Curated YTD headline roundup covering POAP wind-down, Trump Media BTC transfers, Robinhood UK registration, regulatory updates, and security threats.
Regulation & Gov ·
A fourth organized attack targeting Coldcard users may be underway, with approximately 388.9 BTC moved across 462 victim addresses in a concentrated block range, according to Galaxy Research analysis. The activity level was roughly 45 times higher than baseline, and some funds have already been transferred to secondary addresses while additional transactions remain pending with replace-by-fee signaling enabled.
This follows three previously identified attack waves that affected 4,585 addresses and resulted in approximately 1,367.05 BTC being drained. Coldcard halted shipments and destroyed remaining devices running vulnerable firmware, though related products Satscard, Opendime, and Tapsigner were unaffected. The manufacturer released patched firmware protecting newly generated seeds, but users with seeds created on vulnerable firmware must generate new seeds and transfer any remaining holdings immediately.
Recommendations include moving funds off Coldcard devices promptly and using elevated transaction fees. For transactions still pending, replace-by-fee mechanisms may provide an escape route for eligible transactions. The extent of ongoing vulnerability across the broader user base remains unclear, as does the timeline for full recovery of swept funds.