Fetching from the wire…
Security2026-08-06 · source-backed
Fireship walked through it August 5. ColdCard's firmware runs MicroPython, whose weak RNG was supposed to be disabled by setting a flag to 0. Both RNGs exported the same function name, and the crypto library chose between them with an if-not-defined check. The flag was defined. As zero. For five years every seed phrase came from MicroPython's RNG, which on bare metal falls back to chip serial plus a timer, both deterministic, collapsing 128 bits into brute-forceable space. Since July 30 attackers have drained 1,600+ BTC (~$400M) from 7,000+ wallets. No malware, no phishing. Victims are now bidding against attackers to buy back their own coins.
Each link below shares sources, entities, or timing with this story.
7-minute field report published August 11, framing deflationary: the gap between demo reels and lab reality is wider than the funding narrative implies (Fireship). 616,000 views in roughly 24 hours, making it the most-watched skeptical take on embodied AI this week and a usefu...
Judge Rita Lin ruled August 27 that Defense Secretary Hegseth's designation of Anthropic as a supply-chain risk violated the First Amendment and Fifth Amendment due process, ordering the government to rescind all directives against the company (The Verge). Her 59-page opinion...
NVD published this against kazuph/mcp-fetch through 1.6.3 on August 26. isSafeUrl reads the hostname from the parsed URL, which for yields the bracketed string, then tests it with net.isIP, which returns zero for a bracketed value. The entire private-address branch is skipped,...
NVD posted nine advisories on August 25, clustering into one shape: a local server assuming a browser can't reach it. PraisonAI validated MCP origins with request_origin.startswith(allowed) against a localhost allowlist, so an attacker-registered localhost.attacker.com passes...
cua-driver-rs v0.20.0, published August 24, ships a codesigned and notarized macOS universal binary plus a QwenCuaDriver.app, unsigned Linux x86_64/arm64 builds on a glibc 2.31 floor, and Windows builds, with a single @qwen-code/cua-sdk npm package built against those assets....
Siddharth Ahuja reported on August 9 that his account was compromised, his ownership stripped from Blender MCP and Ableton MCP (2,600 stars), and the account suspended while the attacker pushed commits. Two CVEs were also filed against the repo (CVE-2026-10661, CVE-2026-10662)...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.