Crypto World
Coldcard Flaw Exposes Hardware Wallet Testing Blind Spot: Kraken
Coldcard’s five-year seed-generation flaw has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco.
In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware.
“Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco.
His comments follow an ongoing attack that is believed to exploit weak seed phrases generated by affected Coldcard devices. As of Sunday, over 4,500 addresses have been impacted, draining nearly $90 million in Bitcoin.
Coldcard RNG flaw remained undetected for five years
On Thursday, Coinkite disclosed a software flaw that has existed since March 2021, when Coldcard changed its seed-generation process as it integrated a new cryptographic library.
The migration inadvertently routed wallet creation to a weaker MicroPython generator that existed in the codebase, rather than Coldcard’s intended true random number generator (TRNG).
“The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base,” Coinkite said in its postmortem. “At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.”
The presence of the intended random number generator allowed the vulnerability to slip through undetected. Code reviews would confirm the existence and functioning of Coldcard’s TRNG code, but there was no check to ensure this was the RNG actually being called.
Such checks are already standard across the rest of the security industry, said Percoco, referencing NIST SP 800-90B, a US government standard specifying requirements for designing, testing and validating physical true random number generators for cryptographic security and BSI AIS-31, a similar standard created by the German Federal Office for Information Security.
“Hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls,” he said.
“The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception,” said Percoco.
Related: Suspected 4th Coldcard attack wave sweeps 389 Bitcoin: Galaxy’s Thorn
Coldcard said Sunday it has halted all device shipments since confirming the vulnerability on Thursday, and has destroyed all remaining units at its facilities containing the affected firmware.
However, Coinkite has advised users with affected devices not to dispose of them as “it may become essential if funds are recovered.”
“Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.”
Related: Coldcard exploit sparks Bitcoin flight, ‘bullish’ crypto consolidation: Hodler’s Digest, August 2
Crypto World
ZeroStack Warns of Survival Risk After $82.5M Crypto Loss
Nasdaq-listed crypto treasury company ZeroStack warned that substantial doubt exists about its ability to continue operating over the next year, reversing its assessment from three months earlier.
In a Form 10-Q filed with the US Securities and Exchange Commission (SEC) on Friday, ZeroStack reported $2.6 million in cash, negative working capital of $600,000 and an accumulated deficit of $339.1 million as of June 30. The company also posted an $82.5 million fair value loss on digital assets and a net loss of $61.3 million for the first half of 2026.
ZeroStack said its 75.1 million Zero Gravity (0G) tokens had an aggregate cost of $163.3 million and a fair value of $15.2 million as of June 30, leaving the holdings valued about 91% below their recorded costs.
ZeroStack relies on staking rewards and token sales to fund operations, making its ability to raise cash dependent on 0G’s price and trading liquidity.
ZeroStack’s 0G strategy faces a liquidity test
ZeroStack reported $3.8 million in staking revenue during the first half of the year, earning about 6.6 million 0G tokens after validator commissions. It sold nearly 4.9 million tokens for $2.4 million to fund its operating expenses.
The company expects its cash and staking reward sales to cover forecast operating costs and said it could sell some of its treasury holdings if needed. However, management said it could not conclude that those plans would be enough to ease doubts about its ability to continue operating.
Related: BitMart withdrawals appear to slow following wind-down announcement
The latest assessment reverses the company’s position in its previous two reports. In its first-quarter filing, ZeroStack said its cash and staking rewards would be sufficient to meet its working capital requirements and obligations for at least another year.
The company was previously the cannabis and CBD products firm Flora Growth. On Sept. 19, Flora announced $401 million in funding for a 0G treasury strategy, including $35 million in cash and equivalent commitments and more than $366 million in in-kind digital assets. The company subsequently rebranded as ZeroStack and retained its Nasdaq listing.
