#BitcoinTheft
Jacob Irwin-Cline lost \$123K in Bitcoin after a scam driver in London drugged him and stole his phone, spotlighting rising crypto security risks.

#BitcoinTheft #CryptoScam #LondonCrime #CryptoSecurity #BTC
July 18, 2025 at 7:30 PM
🔒 Former IRS agent Chris Janczewski's MacBook Pro was key in solving the Bitfinex hack! His work transformed the blockchain into a digital crime scene, leading to significant seizures. ⚖️ #IRS #BitcoinTheft #CryptoCrime #Blockchain
November 21, 2024 at 5:44 PM
Former LAPD Officer Convicted in $350K Bitcoin Robbery 🚨 A jury found ex-officer Eric Halem guilty of armed robbery & kidnapping, stealing a hardware wallet from a teen. The conviction follows a 2-week trial. Sentencing March 31, 2026. #CryptoNews #BitcoinTheft
Cryptovka
CryptoMarket and Blockchain News
cryptovka.com
March 3, 2026 at 8:11 AM
Phishing Campaign Exploits COLDCARD Vulnerability Fears to Spread ScreenConnect #BitcoinTheft #COLDCARDphishingcampaign
Phishing Campaign Exploits COLDCARD Vulnerability Fears to Spread ScreenConnect
  A new phishing campaign is taking advantage of concerns over a recently revealed COLDCARD wallet vulnerability and the suspected theft of $88.6 million in Bitcoin to trick cryptocurrency users into installing remote-access software. Cybersecurity firm Proofpoint, which identified the campaign, said attackers are sending emails that impersonate COLDCARD and falsely claim that a security audit is being conducted across its hardware cold-storage wallets. The campaign follows the reported theft of around 1,367 Bitcoin, estimated to be worth $88.6 million, from 4,585 addresses. The incident is believed to have been linked to a random number generation flaw affecting several COLDCARD models and firmware versions. The fraudulent emails originate from compliance@coldcardteamnews.com and carry the subject line "Hardware audit now available." Recipients are told that recent security findings have prompted COLDCARD to verify devices across different hardware revisions. "We are writing to inform you of a coordinated security audit now underway across the COLDCARD device network. Recent findings have prompted us to verify the integrity of hardware across all revisions, and your participation is needed," reads the fake security audit emails. The messages direct recipients to a supposed "Security Verification & Incident Reporting Tool." The attackers claim that the process is air-gapped, does not require users to provide their recovery seed and must be completed by August 10. Clicking the "Access the Audit Tool" button takes users to coldcardcompliance.com, a fraudulent website designed to resemble COLDCARD. Visitors are then prompted to click "Start Hardware Audit" to download the alleged diagnostic tool. The site also features a live "Customer Service" chat function, which is presented as a way for users to receive assistance with their COLDCARD devices. According to conversations reviewed by Proofpoint, an operator asks victims whether they are using Windows or macOS before providing further instructions. Windows users are told to execute the downloaded file. When one victim reported seeing a black command window and an administrator prompt, the operator claimed the prompt was necessary to begin installation and instructed the user to select "Yes." Proofpoint suspects that the chat interactions are being conducted by human operators rather than an automated system. This would allow the attackers to address victims' concerns directly and persuade hesitant users to continue with the installation. Fake diagnostic tool installs ScreenConnect Proofpoint said clicking "Start Hardware Audit" downloads a batch file named Coldcard_Diagnostic_Tool.bat from a GitHub account. An analysis by BleepingComputer found that the 25.7MB batch file contains two Base64-encoded files embedded within it. When executed, the script initially appears to run a diagnostic check. In reality, it determines whether the victim has administrator privileges. If elevated access is unavailable, it uses PowerShell to restart itself and trigger a User Account Control prompt. The script subsequently extracts the embedded files into a randomly generated directory inside the Windows temporary folder. The files are saved as setup.msi and docusign.exe before being decoded using Windows certutil. After installing setup.msi, the script launches docusign.exe, displays an "Installation Complete" message and removes the temporary directory. The executable is a legitimate, digitally signed program associated with a DocuSign printer driver and serves as a distraction from the malicious activity. The setup.msi package, however, installs ConnectWise ScreenConnect, a remote-management application that can provide attackers with access to the compromised computer. Proofpoint said the malicious installation connects to activeretirementrelocation[.]com, which serves as the ScreenConnect command-and-control server operated by the attackers. Once a connection is established, threat actors could potentially control the affected computer remotely, steal sensitive information or cryptocurrency, and deploy additional malicious software. Proofpoint also warned that the compromised access could ultimately be leveraged to deploy ransomware.
