rates or index components before settlement if markets become unusually volatile.

Loans and several payment services will also close that day. Binance Pool and Binance Pay will stop supporting the assets at 03:00 UTC. VIP Loan and Flexible Loan positions will close at 07:00 UTC, while cross and isolated margin positions will be settled at 10:00 UTC. Margin borrowing will already be suspended from 06:00 UTC on Aug. 4.

Advertisement

Spot Copy Trading will remove the affected pairs on Aug. 10. Remaining assets may be sold at market prices or transferred to users’ spot accounts when they cannot be sold. Simple Earn will redeem flexible and locked positions after 07:00 UTC on the same day and transfer the assets and accrued rewards to spot accounts.

Four Binance delistings followed earlier risk warnings

The decision was preceded by Monitoring Tags on four of the six tokens. The exchange added PIVX to the tag list on June 18, followed by PYR and VANRY on July 3. ACX received the tag on July 24. The exchange states that tagged assets carry greater volatility and risk and may be removed if they no longer satisfy its listing standards.

As crypto.news previously reported, the ACX warning came days before the latest removal decision. Monitoring Tags do not guarantee delisting, but they require users to pass a risk quiz every 90 days and notify holders that the exchange is conducting closer reviews.

Advertisement

In related coverage, Binance removed 20 tokens from its Alpha platform in May while preparing five other assets for spot delisting. The Alpha removals and full spot delistings were separate processes, but both followed reviews against the exchange’s platform standards.

ACX also entered Binance’s delisting process after Coinbase suspended its trading on July 28. Coinbase said the project team was winding down the token and directed holders to Across documentation.

Across previously proposed replacing its token-based DAO with a U.S. C-corporation. The published plan set out an equity exchange and a USDC buyout at $0.04375. However, legal restrictions apply to the equity option, and the proposal said its estimated timetable could change.

VANRY holders must complete the Base migration themselves

VANRY presents an extra operational issue. The exchange said it will not support Vanar’s contract swap. Holders seeking the replacement token must use the project’s migration portal rather than expecting Binance to complete the conversion automatically.

Advertisement

Vanar announced a 1:1 migration to Base and said the new token would have a supply of 10 billion. The project previously told users that participating centralized exchanges would handle the swap automatically. Binance’s new notice confirms that it is not one of those supporting venues.

The exchange will keep current VANRY withdrawals open through Ethereum and Polygon PoS. That gives Binance users a route to remove their tokens before completing the migration through Vanar’s official portal.

Vanar has warned holders to rely only on links distributed through its verified channels. The project advised users to ignore unsolicited messages and never share wallet seed phrases while completing the migration.

Withdrawals remain open until Oct. 17

The exchange Convert will remove the six assets at 02:00 UTC on Aug. 17, one hour before spot trading ends. Its low-value asset conversion feature will stop supporting them on Aug. 14. Deposits made after 03:00 UTC on Aug. 18 will not be credited.

Advertisement

Withdrawals will remain available until 03:00 UTC on Oct. 17. The exchange may convert balances left on the platform into stablecoins after Oct. 18, but the exchange said that conversion is “not guaranteed.” It will issue another notice where conversion is possible.

When conversion is not feasible, Binance said withdrawals may remain open, subject to network availability. Users should not rely on that possibility because the exchange has not committed to providing an extended withdrawal window.

The removal covers six tokens facing different project conditions rather than one shared event. Binance’s announcement gives users a common timetable but no token-by-token findings. The next confirmed developments will come from project responses, settlement notices and any changes to the withdrawal or migration arrangements.

Advertisement

Source link

Continue Reading

Crypto World

Coldcard’s 5-Year Flaw Shows Hardware Wallet Testing Gaps, Kraken Chief

Published

on

Crypto Breaking News

Coldcard’s five-year seed-generation issue has turned into a wider debate over how hardware wallets are independently verified, according to Kraken’s chief security officer Nick Percoco. In an X post on Sunday, Percoco said the incident should prompt makers of self-custody devices to require end-to-end checks that confirm the randomness source reviewed in testing is the same one actually executed by production firmware.

The comments arrive amid an ongoing exploit believed to target vulnerable Coldcard devices by abusing weak seed phrases. By Sunday, more than 4,500 addresses had reportedly been affected, with losses estimated at nearly $90 million in Bitcoin, according to Cointelegraph’s reporting linked in the original article.

