<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://bizzal70.github.io/itsalreadypriced/feed.xml" rel="self" type="application/atom+xml" /><link href="https://bizzal70.github.io/itsalreadypriced/" rel="alternate" type="text/html" /><updated>2026-08-27T16:43:39+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/feed.xml</id><title type="html">It’s Already Priced.</title><subtitle>Weekly crypto security and market intelligence, plainly explained.</subtitle><author><name>The Desk</name></author><entry><title type="html">Coldcard Ships Firmware After $114M Bitcoin Theft</title><link href="https://bizzal70.github.io/itsalreadypriced/2026/08/23/issue-008/" rel="alternate" type="text/html" title="Coldcard Ships Firmware After $114M Bitcoin Theft" /><published>2026-08-23T00:00:00+00:00</published><updated>2026-08-23T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/2026/08/23/issue-008</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadypriced/2026/08/23/issue-008/"><![CDATA[<p><em>Issue #008 · Week of August 23, 2026</em></p>

<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The market spent the week celebrating a Treasury liquidity trick as if it were a discovery, while the security side quietly cleaned up after a hardware wallet that could not generate a random number, three chains that halted mid-exploit, and a bridge that minted money out of nothing. As usual, the drains were the interesting part and the candles were the loud part. When your cold storage vendor tells you to regenerate every seed, that is not a patch note, that is a confession.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>The headline number belongs to <strong>Coldcard</strong>. <strong>Coinkite</strong> shipped firmware after what CoinDesk pegged at a <strong>$114 million</strong> bitcoin theft (Decrypt rounded it to $130 million), rooted in weak seed generation. The new firmware forces users to add their own entropy when generating wallet seeds, and Coinkite’s warning was blunt: existing vulnerable seeds remain unsafe, so regenerate. A three-week review turned up additional bugs, with AI credited for finding some of them. If your keys came out of an affected device, the exploit is not theoretical and the fix is not automatic. Move your coins.</p>

<p><strong>The Sandbox</strong> contained a bridge exploit that minted unbacked <strong>SAND</strong> on <strong>Base</strong> and <strong>BSC</strong>. The studio halted bridging on both chains and says Ethereum, the chain it claims was unaffected, was where <strong>Upbit</strong> and <strong>Bithumb</strong> still froze SAND transfers under South Korea’s user-protection law. Unbacked mint events are the purest form of DeFi loss: no key was stolen, the contract simply printed collateral that did not exist.</p>

<p><strong>BounceBit</strong> is winding the whole chain down. After a <strong>$3 million</strong> exploit in which the attacker moved roughly <strong>286.5 million BB</strong> across nine wallets before block production was halted, the team decided the answer was to sunset its blockchain entirely and migrate to <strong>BNB Chain</strong>. Halting block production to stop a drain is becoming a genre.</p>

<p><strong>MANTRA</strong>, the Dubai-licensed RWA Layer 1, has been frozen since Thursday evening and blames the <strong>Cosmos EVM module</strong>. It says the incident touched two wallets it controls and that no user funds were taken, but it has notably declined to say whether anything actually left those wallets. Absence of a stated loss is not the same as absence of a loss.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<ul>
  <li><strong>Coldcard seed entropy.</strong> The core flaw was weak randomness in seed generation. User-supplied entropy is now mandatory, which tells you exactly how much they trust the old path.</li>
  <li><strong>Microsoft Entra ID, CVSS 10.0.</strong> A max-severity flaw in the identity platform that Microsoft says it patched before publishing the CVE, with no evidence of exploitation. Bleeping Computer reported a separate max-severity Entra ID flaw exploited in attacks. Identity is the perimeter now, and it is on fire.</li>
  <li><strong>GitLab CVE-2026-19478 (CVSS 9.4).</strong> Code injection allowing an unauthenticated attacker to rewrite or delete public projects. Under active exploitation within days of disclosure. Supply-chain roots do not get more direct.</li>
  <li><strong>Hundreds of leaked AWS keys.</strong> Over 9,300 AWS access keys exposed between 2022 and 2026 remain active and valid. Credential hygiene remains a fiction at scale.</li>
  <li><strong>Cisco Crosswork and Secure Workload.</strong> Nine flaws patched, five scoring a perfect 10.0. Another “comprehensive internal review” that keeps finding perfect scores.</li>
</ul>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p>No named state crew took a bow this week, but the tooling story is the story. <strong>TRM Labs</strong> reports AI adoption in crypto crime rose <strong>40%</strong> over the past year, with attackers using models to surface overlooked vulnerabilities and infiltrate IT firms. That is not a forecast, it is already in the loss numbers, and Coldcard’s own three-week review used AI to find bugs on the same premise. The <strong>Decrypt</strong> piece on a 20-odd developer red team scanning the Bitcoin ecosystem for AI-discoverable flaws is the defensive mirror of the same trend: cheap models handed attackers reach, so someone has to scan first.</p>

<p>On the commodity end, <strong>ToxicPanda</strong> Android malware now targets 349 apps and supports 167 remote commands, abusing VPN permissions to block Google Play. A supply-chain campaign is infecting <strong>Android car head units</strong> built by <strong>DoFun</strong> via their built-in updaters (flagged by <strong>Kaspersky</strong>), enlisting them into a proxy botnet for ad fraud. <strong>SynkLoader</strong> is riding Microsoft Teams phishing with a fake lock screen, and <strong>14 trojanized npm packages</strong> are dropping the AI-assisted <strong>RedC2 4.0</strong> Linux backdoor. The through-line: attackers no longer need originality, just distribution and an updater someone trusts.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>Bitcoin posted its best week since 2023, and the honest reporting credited the plumbing, not the Fed. A <strong>Treasury</strong> buyback tweak that CoinDesk carefully labeled “not QE or YCC” injected liquidity, pushed yields down, and sent BTC roughly 25% higher to test <strong>$80,000</strong>, before slipping back to $77,000. Roughly <strong>$1.2 billion</strong> in shorts were liquidated on the way up. <strong>Strategy</strong> swung from a $13 billion paper loss to a <strong>$1.4 billion</strong> unrealized gain as its holdings crossed back above cost basis. <strong>XRP</strong> led an altcoin rally to its biggest weekly gain in 21 months, <strong>HYPE</strong> ran nearly 40%, and <strong>Zcash</strong> hit an eight-year high near <strong>$850</strong> on <strong>Grayscale’s</strong> ETF push and roughly $10 billion in daily futures volume, most of it derivatives rather than spot. Read that composition carefully.</p>

<p>On the board that actually matters: <strong>Nomura</strong>-backed <strong>Laser Digital</strong> won Japan’s first crypto exchange approval in four years. Washington kept theater running, with <strong>Trump</strong> pushing the <strong>Clarity Act</strong> and the <strong>CFTC</strong> threatening to write its own rules if Congress stalls, even as CoinDesk ran an opinion arguing the Clarity Act is functionally anti-crypto. <strong>MiCA</strong> is now eyeing DeFi lending vaults, where deciding who to regulate is the hard part. <strong>BitMart</strong> is weighing a partial restart and creditor payouts while users report withdrawals stuck on “Processing,” which is the more informative data point.</p>

<p>The reflexivity study of the week comes from the <strong>Cleveland Fed</strong>: crypto investors are driven by beliefs and easily swayed by past returns. Nobody who watched money chase a Treasury buyback headline this week will find that surprising. It was already priced in.</p>

<h2 id="resources">Resources</h2>

<ul>
  <li>https://www.coindesk.com/tech/2026/08/21/coldcard-ships-firmware-after-usd114-million-bitcoin-theft-says-ai-helped-catch-more-bugs</li>
  <li>https://decrypt.co/376270/coldcard-new-security-after-bitcoin-exploit</li>
  <li>Incident trackers (reference standard): <a href="https://rekt.news/leaderboard/">Rekt leaderboard</a> · <a href="https://hacked.slowmist.io/">SlowMist Hacked</a></li>
</ul>

<h2 id="related">Related</h2>

<ul>
  <li><a href="/itsalreadypriced/2026/08/02/issue-005/">A 2021 PRNG Bug Drained $89M From Coldcard Wallets in 41 Minutes</a></li>
  <li><a href="/itsalreadypriced/rtfm/2026/07/15/seed-phrases-and-where-keys-actually-leak/">Seed Phrases and Where Keys Actually Leak</a></li>
  <li><a href="/itsalreadypriced/2026/08/16/issue-007/">The Week Your Trezor Order Became a Home Address</a></li>
</ul>

