A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]

A vulnerability in the random number generation (RNG) component of COLDCARD hardware wallet firmware is suspected to be linked to the theft of approximately $88.6 million in Bitcoin from thousands of wallets. The flaw allowed attackers to potentially reconstruct wallet seeds generated by affected devices.
Digital asset research firm Galaxy Research identified an initial wave of transactions on July 30, draining about 1,083 BTC, valued at $70.2 million, from 1,196 addresses. This 41-minute attack occurred roughly 30 hours before Coinkite, the manufacturer of COLDCARD, publicly disclosed the vulnerability. Galaxy noted that every transaction in this wave used an identical, hardcoded fee rate of 30 satoshis per virtual byte and left no change output, suggesting the use of an automated tool by the attackers.
By August 1, Galaxy Research identified subsequent waves of theft, increasing the estimated total to 1,367 Bitcoin, worth approximately $88.6 million, stolen from 4,585 addresses. The stolen Bitcoin remained in attacker-controlled addresses at the time of Galaxy's report. Separately, Chainalysis observed that attackers prioritized high-value wallets, with about $30 million stolen in the first ten minutes and $1.8 million taken from a single victim, indicating prior identification and study of affected wallets.
Block's Bitcoin Engineering and Security teams, along with other researchers, analyzed the COLDCARD firmware after reports of thefts surfaced. They traced the issue to an integration error in the device's RNG code, disclosing their findings to Coinkite on July 30. The COLDCARD firmware, specifically versions 4.0.1 through 4.1.9 for Mk2 and Mk3 devices, and versions prior to 5.6.0 (standard) or 6.6.0X (Edge) for Mk4, Mk5, and Q devices, contained an error. This error caused the `ngu.random` function to default to MicroPython's deterministic Yasmarang fallback generator instead of the intended STM32 hardware RNG.
The fallback generator relied on the device's microcontroller identifier and system timing values, which are not considered cryptographically secure sources of randomness and could be observable or reconstructable. This allowed attackers to generate potential wallet seeds offline, determine their corresponding Bitcoin addresses, and compare them against addresses visible on the blockchain. A match would confirm the correct seed, enabling the generation of private keys needed to access and steal funds.
Coinkite has released new firmware versions to address the flaw: 4.2.0 or later for Mk2 and Mk3, 5.6.0 or later for standard Mk4 and Mk5 devices, 1.5.0Q or later for standard Q devices, and 6.6.0X or 6.6.0QX for corresponding Edge releases. However, updating the firmware does not remediate seeds generated with the flawed software.
Affected users are advised to verify their existing backup, install the fixed firmware, generate and securely record a new seed, verify the new wallet address on the device, send a small test transaction, and then move their remaining funds. The old backup should be retained until the migration is complete and confirmed.
Coinkite stated that seeds supplemented with at least 50 fair, independent, and private dice rolls are not considered at risk from this specific flaw. While a strong, unique BIP-39 passphrase can make exploitation more difficult, users should still migrate their funds as it does not fix the underlying seed vulnerability. Coinkite's TAPSIGNER, OPENDIME, and SATSCARD products are unaffected due to different codebases. Coinkite also confirmed that all COLDCARD devices awaiting shipment with the vulnerable firmware were destroyed, and customers whose devices had already shipped were contacted via email with a security advisory and migration instructions.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.