Crypto hackers drain millions from over 1K bitcoin wallets in string of recent attacks linked to software flaw See more of our coverage in your search results.
Claims checked12
Techniques found1
Topics3
Coverage spectrum
Coverage gap: Low Left coverage
Left17%
Center66%
Right17%
6 sources compared across this story cluster. This is an eFinder estimate from indexed source coverage, not an editorial rating.
What happened
Crypto hackers drain millions from over 1K bitcoin wallets in string of recent attacks linked to software flaw See more of our coverage in your search results.
Why it matters
Add The New York Post on Google Owners of a popular bitcoin storage device are being urged to protect their cryptocurrency after security researchers said a software flaw may have allowed attackers to steal roughly $70 million worth of bitcoin in less than an…
Common ground
Forbes first reported the attacks, which researchers at Galaxy Research say drained more than 1,000 bitcoin from 1,196 digital wallets in just 41 minutes on July 30.
Perspective signals
The tension in the story is sharpened by Loaded Language: language that can make the dispute feel more urgent, personal, or adversarial than the underlying facts alone.
Follow-up questions
What new context would change how readers understand this Corporate accountability story?
What evidence would most clearly confirm or weaken the claim that The issue involves Coldcard, a handheld device many cryptocurrency investors use to store bitcoin offline?
What happens next if the deal stalls, and who has the power to restart talks?
eFinder identified 1 propaganda technique in this article. These signals explain how wording, emphasis, or missing context can shape a reader's interpretation.
Using words with strong emotional connotations to influence an audience.
Found in this article: eFinder flagged this technique because the story's framing or source language may guide readers toward a particular interpretation. Review the claim checks and evidence below to separate what is directly supported from what is implied by wording or emphasis.
Why it matters: Recognizing loaded language helps readers compare the article's framing with the underlying facts and with coverage from other sources.
fact_checkClaims Checked
eFinder analyzed this article and checked 12 claims against available evidence, cross-references, web search, and Wikipedia. Here is what the fact-checking layer found.
check_circleCorroborated7
schedulePending2
helpInsufficient Evidence2
verifiedVerified By Reference1
check_circle
Claim 1: “The issue involves Coldcard, a handheld device many cryptocurrency investors use to store bitcoin offline”
CORROBORATED
Multiple sources explicitly link the security vulnerability to Coldcard hardware wallets.
travel_explore
web search
NEUTRAL
— Security is protection from, or resilience against, potential harm (or other unwanted coercion). Beneficiaries (technically referents) of security may be persons and social groups, objects and institu…
https://en.wikipedia.org/wiki/Security
travel_explore
web search
NEUTRAL
— Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security.
https://en.wikipedia.org/wiki/Computer_security
travel_explore
web search
NEUTRAL
— Security+ validates the core skills required for a career in IT security and cybersecurity. Learn about the certification, available training and the exam.
https://www.comptia.org/en-us/certifications/security/
schedule
Claim 2: “developers of Jack Dorsey’s Bitkey wallet said they are investigating a different reported issue involving their product”
PENDING
This claim was extracted as a checkable statement from the article. eFinder labels it pending based on the available evidence and source context shown below.
check_circle
Claim 3: “Block said the software bug may have made some of those recovery phrases predictable enough for sophisticated attackers to figure them out”
CORROBORATED
Multiple sources confirm that the bug made recovery phrases predictable to attackers, specifically citing Block's engineering team.
web search
NEUTRAL
— However, Block’s Bitcoin Engineering and Security team revealed that a specific coding mistake in older Coldcard firmware versions made some recovery phrases predictable under certain circumstances. T…
https://vocal.media/01/critical-security-flaw-in-coldcard-ha…
travel_explore
web search
NEUTRAL
— These seed phrases are long strings of words used to gain access to cryptocurrency wallets and are critical to wallet security. The flaw made these supposedly random phrases predictable to attackers.