<p>More: <a href="/itsalreadypriced/">Issues</a> · <a href="/itsalreadypriced/field-notes/">Field Notes</a> · <a href="/itsalreadypriced/rtfm/">RTFM</a></p>

<hr />

<p><em>New Issue every week. Follow <a href="https://x.com/ItsAlreadyPrice">@ItsAlreadyPrice</a> or subscribe via RSS so the next exploit does not surprise you.</em></p>]]></content><author><name>The Desk</name></author><summary type="html"><![CDATA[A hardware wallet burns its own seed generation, three chains halt mid-exploit, and Bitcoin's best week since 2023 arrives courtesy of the Treasury, not the Fed.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" /><media:content medium="image" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">The Week Your Trezor Order Became a Home Address</title><link href="https://bizzal70.github.io/itsalreadypriced/2026/08/16/issue-007/" rel="alternate" type="text/html" title="The Week Your Trezor Order Became a Home Address" /><published>2026-08-16T00:00:00+00:00</published><updated>2026-08-16T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/2026/08/16/issue-007</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadypriced/2026/08/16/issue-007/"><![CDATA[<p><em>Issue #007 · Week of August 16, 2026</em></p>

<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The threat model quietly moved from your seed phrase to your front door. Between <strong>Trezor</strong>, <strong>SafePal</strong>, a French tax breach, and Israel’s largest exchange, the week’s real exploit was logistics metadata, not smart contracts. Meanwhile a president got a bank charter and Bitcoin slid under $63K, which is to say the board rearranged itself exactly as leverage said it would.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>The headline number came from self-custody, not an exchange. Cointelegraph’s <strong>Crypto Biz</strong> logged a <strong>$116 million Bitcoin wallet exploit</strong>, and Galaxy Research separately estimated that <strong>Coldcard</strong>-related thefts could top <strong>$150 million</strong>, with the recent lull suggesting vulnerable holders either migrated or were already emptied. Neither of these is a protocol failure in the DeFi sense. They are the slow, grinding harvest of poorly secured keys, and the money does not come back.</p>

<p>The rest of the week’s damage was data, which converts into money later. <strong>Trezor</strong> confirmed roughly <strong>14,000 customers</strong> exposed through its shipping provider <strong>ShipMonk</strong>: names, emails, phone numbers, and for many, physical shipping addresses. Days later <strong>SafePal</strong> disclosed a breach hitting <strong>nearly 40,000 customers’</strong> order information, same attack vector, same lesson ignored. Both firms will tell you their devices and backups were never touched. True, and beside the point. The leak links a confirmed hardware wallet purchase to a real-world identity and location, which is the exact input a wrench attack requires.</p>

<p>Add the largest crypto exchange in Israel, <strong>Bits of Gold</strong>, where customer identification details and deposit addresses were reportedly compromised, and the <strong>French tax breach</strong> exposing nearly <strong>678,000 taxpayers and businesses</strong>, now on pace to make 2026 France’s worst year ever for violent crimes targeting crypto holders. The exploit surface this week was a spreadsheet of who owns what and where they sleep.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<ul>
  <li><strong>macOS Screen Sharing (CVE-rated 9.8):</strong> The Netherlands’ <strong>NCSC</strong> warned that attackers are actively exploiting a macOS authentication bypass after public exploit code dropped, deploying <strong>Monero</strong> miners. Critical severity, patch available, exploitation already underway. The gap between disclosure and mass abuse is now measured in days.</li>
  <li><strong>DefiLlama phishing apps on the App Store:</strong> The founder said <strong>Apple</strong> removed a fake app only after <strong>DefiLlama</strong> documented it draining a small wallet, and delayed its own mobile launch as a result. The App Store review process is not your security perimeter.</li>
  <li><strong>x402 facilitators failing security tests:</strong> <strong>Coinbase</strong> and 14 other x402 facilitators reportedly failed security tests designed for the coming AI-agent payment economy. File this under systemic risk being built in real time, before the agents even show up to spend.</li>
  <li><strong>SAP Commerce Cloud (max severity):</strong> A maximum-severity RCE was targeted in attacks three days after patching. Not crypto-native, but it runs commerce backends that touch plenty of it.</li>
</ul>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p>The DPRK-flavored social engineering playbook keeps working because it targets people, not code. Singapore attributed <strong>$11.8 million</strong> in losses to <strong>fake LinkedIn crypto job scams</strong>, where malware planted during a bogus coding assessment harvested a session token and bypassed multi-factor authentication to reach a code repository. Stolen tokens, not stolen passwords, remain the path of least resistance.</p>

<p>New malware to note: <strong>AmnesiaStealer</strong>, a macOS info-stealer spreading via <strong>ClickFix</strong> lures, ships a streaming module letting attackers interactively drive the victim’s browser in real time. Session hijacking is graduating from token theft to live remote control. Elsewhere, the <strong>ShinyHunters</strong> crew exposed <strong>1.6 million RingCentral accounts</strong>, and <strong>Clop</strong> claimed 89GB from <strong>Shell</strong>, reminders that the extortion supply chain feeding future crypto-targeting lists never sleeps.</p>

<p>The through-line: every leaked customer database this week is raw material for the next wave of phishing, coercion, and wrench attacks. The threat actors do not need to break your wallet if a courier’s database tells them where to knock.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>The biggest regulatory move was also the most predictable. The <strong>OCC</strong> granted conditional approval for <strong>World Liberty Trust Company</strong>, the <strong>Trump</strong>-linked venture, to operate as a national trust bank and take over issuance of the <strong>USD1</strong> stablecoin from <strong>BitGo</strong>. Senator <strong>Elizabeth Warren</strong> called it the most brazen self-dealing in financial history. Priced in or not, the precedent is set: the family issuing the currency now also runs the bank.</p>

<p>The legislative track went the other way. <strong>Galaxy</strong> cut <strong>CLARITY Act</strong> odds to <strong>10%</strong>, citing unresolved ethics, stablecoin yield, and developer protection issues plus a narrow September Senate window. The <strong>SEC</strong> promptly shelved a crypto rule meeting after the Senate recessed without a vote. Structure over sentiment, again.</p>

<p>Markets did what leverage told them to. <strong>Bitcoin</strong> slipped below <strong>$63,000</strong>, then toward <strong>$62.5K</strong>, ignoring cooperative US inflation while Binance longs faced a cleanout in open interest. The institutional bid, however, kept building underneath: <strong>UBS</strong> grew Bitcoin ETF call options 24-fold, <strong>Morgan Stanley</strong> raised <strong>IBIT</strong> holdings 23%, <strong>JPMorgan</strong> boosted its BTC ETF position 25% and quadrupled its ETH position, and <strong>Paul Tudor Jones</strong>’ firm bought back in after a year of selling. CoinDesk declared the “long bitcoin, short the bankers” era officially over. The bankers won by buying the ETF.</p>

<p>On the plumbing: <strong>Israel’s Bank Leumi</strong> tapped <strong>Galaxy</strong> to offer BTC, ETH, and SOL trading from early 2027, <strong>Ethereum</strong> devs are narrowing 66 proposals for the privacy-focused <strong>Hegotá</strong> upgrade, and <strong>Solana</strong> proposed a fee overhaul to make resource hogs pay while burning more SOL. <strong>Tether</strong> finally cleared a first <strong>KPMG</strong> audit, ending its longest-running criticism, though it still declines to publish the statements. Meanwhile the <strong>ECB</strong> found crypto payment acceptance below 1% in the euro area, a quiet reminder that after all this, almost nobody is paying for coffee with it.</p>

<p>The board shifted toward banks, ETFs, and charters. The risk shifted toward your doorstep. Neither was a surprise if you were reading the explorer instead of the timeline.</p>

<h2 id="resources">Resources</h2>

<ul>
  <li>https://www.reddit.com/r/CryptoCurrency/comments/1vp71ny/trezor_data_breach_exposes_almost_14000_customers/</li>
  <li>https://www.coindesk.com/tech/2026/08/16/crypto-wallet-safepal-reveals-a-data-breach-exposing-nearly-40-000-customers-order-info</li>
  <li>Incident trackers (reference standard): <a href="https://rekt.news/leaderboard/">Rekt leaderboard</a> · <a href="https://hacked.slowmist.io/">SlowMist Hacked</a></li>
</ul>