dlvr.it
August 23, 2026 at 9:28 PM
https://www.newsmason.com?query=%22на%20выборах%22
September 8, 2026 at 4:03 AM
Bitcoin Lightning Nodes Drained Through Critical BTCPay Server Flaw #BitcoinLightningNetwork #BitcoinSecurity #BitcoinTheft
Bitcoin Lightning Nodes Drained Through Critical BTCPay Server Flaw
There has been another security breach of Bitcoin payment infrastructure as attackers exploited critical vulnerabilities in BTCPay Server deployments to steal funds from Lightning nodes. Transactions via Lightning Network are faster and more cost-effective than traditional bitcoin transactions, affecting merchants and other operators.  An attack was observed late Friday involving LND nodes connected to BTCPay Server. Using the vulnerability, an unauthenticated remote attacker may be able to access .macaroon credentials related to Lightning Nodes, according to BTCPay. These credentials grant access to Lightning nodes and, once compromised, could enable the node to be controlled and its funds moved.  According to BTCPay, real funds were stolen, and operators of LND were advised to upgrade immediately to version 2.4.2. A system that cannot be updated should be taken offline until the vulnerability is addressed. No details have yet been provided about how many installations were affected or how much bitcoin was lost. Foundation's CEO Zach Herbert stated that attackers drained the company's BTCPay Lightning node, shut down its payment channels, and transferred the funds available. In contrast, the company's separate hot wallet for BTCPay on-chain was unaffected by the attack. A Bitcoin publication, Citadel21, announced that its Lightning node had also been compromised and swept. Citadel21 stated that only a small amount of funds were stored on the affected node.  A vulnerability was previously reported to BTCPay by members of the Bitcoin Red Team, which is a group that investigates security flaws in Bitcoin-related software. Craig Raw, Rob Hamilton, Calle and Evan Kaloudis were credited with reporting the issue and assisting with its analysis, according to BTCPay.  A key concern of the incident is the risk posed when vulnerabilities are discovered while affected systems remain vulnerable. By the time the public warning was issued, attackers had already exploited the flaw against live servers. After its initial alert, BTCPay clarified that the vulnerability does not affect its standard on-chain wallets, including hot wallets created within the company.  Initially, LND deployments were exposed, however funds stored in LND's own on-chain wallet, which is also under the affected node, may also be vulnerable. While operators attempt to secure affected systems, BTCPay has not provided technical details regarding the flaw. A detailed postmortem is expected to be released within the next few days.  LND Deployments Remain the Primary Exposure BTCPay Server installations configured to use Lightning payments can be affected by the vulnerability. If hackers have compromised macaroon credentials, they can gain access to the affected node, making exposed Lightning funds a direct target. The credential exposure has not affected BTCPay's standard on-chain wallets.  A LND node's on-chain wallet does not receive protection from that security breach, and funds in the wallet may continue to be accessible if the node is compromised. Researchers are taking a close look at widely used codebases following a series of security concerns pertaining to Bitcoin-related software.  The Bitcoin Red Team identified the issue before attackers began exploiting exposed installations, giving operators limited time to implement the available fix. So far, BitcoinPay has not provided detailed technical information regarding this vulnerability while affected operators have begun to secure their systems. It is expected that the project will publish a comprehensive postmortem in the coming days that will provide additional information regarding the flaw, the attack path, and the extent of the breach.  Operators using LND behind BTCPay Server should use version 2.4.2 as their current mitigation plan. Until the vulnerability has been addressed, systems which cannot be patched should remain offline. This incident illustrates the security risks associated with cryptocurrency payment infrastructure as well as the importance of patching exposed Lightning nodes as soon as possible.