Magazine: The real reason DeFi projects that survived 2022 crash are shutting down now
Crypto World
Every Token Binance Delisted Monday Carried a Prior Warning Label
Binance will delist Across Protocol (ACX), Hashflow (HFT), PIVX, Vulcan Forged PYR (PYR), Vanar (VANRY), and Viction (VIC) on August 17.
The exchange said its latest periodic review found the tokens no longer meet its listing standards. Prices crashed within hours of Monday’s announcement before paring some losses.
PIVX and PYR Lead Losses After Binance Delisting Notice
PIVX took the sharpest fall, trading down 19.27% at press time. PYR followed close behind with an 18.31% loss. Hashflow slid to an all-time low of $0.007 after the notice went live. At press time, HFT traded 11.47%.
VIC posted near-identical declines, down 11.24%. ACX held up better than its peers, slipping 5.22%. VANRY was the lone gainer, up 8.23% at press time despite earlier losses.
The gain comes with a catch. Binance will not support Vanar’s contract swap plan, leaving holders to migrate tokens themselves through the project’s portal.
Follow us on X to get the latest news as it happens
The declines come as no surprise. Previous delisting rounds triggered comparable sell-offs, with removed tokens routinely dropping. Losing access to the largest exchange by volume typically drains liquidity and forces holders to exit before trading closes.
Meanwhile, Binance Futures will settle all contracts for the tokens on August 7. Deposits will no longer be credited after August 18, and withdrawals will close on October 17.
Every Delisted Token Carried a Monitoring Tag First
Binance said it weighs factors including team commitment, development activity, trading volume, and network security during reviews. Regulatory changes and tokenomics shifts also feed into the decision.
“When a coin or token no longer meets these standards or the industry landscape changes, we conduct a more in-depth review and potentially delist it,” the exchange added.
The removals follow a now-familiar pattern. Binance added the Monitoring Tag to all 6 tokens before the final decision.
VIC received the label on April 30, followed by HFT on May 22 and PIVX on June 18. PYR and VANRY joined on July 3. ACX was tagged just 10 days ago, on July 24, the fastest turnaround of the batch.
The pattern puts coins like Lisk (LSK) and Stacks (STX) in focus. Both received the Monitoring Tag alongside ACX in July.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
The post Every Token Binance Delisted Monday Carried a Prior Warning Label appeared first on BeInCrypto.
Crypto World
BP Sells North Sea Oil Business as UK PM Eyes New Drilling
BP is putting its North Sea oil business up for sale, ending 60 years of regional production. The UK’s new prime minister is already signaling openness to more drilling there.
BP confirmed the decision Friday after reviewing its global operations. The unit runs five production hubs and employs about 1,100 workers.
A Political Backdrop
The sale lands as political pressure builds on the government to loosen drilling restrictions. Prime Minister Andy Burnham took over after Starmer’s resignation in June. He told US President Donald Trump this week he would take a “pragmatic approach” to North Sea oil and gas.
“There is a resource there. When people are struggling – you can’t ignore that.”
— Andy Burnham, BBC News
The comments follow months of debate. The Iran war pushed oil prices past $110 a barrel earlier this year. That surge revived calls for expanded drilling from Conservatives, Reform UK, and Trump himself.
Some Labour MPs want a looser approach. Others, including former energy secretary Ed Miliband, still defend the party’s pledge against new licenses.
A Sale, Not an Exit
BP CEO Meg O’Neill framed the sale as part of a shift toward BP’s “highest-value opportunities.” BP’s global headquarters will stay in the UK, where the company employs about 13,960 people.
The sale could fetch BP up to £2 billion, according to earlier reporting on failed talks with Ithaca Energy.
Energy Secretary Miatta Fahnbulleh said she was staying in close contact with BP. Her priority is protecting workers and the local community during the sale.
Whether Burnham’s shift in tone leads to new licenses before a buyer arrives remains uncertain.
The post BP Sells North Sea Oil Business as UK PM Eyes New Drilling appeared first on BeInCrypto.
