The Daily Brief: August 13, 2026 — Crypto Safety News
The morning brief
If you read one story today, read the Blockaid point: "private-key compromise is the original sin of crypto." The day’s feed is dominated by a single thread — private-key leakage — and the related knock-on effects across cold storage, phishing, and stablecoin depegs. Start with the Coldcard cluster: the bug in how the device generated seed phrases drained roughly 1,816 BTC (~$116M) over a seven-day window in late July, and adversaries are still moving the funds. Trezor’s warning about rising phishing attempts is the natural sequel — anyone who held a Coldcard in the affected window is now a higher-value target for fake "security update" emails and malicious firmware pages. The address-poisoning stories (the $100K USDT slice, the $26M whale) are a different mechanism but a related lesson: even when the private key is not breached, the *display* of the recipient can be poisoned to redirect funds. Together, three losses in 24 hours span the three main ways custody actually fails in 2026 — device bug, phishing, and lookalike addresses. The Coreum XRPL bridge exploit ($200K) is a smaller reminder that smart-contract deposit-verification flaws remain a live attack surface, even on chains marketed as “fast and cheap.” None of this is novel on a technical level; what is new is the volume. The year-to-date total across the tracked incidents now sits north of $1.2B across 276 hacks, with the second half of the year still ahead. The mitigations we’ve written about before — verify recipient addresses on a hardware wallet’s screen, refuse to type seed phrases anywhere, treat firmware updates as high-trust events — are the same mitigations, but the urgency is higher. The pattern: defense-in-depth behavior is the only defense that scales against attackers who have already accepted that the cost of trying is going down.
Today’s items (15)
Hackers steal over $130M by exploiting bug in offline hardware wallets | TechCrunch
The headline number ($130M) is the campaign-level total; the device-level bug is in the seed-phrase generation routine, which is a fundamentally different failure mode than a phishing attack. Wallets generated on a Coldcard during the affected window should be considered compromised even if the funds have not moved.
Source · techcrunch.com This is considered a “cold” wallet, as opposed to “hot” wallets that are online, such as those in apps, browser extensions, and accounts on commercial crypto exchanges like Binance or Coinbase. As it turns out, hackers figured out that there was a flaw in how Coldcard wallets generated users’ seed p
Is Bitcoin Self-Custody Dead? Inside The Coldcard Hack
The Forbes piece is the long-form companion to the TechCrunch story. It focuses on the industry reaction — the question of whether “cold storage” is still a meaningful category if the device generation step can be backdoored. Worth reading for the analyst quotes on the supply-chain attack surface.
Source · forbes.com On July 30th, attackers began draining bitcoin from addresses linked to seeds generated by compromised “cold storage” wallets. The devices, called Coldcards, were manufactured by Coinkite, and were widely viewed as the best choice for those who are paranoid in the extreme about cybersecurity.
Trezor Warns Of Rising Phishing Attempts Amid Coldcard Hack 2026
Trezor is using the Coldcard incident as a launching pad for a phishing warning — which is the right call. The threat model for anyone who held a Coldcard in the affected window now includes impersonator emails, fake Trezor Suite downloads, and phony firmware update pages.
Source · tronweekly.com LATEST: 🚨 Trezor says it is ... 5, 2026 · Trezor’s alert is consistent with the industry recommendations which state that seed phrases should never be typed on the Web, and that firmware updates should be installed only via official channels....
What happens when a stablecoin depegs for 30 seconds – CoinSpectator – Real-time Cryptocurrency News
Most retail users do not realize how fast a depeg can happen. The 30-second window is the practical reason exchanges need to handle liquidations carefully — and why the next iteration of risk controls will likely include depeg-buffer timeouts.
Source · coinspectator.com Most traders assume depegs are slow. They are not. Inside the 30 second window where arbitrage bots, liquidation cascades, and oracle lag collide to turn a mino
What Is USD1 Stablecoin? A Beginner's Guide to World Liberty Financial in 2026
USD1 is the new entrant in the dollar-pegged stablecoin category. The BitGo custody arrangement is the technical detail that matters most — BitGo is the regulated trust company that holds the reserves, which is the closest thing to a “real” backing in this category.
Source · btcc.com USD1 is a dollar-pegged stablecoin launched by World Liberty Financial in 2025 and designed to maintain a value of around US$1. BitGo issues USD1, while World Liberty Financial and affiliated entities own the USD1 brand and provide related services. USD1 is backed by reserve assets including U.S. do
Coldcard bitcoin exploit exposes crypto's 'original sin' of private keys, Blockaid CEO says | The Block
The “original sin” framing is the cleanest articulation yet of why private-key leakage is the dominant attack vector. The Blockaid data — 75% of H1 2026 losses from private-key compromises — is the line that should anchor any custody decision.