<h2 id="related">Related</h2>

<ul>
  <li><a href="/itsalreadypriced/2026/07/26/issue-004/">Browsers Assemble Their Own Malware While Bridges Bleed $31.7M</a></li>
  <li><a href="/itsalreadypriced/rtfm/2026/07/15/seed-phrases-and-where-keys-actually-leak/">Seed Phrases and Where Keys Actually Leak</a></li>
  <li><a href="/itsalreadypriced/2026/07/19/issue-003/">North Korea Slips Into Consensys While macOS Malware Reads Your Telegram</a></li>
</ul>

<p>More: <a href="/itsalreadypriced/">Issues</a> · <a href="/itsalreadypriced/field-notes/">Field Notes</a> · <a href="/itsalreadypriced/rtfm/">RTFM</a></p>

<hr />

<p><em>New Issue every week. Follow <a href="https://x.com/ItsAlreadyPrice">@ItsAlreadyPrice</a> or subscribe via RSS so the next exploit does not surprise you.</em></p>]]></content><author><name>The Desk</name></author><summary type="html"><![CDATA[Two hardware wallet vendors, a French tax authority, and an Israeli exchange all leaked the one thing that turns crypto wealth into a physical target: where you live.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" /><media:content medium="image" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">The Week Bitcoin’s Own Infrastructure Started Draining Itself</title><link href="https://bizzal70.github.io/itsalreadypriced/2026/08/09/issue-006/" rel="alternate" type="text/html" title="The Week Bitcoin’s Own Infrastructure Started Draining Itself" /><published>2026-08-09T00:00:00+00:00</published><updated>2026-08-09T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/2026/08/09/issue-006</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadypriced/2026/08/09/issue-006/"><![CDATA[<p><em>Issue #006 · Week of August 09, 2026</em></p>

<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The call is coming from inside the house: this was the week Bitcoin’s own tooling, from <strong>Coldcard</strong> to <strong>BTCPay Server</strong> to <strong>Lightning</strong> nodes, became the attack surface instead of the fiat rails everyone worries about. Meanwhile the <strong>DOJ</strong> proposed handing a majority of $225M in verified scam-victim funds to the scammers, which is the kind of settlement you cannot even short. As ever, by the time the alert hits your feed, someone else’s node was already swept hours earlier.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>The headline event is <strong>BTCPay Server</strong>. The open-source Bitcoin payment processor warned of an actively exploited vulnerability that could drain funds, urging operators to update to version 2.4.2 and rotate credentials. Hardware wallet maker <strong>Foundation</strong> and the Bitcoin zine <strong>Citadel21</strong> both confirmed their <strong>Lightning</strong> nodes were swept, in some cases hours before the public alert landed. BTCPay was explicit that the flaw under attack was not the one disclosed in its changelog, which is a polite way of saying the attackers were ahead of the disclosure. Total losses and the number of affected operators remain unknown, which is the usual fog around self-hosted infrastructure.</p>

<p>Second, <strong>Polymarket</strong>. CoinDesk detailed how a five-second timing trick let traders drain millions, a reminder that prediction-market oracles and settlement windows are exploitable long before the CFTC gets around to worrying about “moneyline” odds.</p>

<p>The <strong>Coldcard</strong> exploit from the prior week continued to metastasize, less a single incident than an ongoing war bulletin, driving bitcoiners toward dice-roll entropy for seed generation. <strong>Blockaid</strong>’s CEO framed it as crypto’s “original sin” of private keys meeting AI-accelerated bug discovery.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<ul>
  <li><strong>BTCPay Server (v2.4.2):</strong> Actively exploited, distinct from the changelog CVE. If you self-host, you were the pen test. Restrict remote <strong>Lightning</strong> access and rotate credentials now.</li>
  <li><strong>Metabase zero-day (CVSS 10.0):</strong> Unauthenticated SQL injection, no CVE, exploited in the wild. Confirmed victims include <strong>Framework</strong> and <strong>Tally</strong>. Business-intelligence tooling is a soft underbelly nobody threat-models.</li>
  <li><strong>Bitcoin Core repos:</strong> A volunteer red team says an AI-assisted platform scanned 150 Bitcoin repositories and disclosed more than a dozen vulnerabilities. The same AI leverage that finds these is what drained Coldcard users. Pick your side of that race.</li>
  <li><strong>18-year-old Linux SCTP use-after-free:</strong> Local root plus container escape. Fixed in kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148. Anyone running node infrastructure on stale kernels should patch.</li>
  <li><strong>Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6):</strong> Command injection, now on <strong>CISA KEV</strong> after 792 exploit attempts. <strong>WordPress</strong> pre-auth XSS (CVE-2026-64638) rounds out the week’s patch-now list.</li>
  <li><strong>Permission hygiene:</strong> A useful reminder that a clean seed phrase means nothing if unlimited token allowances, live <strong>WalletConnect</strong> sessions, or exchange API keys still hold withdrawal rights. Audit revocations, not just backups.</li>
</ul>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p><strong>Lazarus Group</strong> and North Korea are back in the docket, not the wild: a US court granted <strong>Bybit</strong> expedited discovery to trace funds from the $1.5B hack, letting the exchange pull account identities and balances from platforms with US operations. Discovery is not recovery, but it is the first crack in the mixer fog.</p>

<p>Wallet-draining crews stayed busy at the endpoint. <strong>ClickFix</strong> attacks are delivering a Go-based macOS stealer that lifts crypto wallets, Keychain data, and cached credentials. Hackers are abusing <strong>BNB Chain</strong> to host malware instructions behind fake CAPTCHAs, per Microsoft, turning the blockchain into a resilient command channel. Nearly 800 malicious <strong>npm</strong> packages shipped a cross-platform RAT and infostealer under AI-generated typo-squat names. And a <strong>Trezor</strong> phishing site reportedly took a user’s life savings, the low-tech classic that never goes out of style. On the enterprise side, <strong>UNC6671</strong> vishing and <strong>Microsoft 365</strong> AitM campaigns continue targeting finance workflows.</p>

<p>On sanctions, <strong>OFAC</strong> designated two Iran-linked crypto exchanges under the “Economic Fury” campaign, tracing over $3M between <strong>Shelbit</strong> and IRGC-linked wallets.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>The week’s most cynical development came from Washington, not a mempool. The <strong>DOJ</strong> filed a proposed settlement handing a majority of $225M in verifiable pig-butchering victim funds to <strong>Infiniweb</strong>, a Philippine POGO tied to the <strong>Prince Group</strong>, and backed a protective order shielding the syndicate. Context: FBI IC3 pegged 2025 crypto investment-fraud losses at $7.2B, part of $11.37B in crypto-linked crime. The rail design is boring and effective: mule accounts, card on-ramps, and exchange accounts opened in the victim’s own KYC.</p>

<p>Legislatively, <strong>Majority Leader Thune</strong> filed cloture on the <strong>CLARITY Act</strong>, setting a September 15 Senate vote that still needs at least seven non-Republican votes. <strong>OKX</strong>’s Rafique already warned that passage optimism is priced into bitcoin, which is the entire thesis of this newsletter in one quote.</p>

<p>Markets stayed structurally soft under the headlines. US spot Bitcoin ETFs drew roughly $1.1B in their best week since April, with <strong>IBIT</strong> taking the bulk, and Bloomberg’s Balchunas tied the inflows partly to the Coldcard hack driving self-custody refugees into funds. Bitcoin tagged $65.3K after a surprise 23,000-job July payrolls miss cut rate-hike odds, yet remains in a death cross with volatility near vanishing. Elsewhere: <strong>Trump Media</strong> unwound its <strong>Crypto.com</strong> CRO treasury deal, leaving CRO holders holding the unburned bag; over 100 crypto projects folded in 2026’s dot-com-style shakeout; and <strong>Brazil</strong>’s central bank ordered up-to-24-hour holds on large cross-border transfers. The board keeps shifting toward tokenized RWAs, tripling to $7.4B, while DeFi spot volume fell roughly 70%. Growth, just not where the hype pointed.</p>

