Blockchain
Curated coverage and analysis in this editorial area.

Coldcard: 2021 Seed Bug Drains 1,778 BTC; Firmware Fix Released August 20
Coinkite issued corrective firmware on August 20, 2026, after an entropy bug present since March 2021 enabled the theft of over 1,778…

DeadLock Leverages Polygon and Session for Takedown-Resistant Ransomware Infrastructure
Microsoft Threat Intelligence dissects DeadLock, a Rust-based ransomware that has compromised over 80 organizations since July 2025, w…

Exposed Directory Reveals Autonomous AI Fleet for Industrial-Scale Crypto Theft
A Chinese-speaking operator orchestrated entire offensive campaigns using multi-vendor AI agents in full-auto mode. A misconfiguration…

DeadLock: The Ransomware Using Polygon to Evade Infrastructure Seizures
DeadLock leverages Polygon smart contracts to rotate proxy servers and host its data leak site, rendering the infrastructure-seizure s…

Trezor: ShipMonk Exposes 13,689 Customers — Where Physical and Digital Security Collide
Logistics provider ShipMonk notified Trezor of unauthorized access exposing personal data for 13,689 customers. The incident lays bare…

ChainDrop: The npm Worm That Broke Cryptographic Trust in Four Hours
The ChainDrop worm infected 444 npm packages using valid SLSA provenance. The failure of automated trust in modern software.

Microsoft Analyzes DeadLock: Rust Ransomware with Decentralized Infrastructure
Microsoft Threat Intelligence published a full technical analysis of DeadLock on August 11, 2026. The Rust-based ransomware has been a…

Aeternum: The Botnet Loader That Uses Polygon as C2
Unit 42 analyzes Aeternum, a C++ botnet loader that moves command-and-control entirely onto the public Polygon blockchain. On August 1…

dYdX Hit by Third Supply-Chain Attack: Compromised npm and PyPI Packages Deliver Wallet Stealer and RAT
DeFi protocol with $1.5T cumulative volume compromised on npm and PyPI. Wallet stealer and remote access trojan distributed via mainta…

ViteVenom: Seven npm Packages Use Blockchain as Unstoppable C2
The ViteVenom campaign distributes malware via npm using Tron, Aptos, and Binance Smart Chain as command-and-control infrastructure. A…

Ill Bloom: 431 Wallets Drained for $3.1M via Insecure PRNG
The Ill Bloom vulnerability exposed 2,114 crypto addresses due to weak pseudorandom number generators. No patch exists: the only defen…

Vishing 2.0 Hits Teams: Fake IT Support Calls Deploy EtherRAT
Palo Alto Networks Unit 42 uncovered a campaign that abuses Microsoft Teams voice calls to impersonate corporate IT support and trick…