Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AICryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Security firm Coinspect has traced $5.7 million in cryptocurrency wallet drains to a weak random number generator in CryptoJS that has existed for 12 years. The vulnerable CryptoJS.lib.WordArray.random() function provided insufficient entropy for generating recovery phrases in five affected crypto wallet applications, enabling attackers to compromise wallets in two major sweeps since late May.
AIColdcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
A firmware vulnerability in Coldcard hardware wallets enabled an attacker to steal approximately $70.2 million in Bitcoin (1,082.65 BTC) from 1,196 addresses in just 41 minutes on July 30. Galaxy Research traced the exploit to a March 2021 firmware integration error that caused seed generation to rely on a predictable software pseudorandom number generator instead of secure random generation. The
AICrypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments
Check Point Research has identified a sophisticated crypto clipper malware campaign that uses multiple distribution channels including paid posts on legitimate news sites, fake reviews, AI-generated narration, and abuse of VirusTotal comments. The threat actor operates through a coordinated infrastructure including WordPress phishing pages, GitHub and SourceForge projects with fake accounts, and Y
AINew Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Zimperium's zLabs has identified Rokarolla, a sophisticated Android banking trojan that targets 217 banking and cryptocurrency applications with 137 remote commands. The malware enables attackers to gain comprehensive control over infected devices, including stealing lock-screen PINs, intercepting SMS messages, manipulating clipboard content to redirect cryptocurrency payments, and disabling Googl
AIEuropol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs
Europol has successfully disrupted AudiA6, a major cryptocurrency laundering service that facilitated money laundering for ransomware gangs and cybercriminal networks. The operation eliminated a critical financial infrastructure that processed an estimated €336 million (~$389 million) in illicit proceeds, representing a significant blow to cybercriminal monetization capabilities.
Critical Zcash Vulnerability Found and Fixed
Security researcher Taylor Hornby discovered a critical vulnerability in Zcash's Orchard privacy pool that could have allowed attackers to create cryptocurrency from nothing by exploiting a validation check flaw. The vulnerability, found using Claude Opus 4.8, has been patched, but there's no way to determine if it was previously exploited. This incident highlights fundamental security concerns wi