Crypto World
Coldcard Vulnerability Highlights Hardware Wallet Testing Gaps, Kraken
Coldcard’s five-year seed-generation flaw has become more than a single-vendor incident, with Kraken’s chief security officer Nick Percoco arguing that it highlights a structural gap in how hardware wallets are independently tested. In particular, he says security reviews often verify that the “right” entropy source exists in the codebase, but may not confirm that production firmware actually calls the validated randomness path.
Percoco’s warning follows an ongoing exploit campaign widely believed to target weak seed phrases produced by affected Coldcard devices. As of Sunday, more than 4,500 addresses were reported impacted, with losses estimated at nearly $90 million in Bitcoin, according to Cointelegraph’s ongoing coverage.
Key takeaways
- Kraken’s Nick Percoco says hardware wallets are often not subject to end-to-end verification that the approved entropy/RNG source is the one production firmware executes.
- Coldcard’s vulnerability traces to a process change approved in March 2021, after Coinkite integrated a new cryptographic library.
- Coinkite’s postmortem describes a shift where seed generation relied on a weaker MicroPython generator instead of the intended TRNG most of the time.
- Percoco points to established standards like NIST SP 800-90B and BSI AIS-31 as models for how entropy sources should be validated.
- Coinkite says it halted shipments of affected devices and destroyed remaining units containing the vulnerable firmware, while advising users not to dispose of hardware immediately.
Why the Coldcard case is a test-process problem, not just a bug
In an X post on Sunday, Percoco characterized the Coldcard issue as a “wake-up call” for hardware-wallet manufacturers. His core point was that consumers are asked to rely on a vendor’s implementation of the system’s most critical function—secure randomness—without a corresponding independent check that the validated randomness path is actually what ends up running in production.
“Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” Percoco wrote, arguing that this gap can allow critical cryptographic expectations to be silently violated.
He contrasted the state of digital-asset self-custody testing with practices in other security-critical sectors. As he framed it, industries that handle sensitive authentication hardware and cryptographic modules typically require more rigorous verification of entropy sources than what is commonly enforced in the hardware-wallet ecosystem.
What Coinkite says went wrong in March 2021
Coldcard’s broader timeline centers on changes made in March 2021. Coinkite disclosed that a software flaw had been present since then, when Coldcard altered its seed-generation approach as part of integrating a new cryptographic library.
According to Coinkite’s postmortem, the migration inadvertently routed wallet creation through a weaker MicroPython generator that already existed in the codebase, rather than using Coldcard’s intended true random number generator (TRNG). The company’s account describes a situation where the TRNG code was present and could be reviewed and confirmed, but it was not the primary source used during seed generation.
Coinkite summarized the problem by saying that “the bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base,” while the carefully crafted TRNG code was being used only “by chance” and “only for less important things.”
This distinction matters because it reframes the vulnerability: rather than the TRNG being entirely missing or nonfunctional, the risk appears to stem from the firmware executing a different randomness source than the one reviewers might reasonably assume would be used for security-critical seed creation.
Standards exist—yet Percoco says they aren’t applied end to end
Percoco said the failure to detect the issue for years is consistent with how many wallet evaluations are structured. He argued that while code reviews can establish that a TRNG is included and appears to work, there is often no systematic check that verifies the entropy source actually invoked by production firmware matches the entropy that was validated.
He pointed to requirements used for physical true random number generator design and validation, citing NIST SP 800-90B, a US standard for cryptographic randomness validation, and BSI AIS-31, an analogous German standard from the Federal Office for Information Security.
“Such checks are already standard across the rest of the security industry,” Percoco said. His broader critique was that hardware wallets currently lack an equivalent, universally enforced process that forces end-to-end validation of the RNG path—from approved design, to tested behavior, to the exact call executed at runtime.
