SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefMonday, August 03, 2026 INTEL CONFIDENCE 64% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY COLDCARD Wallet RNG Flaw Enables $88M Theft | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 4 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by a critical cryptographic vulnerability in Coinkite COLDCARD hardware wallet firmware, where a flawed random number generator (RNG) enabled attackers to steal approximately $88.6 million in Bitcoin. Additionally, Google is developing new security controls for Chrome to block policy-installed extensions from hijacking New Tab pages and search settings. Organizations must also prepare for the security implications of next-generation AI models, such as OpenAI's newly teased Astra model, as automated capabilities continue to advance. |
|
■ CRITICAL STORIES COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft A critical firmware vulnerability in Coinkite COLDCARD hardware wallets allowed attackers to predict seed phrases generated by a flawed random number generator, resulting in the theft of $88.6 million from thousands of cryptocurrency wallets. |
Google Chrome may soon block New Tab hijacker extensions by default Google is implementing defense-in-depth measures to prevent policy-installed extensions from hijacking user search engines and New Tab pages, addressing a common vector for adware and information-stealing campaigns. |
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems OpenAI has announced Astra, a model designed for complex, long-running tasks; while a scientific breakthrough, the rapid evolution of advanced AI increases the potential for sophisticated automated exploitation and social engineering. |
|
■ CVEs IDENTIFIED [CVE-TBD] Coinkite COLDCARD Firmware — Flawed random number generator (RNG) leads to predictable cryptographic seed generation and asset compromise |
[CVE-TBD] Google Chrome (Extensions) — Policy-installed extensions hijacking default search engines and New Tab pages |
|
■ THREAT ACTORS Unknown Threat Actors | Cybercriminals |
Exploited the COLDCARD RNG vulnerability to compromise wallet seeds and steal $88.6 million in cryptocurrency |
|
|
|
■ ATT&CK TTPs | T1600 | | Weak Cryptography | Attackers exploited a flawed random number generator (RNG) in COLDCARD firmware to predict private keys. |
| T1176 | | Browser Extensions | Malicious or policy-installed extensions utilized to hijack Chrome New Tab pages and default search engines. |
|
■ PATCH PRIORITY Coinkite COLDCARD Firmware — Flawed RNG allows complete private key compromise and asset theft [CVE-TBD] — BleepingComputer |
Google Chrome — Upcoming security controls to mitigate extension-based search hijacking [CVE-TBD] — BleepingComputer |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately audit and migrate funds from any Coinkite COLDCARD hardware wallets whose cryptographic seeds were generated using vulnerable firmware versions affected by [CVE-TBD]. |
| 2 | [P2] Implement strict browser extension policies in Google Chrome to block unauthorized policy-installed extensions from altering default search engines or hijacking New Tab pages [CVE-TBD]. |
| 3 | [P2] Establish organizational governance and monitoring policies regarding the integration and use of advanced AI models like OpenAI Astra to mitigate shadow AI risks. |
| 4 | [P3] Ensure all hardware security modules (HSMs) and cold storage provisioning processes utilize multi-source entropy (e.g., dice rolls) rather than relying solely on single-source hardware RNGs. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |