Awarefy
1.66K subscribers
41 photos
2 videos
1 link
Trusted source for COM & Crypto news, updates & scam alerts

Ads: @warrantful
Download Telegram
Channel created
The COLDCARD incident has reportedly led to ~$38M in stolen BTC.

The issue wasn’t broken cryptography, but weak seed entropy. Coinkite says affected Mk4/Mk5/Q devices could generate seeds with only ~72 bits of entropy instead of 128.

Affected users should migrate to a new seed ASAP using patched firmware or an unaffected device.

Attacker:
bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0


@awarefy
2
UPDATE: 1.1K BTC ($71M) has been stolen from Coldcard users

More than 1,200 victims lost their entire Bitcoin holdings overnight, with whales targeted first and over 1,000 BTC stolen.

@awarefy
2
Crypto lost $210.3M to hacks in July 2026 across 30 major incidents — a 177% increase from June's $75.9M.

The COLDCARD incident alone accounted for ~$70M, making it the third-largest crypto theft of 2026 so far.

Top losses:
• COLDCARD — ~$110M
• AFX (Arbitrum) — ~$24M
• Ostium — ~$24M
• BONK — ~$21.2M
• Wanchain Cardano–BNB Bridge — ~$13M

@awarefy
2
JUST IN: Program shows how bad the ColdCard bug was

A duplicated wallet on average would have been created every 1.3mil seed generations. Took 4.7seconds to find a collision with one of wallets on M1 Max

This mistake costed people $86mil (1,367BTC)

@awarefy
2
BNB Chain blames former employee for unauthorized meme token

BNB Chain says a wallet linked to a recently launched meme token was originally created by a former employee for a tutorial and was never intended for official use.

According to the company, the ex-employee retained access to the wallet’s seed phrase after leaving and later used it to generate a new private key and launch the token independently.

@awarefy
3
How attackers compromised Coldcard wallets

Researchers say a flaw in Coldcard firmware caused affected wallets to generate recovery seed phrases from predictable system data—such as processor identifiers and internal timers—instead of using secure hardware randomness.

Rather than attacking the devices directly, hackers recreated the vulnerable seed generation process offline, generated millions of possible seed phrases, matched them against funded Bitcoin addresses on the blockchain, and recovered the corresponding private keys to steal the funds.
The vulnerability reportedly remained unnoticed for five years before being patched.

@awarefy
2
Adform supply chain attack swapped crypto wallet addresses

Attackers compromised Adform's trackpoint-async.js script, turning it into malware that replaced Bitcoin, Ethereum, and Tron wallet addresses on websites using the company's advertising code.

Anyone who copied a crypto address from an affected site on July 27 may have unknowingly pasted an attacker's address instead. The malicious script also modified addresses typed directly into forms.
Adform removed the malicious code, notified customers, and advises users to clear their browser cache and verify wallet addresses before sending funds.

@awarefy
2
⚠️BREAKING: Two French crypto millionaires held hostage and tortured in a 52-hour kidnapping nightmare.

The victims were allegedly beaten, burned, and forced to hand over $30,000 in crypto as captors demanded $150,000. The ordeal ended only after a high-speed police chase, with six people convicted in connection with the attack, per Daily Mail.

CertiK has recorded 50+ wrench attacks targeting crypto holders in H1 2026, with France emerging as a major hotspot for violent crypto-related kidnappings and extortion.

@awarefy
3
⚠️ JUST IN: FBI agent arrested after draining $1M in crypto

An FBI agent was arrested after using classified FBI tools to access a target's crypto wallet and drain $1M

He was caught after he started talking about it to his colleagues.

@awarefy
2
⚠️ UPDATE: Apple Explains the Real Reason for Telegram’s Removal from the App Store

According to Bloomberg, Apple has explained why Telegram was removed from the App Store:

We briefly removed Telegram from the App Store after our review found content that violates our strict guidelines prohibiting child sexual abuse material (CSAM). The app was subsequently restored after the developer promptly removed the content and banned the user who posted it,' Apple tells Bloomberg.

Telegram has also responded on X saying:
“I'm sure this stance will be applied equally to all other apps in the store, in the future right? @Aрple"

@awarefy
2
This media is not supported in your browser
VIEW IN TELEGRAM
⚠️Gram Wallet Is Now Rolling Out

Pavel Durov has announced that Telegram's Gram Wallet is now live for a select group of users, with a gradual rollout to over 1 billion users planned over the next couple of weeks.

@awarefy
🥰21
⚠️BREAKING: A large number of X users are getting password reset emails

The reports suggest possible coordinated phishing or abuse of X’s reset system

@awarefy
🥰1