For investors and security-focused users, the implication is straightforward: if independent testing does not verify the operational link between validated randomness and deployed firmware, the security model can be weakened even when the codebase contains the correct components.
Coldcard and Coinkite response: halted shipments and guidance to users
Following disclosure of the underlying flaw, Coldcard said Sunday it has halted all device shipments since confirming the vulnerability on Thursday. Coinkite also stated it destroyed remaining units at its facilities that contained the affected firmware.
At the same time, Coinkite advised users with affected devices not to dispose of them, noting that they “may become essential if funds are recovered.” The company also said its legal team will coordinate, as warranted, with law enforcement across multiple jurisdictions to support efforts to identify those responsible.
The ongoing nature of the exploit makes the guidance more than a technical footnote. When seed phrase weaknesses are involved, practical remediation often depends on forensic details and the potential recovery process, which can be complicated if devices are discarded.
Earlier reporting from Cointelegraph has described the exploit as targeting weak seed phrases generated by affected Coldcard devices, with additional analysis of theft totals and affected addresses. The scale reported as of Sunday—over 4,500 addresses impacted and losses approaching $90 million in Bitcoin—adds urgency to both user instructions and improvements to how wallets are tested before release.
What to watch next
For the market, the key question is whether this incident drives a measurable shift in independent validation practice—specifically, whether future hardware-wallet reviews will include end-to-end confirmation that production firmware uses the validated entropy source for seed generation. Until that standard becomes routine, incidents like Coldcard’s may continue to reveal weaknesses that are invisible to partial audits.
Crypto World
Bitcoin price faces 5 macro tests this week
Bitcoin traded near $62,747 early on Aug. 3 after reaching an intraday high of $63,697, as investors prepared for five major U.S. economic releases and several closely watched corporate earnings reports.
Summary
- Bitcoin traded near $62,747 after briefly reaching $63,697 as Iran de-escalation produced only limited gains.
- Five major U.S. releases culminate Friday with July payrolls, shaping expectations for Federal Reserve policy.
- AMD, SpaceX and Sandisk report this week, adding corporate catalysts beside major U.S. labor releases.
The week begins with the July ISM Manufacturing PMI on Monday. It ends with the official July employment report on Friday. Between those releases, traders will receive job-opening data, private payroll figures and the ISM Services PMI. Together, the reports could alter expectations for Federal Reserve policy after officials kept interest rates unchanged last week.
Bitcoin’s response to Iran diplomacy remains muted
The first potential catalyst arrived before the U.S. trading week began. President Donald Trump canceled planned strikes against Iran and said negotiations intended to reopen the Strait of Hormuz would begin on Monday.
Oil reacted sharply. Brent crude fell more than 5% to around $83 per barrel, while West Texas Intermediate dropped below $80. Bitcoin briefly moved toward $63,700 but failed to hold the advance, showing a weaker response than energy markets.
Trump has claimed “there’s a deal” concerning the strait. However, no final agreement had been publicly verified early Monday, and Iranian representatives disputed reports that Tehran had already accepted the proposed arrangement. The planned talks therefore represent a diplomatic opening rather than a completed settlement.
The limited Bitcoin move follows a pattern seen during earlier negotiations. As previously reported, oil has often responded more directly because shipping disruptions affect global energy supplies. Bitcoin has remained more sensitive to liquidity, interest rates and institutional demand.
Five U.S. releases could reset Fed expectations
The ISM Manufacturing PMI will arrive at 10 a.m. ET on Monday. The Bureau of Labor Statistics will publish June job openings at 10 a.m. ET on Tuesday, followed by ADP’s July private-employment report and the ISM Services PMI on Wednesday.
The final and most closely watched release is Friday’s July employment report at 8:30 a.m. ET. June payroll growth slowed to 57,000 jobs, while the government revised April and May employment growth lower by a combined 74,000. The unemployment rate fell to 4.2%, partly because the labor force contracted.
