Two Crypto Attacks on July 31 Drain Over $46M via Firmware Flaw and Smart Contract Bug
On July 29–31, 2026, two separate cryptocurrency attacks resulted in combined losses exceeding $46 million across entirely different attack surfaces. COLDCARD, a widely trusted Bitcoin hardware wallet, lost between $38 million and $70 million after a firmware bug dating back to March 2021 was actively exploited — a flawed build setting had silently disabled the hardware random number generator, reducing key entropy and making private keys brute-forceable. Separately, CryptoDAO lost $8.2 million USDT from a BNB Chain vault contract that lacked access controls, allowing any external address to call a restricted function, which the attacker amplified using flash loans. The COLDCARD vulnerability required a specialized firmware and RNG compliance audit to detect, while the CryptoDAO flaw was a well-documented smart contract issue flagged in standard security checklists and automated tools. The incidents highlight that crypto security failures span multiple distinct layers — from embedded hardware firmware to on-chain contract logic — each demanding its own auditing discipline.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in