Issue #006 · Week of August 09, 2026
This Week’s Verdict
The call is coming from inside the house: this was the week Bitcoin’s own tooling, from Coldcard to BTCPay Server to Lightning nodes, became the attack surface instead of the fiat rails everyone worries about. Meanwhile the DOJ proposed handing a majority of $225M in verified scam-victim funds to the scammers, which is the kind of settlement you cannot even short. As ever, by the time the alert hits your feed, someone else’s node was already swept hours earlier.
The Breaches
The headline event is BTCPay Server. The open-source Bitcoin payment processor warned of an actively exploited vulnerability that could drain funds, urging operators to update to version 2.4.2 and rotate credentials. Hardware wallet maker Foundation and the Bitcoin zine Citadel21 both confirmed their Lightning nodes were swept, in some cases hours before the public alert landed. BTCPay was explicit that the flaw under attack was not the one disclosed in its changelog, which is a polite way of saying the attackers were ahead of the disclosure. Total losses and the number of affected operators remain unknown, which is the usual fog around self-hosted infrastructure.
Second, Polymarket. CoinDesk detailed how a five-second timing trick let traders drain millions, a reminder that prediction-market oracles and settlement windows are exploitable long before the CFTC gets around to worrying about “moneyline” odds.
The Coldcard exploit from the prior week continued to metastasize, less a single incident than an ongoing war bulletin, driving bitcoiners toward dice-roll entropy for seed generation. Blockaid’s CEO framed it as crypto’s “original sin” of private keys meeting AI-accelerated bug discovery.
Vulnerabilities Worth Your Attention
- BTCPay Server (v2.4.2): Actively exploited, distinct from the changelog CVE. If you self-host, you were the pen test. Restrict remote Lightning access and rotate credentials now.
- Metabase zero-day (CVSS 10.0): Unauthenticated SQL injection, no CVE, exploited in the wild. Confirmed victims include Framework and Tally. Business-intelligence tooling is a soft underbelly nobody threat-models.
- Bitcoin Core repos: A volunteer red team says an AI-assisted platform scanned 150 Bitcoin repositories and disclosed more than a dozen vulnerabilities. The same AI leverage that finds these is what drained Coldcard users. Pick your side of that race.
- 18-year-old Linux SCTP use-after-free: Local root plus container escape. Fixed in kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148. Anyone running node infrastructure on stale kernels should patch.
- Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6): Command injection, now on CISA KEV after 792 exploit attempts. WordPress pre-auth XSS (CVE-2026-64638) rounds out the week’s patch-now list.
- Permission hygiene: A useful reminder that a clean seed phrase means nothing if unlimited token allowances, live WalletConnect sessions, or exchange API keys still hold withdrawal rights. Audit revocations, not just backups.
Threat Actors & Campaigns
Lazarus Group and North Korea are back in the docket, not the wild: a US court granted Bybit expedited discovery to trace funds from the $1.5B hack, letting the exchange pull account identities and balances from platforms with US operations. Discovery is not recovery, but it is the first crack in the mixer fog.
Wallet-draining crews stayed busy at the endpoint. ClickFix attacks are delivering a Go-based macOS stealer that lifts crypto wallets, Keychain data, and cached credentials. Hackers are abusing BNB Chain to host malware instructions behind fake CAPTCHAs, per Microsoft, turning the blockchain into a resilient command channel. Nearly 800 malicious npm packages shipped a cross-platform RAT and infostealer under AI-generated typo-squat names. And a Trezor phishing site reportedly took a user’s life savings, the low-tech classic that never goes out of style. On the enterprise side, UNC6671 vishing and Microsoft 365 AitM campaigns continue targeting finance workflows.
On sanctions, OFAC designated two Iran-linked crypto exchanges under the “Economic Fury” campaign, tracing over $3M between Shelbit and IRGC-linked wallets.
The Bigger Picture
The week’s most cynical development came from Washington, not a mempool. The DOJ filed a proposed settlement handing a majority of $225M in verifiable pig-butchering victim funds to Infiniweb, a Philippine POGO tied to the Prince Group, and backed a protective order shielding the syndicate. Context: FBI IC3 pegged 2025 crypto investment-fraud losses at $7.2B, part of $11.37B in crypto-linked crime. The rail design is boring and effective: mule accounts, card on-ramps, and exchange accounts opened in the victim’s own KYC.
Legislatively, Majority Leader Thune filed cloture on the CLARITY Act, setting a September 15 Senate vote that still needs at least seven non-Republican votes. OKX’s Rafique already warned that passage optimism is priced into bitcoin, which is the entire thesis of this newsletter in one quote.
Markets stayed structurally soft under the headlines. US spot Bitcoin ETFs drew roughly $1.1B in their best week since April, with IBIT taking the bulk, and Bloomberg’s Balchunas tied the inflows partly to the Coldcard hack driving self-custody refugees into funds. Bitcoin tagged $65.3K after a surprise 23,000-job July payrolls miss cut rate-hike odds, yet remains in a death cross with volatility near vanishing. Elsewhere: Trump Media unwound its Crypto.com CRO treasury deal, leaving CRO holders holding the unburned bag; over 100 crypto projects folded in 2026’s dot-com-style shakeout; and Brazil’s central bank ordered up-to-24-hour holds on large cross-border transfers. The board keeps shifting toward tokenized RWAs, tripling to $7.4B, while DeFi spot volume fell roughly 70%. Growth, just not where the hype pointed.
Resources
- https://thedefiant.io/news/hacks/btcpay-server-tells-operators-to-update-or-shut-down-over-actively-exploited-flaw
- Incident trackers (reference standard): Rekt leaderboard · SlowMist Hacked
Related
- North Korea Slips Into Consensys While macOS Malware Reads Your Telegram
- A 2021 PRNG Bug Drained $89M From Coldcard Wallets in 41 Minutes
- Browsers Assemble Their Own Malware While Bridges Bleed $31.7M
More: Issues · Field Notes · RTFM
New Issue every week. Follow @ItsAlreadyPrice or subscribe via RSS so the next exploit does not surprise you.