Threat Brief — 2026-08-04 — Coldcard losses climb, white hats unmasked
Executive summary. The COLDCARD hardware wallet key-generation flaw has entered its fourth wave of thefts, with losses now estimated at ~$114 million (1,816 BTC) across 5,200+ addresses — a significant jump from the $88.6M figure reported just three days ago. Separately, HackerOne is rolling out mandatory identity verification for researchers, effectively ending the era of truly anonymous bug-bounty submissions and reshaping the incentives for white-hat disclosure.
Top items
- COLDCARD theft estimate revised up to $114M (1,816 BTC) across 5,200+ addresses — fourth wave underway. This is a developing story first reported 2026-08-01 by RSS:xakep, where losses were estimated at $88.6M. The attacker has now drained approximately 1,816 BTC from over 5,200 vulnerable addresses generated by COLDCARD hardware wallets, with a fourth wave of thefts recorded Monday morning. Any user who generated keys on an affected COLDCARD device should assume compromise and migrate funds immediately. (src: RSS:xakep) — first reported 2026-08-01 by RSS:xakep
- HackerOne mandates identity verification, ending anonymous white-hat submissions. HackerOne is requiring all researchers to verify their identities, closing a long-standing anonymity window that many bug hunters relied on. This shifts the power balance toward platforms and regulated entities and may discourage submissions from researchers in high-risk jurisdictions or with privacy concerns. No CVE or active exploit involved; the impact is operational and policy-level for the bug-bounty ecosystem. (src: RSS:anquanke)
Themes
Cryptocurrency supply-chain trust eroding further. The COLDCARD escalation — from $88.6M to $114M in three days — reinforces that hardware wallet RNG flaws are not theoretical; they produce sustained, mechanised draining over weeks. Organisations holding crypto custodied via hardware wallets should audit their key-generation provenance, not just their key storage.
Anonymity under pressure across the security community. HackerOne's identity-verification mandate arrives alongside other recent de-anonymisation trends (automated doxing tools, sanctioned-country developer verification changes). The operational security calculus for researchers and red-teamers is shifting — anonymity is no longer a default but a privilege that platforms can revoke.