dlvr.it
August 29, 2026 at 1:20 PM
Coldcard Bitcoin Wallets Hit by Ongoing Attack Exploiting Key Generation Flaw #BitcoinHack #BitcoinTheft #BitcoinWalletSecurity
Coldcard Bitcoin Wallets Hit by Ongoing Attack Exploiting Key Generation Flaw
A software flaw in Coldcard hardware wallets has raised fresh concerns about the security of offline cryptocurrency storage after a software flaw in Coldcard hardware wallets allowed attackers to drain millions of dollars in Bitcoin.The attack has affected thousands of wallets using Coinkite’s Coldcard devices.  By August 3, about 1,367 Bitcoin worth US$86 million had been stolen from more than 4,500 wallets by August 3. Cold wallets are widely considered among the most secure ways to store cryptocurrency, as they keep private keys away from internet-connected devices. The Coldcard incident shows,offline storage cannot protect funds if there is a weakness in the process by which cryptographic keys are generated.  Predictable Seed Phrases Exposed Bitcoin Wallets The problem centers on how Coldcard devices generated the seed phrases used to recover wallets that will be used to recover and control a Bitcoin wallet in the central issue. A flaw in Coldcard's random-number generation process could produce predictable values instead of sufficiently random keys, according to a Block's engineering team analysis. Coldcard devices included a fallback mechanism based on deterministic information, including serial numbers.  The flaw allowed attackers to calculate vulnerable wallet keys and move the funds. The losses quickly mounted over the following days. According to initial reports, the loss amount on July 31 was approximately US$38 million, however within days, the amount had more than doubled.  Initially, Jonathan Goodman believed all three of his wallets would not be affected after checking. However, he discovered that all three had been emptied within minutes of one another on July 29.  Coinkite Releases Fixed Firmware Bitcoins controlled by seed phrases generated through affected firmware may be at risk, as confirmed by Coinkite. The flaw has also renewed scrutiny of hardware wallet security, regarding the assumptions surrounding hardware wallets, Coinkite has since released fixed firmware for the affected models and release tracks.  Although offline access eliminates many Internet-based attack routes, it does not eliminate vulnerabilities in the hardware, firmware, or cryptographic processes required to create those keys. The incident also shows that keeping a wallet offline does not remove every security risk. Despite being physically disconnected from the internet, a wallet may still be vulnerable if its cryptographic keys can be predicted or reconstructed.  Cold Storage Does Not Eliminate Cryptocurrency Risk The Coldcard attack comes as cryptocurrency theft continues to cause major losses across the industry. Approximately US972 million of cryptocurrency were stolen during the first half of 2026, substantially lower than the US2.3 billion stolen during the same period in 2025, according to TRM Labs. A total of 207 hacking incidents were recorded during the first six months of 2026, the highest total in the firm's history.  A TRM Labs report indicates that infrastructure and key compromises account for approximately 15 percent of incidents, yet 76 percent of losses were caused by them. The incident highlights a basic problem with self-custody that self-custody self-custody does not eliminate the risk of losing funds. Hardware wallets can greatly reduce online threat exposure. Their security still depends on how reliably the device generates and protects private keys.  Affected users should check whether their wallet seeds were generated with vulnerable firmware and follow Coinkite’s guidance that their wallet seeds were generated using vulnerable firmware and follow the manufacturer's remediation instructions.The Coldcard incident shows that keeping a hardware wallet offline is only one part of cryptocurrency security. The software and cryptographic processes used to generate its keys can be just as critical.
