Connect with us

Crypto World

Polkadot ETF realized $4.52 of loss per $1 in staking rewards

Published

on

Polkadot ETF realized $4.52 of loss per $1 in staking rewards

On Friday, the 21Shares Polkadot ETF (TDOT) reported that it realized $4.52 of loss per share by selling Polkadot (DOT) tokens to make each $1 per share of staking payouts last quarter.

The fund sold 98,505 DOT last quarter to generate $107,510 of cash payments to shareholders. Those sales finalized losses of $485,553 due to the dramatic decline of DOT.

Specifically, the price of DOT declined 34% during Q2 2026. For the 12 months ending June 30, 2026, DOT declined 76%.

TDOT shareholders do not actually receive staking rewards denominated in DOT. Instead, the fund must sell DOT to mimick and provide the corresponding staking rewards in USD for its shareholders.

Advertisement

All things considered, the payout is embarrassing. Holding TDOT from April through June this year entitled shareholders $0.146980 per share of payouts, which certainly did not compensate for the fund’s 34% share price decline from $14.95 to $9.86.

All-time stock chart of 21shares Polkadot ETF (Nasdaq:TDOT). Source: TradingView

This is, of course, not any particular fault of 21Shares but rather the fault of DOT itself, which continues to fall out of favor with investors.

DOT was supposed to power parallelized execution capable of roughly 1 million transactions per second across up to 100 parachains, an ‘internet of blockchains’ with shared security, and seamless cross-chain interoperability.

In practice, total value locked across all parachains sits at less than $100 million, and DOT trades near 97% below its all-time high as investors find more utility elsewhere.

Paying out staking rewards crystallizes DOT losses

TDOT records cash payouts as a distribution of staking income. Nothing in the filing hides the mechanism by which it realized losses, and shareholders cannot interpret the cause of this $485,553 loss as unrelated to generating staking payouts.

Advertisement

Indeed, the trust unambiguously states, “Aggregate distributions of $107,510 or $0.146980 per share reduced the Trust’s DOT holdings through the sale of DOT to generate cash.”

That crystallized more than four dollars of permanent loss for every $1 it distributed.

By comparison, four peer crypto staking funds disclosed a realized loss in Q2, yet none lost more than $0.89 per $1 distributed. Respectively, Invesco’s Galaxy Solana fund realized $0.89 of loss, the same sponsor’s Solana fund disclosed $0.74 of loss, its Sui fund finalized $0.31, and BlackRock’s staked ether fund reported $0.25.

Read more: Where are the Ethereum founders 11 years after the genesis block?

Advertisement

Realizing losses as Polkadot continues to crash

Shareholders, not these sponsors, bear those losses. The entities behind these funds make money running their products, regardless of the price of crypto.

Specifically, TDOT names 21Shares US LLC as the fund’s sponsor, wholly owned by 21co Holdings Limited. Crypto prime broker FalconX finished buying that parent in November 2025. CEO Russell Barlow and President Duncan Moir signed the quarterly report on August 14.

The trust’s original backer was the Web 3.0 Technologies Foundation, the Swiss entity behind Polkadot. It seeded the fund in January 2025 with DOT worth about $53 million, or roughly $88 per share. Shares closed Q2 at $9.86 per share.

Sadly, selling DOT to generate cash for staking reward payouts was not even the quarter’s most expensive liquidation. Instead, outright redemptions from investors who wanted out of the fund forced the trust to realize another $1.76 million of loss during the quarter. 

Moreover, selling DOT to pay its own ‘sponsor fee’ cost $253,417. Total realized losses for the quarter totaled $2.5 million.

Advertisement

The first distribution, $0.090846 per share, carried a May 14 record date and paid the next day. The second, $0.056134 per share, followed with a June 29 record date, a shrinking payout on a shrinking asset.

Both landed inside a quarter in which DOT fell 34%. The coin slid from $1.25 on March 31 to $0.82 on June 30.

Competition is thinning rather than growing. Grayscale withdrew its own Polkadot ETF registration on August 7, and crypto ETF net asset values are down across the board since early 2025.

Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on XBluesky, and Google News, or subscribe to our YouTube channel.

Advertisement

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

BitMart founder dismisses calls for audit as users report blocked funds, unpaid employees

Published

on

BitMart founder dismisses calls for audit as users report blocked funds, unpaid employees

“We have collected full evidence of the content on X, all of which is fabricated rumors,” Lee said. “During daytime US time, we will file a police report and send a lawyer’s letter to X, demanding technical and data forensics.”

