A newly disclosed firmware exploit affecting Coldcard hardware wallets has renewed scrutiny over the security of self-custody Bitcoin storage.
The vulnerability has been linked to concerns about firmware integrity, though specific technical details about the nature of the exploit, affected device versions, or confirmed losses were not provided in the available reporting.
For holders using hardware wallets, the incident is a reminder to verify firmware sources, check for official security advisories from the manufacturer, and avoid installing unverified updates.
📈 Wall Street's Bitcoin ETFs Sit on $16.3B Unrealized Loss
US spot Bitcoin ETFs are collectively underwater, with Bloomberg Intelligence estimating the average net cost basis of ETF capital at $82,249 per coin — roughly 22% above current prices — translating to $16.33 billion in unrealized losses.
An August 14 deadline requires large investment managers to disclose their June 30 Bitcoin ETF holdings via regulatory filings. The disclosures will reveal which institutional players have reduced or exited positions since the market downturn began.
The filings represent the most transparent look yet at institutional behavior during this correction, making August 14 a closely watched date for gauging Wall Street's conviction in Bitcoin exposure.
🤖 AI&Future Tech
New models. Billion-dollar bets. Chips, robots, launches — the pace never slows down.
AI · Big Tech · Gadgets · Robotics. The short version of everything that matters.
🔐 $70M in Bitcoin Drained Without Touching the Devices
Galaxy Research has detailed how attackers stole over 1,000 BTC — worth approximately $70 million — from nearly 1,200 cold wallets, without ever physically accessing the hardware.
The vulnerability was not in the devices themselves but in weak seed generation. Poor randomness during wallet setup allowed the attacker to recreate likely private keys entirely offline, then sweep funds from affected wallets. The search for additional vulnerable wallets is reportedly still ongoing.
Cold wallets are widely considered the gold standard for crypto security, but this case shows that a compromised seed generation process can nullify that protection entirely. Users relying on hardware wallets should verify that their seed phrases were generated with strong, verified randomness — and consider migrating funds if there is any doubt about the integrity of the original setup.
⚖️ Bessent quotes Satoshi to push Senate crypto vote
US Treasury Secretary Scott Bessent invoked Bitcoin creator Satoshi Nakamoto to pressure Senate Democrats into holding an immediate vote on the Clarity Act, a bill aimed at establishing regulatory clarity for crypto markets.
Bessent used the reference as a rhetorical push to accelerate legislative action, framing the bill as aligned with the foundational principles behind Bitcoin's creation.
The Clarity Act is part of a broader effort in Washington to define the regulatory framework governing digital assets in the United States.
⚖️ MiCA transition period ends — EU crypto firms must hold licence now
The European Securities and Markets Authority has confirmed the end of MiCA's transitional period. Crypto-asset service providers that were operating under legacy national regimes across the EU must now hold a full MiCA authorisation or cease offering services to EU clients.
ESMA has drawn a clear line: no MiCA licence means no access to the EU market. Firms that have not secured authorisation are expected to wind down EU-facing operations until they comply.
The move marks a significant shift in how crypto businesses can operate within the bloc, replacing fragmented national frameworks with a single unified licensing standard under MiCA.