<h2 id="resources">Resources</h2>

<ul>
  <li>https://thedefiant.io/news/hacks/btcpay-server-tells-operators-to-update-or-shut-down-over-actively-exploited-flaw</li>
  <li>Incident trackers (reference standard): <a href="https://rekt.news/leaderboard/">Rekt leaderboard</a> · <a href="https://hacked.slowmist.io/">SlowMist Hacked</a></li>
</ul>

<h2 id="related">Related</h2>

<ul>
  <li><a href="/itsalreadypriced/2026/07/19/issue-003/">North Korea Slips Into Consensys While macOS Malware Reads Your Telegram</a></li>
  <li><a href="/itsalreadypriced/2026/08/02/issue-005/">A 2021 PRNG Bug Drained $89M From Coldcard Wallets in 41 Minutes</a></li>
  <li><a href="/itsalreadypriced/2026/07/26/issue-004/">Browsers Assemble Their Own Malware While Bridges Bleed $31.7M</a></li>
</ul>

<p>More: <a href="/itsalreadypriced/">Issues</a> · <a href="/itsalreadypriced/field-notes/">Field Notes</a> · <a href="/itsalreadypriced/rtfm/">RTFM</a></p>

<hr />

<p><em>New Issue every week. Follow <a href="https://x.com/ItsAlreadyPrice">@ItsAlreadyPrice</a> or subscribe via RSS so the next exploit does not surprise you.</em></p>]]></content><author><name>The Desk</name></author><summary type="html"><![CDATA[Lightning nodes drained, Coldcard fallout, a Polymarket five-second trick, and the DOJ hands scam victims' money to the scammers.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" /><media:content medium="image" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">A 2021 PRNG Bug Drained $89M From Coldcard Wallets in 41 Minutes</title><link href="https://bizzal70.github.io/itsalreadypriced/2026/08/02/issue-005/" rel="alternate" type="text/html" title="A 2021 PRNG Bug Drained $89M From Coldcard Wallets in 41 Minutes" /><published>2026-08-02T00:00:00+00:00</published><updated>2026-08-02T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/2026/08/02/issue-005</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadypriced/2026/08/02/issue-005/"><![CDATA[<p><em>Issue #005 · Week of August 02, 2026</em></p>

<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The safest wallet in Bitcoin turned out to have shipped with a broken random number generator in March 2021, and it took five years and 41 minutes for someone to collect. The lesson is not that self-custody is dead; it is that “air-gapped” means nothing when the entropy was compromised before the device ever touched your desk. Everything else this week (Iran’s $4 billion laundry, a supply-chain clipboard swap, another DeFi oracle shortfall) was already priced into the threat model. Coldcard just made people read it.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>The week belongs to <strong>Coldcard</strong>. On July 30 an attacker swept <strong>1,196 Bitcoin addresses in 41 minutes</strong>, taking roughly <strong>1,082 BTC</strong> worth about <strong>$70 million</strong> at the time, per <strong>Galaxy Research</strong>; <strong>CoinDesk</strong> and others put the running total near <strong>$89 million</strong> as the sweep expanded to some <strong>4,500 addresses</strong>. The root cause is not glamorous: a <strong>March 2021 firmware integration error</strong> routed seed generation on the <strong>Coldcard MK3</strong> to a deterministic software PRNG, producing low-entropy keys that were trivially guessable. The device was never touched. The seeds were doomed the day they were generated. <strong>CryptoQuant</strong> flagged the aftermath as the largest sub-1 BTC movement since <strong>FTX</strong>, as spooked holders shuffled coins in a hurry. Do not expect recovery; the stolen BTC is already a candidate for <strong>Monero</strong> and <strong>L-BTC</strong> laundering paths.</p>

<p>Separately, <strong>MetronomeDAO</strong> disclosed a <strong>$15.7 million synth shortfall</strong> (6,367 msETH and 4.57 million msUSD unbacked), blaming years of accumulated “unbacked float” from <strong>Chainlink</strong> price-feed latency in its swap module. The treasury staged <strong>$34 million</strong> in defensive positions to close the gap. Oracle lag is not a hack, but it drains just the same.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<ul>
  <li><strong>Coldcard MK3 low-entropy seeds:</strong> If you generated a seed on an affected MK3, the device is compromised as a generator. Regenerate entropy elsewhere (<strong>Sparrow</strong>, <strong>Electrum</strong>, dice) and load it on. The hardware still signs fine; it just cannot be trusted to roll the dice.</li>
  <li><strong>Adform supply-chain clipboard swap:</strong> Attackers poisoned a JavaScript file served by ad-tech firm <strong>Adform</strong>, rewriting copied crypto wallet addresses client-side. Detected July 27, removed, and reported. Anyone who copied a <strong>Bitcoin</strong> address on an affected site that day should verify where their funds actually went.</li>
  <li><strong>Rails Active Storage RCE:</strong> A critical flaw lets an unauthenticated attacker read arbitrary files from a Rails app, with escalation to remote code execution. Patch it; exchanges and custodians run more Rails than they admit.</li>
  <li><strong>Adobe Campaign Classic (CVE-2026-48449, CVSS 10.0):</strong> Incorrect authorization enabling arbitrary code execution without user interaction. Maximum severity, minimal excuse.</li>
</ul>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p>No confirmed attribution on the Coldcard sweep yet, though the speed and the immediate pivot toward privacy-chain laundering suggest a prepared, professional operation rather than an opportunist. Predictably, the timeline is already spawning conspiracy theories about the vendor; ignore them until someone shows the block explorer.</p>

<p>The state-actor side stayed busy. Reuters, via <strong>The Block</strong>, detailed Dubai-based <strong>Shelbit</strong> moving over <strong>$4 billion since May 2024</strong> through a network tied to Iranian gambling sites, the central bank, and the <strong>IRGC</strong>, including <strong>$676 million to Binance</strong> in an alleged sanctions-evasion operation. Separately, <strong>OFAC</strong> sanctioned two Iranian firms, including <strong>Hormuz Safe</strong>, for accepting <strong>Bitcoin</strong> as payment for Strait of Hormuz passage. Elsewhere, <strong>Storm-2945</strong> (an operational sub-cluster of <strong>Midnight Blizzard</strong>) ran the <strong>CaptiveCrunch</strong> campaign, pushing fake browser updates over hijacked hotel Wi-Fi to deliver the <strong>CornFlake</strong> RAT. The AI-assisted attack trend also matured: a Chinese-speaking actor wired <strong>DeepSeek</strong> to the open-source <strong>Hermes Agent</strong> for autonomous attacks on exposed servers, and <strong>ESET</strong> logged a broader rise in AI-assisted malware.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>The Coldcard fallout has a market signature: <strong>CoinDesk</strong> notes investors are sending BTC <em>back to exchanges</em>, and the incident is being framed as a possible tailwind for <strong>ETFs</strong>. That is the quiet story. Every self-custody catastrophe is a custody-product marketing budget. Spot <strong>Bitcoin ETFs</strong> closed July with <strong>$172.4 million</strong> in inflows but remain <strong>$5.3 billion</strong> negative year to date, so the funnel is real but not yet a flood.</p>

<p>Macro stayed heavy. <strong>Bitcoin</strong> slipped to two-week lows as the <strong>Fed’s</strong> fifth straight hold and <strong>3.7% PCE</strong> shut the door on near-term cuts, and the <strong>BoJ</strong> intervened to defend the yen near 160. <strong>Tether</strong> posted a <strong>$1.5 billion</strong> Q2 operating profit even as its excess reserve buffer fell by more than <strong>$4 billion</strong>. <strong>Coinbase</strong> missed on Q2 and split Wall Street, while <strong>Base</strong> sequencer revenue fell despite record volume, a reminder that L2 throughput and L2 profit are different columns.</p>

<p>On the regulatory board, <strong>Circle</strong> stacked a <strong>NYDFS</strong> trust charter on top of its federal OCC approval, tightening USDC’s oversight footprint. <strong>Minnesota’s</strong> crypto ATM ban took effect after roughly <strong>$1 million</strong> in reported kiosk scam losses, largely from seniors. And the <strong>Bank of Italy</strong> poured cold water on the stablecoin remittance narrative, finding fiat conversion and payment infrastructure, not blockchain fees, drive most cost and settlement differences. The rails are still the rails, even when you tokenize them.</p>

