Why it matters: A hardware wallet is supposed to solve one problem: keep your Bitcoin keys somewhere no attacker can reach them. This week showed what happens when the flaw sits inside the wallet itself. A firmware bug that's been shipping in Coldcard devices since 2021 let an attacker guess supposedly random seed phrases from the outside, no physical access, no phishing, no malware required, and drain funds from thousands of addresses. The running total is already past $88 million, and it's still climbing.
The operation has run for nearly a year, impersonating 72 popular Windows tools to steal crypto and passwords
A hot potato: The developer behind popular Windows optimization tool Wintoys has uncovered a sophisticated cybercrime operation that mimics dozens of popular Windows apps through duplicate websites built to look uncannily like the real thing. The fraudulent sites reportedly distribute malware capable of compromising user privacy, hijacking account credentials, and draining crypto wallets.
Get Off My Phone: The recently unveiled case brought by the US Department of Justice against a GrapheneOS user is rekindling debate around privacy and effective operational security on mobile devices. The GrapheneOS Foundation has joined that debate, reaffirming some key points about the operating system's security features and whether previously deleted data can ever be recovered.
GrapheneOS is a security focused mobile OS for Google Pixel phones (soon Motorola). Based on Android's open source roots, it adds extensive hardening features, stronger app sandboxing, and granular permissions while allowing users to install Google Play services as regular apps. The project has grown past 400,000 active users. Its tools recently made the headlines after prosecutors treated the OS's remote wipe feature as evidence.
Prosecutors say the OS erased evidence, but advocates warn the case could criminalize security tools
A hot potato: A federal case in Atlanta is raising questions about a privacy-focused mobile operating system, with prosecutors arguing that its features were used to erase evidence. The US Department of Justice is attempting to prosecute Atlanta resident Sam Tunick under a federal statute that makes it a crime to destroy property in an effort to prevent it from being seized.
Tails has introduced a safer shutdown process to help prevent data loss. It's also replacing GNOME Videos with the more secure Celluloid media player, updating Tor Browser, and refreshing firmware packages for improved graphics and Wi-Fi hardware support.
The OpenAI – Hugging Face hacking incident is either a wake-up call or a very convenient story
Connecting the dots: The AI boom has intensified old fears about the dangers of increasingly autonomous software, but those debates have mostly stayed theoretical, confined to research papers and thought experiments rather than real incidents. A newly disclosed episode involving an OpenAI test model may have added some real-world weight to those fears, even if the full scope of the damage is still being sorted out.
Windows 10 holdouts carry nearly 3x the security risk of Windows 11, report finds
Facing the Flaw: Many organizations have already migrated to Windows 11, but a few diehards are refusing to leave Windows 10 behind. In fact, millions of computers are still running the aging, albeit perfectly functional, operating system, and according to one market analysis, that could soon turn into a security disaster.
AI is finding more Windows bugs than ever, but patches still aren't reliable
Microbugs: Microsoft has released yet another Patch Tuesday with record-breaking figures. The latest cumulative update for supported Windows editions is significant in both quality and quantity. However, some Dell machines will not receive the update anytime soon due to compatibility issues.