dlvr.it
August 21, 2026 at 7:46 AM
Canadian Bitcoin Users Seek Legal Action Against Coinkite After $155 Million Hack

🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️

#cryptocurrency #legalaction #bitcointheft

View full AI summary:
Canadian Bitcoin Users Seek Legal Action Against Coinkite After $155 Million Hack
A U.S. firm specializing in distressed cryptocurrency claims, 117 Partners, is organizing victims of the Coinkite Inc. hack to pursue legal action against the Toronto-based crypto wallet provider. The hack exploited a software vulnerability in Coldcard hardware wallets, stealing over $155 million worth of bitcoin. Canadian users account for more than 25% of losses, according to blockchain analysis firm Chainalysis. Lawyers are exploring two legal avenues: product liability lawsuits against Coinkite or tracing stolen funds to freeze them before conversion to fiat currency. While recovery remains uncertain due to the scale of losses and potential fund disappearance, victims are being encouraged to submit claims through 117 Partners' intake form. The company previously handled FTX bankruptcy claims but is currently focused on helping Coinkite victims organize their cases rather than purchasing claims immediately. Legal experts warn that suing Coinkite risks bankrupting the firm, making alternative recovery strategies critical for affected users.
en.killbait.com
August 8, 2026 at 4:02 AM
Coldcard Wallet Security Incident Linked to Multi-Million Dollar Bitcoin Theft #BitcoinTheft #BitcoinWalletSecurity #Coinkite
Coldcard Wallet Security Incident Linked to Multi-Million Dollar Bitcoin Theft
  There has been a connection between a critical firmware flaw in the Coldcard hardware wallet and one of the largest cryptocurrency thefts of the year, after hackers allegedly drained nearly $70.2 million in Bitcoins (BTC) from 1,196 wallets on July 30 by exploiting a critical firmware flaw, according to Galaxy Research.  A firmware integration error introduced in March 2021 is responsible for the vulnerability, which affects Coldcard, a Bitcoin-only hardware wallet developed by Canadian company Coinkite. According to security researchers, affected firmware versions generated wallet recovery seeds using deterministic software-based pseudorandom number generators (PRNGs) rather than the hardware random number generators (RNGs) of the devices. In this way, the amount of randomness necessary to create cryptographic seeds has been significantly reduced.  Block researchers explained that, under certain circumstances, an attacker could reproduce seed values offline under sufficient knowledge of the device's unique identification number and internal state. Attackers can then identify and steal funds from vulnerable wallets by matching those candidate seeds against publicly available blockchain addresses.  It was found that the flaw occurred as a result of a production configuration error resulting in affected Coldcard devices relying on MicroPython's Yasmarang pseudorandom number generator instead of the hardware random number generator intended for them.  During initialization of the fallback algorithm, unique identifiers and timer values of the device were used without the collection of fresh entropy, leading to significantly more predictable recovery seeds. Contrary to conventional cryptocurrency attacks directed towards exchanges, smart contracts, and online wallets, this incident involved hardware wallets designed to remain offline.  According to security experts, the compromise did not require the device to be connected directly to the internet. As an alternative, attackers are alleged to have generated a large number of possible recovery seeds offline, derived the addresses of the corresponding wallets, and compared them with blockchain records available on the Internet until they found matching wallets containing Bitcoins.  As determined by investigators, the attacker generated candidate recovery seeds using hardware configured under similar conditions, then deduced the Bitcoin address corresponding to each seed. The address of a blockchain is publicly visible, and matching the address of a recreated seed to the address of an active wallet would allow the attacker to retrieve the private keys and transfer funds without physically accessing the victim's device.  A firmware update was released by Coinkite on July 31 for all Coldcard models that were affected. However, the company has stressed that installing the update alone will not secure wallets that have been created with vulnerable firmware.  Users whose recovery seeds were generated on affected versions have been advised to generate new seeds utilizing the patched firmware and transfer their Bitcoin to new wallets as soon as possible. It is important to note that even when an old seed is restored on an updated firmware or another wallet, the underlying weakness remains.  