Coldcard firmware flaw linked to $70M Bitcoin theft; Adform supply-chain attack
ID: 634d134b-5a0a-5321-bc1f-434af386cc30
STIX ID: report--634d134b-5a0a-5321-bc1f-434af386cc30
Feed Name: defend.network
This briefing details multiple high‑severity cyber incidents: a firmware RNG flaw in Coldcard hardware wallets that was actively exploited to steal ~1,082.65 BTC in minutes, a supply‑chain compromise of Adform’s JavaScript that injected wallet‑swapping code into customer sites, a critical Ruby on Rails Active Storage vulnerability with RCE potential, and ongoing malware/espionage activity including CornFlake RAT distribution via hijacked hotel Wi‑Fi and a Chinese‑speaking APT using OctLurk and SilkLurk; it urges immediate firmware checks, patching, script integrity verification, forensic hunts, and other mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
