Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.

A recent report by Galaxy Research has linked a suspected theft of approximately 1,367.05 Bitcoin, valued at nearly $89 million, to a weakness in the seed generation process of COLDCARD hardware wallets. The research suggests that seeds generated on these devices may have been susceptible to compromise, leading to the significant loss of funds.
The core of the issue appears to be a flaw in the entropy or randomness used during the generation of cryptographic seeds on COLDCARD devices. Hardware wallets rely on robust random number generation to create unique and unpredictable seeds, which are the master keys to a user's cryptocurrency. If the randomness is insufficient or predictable, an attacker could potentially re-create or guess a seed, thereby gaining unauthorized access to the associated funds. This class of vulnerability often stems from issues in the device's true random number generator (TRNG) or pseudorandom number generator (PRNG) implementation.
Coinkite, the manufacturer of COLDCARD, has acknowledged the situation. Their statement indicates that devices that have already generated seeds using the potentially flawed process cannot be retroactively repaired through software updates. This means that users who generated their seeds on affected devices would need to migrate their funds to a new, securely generated seed on a different device or a device with a confirmed patched seed generation mechanism.
The scope of this issue would primarily affect users who generated their wallet seeds on COLDCARD devices during the period when the vulnerability was present. It underscores the critical importance of secure seed generation in hardware wallets, as the seed is the single point of failure for the entire wallet. Without a strong, unpredictable seed, the security assurances of a hardware wallet are severely undermined.
Typical mitigation advice for users of hardware wallets, particularly when a seed generation flaw is identified, includes immediately moving funds to a new wallet with a securely generated seed. Users are often advised to verify the integrity of their hardware wallet's firmware and to ensure they are using the latest, officially released versions. For new devices, it is generally recommended to generate a seed on a trusted, air-gapped computer or directly on the hardware wallet itself, ensuring no compromise during the generation process.
This incident highlights the ongoing challenges in securing digital assets, even with specialized hardware. It reinforces the industry's focus on rigorous auditing of cryptographic implementations, particularly in critical components like random number generators. The immutability of a compromised seed, as noted by Coinkite, serves as a stark reminder that foundational cryptographic weaknesses can have long-lasting and financially devastating consequences for users.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.