<p>By the time it is news, it is already priced in. The Coldcard seeds were priced in five years ago. The rest of us just found out this week.</p>

<h2 id="resources">Resources</h2>

<ul>
  <li>https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html</li>
  <li>https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million</li>
  <li>https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices</li>
  <li>Incident trackers (reference standard): <a href="https://rekt.news/leaderboard/">Rekt leaderboard</a> · <a href="https://hacked.slowmist.io/">SlowMist Hacked</a></li>
</ul>

<h2 id="related">Related</h2>

<ul>
  <li><a href="/itsalreadypriced/rtfm/2026/07/29/multisig-and-threshold-signing-beyond-buying-a-safe/">Multisig and Threshold Signing, Beyond Buying a Safe</a></li>
  <li><a href="/itsalreadypriced/2026/07/12/issue-002/">Issue #002 — Week of July 12, 2026</a></li>
  <li><a href="/itsalreadypriced/rtfm/2026/07/15/seed-phrases-and-where-keys-actually-leak/">Seed Phrases and Where Keys Actually Leak</a></li>
</ul>

<p>More: <a href="/itsalreadypriced/">Issues</a> · <a href="/itsalreadypriced/field-notes/">Field Notes</a> · <a href="/itsalreadypriced/rtfm/">RTFM</a></p>

<hr />

<p><em>New Issue every week. Follow <a href="https://x.com/ItsAlreadyPrice">@ItsAlreadyPrice</a> or subscribe via RSS so the next exploit does not surprise you.</em></p>]]></content><author><name>The Desk</name></author><summary type="html"><![CDATA[A five-year-old firmware defect emptied cold storage that never left the drawer, and the crowd is running back to exchanges.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" /><media:content medium="image" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Browsers Assemble Their Own Malware While Bridges Bleed $31.7M</title><link href="https://bizzal70.github.io/itsalreadypriced/2026/07/26/issue-004/" rel="alternate" type="text/html" title="Browsers Assemble Their Own Malware While Bridges Bleed $31.7M" /><published>2026-07-26T00:00:00+00:00</published><updated>2026-07-26T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/2026/07/26/issue-004</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadypriced/2026/07/26/issue-004/"><![CDATA[<p><em>Issue #004 · Week of July 26, 2026</em></p>

<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The malware this week did not arrive as a file; it arrived as instructions and let your browser do the assembly. Meanwhile the CeFi graveyard added another headstone, DPRK ran both sides of the crime (stealing funds, then arresting the launderers), and the market spent its energy debating quantum roadmaps instead of reading the withdrawal queues. As always, by the time the token cratered 59%, the exit was already priced in.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>The headline number belongs to two <strong>Ethereum</strong> bridges that lost a combined <strong>$31.7 million</strong> within hours of each other, with a third protocol halting staking as the contagion spread. Bridges remain the softest target in the stack, and nothing about that has changed in three years.</p>

<p>Elsewhere, crypto payments firm <strong>Triple-A</strong> was drained for <strong>$9.7 million</strong> in a wallet compromise. And the slow-motion breach nobody labels a breach continued: <strong>BitMart</strong> announced it will wind down after nine years, its <strong>BMX</strong> token cratering roughly 59% in 24 hours while users reported withdrawal delays. The global CEO says he learned of the closure when it went public and was told his employment was ending on July 24. When the people running the exchange find out from the press, the depositors were never going to be first in line.</p>

<p><strong>BitMEX</strong> joined the wind-down list with its own legal tail: <strong>Arthur Hayes</strong>, <strong>Samuel Reed</strong>, and <strong>Benjamin Delo</strong> face a proposed class action alleging an “Insider Trading Desk” and deliberate server freezes tied to 623 BTC in liquidation claims. Old allegations, new courtroom, same collateral.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<ul>
  <li><strong>SourTrade malvertising</strong> (detailed by <strong>Confiant</strong> on July 23): fake <strong>TradingView</strong>, <strong>Solana</strong>, and <strong>Luno</strong> pages ship malware in pieces and have the victim’s browser assemble the final Windows executable in memory using the legitimate <strong>Bun</strong> runtime. No single malicious payload sits at a fixed URL to block, which is the entire point.</li>
  <li><strong>Fastjson 1.x</strong> (<strong>CVE-2026-16723</strong>, CVSS 9.0): unauthenticated RCE in Alibaba’s Java JSON library, actively exploited in <strong>Spring Boot</strong> apps, with no patch available. If you run this, you are already exposed.</li>
  <li><strong>GitLab RCE PoC</strong>: working exploit published July 24 for a flaw <strong>GitLab</strong> patched on June 10. Any authenticated user who can push to a project owns unpatched self-managed 18.11.3 servers. Six weeks was your grace period.</li>
  <li><strong>Certighost</strong>: a low-privileged Active Directory user obtains a Domain Controller certificate, then pulls the krbtgt secret via DCSync. Full domain compromise from a nobody account.</li>
  <li><strong>AgentForger</strong> (Zenity Labs): a single phishing link could build and deploy a rogue autonomous agent inside a victim’s org via <strong>ChatGPT Workspace Agents</strong>. Patched by OpenAI on June 8, but a preview of where the next class of breaches lives.</li>
  <li><strong>Supply-chain defenses, finally</strong>: <strong>GitHub</strong> and <strong>PyPI</strong> added a time-based cooldown to <strong>Dependabot</strong> to blunt the window when a freshly published malicious package gets auto-pulled. A structural fix, not a signature. Rare and welcome.</li>
</ul>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p><strong>North Korea</strong> worked both ends of the table. <strong>BlueNoroff</strong> was found running an active phishing kit that impersonates <strong>Zoom</strong> and <strong>Microsoft Teams</strong> via typosquatted domains, profiling victims’ crypto wallets before delivering malware in ClickFix-style social engineering. At the same time, Daily NK reports the DPRK arrested former state cyber operators accused of hacking two of its own state banks and laundering the proceeds through crypto. The regime tolerates crimes committed for the state, not against it.</p>

<p><strong>Golden Chickens</strong> resurfaced with four new malware families (TinyEgg, ChonkyChicken and a modular variant, plus a browser credential stealer), proving that public disclosure inconveniences these operations without ending them.</p>

<p>On the AI-abuse front, a threat actor pointed the open-source <strong>Hermes AI agent</strong> in unattended “YOLO” mode at <strong>Thailand’s Ministry of Finance</strong>, letting it hunt for root and traverse the network autonomously. This is the automation of post-exploitation, and it is no longer theoretical.</p>

<p>And a reminder that social engineering, not clever cryptography, is the primary attack surface: <strong>Binance</strong> now red-teams its own staff monthly against exactly this. They are not being paranoid.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>The board is tilting toward real-world assets. On <strong>Hyperliquid</strong>, tokenized RWAs (stocks, commodities, indices) became the largest trading category for the first time, more than half of weekly volume, prompting <strong>ARK</strong> to declare a regime change. <strong>CoinDesk</strong> noted the institutional influx has quietly killed the memecoin craze. In Brazil, farmers tokenized dairy cows to collateralize loans on <strong>B3</strong>, ten cows backing a $19,600 credit, which is either the future of RWA lending or the most literal bull market on record.</p>

<p>On the regulatory front, the <strong>CLARITY Act</strong> is on the ropes: <strong>Galaxy</strong> cut its passage odds to 30% as Senate Majority Leader <strong>John Thune</strong> signaled it likely misses the August recess, with Democrats rejecting the GOP ethics language. The <strong>EU</strong> dropped its 21st Russia sanctions package, targeting a claimed $120B crypto network and adding <strong>HTX</strong>, <strong>EXMO</strong>, <strong>Rapira</strong>, and others to a transaction ban starting August 23, while <strong>Chainalysis</strong> flagged the new third-country ban mechanism. Meanwhile the <strong>OCC</strong> denied <strong>Wise’s</strong> national trust charter over AML/CFT concerns, an unusual rejection amid a wave of approvals; Wise plans to refile under the <strong>GENIUS Act</strong>.</p>

<p>The infrastructure keeps quietly rotting and rebuilding at the edges: <strong>Poolin</strong>, once Bitcoin’s biggest mining pool, filed for bankruptcy, still owing 11,700 users. <strong>Odos</strong> and <strong>Dango</strong> are shutting down. And <strong>Samsung Wallet</strong> will add stablecoin support including <strong>Circle’s USDC</strong>, which puts stablecoins on hundreds of millions of phones with no timeline attached. That last one, if it ships, matters more than any price chart this week.</p>