The Federal Reserve held its target rate at 3.5% to 3.75% on July 29. Its statement said economic activity continued to expand at a solid pace despite elevated uncertainty connected partly to the Middle East conflict. The decision passed by a 9–3 vote.
Stronger employment or services data could support expectations that the Fed will keep rates elevated or consider another increase. A broader slowdown could reduce pressure on bond yields and support risk assets. Neither outcome guarantees a Bitcoin breakout because markets will react to how far each figure differs from expectations.
Bitcoin needs more than one favorable report
Bitcoin’s muted response to the canceled Iran strikes suggests that one positive headline may not be enough to end the current consolidation. A durable move would likely require several data points to tell the same economic story.
For example, weak job openings followed by slowing private payrolls and softer official employment growth could strengthen the case that labor demand is cooling. However, that effect could be offset if the ISM reports show rising input prices or stronger services activity.
Crypto markets have reacted quickly to labor surprises before. As crypto.news reported, Bitcoin moved above $62,000 after June payroll growth missed forecasts, as traders reduced expectations for tighter monetary policy.
Still, the latest Fed decision showed that policymakers remain focused on inflation as well as employment. In related coverage, Bitcoin weakened before the July meeting as traders reduced risk and waited for clearer guidance.
Earnings add another test before Friday’s jobs report
Corporate results will create another source of volatility. AMD and SpaceX are scheduled to publish quarterly results after Tuesday’s market close. Sandisk will report on Wednesday, followed by other major U.S. companies later in the week.
FactSet reported that 61% of S&P 500 companies had released second-quarter results by July 31. Of those companies, 86% exceeded earnings estimates and 77% surpassed revenue forecasts. The index’s blended annual earnings growth rate stood at 47.4%.
Strong technology earnings could support general risk appetite. However, those companies do not provide a direct catalyst for Bitcoin comparable with interest-rate expectations, ETF demand or changes in dollar liquidity.
The clearest timetable is therefore Monday’s manufacturing report, Tuesday’s job openings, Wednesday’s private payroll and services data, and Friday’s official employment figures. A Bitcoin breakout would require sustained buying after those releases rather than a brief reaction to one favorable number.
Crypto World
Trump Media has moved out 7,000 bitcoin, leaving only likely loan collateral
But whatever the label on Sunday’s transaction, the direction has not changed since December.
Trump Media bought 11,542 bitcoin for about $1.37 billion at an average of $118,522 a coin, close to the top of last year’s cycle. Wallets linked to the company have since moved out 7,281 of them.
Onchain analytics firm Lookonchain said those flows as sales averaging $74,855 a coin, which against the original cost basis would mark roughly $318 million in realized losses, with another $237 million sitting unrealized on what is left.
And the treasury has been shrinking faster than the business it sits on. Trump Media posted a $405.9 million net loss in the first quarter on $871,200 in revenue, with $368.7 million of that coming from markdowns on digital assets and equity holdings, including 756 million Cronos tokens acquired through the Crypto.com partnership that has now handled two of these transfers.
Crypto.com is one of the company’s two named custodians alongside Anchorage Digital, so a deposit there is what a custody move would look like. It also runs the exchange, so it is exactly what a sale would look like too, and the chain will not separate them.
The answer will be in the second-quarter 10-Q. A sale shows up as a realized loss on the income statement, while a custody move shows up nowhere. Whatever the wallets have been doing since December has to appear in one column or the other.
Crypto World
Bitcoin slips under $63,000 despite Iran deal hopes as Coldcard losses rattle market
Treasuries rallied across the curve as the oil move eased inflation worries, taking the 10-year yield down four basis points to 4.69% after it hit its highest since January 2025 last week. Nasdaq 100 futures and European share futures both gained 0.8%. Gold added 0.3% to about $4,060 an ounce.
Falling oil, falling yields and rising stock futures usually give crypto a lift. This time bitcoin ignored all three — because the pressure on it is coming from a broken hardware wallet rather than from the macro.