Regarding unpaid staff, the founder of the Cayman Islands-based crypto exchange said, employee assets “are not prioritized over client assets, everyone is a client, and there are no privileges.”

An X user known as BeardStaff said their assets had been inaccessible since the July 26 announcement, and that a dedicated VIP manager removed them from Telegram the day withdrawals stalled. “Where is my $10 million?” they posted.

Another user cut straight to Lee’s hacked account claim.

Advertisement

“No one asked you if the account was hacked or not,” wrote @chicha_liam. “Answer what people have been asking you since July 26. When will users be able to withdraw their funds?”

Onchain investigator ZachXBT also pushed back. “If you actually have the liquidity, then simply return the funds to everyone instead of posting vague statements.”

Roshan Dharia, CEO of distressed investment firm Echo Base, told CoinDesk via Telegram that his firm has offered BitMart a funded restructuring package including debtor-in-possession financing and equity at emergence, underwritten by Echo Base as a claimholder. He said BitMart has not responded.

Source link

Advertisement
Continue Reading

Crypto World

VIX ‘Fear Gauge’ Falls To Year’s Low. A Bad Sign For The Stock Market?

Published

on

VIX 'Fear Gauge' Falls To Year's Low. A Bad Sign For The Stock Market?

The stock market’s so-called fear gauge fell Friday to the lowest level of the year, showing remarkable optimism among investors despite worries of higher interest rates and an unclear path for the Iran conflict. To some strategists, this is an uncomfortable sign of market complacency. Yet, there’s reason to remain bullish for now. The Cboe Market Volatility index, better known…

Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Source link

Continue Reading

Crypto World

Sec Tokenized Stock Plan Could Bring 24/7 Trading to U.S. Markets

Published

on

Crypto Breaking News

The SEC is developing an innovation exemption for platforms seeking to offer tokenized securities. The framework could let firms trade digital versions of U.S. stocks under federal requirements. Meanwhile, SEC Chair Paul Atkins supports efforts to move financial markets onto blockchain networks.

The proposed structure could allow continuous trading and faster blockchain settlement for eligible securities. It could also connect digital share records with established market systems and securities rules. However, the SEC still must address custody, surveillance, clearing, settlement, and investor protection.

The agency recently canceled a meeting that could have covered parts of its crypto regulatory agenda. Officials cited a scheduling issue, and the cancellation did not change requirements. Therefore, platforms seeking tokenized stock markets must continue operating within current regulations.

24/7 Trading Could Reshape Equity Markets

Tokenized stocks could extend trading beyond the fixed hours used by traditional U.S. exchanges. Blockchain networks can process transactions continuously, supporting trading at night, on weekends, and on holidays. Consequently, eligible markets could operate on schedules that differ from conventional venues.

Advertisement

The technology could shorten settlement times by recording ownership changes directly on blockchain networks. Yet tokenization does not remove market duties, because securities still require safeguards and clear ownership rights. Moreover, firms must determine how digital shares connect with brokers, custodians, clearing systems, and infrastructure.

The SEC has supported experiments involving blockchain-based securities infrastructure. Its no-action relief for a DTCC pilot covers selected equities, ETFs, and Treasury securities. Nasdaq has also developed infrastructure for trading and settlement of tokenized securities.

Wall Street Builds Tokenization Infrastructure

Financial firms and crypto companies are building systems that could support blockchain-based securities markets. These efforts focus on trading, custody, settlement, and links between digital networks and financial infrastructure. As a result, tokenization is moving beyond experiments and into market structure discussions.

The SEC is also considering changes that could affect trading models and competition. An August 11 submission from Ondo Finance backed proposed Regulation NMS changes affecting alternative market structures. Those changes could create more room for trading models outside traditional order books.