<h2 id="resources">Resources</h2>

<ul>
  <li>https://www.reddit.com/r/CryptoCurrency/comments/1v6940c/two_ethereum_bridges_lose_317m_within_hours_as/</li>
  <li>https://www.reddit.com/r/CryptoCurrency/comments/1v6aplc/crypto_payments_firm_triplea_hit_by_97_million/</li>
  <li>https://thedefiant.io/converge/cefi/bitmart-to-wind-down-exchange-end-trading-by-aug-26</li>
  <li>Incident trackers (reference standard): <a href="https://rekt.news/leaderboard/">Rekt leaderboard</a> · <a href="https://hacked.slowmist.io/">SlowMist Hacked</a></li>
</ul>

<h2 id="related">Related</h2>

<ul>
  <li><a href="/itsalreadypriced/2026/07/19/issue-003/">North Korea Slips Into Consensys While macOS Malware Reads Your Telegram</a></li>
  <li><a href="/itsalreadypriced/2026/07/12/issue-002/">Issue #002 — Week of July 12, 2026</a></li>
  <li><a href="/itsalreadypriced/rtfm/2026/07/08/token-approvals-and-the-infinite-allowance/">Token Approvals and the Infinite Allowance</a></li>
</ul>

<p>More: <a href="/itsalreadypriced/">Issues</a> · <a href="/itsalreadypriced/field-notes/">Field Notes</a> · <a href="/itsalreadypriced/rtfm/">RTFM</a></p>

<hr />

<p><em>New Issue every week. Follow <a href="https://x.com/ItsAlreadyPrice">@ItsAlreadyPrice</a> or subscribe via RSS so the next exploit does not surprise you.</em></p>]]></content><author><name>The Desk</name></author><summary type="html"><![CDATA[A week where the malware built itself, two Ethereum bridges emptied in hours, and the exchange rot spread from BitMEX to BitMart.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" /><media:content medium="image" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">North Korea Slips Into Consensys While macOS Malware Reads Your Telegram</title><link href="https://bizzal70.github.io/itsalreadypriced/2026/07/19/issue-003/" rel="alternate" type="text/html" title="North Korea Slips Into Consensys While macOS Malware Reads Your Telegram" /><published>2026-07-19T00:00:00+00:00</published><updated>2026-07-19T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/2026/07/19/issue-003</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadypriced/2026/07/19/issue-003/"><![CDATA[<p><em>Issue #003 · Week of July 19, 2026</em></p>

<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The threat this week did not knock on the door, it filled out an onboarding form. <strong>Consensys</strong> paid a North Korean developer to work on <strong>MetaMask</strong>, which is either a hiring failure or a preview of every remote-first company’s next incident report. The exploits that mattered were quiet, the supply chain was busy, and Bitcoin obligingly sold off into a Fed meeting nobody expects to be dovish.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>The headline number this week is a recovery, not a loss. The attacker behind the May 7 <strong>TrustedVolumes</strong> exploit (an RFQ market maker used by <strong>1inch Fusion</strong>, drained of roughly $5.87M to $6.7M in WETH, USDT, WBTC, and USDC via a bug in its custom RFQ swap proxy) sent back <strong>1,122.12 ETH</strong>, about $2.07M, on July 17. This is the same operator responsible for the March 2025 <strong>1inch Fusion V1</strong> exploit. Partial restitution from a repeat offender is not redemption, it is inventory management.</p>

<p>Elsewhere, <strong>Dunamu</strong>, operator of <strong>Upbit</strong>, drew a sanctions process from South Korean regulators over a roughly $36M hack, a case complicated by the fact that the Virtual Asset User Protection Act contains no explicit penalty provisions for system breaches. Regulators want to punish something the law forgot to define. A fake exchange also drained over $240K from hundreds of retail victims, the kind of loss that never trends but always recurs.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<ul>
  <li><strong>wp2shell (WordPress Core):</strong> Two flaws, now with CVE IDs and a public proof-of-concept, let an anonymous HTTP request run code on a bare install with zero plugins. Every <strong>6.9</strong> and <strong>7.0</strong> site was in range. Patch is not optional.</li>
  <li><strong>HollowByte (OpenSSL):</strong> An 11-byte TLS request makes an unpatched server reserve up to 131 KB for a message that never arrives. On glibc systems, that memory is gone until restart. The fix shipped in June with no CVE and no changelog entry, which is its own kind of vulnerability.</li>
  <li><strong>LegacyHive (Windows):</strong> A researcher published a zero-day granting admin privilege escalation on fully patched systems. No vendor fix at disclosure.</li>
  <li><strong>SonicWall SMA 1000:</strong> Volexity attributes pre-disclosure zero-day exploitation of the VPN appliances to <strong>UTA0533</strong>, with root access obtained since June 22. Edge devices remain the softest perimeter you own.</li>
  <li><strong>7-Zip RCE:</strong> Version 26.02 patches remote code execution via a crafted archive. The oldest attack vector still works because someone always opens the file.</li>
</ul>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p>The <strong>DPRK</strong> headline is <strong>Consensys</strong> unknowingly outsourcing developer work on <strong>MetaMask</strong> to a North Korean operative introduced via a “reputable third-party service provider.” The vetting chain broke exactly where it always does, at the trusted intermediary. In parallel, North Korean actors tied to the <strong>Contagious Interview</strong> campaign are hiding four-stage <strong>OTTERCOOKIE</strong>-aligned payloads (a browser-credential and crypto-wallet stealer, plus a file stealer) inside SVG flag images delivered through fake coding tests. The lure is a job, the payoff is your seed phrase.</p>

<p>Supply-chain crews stayed busy. <strong>Checkmarx</strong> flagged seven malicious <strong>Vite</strong> npm packages (<strong>ViteVenom</strong>, an expansion of <strong>ChainVeil</strong>) using blockchain-based C2 spanning <strong>Tron</strong> and other chains. <strong>SlowMist</strong> documented macOS malware that hijacks <strong>Telegram</strong> sessions and decrypts crypto wallets or phishes recovery phrases via fake apps, while <strong>Kaspersky</strong> identified a separate framework targeting investors through trojanized GitHub apps. <strong>Microsoft</strong> meanwhile warns of surging <strong>ACR Stealer</strong> activity using ClickFix lures to lift browser tokens and Microsoft 365 files. Also billed this week: the <strong>Scattered Spider</strong>-linked pair sentenced in the UK over a $115M ransom scheme.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>Regulators missed their own deadline: US agencies blew past the <strong>GENIUS Act</strong> one-year mark, issuing 10 proposed rules instead of final ones, with the Jan. 18, 2027 effective date unmoved and the implementation window now compressed. Add <strong>USDT</strong> facing a two-year countdown on US platforms and <strong>OKX Europe</strong> offering voluntary USDT-to-USDC conversion under <strong>MiCA</strong>, and Tether’s regulatory runway keeps shortening. France, for its part, ordered ISPs to geoblock <strong>Polymarket</strong> on gambling grounds, timed to the World Cup third-place match.</p>

<p>Markets did what macro told them. Bitcoin slid toward <strong>$63,000</strong>, with the <strong>Coinbase</strong> premium negative for a record 60 straight days and roughly two-thirds of exchange inflows coming from long-term holders selling at a loss. The proximate trigger was an AI-driven chip rout after Moonshot’s <strong>Kimi K3</strong> beat Western frontier models on key benchmarks, dragging risk assets down together. Meanwhile the money kept coming from Wall Street’s side: <strong>Citadel Securities</strong> put $400M into <strong>Crypto.com</strong> at a $20B valuation, and <strong>ZachXBT</strong> picked a fight with <strong>Trezor</strong> over hardware wallet safety. On the debate about who moves markets, note <strong>DOJ</strong> is reportedly dropping charges against an alleged $722M Ponzi operator, which tells you more about enforcement priorities than any rule ever will.</p>