As CoinDesk reported Sunday, a third wave of sweeps against Coldcard-generated addresses were found over the weekend, bringing observed losses to 1,367 bitcoin, nearly $89 million, across 4,585 addresses.
The average haul per address has fallen with each wave, which suggests the attacker has worked through the large balances, and later moved to emptying wallets worth a few thousand dollars.
Wave one took 1,083 bitcoin from 1,196 addresses on July 30, but wave three took 208 BTC from 1,912 wallets, which is more wallets for a fifth of the money.
Meanwhile, ether funds took small inflows on Friday while bitcoin funds saw an outflow, an unusual split for a market where bitcoin normally sets the direction and ether follows.
Crypto World
PayPal stablecoin strategy expands after $486.4B quarter
PayPal reported its second-quarter results on July 28, saying total payment volume reached $486.4 billion for the three months ended June 30.
Summary
- PayPal processed $486.4 billion in second-quarter payment volume, rising 10% from the prior year period.
- The company created Payment Services & Crypto, grouping PYUSD with Braintree and merchant processing operations.
- PYUSD supply stood near $2.7 billion, below the more than $4 billion recorded in March.
That was up 10% from a year earlier, or 9% on a currency-neutral basis. The company also placed stablecoins inside its formal innovation plan and confirmed a three-business structure that includes Payment Services & Crypto.
The organizational shift gives crypto a clearer place inside PayPal, but it is not a stand-alone digital asset business. The division also includes Braintree, small-business processing and value-added merchant services. PayPal said the model is designed to combine those capabilities with crypto products, including PayPal USD.
PayPal’s Q2 results give the crypto unit a larger base
Net revenue rose 5% to $8.68 billion, while transaction margin dollars increased 1% to $3.9 billion. Adjusted free cash flow reached $1.83 billion. However, GAAP net income fell 12% to $1.10 billion, and GAAP operating margin contracted to 16.4% from 18.1% a year earlier.
Non-GAAP earnings were $1.38 per share, down 1% year over year. PayPal raised its full-year non-GAAP earnings guidance to about $5.38 per share and lifted its transaction margin dollar outlook to roughly $15.6 billion. Shares gained about 4% on earnings day as investors reacted to the results and updated guidance.
The company also recorded $81 million in net losses on strategic investments and crypto assets held for investment. That figure combines two categories. PayPal did not disclose how much came from crypto alone, so the entire $81 million should not be presented as a digital asset loss.
PayPal said the combined portfolio reduced GAAP earnings by about $0.07 per share during the quarter. It excludes those gains and losses from non-GAAP results because it says it does not actively trade the investments or use them to fund normal operations.
PayPal stablecoin strategy now sits inside a dedicated division
PayPal’s earnings presentation listed stablecoins alongside agentic commerce and identity and biometrics under its “innovating with discipline” plan. The presentation said the company intends to use its consumer and merchant network, risk systems and trust infrastructure across those areas.
During the earnings call, CEO Enrique Lores said PayPal plans to launch more merchant products supported by PYUSD and agentic payments over time. He said those capabilities “can support future growth,” making the statement a company forecast rather than a confirmed financial result.
PayPal formally announced the three-business model in April. Payment Services & Crypto now sits alongside Checkout Solutions & PayPal and Consumer Financial Services & Venmo. The crypto division combines PYUSD with Braintree, merchant processing and other platform services.
However, PayPal has not started reporting separate revenue, profit or transaction volume for the crypto portion of the division. The new structure shows a larger strategic role for stablecoins, but the company has not yet provided figures showing how much PYUSD contributes to its financial performance.
PYUSD expansion continues despite lower on-chain supply
PYUSD’s circulating supply stood near $2.7 billion in early August, according to DefiLlama. That was below the more than $4 billion recorded in March and about 4.9% lower over the previous month. The decline shows that wider distribution has not produced uninterrupted supply growth.