Advertisement

Tokenized shares would remain securities when blockchain networks record their ownership. SEC materials have distinguished between issuer-backed tokens and third-party models, which can affect shareholder rights. Therefore, the exemption could shape how firms issue, trade, custody, and settle U.S. equities.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Crypto World

Nvidia Stock: Chipmaker Invests In Potential AI Infrastructure IPO. Here’s Why

Published

on

Nvidia Stock: Chipmaker Invests In Potential AI Infrastructure IPO. Here's Why

AI data-center and energy developer SB Energy is reportedly gulping down $1.5 billion in funding from Nvidia. The capital will help it flesh out gigawatt-scale power generation in Ohio, per Reuters. Nvidia stock topped 227 a share Monday morning, then eased; it hovered above 226 a share midmorning. Backed by SoftBank (SFTBY) and OpenAI, SB Energy is a key developer…

Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Source link

Continue Reading

Crypto World

Will Mark Cuban eat his words with his newest crypto prediction?

Published

on

Will Mark Cuban eat his words with his newest crypto prediction?

On Saturday afternoon, Mark Cuban posted another crypto prediction, “Chips as an asset class will be the new crypto.” Within a day, the controversial, 10-word thesis became a trending topic and racked up over 1.2 million views.

The replies doubled as a highlight reel of Cuban’s dismal record with prior crypto predictions.

Cuban has been incorrectly predicting crypto prices for more than seven years, including a banana-based valuation framework and numerous deleted posts that are doubly embarrassing after Cuban both failed to predict crypto prices and then tried to erase the evidence.

Cuban also promoted an Iron Finance yield farm mere days before it imploded and went to $0, plus a “risk free” lender that went bankrupt.

He has also experienced a six-figure phishing loss of digital assets due to poor security and self-owned by selling out of his bitcoin (BTC) position.

Before anyone weighs in on Cuban’s belief that computer chips will outperform crypto, below is a review of his expired predictions.

‘I’d rather have bananas’

In a 2019 Wired interview, Cuban said BTC had even less intrinsic value than baseball cards, comic books, or artwork.

Advertisement

Confidently, he delivered a line that still haunts him, “I’d rather have bananas, I can eat bananas. Crypto, not so much.”

Weeks later, he doubled down, telling Forbes’ audience that BTC had “no chance” of becoming a reliable currency.

Since Cuban’s September 27, 2019 bearish opinion, the price of BTC has rallied 670%. BTC was trading near $8,200 at the time of Cuban’s “no chance” call.

Deleting his comparison of crypto to dot-com

By January 2021, Cuban was comparing crypto trading to the dot-com stock trading bubble of the late 1990s.

Advertisement

That post has since vanished from his account. 

A few months after he deleted that post, in an October 2021 social audio space on Twitter, Cuban called BTC “the best store of value” and said he actually owned it.

Read more: Serial crypto failure Mark Cuban says he’s in it for the apps

Mark Cuban’s 206% yield farm went to $0

Cuban’s confusing about-face and attempts to make amends with the BTC community in October 2021, above, makes more sense in light of his June 2021 comments.

Advertisement

That summer, Cuban was a crypto yield farmer. He blogged (archive) about earning “an annualized return of about 206%” as a liquidity provider in a DAI/TITAN pool.

DAI was a stablecoin by MakerDAO, and TITAN was an Iron Finance token. Days later, TITAN fell from around $64 to $0.

Mortified, Cuban deleted his blog post

Iron Finance itself described the wipeout as a bank run. The project never recovered.

Advertisement

Cuban admitted in another since-deleted post that he got hit like everybody else. He then told Bloomberg, “Even though I got rugged on this, it’s really on me for being lazy” by email. 

Voyager Digital wasn’t ‘risk free’

Undeterred, Cuban’s basketball team the Dallas Mavericks signed Voyager Digital that October as their first crypto sponsor. Voyager spent north of $25 million on the five-year deal. 

Cuban called Voyager’s yields “as close to risk free as you’re going to get in the crypto universe” while promoting the platform. 

Voyager filed for bankruptcy in July 2022, and a class action soon accused Cuban of helping promote its alleged Ponzi scheme. 

Advertisement

A Florida judge dismissed the case on jurisdictional grounds last December. Investors asked an appeals court to revive it in June.

Pumping DOGE repeatedly

Cuban’s Mavericks became the first NBA team to accept Dogecoin (DOGE) payments in March 2021. Cuban exclaimed the launch as the price of DOGE pumped 20% that day.

On August 15 of that year, he further effused, “DOGE’s imperfections and simplicity are it’s [sic] greatest strengths,” coinciding with another 18% single-day rally in DOGE.

Eventually, trying to downplay his prior months of promotion, he disclosed a mere “$494” worth of personal DOGE holdings by August 17, 2021.

