Daily Security Intel

Archives
Log in
Subscribe
August 2, 2026

[SecurityIntel] 02 Aug | Coldcard Wallet Flaw Leads to $70M Theft

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, August 02, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Coldcard Wallet Flaw Leads to $70M Theft

CRITICAL

5

C2 IPs

0

OTX IOCs

9

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by critical vulnerabilities and sophisticated delivery vectors, including a maximum-severity CVSS 10.0 flaw in Adobe Campaign Classic and a critical RCE vulnerability in the Ruby on Rails Active Storage framework. Additionally, threat actors are actively exploiting hardware wallet firmware flaws and hijacking hotel Wi-Fi networks to deliver surveillance malware like the CornFlake RAT. Organizations must prioritize patching web frameworks and enterprise software while enforcing strict network access controls for remote workers.

■ CRITICAL STORIES

CRITICAL#1

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft

A firmware vulnerability in Coldcard hardware wallets allowed attackers to drain $70.2 million across 1,196 Bitcoin addresses in just 41 minutes, highlighting severe risks in hardware-based crypto storage.

CRITICAL#2

Adobe Campaign Classic CVSS 10.0 Flaw Allows Zero-Interaction RCE

A maximum-severity vulnerability (CVE-2026-484) in Adobe Campaign Classic enables unauthenticated arbitrary code execution without any user interaction, posing a severe threat to enterprise marketing platforms.

CRITICAL#3

Ruby on Rails Patches Critical Active Storage Flaw with RCE Potential

A critical vulnerability in the Rails Active Storage framework allows unauthenticated attackers to read arbitrary files and potentially escalate to remote code execution (RCE).

HIGH#4

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver CornFlake RAT

Threat actors are hijacking hotel Wi-Fi networks to serve fake browser updates that install 'CornFlake' surveillance malware, capable of capturing keystrokes, webcam, and microphone data.

■ CVEs IDENTIFIED

CVE-2026-484

Adobe Campaign Classic (ACC) — Arbitrary code execution without user interaction

Critical (CVSS 10.0)

[CVE-TBD]

Ruby on Rails (Active Storage) — Unauthenticated arbitrary file read and potential remote code execution (RCE)

Critical

[CVE-TBD]

Coinkite Coldcard Firmware — Firmware flaw allowing unauthorized draining of cryptocurrency wallets

Critical

[CVE-TBD]

Adform JavaScript — Script poisoning leading to cryptocurrency wallet address swapping

High

■ THREAT ACTORS

Unknown

Cybercriminal

Hijacked hotel Wi-Fi to distribute CornFlake RAT via fake browser updates

Unknown

Cybercriminal

Exploited Coldcard firmware flaw to steal $70.2 million in Bitcoin

Unknown

Cybercriminal

Poisoned Adform JavaScript to swap cryptocurrency wallet addresses

■ ATT&CK TTPs

T1195.001
Supply Chain Compromise: Compromise Software Dependencies and Tools | Poisoned Adform JavaScript distributed to customer sites to swap crypto addresses
T1557.002
Adversary-in-the-Middle: Wi-Fi | Hijacked hotel Wi-Fi networks to serve fake browser updates
T1566
Phishing | AMOS stealer distribution and campaigns targeting AI solutions providers like ChatGPT
T1190
Exploit Public-Facing Application | Exploitation of Adobe Campaign Classic (CVE-2026-484) and Ruby on Rails Active Storage flaws
T1125
Video Capture | CornFlake RAT capturing webcam images from infected hosts
T1056.001
Keylogging | CornFlake RAT capturing keystrokes on infected hosts

■ PATCH PRIORITY

[P3 PATCH NOW]≤1 week

CRITICAL — Adobe Campaign Classic (ACC) — Zero-interaction arbitrary code execution vulnerability (CVE-2026-484) — [THN]

[P3 PATCH NOW]≤1 week

CRITICAL — Ruby on Rails (Active Storage) — Unauthenticated arbitrary file read and potential RCE — [BC] / [SW]

[P3 PATCH NOW]≤1 week

CRITICAL — Coinkite Coldcard — Firmware flaw leading to massive cryptocurrency theft — [THN]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Adobe Campaign Classic immediately to address the CVSS 10.0 vulnerability (CVE-2026-484) to prevent zero-interaction arbitrary code execution.
2[P1] Update Ruby on Rails installations to the latest patched version to mitigate the critical Active Storage file read and RCE vulnerability.
3[P1] Update Coinkite Coldcard hardware wallet firmware to the latest secure version to protect against the critical wallet-draining vulnerability.
4[P2] Implement robust endpoint protection on macOS devices to detect and block Atomic MacOS Stealer (AMOS) infections.
5[P2] Enforce VPN usage on public and hotel Wi-Fi networks to mitigate Adversary-in-the-Middle attacks distributing the CornFlake RAT.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 01 Aug | TeamCity RCE and Autonomous AI Attacks Escalate
Powered by Buttondown, the easiest way to start and grow your newsletter.