Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
2026-08-03T01:23:59Z•19df2178fc1d24d6e82832977a596ae4d97d6ebb8f61267b3dd52189f035b5a4
CVE-2026-20316CVE-2026-48449CVE-2026-59726CVE-2026-66066AI-securityBYOVDactive-exploitationarbitrary-file-readcloud-securitycryptocurrency-theftmalwaremobile-securitynetwork-securityphishingremote-code-executionstate-sponsored-threatssupply-chain-compromisevulnerabilitieszero-day
What happened
The feed highlights multiple significant cybersecurity developments, including actively exploited zero-days, critical unauthenticated remote code execution and arbitrary file-read vulnerabilities, cloud tenant data exposure, supply-chain compromises, malware campaigns, phishing, and state-sponsored activity. The most severe items include Adobe Campaign Classic CVE-2026-48449, Ruby on Rails CVE-2026-66066, Ruflo CVE-2026-59726, Cisco FMC CVE-2026-20316 exploitation, and an Azure Cosmos DB sandbox escape. The reporting also describes major cryptocurrency theft and browser-side wallet address hij
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 19df2178fc1d24d6e82832977a596ae4d97d6ebb8f61267b3dd52189f035b5a4
- Enrichment time
- 2026-08-03T01:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.