Galaxy Research has reported that the stolen funds were transferred in batches over a period of six Bitcoin blocks rather than through a single continuous transaction. Observations by researchers indicated that three interconnected blocks did not show any related activity, indicating that the transactions were deliberately grouped before being broadcast.  Coldcard versions 4.0.1 to 4.1.9, Mk4 and Mk5 versions before 5.6.0, Q versions before 1.5.0Q, and Edge builds released prior to the latest patches are affected by this firmware. The vulnerability has been estimated by Coinkite to reduce the effective entropy of wallet recovery seeds by approximately 40 bits for Mk3 devices and around 72 bits for Mk4, Mk5 and Q devices. This results in significantly lower levels of security than a standard 12-word BIP-39 seed's 128-bit encryption.  Researchers noted that practical challenges in recovering a seed are still influenced by factors such as device characteristics, boot timing and computational resources. It was noted by Coinkite that wallets generated with at least 50 fair and private dice rolls do not suffer from this vulnerability. Despite the fact that a strong passphrase provided additional security, users should nonetheless replace vulnerable seeds with stronger BIP-39 passphrases.  Multisignature wallets will not be compromised if all signing devices are not affected by the same issue. There has been no public identification of the attacker. According to Galaxy Research, the observed on-chain transaction patterns indicate a coordinated wallet sweep, but do not conclusively indicate theft. Researchers also observed that blockchain activity followed a distinctive transaction pattern, though they cautioned that on-chain analysis alone cannot conclusively prove theft.  The pattern instead pointing to coordinated wallet sweeps consistent with a single operator or related group of operators, which has raised concerns over the importance of secure random number generation in cryptocurrency wallets. In order to store cryptocurrency offline securely, hardware devices that remain disconnected from the internet must maintain strong cryptographic entropy during wallet creation, and any weakness in that process can compromise its security.  After Coinspect released the "Ill Bloom" vulnerability in just weeks past, another weak random number generation vulnerability has led to more than $5 million worth of cryptocurrency theft across Bitcoin, Ethereum, Tron, Rootstock and Polygon, with the "Ill Bloom" vulnerability being linked to more than $5 million in cryptocurrency thefts. Even wallets designed with strong offline security can be compromised by vulnerabilities in cryptographic randomness.  A subsequent update from Galaxy Research identified two more suspected Coldcard-related wallet sweeps, which increased the estimated losses to 1,367.05 Bitcoins, worth approximately $88.6 million across 4,585 addresses, for a total of 1,367.05 Bitcoins. In addition to sharing details with federal investigators, compliance organizations and cybersecurity teams about nearly 600 suspected attacker-controlled addresses, the firm said the activity is ongoing.
dlvr.it
August 3, 2026 at 3:04 PM
A UK man claims his wife used a CCTV camera to steal his $172M Bitcoin password. Could love really lead to such betrayal? #BitcoinTheft

https://gizmodo.com/uk-man-accuses-spouse-of-stealing-172-million-bitcoin-password-via-cctv-camera-2000734846
UK Man Accuses Spouse of Stealing $172 Million Bitcoin Password via CCTV Camera
Code is law, some say. That doesn t mean normal laws do not apply.
gizmodo.com
March 18, 2026 at 12:31 AM
A 19-year-old pleads guilty in a $410M Bitcoin heist that culminated in his parents' kidnapping. What would you do in his shoes? #BitcoinTheft

https://www.1news.co.nz/2025/06/21/man-pleads-guilty-after-410m-bitcoin-theft-led-to-parents-kidnapping/
Man pleads guilty after $410m Bitcoin theft led to parents kidnapping
Veer Chetal, 19, was one of three men charged with stealing 4100 Bitcoins from a victim in Washington, DC last August.
www.1news.co.nz
June 21, 2025 at 10:31 PM
Blockchainbulletin News!
🚀⚡️💰 $7M of stolen Bitcoin frozen thanks to ZachXBT and Binance! Learn how they're fighting back against crypto theft. #BitcoinTheft #BinanceSecurity #CryptoRecovery

Click here↓↓↓
blockchainbulletin.net/2025/05/03/z...
ZachXBT & Binance Team Up: $7M of Stolen Bitcoin Frozen! - blockchainbulletin
🚀⚡️💰 $7M of stolen Bitcoin frozen thanks to ZachXBT and Binance! Learn how they're fighting back against crypto theft. #BitcoinTheft #BinanceSecurity #CryptoRecovery
blockchainbulletin.net
May 3, 2025 at 8:00 AM