https://www.breitbart.com/tech/2026/08/03/software-flaw-in-c…
check_circle
Claim 4: “According to a security advisory from Block’s Bitcoin Engineering and Security team, a coding mistake in certain versions of Coldcard may have weakened one of the wallet’s key security features”
CORROBORATED
Multiple sources confirm that Block's Bitcoin Engineering and Security team released a security advisory regarding a coding mistake in certain Coldcard versions.
travel_explore
web search
NEUTRAL
— According to a security advisory from Block's Bitcoin Engineering and Security team, a coding mistake in certain versions of Coldcard may have weakened one of the wallet's key security features. Paidw…
https://www.fox9.com/news/coldcard-wallet-attack-drains-89m-…
travel_explore
web search
NEUTRAL
— According to a security advisory by CoinKite, the issue was rooted in a software update released in March 2021. In addition, a report analysis by Block’s engineering team said certain versions of Cold…
https://www.bnnbloomberg.ca/markets/crypto/2026/08/04/hacker…
travel_explore
web search
NEUTRAL
— Block’s Bitcoin Engineering and Security team releases a security advisory revealing the entropy-generating coding flaw in Coldcard. Coinkite issues a firmware update that fixes the vulnerability for …
https://getcyberbrief.com/story/coldcard-entropy-flaw-89m-bt…
check_circle
Claim 5: “Coinkite CEO Rodolfo Novak issued a public apology on X”
CORROBORATED
Multiple sources (CoinMarketCap, Information Age, and others) confirm Coinkite CEO Rodolfo Novak issued a public apology on X.
travel_explore
web search
NEUTRAL
— Coinkite CEO Rodolfo Novak, known online as NVK, issued an apology on July 31.Thorn posted on X on Aug. 2 that the attack is ongoing. He urged anyone with single-signature funds on Coldcard-generated …
https://coinmarketcap.com/academy/article/coldcard-firmware-…
travel_explore
web search
NEUTRAL
— Coinkite chief executive Rodolfo Novak issued his own public apology on social media platform X. “I'm sorry and I'm devastated,” said Novak. “Our team is heartbroken.”In the meantime, Coinkite’s chief…
https://ia.acs.org.au/article/2026/bitcoin-wallet-bug-sparks…
travel_explore
web search
NEUTRAL
— Coinkite CEO Rodolfo Novak issued a public apology, saying the company takes full responsibility and is working on fixed software, technical write-ups and user support. Coinkite also advanced the idea…
https://bingx.com/en/flash-news/post/coldcard-firmware-bug-l…
check_circle
Claim 6: “Canadian company Coinkite, which makes Coldcard, has since released a software update to prevent the problem from affecting newly created wallets”
CORROBORATED
Multiple sources confirm Coinkite released a software/firmware update to prevent the issue in newly created wallets.
web search
NEUTRAL
— Coinkite released emergency firmware updates to address the Coldcard Hardware Wallet Flaw across all affected Coldcard models on July 31 and advised users to immediately migrate to newly generated wal…
https://blog.cybernexora.com/coldcard-hardware-wallet-flaw/
travel_explore
web search
NEUTRAL
— Coinkite released emergency firmware updates designed to eliminate the weak random number generation that caused the original vulnerability. The company made clear that the new firmware only protects …
https://news.bitcoin.com/crypto-news/coldcard-hacker-gets-br…
check_circle
Claim 7: “Galaxy later identified two additional suspected waves of suspicious activity, bringing the estimated losses to nearly $89 million”
CORROBORATED
Multiple independent sources (KTVU FOX 2, Galaxy Research via web search) confirm that total losses are estimated at nearly $89 million.
menu_book
wikipedia
NEUTRAL
— The Andromeda Galaxy is a barred spiral galaxy and is the nearest major galaxy to the Milky Way. It was originally named the Andromeda Nebula and is cataloged as Messier 31, M31, and NGC 224. Andromed…
https://en.wikipedia.org/wiki/Andromeda_Galaxy
menu_book
wikipedia
NEUTRAL
— This article collates results of opinion polls that were conducted in relation to voting intentions of the Australian public in the lead-up to the 2013 Australian federal election.