Advertisement

In September 2023, a phishing attack drained around $870,000 from one of Cuban’s crypto wallets. 

He admitted the loss was due to him downloading compromised MetaMask software.

Protos reported at the time that he saved a further $2.5 million only by contacting Coinbase before the attacker did.

Add this not-so-luminous example to the list of Cuban’s dubious crypto actions.

Advertisement

Selling out entirely

Then came his capitulation. This May, Cuban claimed, “Bitcoin has lost the plot.” BTC, he lamented, should have been but was not outperforming gold’s then-recent rally.

When bitcoiners dogpiled into the comment section, he boasted about alleged sales at higher prices. “My lowest sales price was 88k. Started in the 120s,” he claimed.

A fuller disclosure emerged this month in an interview from Paris’ RAISE Summit. Cuban said he had sold “98%” of a BTC position once worth “hundreds of millions.” The small DOGE position, he said, he kept.

BTC was trading near $63,000 this weekend. That is well below the $88,000 bottom of Cuban’s exit range, if his autobiographical version of events is actually true. After seven years of bananas, rug pulls, and bankrupcies, the crypto trade that worked out for Cuban was his exit.

Advertisement

Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on XBluesky, and Google News, or subscribe to our YouTube channel.

Source link

Advertisement
Continue Reading

Crypto World

The Odyssey pirated downloads target crypto wallets

Published

on

Address poisoning attack drains $100K USDT

Fake downloads of The Odyssey have begun spreading Lumma Stealer malware through files disguised as high-quality movie releases, putting crypto wallets, passwords, and browser sessions at risk.

Summary

  • Fake The Odyssey downloads use .exe files disguised as 1080p, WEBRip, and Blu-ray releases.
  • Lumma Stealer can collect crypto wallet data, passwords, payment details, and authentication cookies.
  • Bitdefender blocked malicious downloads and identified three domains connected to the malware.
  • U.S. authorities previously linked LummaC2 to at least 1.7 million information-theft incidents.

Bitdefender reported on Aug. 6 that its researchers had found malicious Windows executables using filenames designed to resemble pirated copies of The Odyssey, only days after the film’s release.

The Odyssey downloads conceal Windows executables

Disguised as video files, the downloads use familiar torrent labels such as 1080p, WEBRip, Blu-ray, and H264 to make the listings appear authentic. Bitdefender identified filenames including “the odyssey 2160phd (2026) engsubs eztv.exe,” “the odyssey 2026 1080p h264-djt.exe,” and “the odyssey 2026 1080p webrip-lama.exe.”

Rather than opening a movie, each .exe file launches software built to infect a Windows computer. Bitdefender said its security products prevented users from downloading or running the detected files, although the researchers warned that other filenames may also be circulating.

Attackers can make the disguise harder to spot by changing the executable’s icon to resemble VLC Media Player or an ordinary video file. Windows installations hide known file extensions by default, according to Bitdefender, which means a user may see a movie-style name and VLC icon without noticing the .exe ending.

People searching torrent sites may also expect unusual filenames, compressed folders, or a bundled video player, giving the malicious file another layer of cover. Bitdefender said the lure does not require a complex trick because the victim has already decided to download an unofficial copy from an unverified source.

Advertisement

Lumma Stealer can capture wallets and browser sessions

Once executed, Lumma Stealer searches the infected computer for browser passwords, saved payment information, autofill records, remote desktop credentials, and cryptocurrency wallet data, according to the security firm.

The malware also collects browser authentication cookies. Bitdefender warned that stolen cookies can let an attacker take over an active account session even when the victim has enabled multi-factor authentication, since the criminal may reuse a session that has already passed the login check.

Known as LummaC2, the malware is an information stealer developed in Russia and sold to other criminals as a service, according to Bitdefender and U.S. authorities. Its availability through underground markets allows buyers to run data-theft campaigns without building their own malware.

Advertisement

During its examination of the Odyssey files, Bitdefender observed attempts to contact command-and-control infrastructure associated with Lumma Stealer. Researchers identified the domains auditva[.]cyou, myroayy[.]cyou and logmabx[.]click, which the company said it had blocked for its customers.

Unlike some earlier versions, the samples found in the latest movie campaign did not use separate droppers or persistence tools, Bitdefender said. The operators instead appeared satisfied with collecting and sending available information during the initial execution.

