Threat Brief — 2026-08-01 — Wallets Drained, Backdoors That Survive Wipes
Executive summary: Galaxy Research has now mapped the full scale of the Coldcard hardware-wallet firmware flaw: 1,196 Bitcoin addresses swept in 41 minutes for $70.2M—nearly double the BTC total first reported yesterday. Microsoft has failed to fully remediate the Copilot prompt-worm vulnerability 144 days after disclosure. Russian state actors' OWAReaper backdoor has gained new technical detail showing GitHub-aware persistence that survives Windows reinstalls. Separately, Senator Schumer is pressing Apple over Chinese military-linked memory chips potentially entering iPhones.
Top items
- Coldcard wallet flaw scope confirmed at $70.2M — Galaxy Research mapped the complete sweep: an attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, stealing 1,082.65 BTC (~$70.2M), tied to a firmware flaw in the Bitcoin-only Coldcard hardware wallet. This significantly expands the originally reported 594 BTC figure. (First reported 2026-08-01 by RSS:xakep.) (src: The Hacker News)
- OWAReaper backdoor detail deepens: GitHub-aware, survives Windows reinstall — New technical reporting on the Russian state-group Exchange OWA zero-day exploit reveals the OWAReaper backdoor reads edits on GitHub to cover its tracks and cannot be removed by reinstalling Windows, making eradication extremely difficult for defenders. (First reported 2026-07-30 by BleepingComputer.) (src: SecurityLab)
- Microsoft Copilot prompt worm remains unpatched after 144 days — Microsoft has not fully remediated the Copilot vulnerability that enables an automated prompt-worm attack method, 144 days after being notified. The persistence of this gap extends the window for AI-assisted social engineering at scale. (First reported 2026-07-30 by RSS:xakep.) (src: SecurityLab)
- Schumer presses Apple over Chinese military-linked memory chips — Senator Chuck Schumer led a call to Tim Cook urging scrutiny of memory chips from CXMT and YMTC, companies linked to the Chinese military, which could end up in iPhones—raising supply-chain and national-security concerns about component provenance. (src: SecurityLab)
Themes
Persistence is the weapon of choice. Whether it's OWAReaper surviving OS reinstalls or Microsoft's 144-day failure to patch Copilot, attackers and flawed systems are increasingly hard to evict once embedded. Defenders should prioritise detection and eradication playbooks over initial-compromise prevention alone.
Supply-chain trust extends beyond software. The Coldcard firmware flaw and the CXMT/YMTC chip concern both illustrate that hardware provenance—wallet firmware and silicon components—is an under-examined attack surface.