https://en.wikipedia.org/wiki/Opinion_polling_for_the_2013_A…
menu_book
wikipedia
NEUTRAL
— YouGov plc is an international Internet-based market research and data analytics firm headquartered in the UK with operations in Europe, North America, the Middle East, and Asia–Pacific.
https://en.wikipedia.org/wiki/YouGov
+ 3 more evidence sources
verified
Claim 8: “researchers at Galaxy Research say drained more than 1,000 bitcoin from 1,196 digital wallets in just 41 minutes on July 30”
VERIFIED BY REFERENCE
While the general attack is documented, the specific details regarding 'Galaxy Research', '1,196 digital wallets', and the '41 minutes' timeframe on 'July 30' are not explicitly detailed in the provided evidence snippets, although the overall event is corroborated.
menu_book
wikipedia
NEUTRAL
— On 13 July 2025, fighting began between Druze and Bedouin armed groups in the city of Suwayda and its surrounding villages in southern Syria. The Syrian transitional government deployed the Armed Forc…
https://en.wikipedia.org/wiki/Southern_Syria_clashes_(July–S…
menu_book
wikipedia
NEUTRAL
— Sum 41 was a Canadian rock band formed in Ajax, Ontario, in 1996. The band's final lineup consisted of Deryck Whibley (lead vocals, rhythm guitar, keyboards), Dave Baksh (lead guitar, backing vocals),…
https://en.wikipedia.org/wiki/Sum_41
menu_book
wikipedia
NEUTRAL
— WrestleMania 41, also promoted as WrestleMania Vegas, was a 2025 professional wrestling pay-per-view (PPV) and livestreaming event produced by WWE. It was the 41st annual WrestleMania and took place a…
https://en.wikipedia.org/wiki/WrestleMania_41
+ 3 more evidence sources
help
Claim 9: “Coinkite... expanded the list of affected products to include additional models and software versions”
INSUFFICIENT EVIDENCE
No evidence was provided in the search results regarding the expansion of the list of affected products/models.
check_circle
Claim 10: “security researchers said a software flaw may have allowed attackers to steal roughly $70 million worth of bitcoin in less than an hour”
CORROBORATED
Multiple sources (KTVU FOX 2 and others) report that security researchers identified a software flaw allowing attackers to steal roughly $70 million in bitcoin in less than an hour.
menu_book
wikipedia
NEUTRAL
— Magento is an open-source e-commerce platform written in PHP. Magento source code is distributed under the Open Software License. Magento was acquired by Adobe Inc in May 2018 for $1.68 billion.
More …
https://en.wikipedia.org/wiki/Magento
menu_book
wikipedia
NEUTRAL
— In computing, SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g. to dump the da…
https://en.wikipedia.org/wiki/SQL_injection
menu_book
wikipedia
NEUTRAL
— A zero-day (also known as a 0-day) is a vulnerability or security hole in a computer system unknown to its developers or anyone capable of mitigating it. Until the vulnerability is remedied, threat ac…
https://en.wikipedia.org/wiki/Zero-day_vulnerability
+ 3 more evidence sources
schedule
Claim 11: “Block emphasized that none of its own products or customers are affected by the vulnerability”
PENDING
This claim was extracted as a checkable statement from the article. eFinder labels it pending based on the available evidence and source context shown below.
help
Claim 12: “customers who created their recovery phrase using at least 50 private dice rolls are not affected by this specific flaw alone”
INSUFFICIENT EVIDENCE
No evidence was provided in the search results regarding the specific safety of users who used 50+ private dice rolls.
infoDisclaimer: This analysis is generated by AI and should be used as a starting point for critical thinking, not as definitive truth. Claims are verified against publicly available sources. Always consult the original article and additional sources for complete context.