On-chain supply is not the same as PayPal revenue or customer adoption. Tokens can be minted or redeemed as demand changes across exchanges, wallets and decentralized finance platforms. Therefore, the lower supply does not establish that PayPal’s stablecoin business is losing money.
PayPal expanded PYUSD access to 70 markets in March. Eligible users can buy, hold, send and receive the stablecoin through PayPal, while some can earn rewards. Paxos issues PYUSD and publishes monthly reserve reports and third-party attestations.
As crypto.news previously reported, PYUSD also became native on Polygon on July 9 through the network’s Open Money Stack. The integration combines wallets, fiat ramps, compliance tools and blockchain settlement for businesses seeking cross-border payment and payout services.
In related coverage, crypto.news reported that PayPal and MoonPay launched PYUSDx, allowing developers to create application-specific stablecoins backed by PYUSD. The platform could broaden PYUSD’s role beyond PayPal’s consumer wallet, although adoption remains unconfirmed.
What comes next for PayPal’s crypto push
PayPal expects to deliver “at least $1.5 billion” in gross annualized cost savings over the next two to three years, including about $400 million by year-end. Those targets are forward-looking and depend on the company completing its reorganization, technology upgrades and spending changes.
The next measurable checkpoints will be PayPal’s third-quarter results, any separate disclosure on Payment Services & Crypto, and monthly PYUSD reserve and supply data. New merchant integrations would also show whether the stablecoin is gaining use beyond trading and incentive-driven decentralized finance activity.
The U.S. angle centers on whether a large public payments company can turn a regulated dollar token into a merchant service. Paxos issues PYUSD under a national trust charter supervised by the Office of the Comptroller of the Currency. That structure may support institutional acceptance, but regulatory status alone does not guarantee transaction growth.
For now, PayPal has made stablecoins more visible in its operating model while its core payments network continues to grow. The company still needs to show how PYUSD contributes to revenue, merchant retention or transaction margins before investors can measure the financial value of the strategy.
Crypto World
Bitcoin hits $62K while Coinbase premium hits 77-day negative streak

The persistent discount suggests US spot buyers have remained less aggressive than overseas traders even as US Bitcoin ETF inflows turned positive in July.
Crypto World
Coldcard losses rise as fourth attack wave sweeps 448 BTC
Galaxy Research head Alex Thorn identified a suspected fourth coordinated Coldcard attack wave on Aug. 3, with his running estimate later rising to 448.7 Bitcoin moved from 709 potential victim addresses.
Summary
- 448.7 BTC moved from 709 suspected victim addresses during a fourth coordinated Coldcard attack wave.
- Galaxy measured 13.8 sweeps per block, roughly 45 times its earlier control-window rate across blocks.
- Fixed firmware protects newly generated seeds, but existing vulnerable seeds still require complete wallet migration.
Thorn described the addresses as “LIKELY Coldcard victims,” saying their unspent outputs and transaction behavior matched the vulnerable-wallet pattern. The wording matters.
Galaxy’s findings come from blockchain analysis, not device records or a final law-enforcement attribution. Coinkite had not separately confirmed the fourth-wave total in its latest public advisory.
Coldcard attack activity rose 45 times above baseline
Thorn’s first snapshot covered blocks 960,778 through 960,792. It identified 218 transactions involving 462 possible victim addresses and about 388.9 BTC. His updated estimate later expanded the event to hundreds of transactions affecting 709 addresses and moving 448.7 BTC.
Galaxy measured 13.8 sweeps per block, compared with 0.3 during a pre-incident control period. Most transactions sent each victim’s funds to a fresh destination rather than one shared collection wallet. Some funds had already moved to second-hop addresses, making the flow harder to follow.
Before the latest activity, Galaxy had mapped three suspected waves involving 1,367.05 BTC across 4,585 addresses.As crypto.news reported, the first wave alone moved 1,082.65 BTC from 1,196 addresses during a 41-minute period on July 30.