<h2 id="resources">Resources</h2>

<ul>
  <li>https://www.reddit.com/r/CryptoCurrency/comments/1uzlx2j/the_attacker_behind_the_may_58m_trustedvolumes/</li>
  <li>https://www.reddit.com/r/CryptoCurrency/comments/1v0gvt1/a_fake_crypto_exchange_has_drained_240k_from/</li>
  <li>https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html</li>
  <li>https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/</li>
  <li>https://www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-grants-hackers-admin-access/</li>
  <li>https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html</li>
  <li>https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/</li>
  <li>https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html</li>
  <li>Incident trackers (reference standard): <a href="https://rekt.news/leaderboard/">Rekt leaderboard</a> · <a href="https://hacked.slowmist.io/">SlowMist Hacked</a></li>
</ul>

<h2 id="related">Related</h2>

<ul>
  <li><a href="/itsalreadypriced/field-notes/2026/07/19/field-note/">Field Note — July 19, 2026</a></li>
  <li><a href="/itsalreadypriced/field-notes/2026/07/18/field-note/">Field Note — July 18, 2026</a></li>
  <li><a href="/itsalreadypriced/field-notes/2026/07/17/field-note/">Field Note — July 17, 2026</a></li>
</ul>

<p>More: <a href="/itsalreadypriced/">Issues</a> · <a href="/itsalreadypriced/field-notes/">Field Notes</a> · <a href="/itsalreadypriced/rtfm/">RTFM</a></p>

<hr />

<p><em>New Issue every week. Follow <a href="https://x.com/ItsAlreadyPrice">@ItsAlreadyPrice</a> or subscribe via RSS so the next exploit does not surprise you.</em></p>]]></content><author><name>The Desk</name></author><summary type="html"><![CDATA[DPRK infiltrates a MetaMask developer, npm and SVG supply-chain tricks proliferate, and hardware wallets take fire, all while Bitcoin bleeds toward $63K on an AI-driven risk-off.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" /><media:content medium="image" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Issue #002 — Week of July 12, 2026</title><link href="https://bizzal70.github.io/itsalreadypriced/2026/07/12/issue-002/" rel="alternate" type="text/html" title="Issue #002 — Week of July 12, 2026" /><published>2026-07-12T00:00:00+00:00</published><updated>2026-07-12T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/2026/07/12/issue-002</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadypriced/2026/07/12/issue-002/"><![CDATA[<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The interesting money this week did not move on price, it moved on code that should never have shipped: a Supra oracle that trusted a fabricated update, and two package registries serving malware to anyone who typed <code class="language-plaintext highlighter-rouge">npm install</code>. Everyone else spent the week arguing about whether Bitcoin is in the second half of a bear market. Meanwhile the supply chain quietly turned into the attack surface, again.</p>

<h2 id="the-breaches">The Breaches</h2>

<p><strong>Bonzo Lend</strong>, a lending protocol on <strong>Hedera</strong>, lost roughly <strong>$9 million</strong> when an attacker inflated the value of <strong>SAUCE</strong> collateral and borrowed against it. The root cause was not Bonzo’s contracts but <strong>Supra</strong>’s on-chain oracle verifier, which accepted a manipulated price update as legitimate. A second wallet borrowed another ~<strong>$1 million</strong> through the same flaw, then self-identified as a white hat and said it would return the funds. The protocol shed <strong>77% of its total value locked</strong> as everyone else did the sensible thing and left. When your solvency depends on a third party’s verifier logic, that verifier is your smart contract whether you audited it or not.</p>

<p>Separately, a long-time <strong>Solana</strong> holder had <strong>181,000 SOL</strong> (about <strong>$14.2 million</strong>) drained, per <strong>ZachXBT</strong>. The funds were sold, bridged to <strong>Ethereum</strong>, and converted into roughly <strong>7,918 ETH</strong>, the standard laundering choreography. Billed as the largest single-individual crypto theft on record, though the more useful lesson is the boring one: bridged-and-swapped means the window to freeze anything closed before the news did.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<ul>
  <li><strong>The jscrambler npm package (8.14.0) was compromised</strong> and shipped a Rust infostealer via a <code class="language-plaintext highlighter-rouge">preinstall</code> hook, with builds for Windows, macOS, and Linux. <strong>Socket</strong> flagged it six minutes after publication, which is fast, and still not fast enough if your CI pulled it in that window.</li>
  <li><strong>Injective Labs’ GitHub was compromised</strong> and used to push a malicious <code class="language-plaintext highlighter-rouge">@injectivelabs/sdk-ts@1.20.21</code> to npm, with fake telemetry that exfiltrated wallet private keys and seed phrases. Two crypto-adjacent supply chain hits in one week is not a coincidence, it is a pattern.</li>
  <li><strong>Ledger’s Donjon team demonstrated a laser fault attack on Tangem cards</strong> that resets the wallet password by bypassing a recovery-state check in firmware. The cards cannot be patched. <strong>Tangem</strong> calls the everyday-user risk “virtually non-existent,” which is true right up until someone has physical access and a lab bench.</li>
  <li><strong>AI found an Ethereum consensus bug</strong> that could take validators offline, but humans had to write the proof-of-concept. Useful reminder that the machine finds the smell; a person still has to open the drain.</li>
  <li><strong>Ghostcommit</strong> hides prompt injection inside PNG files, slipping past AI code reviewers <strong>CodeRabbit</strong> and <strong>Bugbot</strong> (which never open images), then convincing a coding agent to dump a repo’s <code class="language-plaintext highlighter-rouge">.env</code> secrets into code. As the industry bolts AI agents onto everything, the attack surface follows.</li>
</ul>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p>No named nation-state crew claimed this week’s crypto thefts, but the tradecraft speaks for itself. The <strong>jscrambler</strong> and <strong>Injective Labs</strong> compromises follow the now-familiar developer-targeting playbook: poison a trusted package, wait for the install hook, harvest keys. This is the same category of attack that has kept <strong>DPRK</strong>-aligned actors funded, whether or not attribution lands here.</p>

<p>Elsewhere, <strong>O-UNC-066</strong> (tracked by <strong>Okta</strong>) is running voice-phishing that pushes <strong>Microsoft 365</strong> users into enrolling attacker-controlled <strong>Entra</strong> passkeys for data extortion, a reminder that passkeys move the weak link to enrollment, not eliminate it. China-linked <strong>Silver Fox</strong> deployed a new Rust RAT, <strong>MODBEACON</strong>, using gRPC streaming for encrypted C2. And on the enforcement side, a <strong>Ryuk ransomware</strong> operator pleaded guilty in the US facing 15 years, while a jailed launderer was charged with moving <strong>$290,000</strong> in court-forfeited crypto from a <strong>Kraken</strong> account while behind bars. The crypto never sleeps, even when its custodian is incarcerated.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>The board shifted on regulation and custody more than on price. <strong>Circle</strong> won final <strong>OCC</strong> approval for a national trust bank (<strong>First National Digital Currency Bank</strong>), eventually to hold USDC reserves under direct federal supervision; the stock popped over 10%. A <strong>CBDC ban</strong> became US law via the <strong>21st Century ROAD to Housing Act</strong>, which <strong>Trump</strong> declined to sign but did not veto, blocking a Fed digital dollar through 2030.</p>

<p>On flows, US spot <strong>Bitcoin</strong> ETFs just closed their worst month on record with roughly <strong>$4.5 billion</strong> of June outflows, and combined BTC/ETH ETFs snapped an eight-week outflow streak with a modest <strong>$282 million</strong> inflow, recovering about 3% of the <strong>$9.46 billion</strong> bled over the prior two months. More telling: Bitcoin exchange reserves sit near a seven-year low, and coins leaving the ETF wrapper are not landing on <strong>Coinbase</strong> or <strong>Binance</strong>, they are moving to self-custody. <strong>Binance</strong>’s co-CEO says 70% of EU withdrawals post-<strong>MiCA</strong> went to self-custody rather than licensed platforms. A custody-preference signal, and given this week’s <strong>EU DAC8</strong> registry concerns (France’s tax-clerk-to-kidnapping-gang leak being the cautionary tale), you can see why people prefer keys they hold. Which brings us back to the top of the issue: keys you hold are keys you can also lose to a laser, a poisoned package, or a bad oracle. Pick your counterparty risk carefully, because you never actually escape it.</p>