Source · theblock.co Blockaid said in its most recent report that nearly 75% of the funds lost to crypto exploits during the first half of 2026 resulted from private-key compromises.
Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit | Fortune
The Galaxy Research on-chain analysis is the most useful detail in the Fortune piece — 1,816 BTC moved off the affected addresses, which gives a hard lower bound on the loss. The update timeline suggests the attackers had access to the seed phrases for at least a week before the first drain.
Source · fortune.com An on-chain analysis by blockchain intelligence firm Galaxy Research revealed that the hackers have already moved approximately 1,816 Bitcoin, worth nearly $116 million, off those wallets.
Bitcoin at Center of $1.2 Billion Crypto Hack Wave Spanning 276 Exploits - COINOTAG
276 hacks in 2026 is the cumulative denominator. The fact that losses are spread across BTC, ERC-20, and bridge exploits tells you the attack surface is broad — there is no single vector to defend against.
Source · en.coinotag.com REKT data shows 276 crypto hacks totaling $1.2B in 2026. Coldcard exploit drains 1,719 BTC, BTCPay patches critical flaw, Binance sues RedotPay for $472.8M.
Phishing attack drains $25.6 million from crypto whale, second loss tied to same wallet
The same address was hit in September 2023 and again this week — a $24.2M loss then, $25.6M now. The pattern is approval-phishing: a malicious token approval that lets the attacker drain any token in the wallet. Approvals should be limited by spend cap and revoked proactively.
Source · en.coin-turk.com In September 2023, the same address fell victim to a phishing exploit facilitated by malicious token approvals, according to analyst Specter. That breach resulted in the loss of $24.2 million, including 4,851 Rocket Pool ETH and 9,579.2 Lido ...
Address poisoning attack drains $100K USDT
The 0.005 USDT dust transaction is the giveaway — any address in your history that has sent you a tiny amount that you did not request is a poisoned-address candidate. The fix is to verify the full address on a hardware wallet’s screen, not match the first/last four characters.
Source · crypto.news An attacker then inserted a fraudulent address into the history with a 0.005 USDT dust transaction, after which the victim mistakenly sent 49,999,950 USDT to the poisoned address.
Address poisoning attack drains $100K USDT
This is the second report of the same $100K USDT loss — independent confirmation with the 66-day gap between the dust transaction and the drain. The behavioral pattern is now: send dust → wait months → exploit when the victim is in a hurry.
Source · cryptonews.net A crypto user has lost approximately 100,000 $USDT after transferring the funds to a lookalike wallet address planted in the victim’s transaction history 66 days earlier. Cyvers Alerts reported on Aug. 11 that its monitoring system detected the loss after the victim sent funds to an address controll
Public-key cryptography - Wikipedia
The Wikipedia refresher is the canonical reference for the underlying cryptography. The side-channel attack mention is the operational point — even mathematically secure schemes can be defeated by implementations that leak information through timing, power, or EM emissions.
Source · en.wikipedia.org The "knapsack packing" algorithm was found to be insecure after the development of a new attack. As with all cryptographic functions, public-key implementations may be vulnerable to side-channel attacks that exploit information leakage to simplify the search for a secret key.
Crypto Whale Loses $26M After Apparent Private Key Compromise
The TLBL-linked wallet suggests a single-entity treasury provider. The “private-key compromise” framing is the third such incident in the day’s feed — the convergence is the actual story, not the individual amounts.
Source · cryptopotato.com The slight difference between the figures from Lookonchain and PeckShield comes from the asset valuations included in their respective tracking. Both accounts, however, point to the same broad event — a large TLBL-linked wallet was drained, with private-key compromise identified as the apparent caus
Fryday #3: The Contract Is No Longer the Whole Attack Surface | by Aleksandr Korolev | Aug, 2026 | Block Magnates
TRM Labs' H1 2026 count (207 hacks, ~$972M) is the cleanest year-over-year comparison in the day’s feed. The “incidents more than doubled, dollars are down” pattern is the deeper signal — attackers are optimizing for higher-frequency, lower-payout exploits.
Source · blog.blockmagnates.com TRM Labs recorded 207 crypto hacks and approximately $972 million stolen in H1 2026, compared with 83 incidents and about $2.3 billion in H1 2025. The number of incidents more than doubled while total losses fell because 2025 contained unusually ...
Coreum Hack (2026) - $200K Lost | Smart Contract Hacking
The Coreum-XRPL bridge deposit-verification flaw is a useful contrast to the day’s private-key stories — same outcome (loss of funds), different mechanism (logic bug in the bridge relay). The 97-minute window from exploit to drain is the operational signal.
Source · smartcontractshacking.com On August 9, 2026, the Coreum cross-chain bridge connecting to the XRP Ledger (XRPL) was exploited due to a deposit verification flaw, resulting in the theft of 199,916 XRP (valued at approximately $200,000) across 94 transactions within 97 minutes.