Security firm Coinspect reports that a wallet vulnerability dating back to 2018 resulted in the theft of $3.14 million last month, with Chinese users' assets at higher risk.
Related
Warning: A wallet generation vulnerability known as "Ill Bloom" leaves thousands of accounts at risk.
PANews reported on July 6th that, according to Coinspect Security, a wallet generation vulnerability called "Ill Bloom" is being exploited by attackers, allowing them to control affected wallets and steal funds. This vulnerability has affected wallets on multiple blockchains since 2018, and the affected wallets were still being generated weeks ago, indicating it did not originate from a single software wallet. Coinspect stated that hundreds of accounts had already lost approximately $3 million on May 27th, and another $2 million has been transferred from exposed wallets in the last few hours. Thousands of accounts remain at risk, covering Bitcoin, Ethereum and L2, Tron, and Solana. Coinspect has released an affected address checking tool and is urging wallet providers to integrate lightweight weak seed phrase detection functionality.
The Ministry of Industry and Information Technology issued a risk warning regarding the potential security backdoors in the AI programming tool Claude Code.
According to Odaily Odaily, the Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) of the Ministry of Industry and Information Technology recently discovered that the AI programming tool Claude Code has a security backdoor vulnerability, which poses a serious threat. Claude Code is an AI programming tool developed by Anthropic, an American company, which can autonomously complete code writing and repair tasks based on text requirements. Due to its built-in monitoring mechanism, it can send sensitive information such as user location and identity to remote servers without the user's consent. The affected Claude Code versions are 2.1.91 to 2.1.196. It is recommended that relevant units and users immediately conduct a comprehensive investigation. For development terminals that have installed the above-mentioned affected versions, they should immediately uninstall or upgrade to the latest secure version that has removed the relevant backdoor code. Strengthen the control of external access permissions and traffic monitoring of development tools within the core business network segment to prevent the unauthorized transmission of sensitive data.
Bitcoin Wallet Maker BitBox Says AI Found Severe Flaws in Firmware
The Swiss hardware-wallet maker found two severe bugs with the help of frontier AI models, and warns that older firmware leaves you exposed.
Crypto hacker losses decreased by 47% year-on-year in the first half of 2026, but the overall security situation has not improved.
According to Foresight News , citing Cointelegraph, total losses from cryptocurrency security incidents in the first half of 2026 amounted to approximately $1.32 billion, a 46.8% decrease year-over-year. However, CertiK warns that this figure is misleading. The data from the same period last year was severely distorted by the massive $1.4 billion theft from Bybit, the largest single hack in history. In reality, attackers are becoming more targeted and destructive. Specifically, phishing attacks resulted in $508.2 million in losses in the first quarter, while losses in the second quarter rose 59% quarter-over-quarter to $807.5 million. Over 70% of these losses came from the KelpDAO and Drift Protocol incidents, both believed to be the work of North Korean state-sponsored hackers. A report from TRM Labs during the same period also indicated that the number of attacks surged from 83 to 207 in the first half of the year, the highest on record, with smart contract vulnerability attacks accounting for 60%. CertiK also points out that private key and multi-signature wallet management remain the most vulnerable security areas that attackers can exploit. He recommends that protocol providers strengthen private key management from multiple levels, including hardware security, multi-signature governance, and geographically dispersed signers.
Bitget confirms $351M security breach, suspends withdrawals
Bitget said unauthorized transfers affected a limited number of hot wallets, while cold wallets and most platform assets remained unaffected.
Stablecoin payments firm dtcpay closes $25M round with SBI backing
Dtcpay plans to expand its merchant network and payment products after completing a $25 million Series A backed by Japan’s SBI Group.