<h2 id="resources">Resources</h2>

<ul>
  <li>https://www.coindesk.com/web3/2026/07/11/lending-protocol-bonzo-loses-77-of-value-locked-as-usd9-million-oracle-exploit-rattles-hedera</li>
  <li>https://www.reddit.com/r/CryptoCurrency/comments/1uti7ci/biggest_hack_from_an_individual_in_crypto_history/</li>
  <li>https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html</li>
  <li>https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html</li>
  <li>https://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.html</li>
  <li>Incident trackers (reference standard): <a href="https://rekt.news/leaderboard/">Rekt leaderboard</a> · <a href="https://hacked.slowmist.io/">SlowMist Hacked</a></li>
</ul>]]></content><author><name>The Desk</name></author><summary type="html"><![CDATA[A $9M oracle exploit, a $14.2M wallet drain, and two poisoned software supply chains, all landing while everyone stared at ETF flow charts.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" /><media:content medium="image" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Issue #000: It’s Already Priced.</title><link href="https://bizzal70.github.io/itsalreadypriced/2026/07/05/issue-000/" rel="alternate" type="text/html" title="Issue #000: It’s Already Priced." /><published>2026-07-05T00:00:00+00:00</published><updated>2026-07-05T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/2026/07/05/issue-000</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadypriced/2026/07/05/issue-000/"><![CDATA[<p>Markets move on information. By the time a headline reaches your feed, the people who were going to act on it already did. The price you see is the crowd’s answer to yesterday’s question. It’s already priced in.</p>

<p>Security is the one edge the market keeps mispricing. A protocol trades on its TVL and its narrative right up until the afternoon a signer key leaks or a rounding error in a lending contract turns into an eight-figure withdrawal. Then the discount arrives all at once. This publication is built around that gap.</p>

<h2 id="what-this-is">What This Is</h2>

<p>Three things, every week, on a fixed cadence.</p>

<p><strong>Issues</strong> land weekly. The roundup: the exploits that drained real money, the wallets and contracts worth watching, and the market or regulatory moves that actually shift the board. If it did not move funds or change the rules, it does not make the cut.</p>

<p><strong>Field Notes</strong> land daily. One thing. A theft in progress, an address worth flagging, or a habit that keeps your keys yours. Short enough to read before your coffee cools.</p>

<p><strong>RTFM</strong> lands on Wednesdays. Long-form and technical. How custody actually works, how funds actually get stolen, and what the people who do not get drained do differently.</p>

<h2 id="the-rules">The Rules</h2>

<p>Every claim here is meant to be checkable. Thefts and exploits link to block explorers and incident trackers. Tokens resolve to canonical market-data pages. No screenshots as evidence, no anonymous alpha, no price targets. If we cannot source it, we do not run it.</p>

<p>We do not tell you what to buy. We tell you where the money went and why.</p>

<h2 id="sources">Sources</h2>

<ul>
  <li>Market-data reference standard: <a href="https://www.coingecko.com/">CoinGecko</a></li>
  <li>On-chain reference standard: <a href="https://etherscan.io/">Etherscan</a> and equivalent chain explorers</li>
  <li>Incident reference standard: <a href="https://rekt.news/leaderboard/">Rekt News leaderboard</a> and <a href="https://hacked.slowmist.io/">SlowMist Hacked</a></li>
</ul>

<p>First Issue proper drops next week.</p>]]></content><author><name>The Desk</name></author><summary type="html"><![CDATA[Why another crypto newsletter, and why this one leads with security.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" /><media:content medium="image" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Issue #001 — Week of July 05, 2026</title><link href="https://bizzal70.github.io/itsalreadypriced/2026/07/05/issue-001/" rel="alternate" type="text/html" title="Issue #001 — Week of July 05, 2026" /><published>2026-07-05T00:00:00+00:00</published><updated>2026-07-05T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadypriced/2026/07/05/issue-001</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadypriced/2026/07/05/issue-001/"><![CDATA[<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>Markets spent 2026 pricing the upside: more ETFs, a friendlier SEC, a White House that does not want to tax your coffee-money bitcoin. The other half of the board, where North Korea drains the better part of a billion dollars a year, is not in any chart. This week handed us both at once, plus a rare reminder that the good ending exists. It is just the exception.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>June’s largest single loss was <strong>Humanity Protocol</strong>, over $30 million. The contracts held. The private keys did not: they had been backed up to a developer machine already carrying malware. Quantstamp flags tooling consistent with North Korean crews, the proceeds moved across Bitcoin, Solana, Hyperliquid, and BNB Chain, and researchers see possible overlap with the Kelp attacker. Your custody is only as strong as the laptop your backups touched.</p>

<p>The month around it, per PeckShield: <strong>$75.87 million across 40 incidents</strong>, down 7.13% from May’s $81.7 million. The rest of the ledger read like every month before it. <strong>Syscoin Bridge</strong> for roughly $10 million, a <strong>JaredFromSubway MEV bot</strong> for $7.5 million, <strong>Secret Network</strong> for $4.67 million. Bridges, contracts, and stolen keys, in that order, forever.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<ul>
  <li><strong>Aptos Move VM, stale-cache type confusion</strong> — Researchers at <strong>Hexens</strong> showed how the bug let an attacker treat one on-chain resource as another and seize protocol permissions. Direct exposure was low single-digit billions; systemic blast radius across bridges, USDC administration, and exchanges was put near <strong>$70 billion</strong>. Reproduced with a $3,000 server simulating a third of the validator set at roughly 90% success. Reported through the bug bounty on February 25, patched to mainnet within hours, no funds lost. This is what the good ending looks like.</li>
  <li><strong>The evergreen you can fix today</strong> — none of the month’s key-theft losses needed a zero-day. Malware-infected developer boxes and live token approvals did the work. Revoke stale allowances, keep backups off connected machines.</li>
</ul>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p><strong>Chainalysis</strong> attributes roughly <strong>76% of 2026 hack losses to state-backed actors</strong>, most tracing to <strong>Lazarus</strong>. Two April jobs set the year’s tone. <strong>Kelp DAO</strong> lost about $290 million through a LayerZero-based bridge. <strong>Drift</strong>, Solana’s largest perpetual-futures venue, lost about $285 million in twelve minutes, after a six-month, in-person social-engineering campaign bought the crew admin access. Bridges and people keep breaking faster than cryptography does.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>The <strong>SEC</strong> is signaling a “neutral” posture on crypto ETFs, its investment-management leadership publicly conceding it handled them poorly and lost industry trust. Filings are up to roughly <strong>1,800 this year</strong>, about 50% more than last. The President has come out against capital-gains tax on bitcoin used as payment. The access story is being priced in aggressively. The security story is not being priced at all. By the time a breach is news, the discount has already arrived. The keys get priced first.</p>

<h2 id="resources">Resources</h2>

<ul>
  <li>Aptos Move VM flaw: <a href="https://www.coindesk.com/tech/2026/07/04/how-ethical-hackers-with-just-a-usd3-000-server-found-a-flaw-that-could-ve-put-usd70-billion-in-crypto-at-risk">CoinDesk</a></li>
  <li>June totals (PeckShield): <a href="https://finance.yahoo.com/markets/crypto/articles/hackers-steal-75-87-million-040719406.html">Yahoo Finance</a></li>
  <li>2026 state-actor attribution: <a href="https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/">Chainalysis</a></li>
  <li>Kelp DAO ~$290M: <a href="https://www.bloomberg.com/news/articles/2026-04-19/crypto-hack-worth-290-million-triggers-defi-contagion-shock">Bloomberg</a> · Drift ~$285M: <a href="https://www.forbes.com/sites/jemmagreen/2026/04/11/285m-hack-proved-defis-decentralisation-promise-is-still-a-fiction/">Forbes</a></li>
  <li>SEC ETF posture: <a href="https://www.theblock.co/post/383241/crypto-regulation-2026-sec-ambitious-agenda-empowered-cftc">The Block</a></li>
  <li>Incident trackers (reference standard): <a href="https://rekt.news/leaderboard/">Rekt leaderboard</a> · <a href="https://hacked.slowmist.io/">SlowMist Hacked</a></li>
</ul>]]></content><author><name>The Desk</name></author><summary type="html"><![CDATA[The machines kept stealing while Washington kept smiling. State-backed crews are past $840M for the year, a $70B flaw got quietly patched with nobody hurt, and the SEC suddenly wants to be liked. Only half of that is priced in.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" /><media:content medium="image" url="https://bizzal70.github.io/itsalreadypriced/assets/og-card.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry></feed>