Adding the fourth-wave estimate would bring the observed total to about 1,815.75 BTC across 5,294 addresses, assuming the groups do not overlap. That figure is an arithmetic estimate, not a loss total confirmed by Coinkite, police or every wallet owner. Galaxy has also said blockchain data cannot prove whether one operator conducted every wave.
Unconfirmed transactions may offer a narrow escape
Thorn said similar transactions remained in Bitcoin’s mempool awaiting confirmation. A user who still controls the affected keys may be able to broadcast a conflicting transaction that pays a higher fee and sends the funds to a secure wallet.
Bitcoin Core documentation says opt-in Replace-by-Fee transactions can be replaced while they remain unconfirmed. That option disappears once a transaction enters a block. A replacement is also “not guaranteed” to win, so the warning applies only to users who can identify an unconfirmed spend and act before miners confirm it.
Coldcard users still need completely new seeds
Coinkite traced the problem to an RNG integration error introduced during a March 2021 firmware change. The company estimates that affected Mk2 and Mk3 seeds may have about 40 bits of effective entropy. Seeds generated on affected Mk4, Mk5 and Q releases may have about 72 bits rather than the intended 128.
Block’s engineering team independently found that the firmware called a deterministic MicroPython fallback instead of the intended hardware random-number generator. Block cautioned that it had “not done full empirical testing to confirm exploitability,” while saying active theft reports justified early disclosure.
Coinkite has released fixed firmware: version 4.2.0 for Mk2 and Mk3, 5.6.0 for Mk4 and Mk5, 1.5.0Q for Q, and 6.6.0X or 6.6.0QX for Edge releases. Updating alone does not repair an existing vulnerable seed. Users must generate a new seed on fixed firmware, verify a receiving address, send a small test and then migrate the balance.
The company says seeds created with at least 50 fair, private dice rolls are not considered exposed by this RNG issue alone. A strong, unique BIP-39 passphrase adds another barrier, but Coinkite still recommends migration. TAPSIGNER, OPENDIME and SATSCARD use different codebases and are not covered by the advisory.
In related coverage, crypto.news detailed the migration steps after Galaxy’s prior estimate reached $88.6 million. The next verified updates will come from Galaxy’s address mapping, Coinkite’s promised technical review and any public action by exchanges or law enforcement.
-
Business4 days agoWhy Trees Belong on the Risk Register
-
Fashion3 days agoWeekend Open Thread: Wit & Wisdom
-
Politics2 days agoMeta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
-
Entertainment6 days ago‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
-
Politics7 days agoLuke Littler dismantles Gerwyn Price to retain title in Blackpool
-
Crypto World2 days agoMicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
-
Politics6 days agoThe Part of the Electric Transition Nobody Wants to Discuss
-
Business5 days agoMajor shareholder moves on Canyon
-
Crypto World2 days agoXRP Ledger v3.3.0 brings five institutional features
-
News Videos4 days agoBitcoin Enters the 3rd Stage of the Bear Market
-
Crypto World5 days agoKraken Enables Retail Access to Jersey Mike’s IPO via Tokenized Shares
-
Tech6 days agoNew macOS Sequoia & Sonoma security updates for older Macs
-
News Videos5 days agoClaude: Build Financial Dashboards in Minutes (2026)
-
Politics4 days agoLuke Littler’s dominance sparks GOAT debate
-
Business5 days agoJohnson & Johnson agrees to $5.5B settlement over talc cancer claims
-
Sports3 days agoSeema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
-
Crypto World22 hours agoCrypto PAC spending tops $2M in Michigan House race
-
Business3 days agoTrump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
-
Tech5 days agoGemini can now summarize the messiest comment threads in Google Docs
-
Tech1 day agoESET tracks rise in malicious AI skills and adaptable malware

You must be logged in to post a comment Login