Coldcard Seed Flaw, Adform Script Poisoning & Adobe 10.0 (08/02/2026)
- › A firmware integration error shipped in March 2021 let attackers regenerate Coldcard wallet seeds offline, draining 4,585 addresses worth about $88.6 million.
- › Attackers poisoned a JavaScript file served by ad tech firm Adform, rewriting cryptocurrency wallet addresses in the clipboards of visitors to customer sites.
- › Adobe patched CVE-2026-48449, a CVSS 10.0 authorization flaw in Campaign Classic that runs code with no user interaction.
- › Arch Linux disabled AUR package adoption after attackers took over more than 200 packages to push a Rust infostealer.
- › Amgen says attackers pulled patient health data and R&D material out of cloud systems run by third-party providers.
A firmware integration error that shipped in March 2021 paid out roughly $88.6 million over one weekend. Treat your randomness source as a supply chain component, because that is how the attacker treated it. Adform’s poisoned ad script and the Arch Linux AUR takeovers ran the same play one layer up, compromising a single distribution point to reach everyone downstream, and Adobe capped the day with a CVSS 10.0 in Campaign Classic.
Top 5 Critical Security Alerts
1. A 2021 Coldcard Firmware Bug Cashed Out for $88.6 Million
An attacker swept 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million. Galaxy Research traced it to a March 2021 Coldcard firmware change that routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator, so anyone who could work out the device ID and timer state could regenerate seed candidates offline with no physical access. Later waves pushed Galaxy’s running total to 4,585 addresses and 1,367.05 BTC, roughly $88.6 million. Coinkite believes the attacker used AI to find the flaw in its open source firmware, and says its own AI audit of the same code weeks earlier turned up nothing. The Hacker News
Operator Note: Coinkite shipped emergency firmware on July 31, but patching does not fix a seed that was already generated weakly. Affected users have to generate a new seed on patched firmware and move the coins, because restoring the old one carries the flaw forward.
2. Adform’s Ad Script Was Rewritten to Swap Wallet Addresses
Attackers modified a JavaScript file served by advertising technology firm Adform, turning it into a browser-side tool that replaced cryptocurrency wallet addresses copied to a visitor’s clipboard with attacker-controlled ones. Adform detected it on July 27, removed the code, notified clients, and reported it to authorities. Every site running that tag served the malicious payload without touching its own infrastructure. BleepingComputer
Operator Note: Count the third-party scripts on your checkout and payment pages, then ask who at your company would notice if one of them changed. Subresource integrity and a strict Content Security Policy are the controls that make this survivable, and we walked through both in client-side supply chain defense.
3. Adobe Campaign Classic Ships a CVSS 10.0 With No User Interaction Required
Adobe patched CVE-2026-48449, an incorrect authorization flaw in Campaign Classic scoring a maximum 10.0, which allows arbitrary code execution without any user action. The same update fixes CVE-2026-48448, a CVSS 8.6 SQL injection permitting arbitrary file reads. Fixed builds are ACC v7 7.4.3 build 9398 on Windows and Linux, and Adobe says it has seen no exploitation yet. The Hacker News
Operator Note: Marketing automation platforms hold your whole customer list and tend to sit outside the patch cadence IT tracks. Put a 10.0 with no interaction requirement on this week’s change calendar.
4. Arch Linux Pulled the Plug on User Repository Package Adoption
The Arch Linux project temporarily disabled adoption of Arch User Repository (AUR) packages after attackers took over more than 200 existing or orphaned packages, following a June campaign that hit over 400. The payload is a two-stage loader that checks for debuggers and sandboxes before pulling a Rust infostealer that goes after browser credentials, cryptocurrency wallets, SSH keys, and API credentials, then uses those keys to move laterally. BleepingComputer
Operator Note: An orphaned package is an unowned asset with a live install base, which is the cheapest thing an attacker can buy. The same logic applies to any abandoned internal repo or unmaintained plugin still sitting in your build.
5. Amgen Loses Patient Data From Somebody Else’s Cloud
Amgen found unauthorized activity in July across multiple cloud environments operated by third-party providers, and determined the incident was material on July 29. Attackers took patient protected health information along with proprietary business data and research material. The company has not named the providers, the number of people affected, or a threat actor. BleepingComputer
Operator Note: The breach notification obligation lands on Amgen while the environment belonged to a vendor. Your contracts should already answer who investigates, who notifies, and who pays, because you will be negotiating that in the middle of an incident otherwise.
Additional Security Alerts
Threat Intelligence
- Atomic macOS stealer keeps landing: SANS ISC published a walkthrough of an AMOS infection chain, a reminder that macOS endpoints in your fleet need the same credential-theft detections you built for Windows. SANS ISC
- Phishing campaigns now impersonate AI providers: SANS ISC spotted campaigns built around ChatGPT and similar AI services rather than banks or shipping firms, trading on a user’s fear of losing access to a tool they now depend on. SANS ISC
Security Tools & Best Practices
- Rails patches a critical Active Storage flaw: An unauthenticated attacker could read arbitrary files from a Rails application, with potential to escalate to remote code execution. Patch and check your file-serving paths. BleepingComputer
- Chrome moves to block New Tab hijacker extensions: Google is preparing a feature that stops policy-installed extensions from taking over the New Tab page or changing the default search engine. BleepingComputer
Emerging Security Technologies
- A worm that spreads through Word documents and Copilot: A researcher demonstrated invisible prompt injections hidden inside documents that copy themselves into new files every time the document gets reused. Microsoft confirmed the issue and has not fixed it after 144 days and two attempts. The Decoder
- Apple’s bug bounty inbox is full of AI-generated noise: Apple capped submissions per researcher because fabricated AI reports were clogging review, and an Italian startup was initially unable to report a macOS flaw valued at up to $200,000. The Decoder
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.