Security Check-in Quick Hits: Coldcard $70M Bitcoin Drain, Adform Crypto Clipboard Swap, Adobe Campaign Classic CVSS 10.0 RCE & Hotel Wi-Fi CornFlake RAT
For August 2, 2026
Coldcard Hardware Wallet Flaw Linked to ~$70 Million Bitcoin Theft
A firmware bug in Coinkite’s Coldcard Bitcoin hardware wallets turned “air-gapped” cold storage into a predictable target. Starting with firmware versions around March 2021 (notably Mk3 and later expanded to other models), seed generation fell back to a weak software PRNG instead of the intended hardware random-number generator. This collapsed the entropy enough that an attacker could enumerate candidate seeds offline, derive addresses, match them against the public blockchain, and sweep funds—without ever touching a physical device.
On July 30, 2026, attackers drained 1,196 addresses of approximately 1,082.65 BTC (about $70.2 million at the time) in a 41-minute window. Galaxy Research mapped the on-chain pattern; many wallets were single-signature and had been dormant for years. Coinkite shipped emergency firmware the next day and urged users who generated seeds on affected versions to create entirely new seeds on patched devices (updating firmware alone does not fix an already-generated weak seed). The incident is a stark reminder that even reputable hardware wallets can harbor long-lived software defects, and that AI-assisted code review may now help both defenders and attackers equally.
Adform Supply-Chain Attack: Poisoned Ad Script Swaps Crypto Wallet Addresses
Attackers compromised a widely embedded JavaScript tracking file (trackpoint-async.js) served by European ad-tech firm Adform from s2.adform.net. The malicious code turned legitimate customer websites into in-browser crypto clippers: it monitored the clipboard (polling every few seconds), rewrote Bitcoin, Ethereum, and Tron addresses on the page or in form fields, and replaced them with attacker-controlled addresses. It also beaconed basic page context to a remote host.
Adform detected and removed the malicious code on July 27, 2026, notified clients, and reported the incident. The payload did not install persistent malware or survive page close, but cached copies of the script could linger. Users who visited affected sites that day are advised to clear browser caches and double-check every wallet address before sending funds. This classic supply-chain hit shows how a single shared third-party resource can silently weaponize thousands of unrelated sites.
Adobe Campaign Classic CVSS 10.0 Flaw Enables Code Execution Without User Interaction
Adobe released updates for a maximum-severity incorrect-authorization vulnerability (CVE-2026-48449, CVSS 10.0) in Campaign Classic (ACC), its enterprise marketing-automation platform. The flaw allows arbitrary code execution in the context of the current user with no user interaction required; a related high-severity SQL-injection issue (CVE-2026-48448, CVSS 8.6) permits arbitrary file reads.
Affected versions are ACC v7 7.4.3 build 9397 and earlier (Windows and Linux, primarily on-premise and hybrid deployments). Adobe states it is unaware of active exploitation in the wild. Organizations running the platform should apply the patched builds immediately. Perfect-10 scores with zero-interaction RCE remain high-priority for any internet-facing or internal enterprise tool that handles customer data or campaign logic.
Hijacked Hotel Wi-Fi Delivers CornFlake Surveillance RAT
Microsoft and partners detailed “CaptiveCrunch,” an ongoing campaign (observed since at least early May) in which threat actors compromise hotel and hospitality captive-portal gateways. Once they control the gateway’s DNS, they redirect connectivity checks and browsing to fake browser/OS update pages (sometimes with ClickFix-style instructions). Victims who follow the prompts install CornFlake, a Go-based remote-access trojan.
CornFlake can capture webcam images, microphone audio, keystrokes, screenshots, clipboard data, browser cookies/passwords (including some App-Bound Encryption cases), and open a remote shell. It persists as a disguised service. Microsoft attributes the activity to Storm-2945, assessed as a sub-cluster of Midnight Blizzard (APT29 / Cozy Bear), linked to Russia’s SVR. Recommended mitigations include always-on full-tunnel VPNs that handle DNS before the local gateway, and never accepting software updates offered through public Wi-Fi portals.
These four stories—hardware-wallet entropy failure at scale, ad-tech supply-chain clipboard theft, a perfect-10 enterprise RCE, and nation-state hotel Wi-Fi surveillance—illustrate the breadth of today’s threat surface: crypto infrastructure, third-party scripts, marketing platforms, and everyday travel networks. Patch, verify addresses, rotate seeds where needed, and treat public Wi-Fi as hostile by default.