Key takeaways

  • Kraken’s Nick Percoco argues hardware wallet certification should include verification that the approved entropy path is what production firmware uses in practice.
  • Coldcard’s RNG-related flaw allegedly persisted for years after a seed-generation change introduced an unintended reliance on a weaker generator.
  • Percoco cited existing standards used in the broader security and payments industries—such as NIST SP 800-90B and BSI AIS-31—as models for what should be standard for crypto self-custody.
  • Coinkite says affected firmware has been halted in shipments and that remaining units containing the vulnerable code were destroyed, while it advised users not to discard certain devices.

A hardware wallet “wake-up call” for entropy verification

Percoco’s central point is about trust boundaries. Hardware wallet users are asked to rely on a manufacturer’s implementation of the randomness function that ultimately underpins seed phrase generation—yet, he said, there is often no independent method to confirm that the verified randomness source is the one the device will actually call in production.

“Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” Percoco wrote in his Sunday post.

He described this gap as an industry-wide weakness rather than a one-off mistake, noting that while some certifications exist for hardware components and secure elements, they do not “systematically force end-to-end verification” of the entropy source through to production code execution.

Advertisement

Percoco contrasted the crypto self-custody space with practices in other sectors. He pointed to the payments industry’s use of independent lab testing for devices that collect sensitive inputs, and to government expectations in the US around cryptographic module validation and entropy source testing.

How the Coldcard flaw allegedly slipped through

According to the original reporting, the vulnerability traces back to a software change disclosed by Coinkite. The company said the relevant issue has existed since March 2021, when Coldcard altered its seed-generation process as it integrated a new cryptographic library.

The update, per Coinkite’s postmortem referenced in the article, unintentionally routed wallet creation to a weaker MicroPython generator already present in the codebase. Coinkite’s explanation indicated that Coldcard’s intended true random number generator (TRNG) code existed and could be present and functioning, but was not reliably the one used for the core randomness needed for seeds.

In other words, reviewers could verify that the TRNG code was present and worked—but, without a mechanism to ensure the device actually called that TRNG during seed generation, the system could still produce outcomes derived from a different generator than intended.

Advertisement

The practical consequence is that seed phrases generated under the affected conditions may become more predictable than they should be. That predictive weakness is widely viewed by the security community as especially dangerous in wallet designs because compromised seeds can enable theft without needing to break keys directly.

Attack fallout and what’s changing for users

The ongoing exploit believed to target weak seed phrases generated by affected Coldcard devices has already resulted in extensive on-chain activity. As of Sunday, Cointelegraph’s figures cited in the original article reported over 4,500 impacted addresses and losses approaching $90 million in Bitcoin.

Coldcard (Coinkite) said it has halted all device shipments since confirming the vulnerability on Thursday. It also stated it destroyed remaining units at its facilities that contained the affected firmware.

At the same time, the company advised users with affected devices not to dispose of them immediately, saying doing so might become “essential if funds are recovered.” The company also indicated its legal team would coordinate with law enforcement across multiple jurisdictions to support efforts identifying those responsible.

Advertisement

For affected owners, the new information underscores a key operational point: device handling decisions may need to be aligned with recovery processes rather than treated as purely disposal or cleanup tasks. While that doesn’t eliminate the security risk of continuing exposure, it suggests an active incident-response posture where retaining evidence or workable hardware could matter.

Standards exist—what’s missing is enforcement

Percoco’s critique points to a tension that many investors and builders may recognize: crypto security often emphasizes reviewing code paths and cryptographic primitives, but not always the end-to-end behavior under production conditions—especially the specific entropy source used at runtime.

He referenced NIST SP 800-90B, which sets requirements for designing, testing and validating physical true random number generators for cryptographic security, and BSI AIS-31, a similar standard from Germany’s Federal Office for Information Security. In his view, such frameworks make it more difficult for systems to “pass review” without proving that the approved randomness pathway is actually used for critical operations.

Whether regulators and certifiers will adapt those expectations to consumer self-custody products remains uncertain. However, the Coldcard case demonstrates why the distinction matters: even when a correct TRNG implementation exists in the codebase, the seed-generation workflow can still be compromised if production firmware routes randomness differently than what independent review assumes.

Advertisement

Next, investors and users should watch for two things: clarification from Coinkite on exactly how to identify which devices/firmware are affected and what remediation steps best reduce future risk, and whether independent testers or certifiers move toward stronger “entropy source at runtime” validation—an area Percoco argues should not remain optional in digital asset custody.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Crypto World

Micron’s 39% Plunge and SK Hynix, Samsung’s $1.3T Spending Worries US Chipmakers

Published

on

Micron has seen substantial growth, but also a decline, in the last six months.