Previous movie-based Lumma attacks used extra methods to avoid detection. Bitdefender found delayed execution when security software was present, encrypted payload delivery through AutoIt scripts, and other checks in a 2025 campaign built around fake copies of Mission: Impossible – The Final Reckoning.

U.S. agencies previously disrupted LummaC2 infrastructure

For U.S. crypto holders, LummaC2 has already drawn action from federal law enforcement. In May 2025, the Justice Department obtained warrants to seize five internet domains used by the malware’s administrators, while Microsoft filed a separate civil case covering about 2,300 other domains tied to the operation.

Advertisement

Court documents cited by the department said the FBI had identified at least 1.7 million cases in which LummaC2 was used to steal information. Listed targets included browser records, email and bank login details, autofill data, and crypto seed phrases that could provide access to virtual asset wallets.

“Malware like LummaC2 is deployed to steal sensitive information such as user login credentials from millions of victims in order to facilitate a host of crimes, including fraudulent bank transfers and cryptocurrency theft,” Matthew Galeotti, then-head of the Justice Department’s Criminal Division, said in the announcement.

The federal operation seized two domains on May 19, 2025. After LummaC2 administrators told customers about three replacement domains the next day, U.S. authorities seized the new addresses as well, according to the department.

Alongside the seizures, the Cybersecurity and Infrastructure Security Agency and the FBI issued a technical advisory describing how LummaC2 enters computers and removes sensitive information. The Justice Department directed people who believe a device has been compromised to contact the FBI’s Internet Crime Complaint Center or a local field office.

Advertisement

The appearance of new Lumma-linked domains in Bitdefender’s 2026 findings indicates that malware campaigns using the family continued after the 2025 enforcement operation. Bitdefender did not provide a victim count, estimated crypto loss, or geographic breakdown for the Odyssey campaign.

Crypto malware is using familiar content as bait

Movie torrents are one part of a series of malware campaigns that package harmful code inside content, applications, or tools that users actively seek.

Earlier in August, crypto.news reported that Microsoft had found a fake CAPTCHA campaign using BNB Chain smart contracts to retrieve attack instructions. Microsoft said the operation targeted thousands of consumer and business devices each day and delivered several malware families, including Lumma Stealer.

Instead of downloading a movie, people caught in that campaign were instructed to open Windows Run, Terminal, or PowerShell and paste a command supplied by the attacker. Microsoft warned that successful infections could expose credentials, install remote-access tools, and create an entry point for ransomware.

Advertisement

Mobile users have faced a different form of wallet theft. In July, reports renewed attention around SparkKitty mobile malware, which Kaspersky had previously found inside iOS, Android, and third-party applications. The spyware collected images from phone galleries, where some users had stored screenshots of wallet recovery phrases, passwords, and QR codes.

Developer tools have also become a delivery route. Socket disclosed in May that the TrapDoor malware campaign involved at least 34 harmful packages and 384 connected versions across npm, PyPI, and Rust repositories. According to the security company, the packages targeted crypto and artificial intelligence developers while seeking wallet data, GitHub tokens, cloud credentials, and SSH keys.

For the latest movie campaign, Bitdefender advised users to watch films through legitimate streaming services, avoid executables advertised as videos, and keep Windows and security software updated. The company also recommended enabling file extensions in Windows Explorer so an .exe file cannot appear to be an ordinary movie.

Advertisement

Source link

Continue Reading

Crypto World

Fourth crypto exchange shuts down in just six weeks

Published

on

Fourth crypto exchange shuts down in just six weeks

US-based crypto exchange ABFinance, founded by ByBit’s former CEO Helen Liu, closed its doors last week before it ever opened.

ABFinance announced last Friday that the exchange’s planned launch will no longer go forward and that it is “winding down in an orderly manner.”

ABFinance lasted six months

Liu founded the exchange in March before stepping down from her ByBit co-CEO role on April 30, 2026. 

After ABFinance’s closure, Liu thanked her team and said: “It’s difficult to see this chapter come to an end.”

Advertisement

Over the last six weeks, BitMart, BitMEX, and AscendEX have also announced that they will be closing shop. 

Read more: AscendEx shutdown: Uncertainty over withdrawals as hot wallets lack funds

Exchanges are leaving users worried for their funds

BitMart closed down despite its bullish outlook, and now, after it has continued to process withdrawals at an incredibly slow pace, users have begun to speculate that the exchange might be insolvent. 