Micron Technology (NASDAQ: MU) closed at $823 per share on Friday, July 31, down 5.90% on the day and as much as 39% below its high this year.

The slide is rattling more than one US chipmaker. SK Hynix and Samsung’s plan to spend up to $1.3 trillion combined on new capacity is adding pressure, just as SanDisk, another US memory maker, has fallen 41% in the past month.

Why Rivals Are Racing to Add Capacity

South Korean officials have tied the expansion to a national plan to secure the country’s position in AI-era chip supply. Reports on the combined Samsung and SK Hynix investment have ranged from $575 billion to $1.3 trillion, reflecting how quickly spending plans have escalated this year.

Micron has seen substantial growth, but also a decline, in the last six months.
Micron has seen substantial growth, but also a decline, in the last six months. Image Source: Trading View

Demand for high bandwidth memory used in AI accelerators has outpaced supply for more than a year, a shortage Micron’s own management does not expect to ease before 2028.

That squeeze helped push SK Hynix stock down 13% on capex concerns even as Samsung posted an 1,800% profit jump last quarter, and it is also fueling the rise of Chinese challenger CXMT, whose stock has kept climbing since its IPO.

Advertisement

What It Means for US Chipmakers

Micron trades at a forward price to earnings ratio near 19.8, with a market capitalization of about $930 billion. Wall Street analysts rate the stock a strong buy, even as short-term technical indicators point toward a sell signal.

SanDisk faces a similar squeeze. Its stock crash has erased much of a euphoric rally, though the company still holds a year-to-date gain of about 362%, a sign of how fast memory stocks moved before this pullback.

Coverage of Micron itself is split, though. One analysis modeled a path to roughly $1,000 per share by mid-2028 if pricing power holds. Another warned that rising AI infrastructure costs could force hyperscalers to slow spending before Micron’s new capacity, including plants in Idaho and New York, comes fully online.

Micron’s next earnings report, due September 29, will show whether US chipmakers can hold their pricing power as SK Hynix, Samsung, and CXMT race to close the capacity gap.

Advertisement

The post Micron’s 39% Plunge and SK Hynix, Samsung’s $1.3T Spending Worries US Chipmakers appeared first on BeInCrypto.

Source link

Continue Reading

Crypto World

South Korea Records $367M in Stablecoin Outflows

Published

on

South Korea Records $367M in Stablecoin Outflows

South Korea saw 560.3 billion won ($367 million) in stablecoin outflows to overseas exchanges in June, extending the country’s streak of monthly net stablecoin outflows to 18 consecutive months. 

The figure comes from Financial Supervisory Service (FSS) data obtained by Yonhap News Agency through People Power Party lawmaker Lee Jong-wook. South Korea’s five major crypto exchanges — Upbit, Bithumb, Coinone, Korbit and Gopax — transferred 2.7 trillion won ($1.81 billion) in stablecoins offshore in June and received 2.2 trillion won ($1.44 billion) from foreign platforms.

Market participants cited by Yonhap attributed the transfers to demand for products restricted or unavailable on domestic exchanges, such as overseas derivatives, tokenized real-world assets (RWAs), decentralized finance and staking products. 

Lee has called on the government to reassess how it protects investors and supervises cross-border crypto activity as stablecoin outflows continue. “The government must comprehensively examine its investor protection and supervisory frameworks again and move swiftly to improve regulations,” he said, according to The Korea Times.

Advertisement

South Korea weighs tighter rules for offshore activity

The outflows come as South Korea works to complete a broader legal framework for digital assets. On Thursday, a policy report recommended that authorities introduce an interim licensing guidance and phase in stablecoin regulations before the Digital Asset Basic Act is finalized. 

The proposed act would create the country’s first comprehensive digital asset framework, including rules for stablecoin issuance, disclosures and market activity. However, lawmakers have yet to reconcile multiple proposals, with disagreements over which institutions should be allowed to issue won-pegged stablecoins contributing to delays. 

Related: South Korea plans stablecoin rules as opposition pushes crypto tax repeal

South Korean regulators have also sought to expand reporting requirements for crypto transfers. On June 22, South Korea’s Financial Intelligence Unit (FIU) proposed extending Travel Rule reporting requirements to transactions below 1 million won (about $650).

Advertisement

The FIU also called for stronger action against unregistered overseas exchanges serving South Koreans. The agency said uneven licensing and supervision across jurisdictions created opportunities for regulatory arbitrage, a concern underscored by the country’s continued stablecoin outflows.

Magazine: The real reason DeFi projects that survived 2022 crash are shutting down now

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025