BitMart’s founder recently threatened legal action against posts from an official BitMart account demanding transparency on the status of user funds.

Advertisement

This prompted crypto detective ZachXBT to note, “If you actually have the liquidity then simply return the funds to everyone instead of posting vague statements?” 

BitMEX said it will close down in September, leaving users wondering what it will do about $270 million sitting in a house insurance fund. 

AscendEX also shut down amid withdrawal worries after ZachXBT flagged that the exchange was missing large sums of ETH, USDT, USDT, SOL, and more in its reserves.

Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on XBluesky, and Google News, or subscribe to our YouTube channel.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

Pilots and Flight Attendants Face a Real Cancer Risk. Frequent Flyers Shouldn’t Panic

Published

on

Pilots and Flight Attendants Face a Real Cancer Risk. Frequent Flyers Shouldn’t Panic

The approach rested on simple logic. If cosmic radiation were truly driving cancer among air crew, the signal should appear specifically in the cancers that radiation is known to cause (breast, prostate, melanoma, and certain leukemias), and the signal should not appear in cancers like colon cancer that aren’t caused by this type of radiation. We would also expect to see higher rates of radiation-associated cancers among other types of workers exposed to radiation, like nuclear technologists. Meanwhile, unless something about aviation other than flying was associated with these cancers, we wouldn’t expect to see higher rates in aviation workers who remain on the ground, like aircraft mechanics and assemblers.

The pattern was hard to miss. Among all 503 occupations, flight attendants and pilots had the highest and second-highest share of deaths from radiation-related cancers—6.9% and 6.7%, respectively, after accounting for differences in age, sex, and other factors—a proportion that exceeded that of nuclear technologists. For cancers unrelated to radiation, aircrew sat near the middle of the pack. And our comparison groups fell exactly where the radiation hypothesis predicted; nuclear technologists ranked near the top, while ground-based aviation workers did not.

Source link

Continue Reading

Crypto World

Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers

Published

on

Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers

Cryptocurrency broker Bits of Gold said personal data belonging to roughly 200,000 customers was stolen by hackers, the company reported.

The Tel Aviv, Israel-based company reported the security breach on Sunday, saying a hacker gained unauthorized access to a third-party data analytics network and,gained access to customers’ names, national ID numbers, emails, phone numbers, IP addresses, bank account details, and public wallet addresses.

“Upon detection of the incident, we blocked access and disconnected the system from the information sources, so this access ended,” the company stated.

Bits of Gold said no funds, private keys, passwords, CVV codes, or scanned ID documents were exposed. The broker said its initial findings indicate the attack was part of a broader global incident that hit other companies simultaneously.

Advertisement

It is the third data breach reported within the crypto industry in the last week. Data from nearly 40,000 SafePal users was stolen on Sunday after a third-party vendor suffered a security breach. In a similar attack, personal data from almost 14,000 Trezor wallet customers was exposed on August 13 after its fulfillment partner, ShipMonk, was compromised.

Source link

Continue Reading

Crypto World

How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds

Published

on

How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds

Hardware wallets are somewhere in between a paper wallet and a browser-based hot wallet. They’re harder to hack than software, harder to lose than paper, but they’re not infallible. They can be lost or stolen, and users need to be able to trust the device to create their keys properly in the first place.

“Air-gapped systems help, but they are not a perfect fix,” Bobby Gray, founder of TEXITcoin, told CoinDesk. “Security has to begin with how the keys are generated and continue through every part of the custody process.”

This is, unfortunately, where things went wrong for Coinkite, the maker of the Coldcard wallet.

A bug in the system

In March 2016, the Toronto-based bitcoin company told customers it was sunsetting its hosted hot wallet. Running an online financial services company had brought persistent floods of junk internet traffic aimed at knocking their services offline, along with mounting legal costs and regulatory complications.

Advertisement

Instead, Coinkite said it wanted to try something different. It wanted to build decentralized hardware and “software-not-as-a-service.” That was early in crypto’s history, before Bitcoin’s second halving, when one entire bitcoin was trading slightly above the $400 mark.

Coinkite’s pivot first produced Opendime in April 2016. The small USB stick generated and concealed a private key, allowing bitcoin to be passed from one person to another like a physical bearer instrument. Physically breaking the device’s seal revealed the key and allowed the funds to be spent.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025