[SecurityIntel] 02 Aug | Coldcard Wallet Flaw Leads to $70M Theft
SECURITYINTEL DAILY BRIEF ■ Threat Intel Brief Sunday, August 02, 2026 INTEL CONFIDENCE 70% THREAT LEVEL CRITICAL THREAT OF THE DAY Coldcard Wallet Flaw Leads to $70M Theft CRITICAL 5 C2 IPs 0 OTX IOCs 9 ARTICLES ■ ANALYST TLDR Today's threat landscape is highlighted by critical vulnerabilities and sophisticated delivery vectors, including a maximum-severity CVSS 10.0 flaw in Adobe Campaign Classic and a critical RCE vulnerability in the Ruby on Rails Active Storage framework. Additionally, threat actors are actively exploiting hardware wallet firmware flaws and hijacking hotel Wi-Fi networks to deliver surveillance malware like the CornFlake RAT. Organizations must prioritize patching web frameworks and enterprise software while enforcing strict network access controls for remote workers. ■ CRITICAL STORIES CRITICAL #1 Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft A firmware vulnerability in Coldcard hardware wallets allowed attackers to drain $70.2 million across 1,196 Bitcoin addresses in just 41 minutes, highlighting severe risks in hardware-based crypto storage. CRITICAL #2 Adobe Campaign Classic CVSS 10.0 Flaw Allows Zero-Interaction RCE A maximum-severity vulnerability (CVE-2026-484) in Adobe Campaign Classic enables unauthenticated arbitrary code execution without any user interaction, posing a severe threat to enterprise marketing platforms. CRITICAL #3 Ruby on Rails Patches Critical Active Storage Flaw with RCE Potential A critical vulnerability in the Rails Active Storage framework allows unauthenticated attackers to read arbitrary files and potentially escalate to remote code execution (RCE). HIGH #4 Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver CornFlake RAT Threat actors are hijacking hotel Wi-Fi networks to serve fake browser updates that install 'CornFlake' surveillance malware, capable of capturing keystrokes, webcam, and microphone data. ■ CVEs IDENTIFIED CVE-2026-484 Adobe Campaign Classic (ACC) — Arbitrary code execution without user interaction Critical (CVSS 10.0) [CVE-TBD] Ruby on Rails (Active Storage) — Unauthenticated arbitrary file read and potential remote code execution (RCE) Critical [CVE-TBD] Coinkite Coldcard Firmware — Firmware flaw allowing unauthorized draining of cryptocurrency wallets Critical [CVE-TBD] Adform JavaScript — Script poisoning leading to cryptocurrency wallet address swapping High ■ THREAT ACTORS Unknown Cybercriminal Hijacked hotel Wi-Fi to distribute CornFlake RAT via fake browser updates Unknown Cybercriminal Exploited Coldcard firmware flaw to steal $70.2 million in Bitcoin Unknown Cybercriminal Poisoned Adform JavaScript to swap cryptocurrency wallet addresses ■ ATT&CK TTPs T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Tools | Poisoned Adform JavaScript distributed to customer sites to swap crypto addresses T1557.002 Adversary-in-the-Middle: Wi-Fi | Hijacked hotel Wi-Fi networks to serve fake browser updates T1566 Phishing | AMOS stealer distribution and campaigns targeting AI solutions providers like ChatGPT T1190 Exploit Public-Facing Application | Exploitation of Adobe Campaign Classic (CVE-2026-484) and Ruby on Rails Active Storage flaws T1125 Video Capture | CornFlake RAT capturing webcam images from infected hosts T1056.001 Keylogging | CornFlake RAT capturing keystrokes on infected hosts ■ PATCH PRIORITY [P3 PATCH NOW] ≤1 week CRITICAL — Adobe Campaign Classic (ACC) — Zero-interaction arbitrary code execution vulnerability (CVE-2026-484) — [THN] [P3 PATCH NOW] ≤1 week CRITICAL — Ruby on Rails (Active Storage) — Unauthenticated arbitrary file read and potential RCE — [BC] / [SW] [P3 PATCH NOW] ≤1 week CRITICAL — Coinkite Coldcard — Firmware flaw leading to massive cryptocurrency theft — [THN] ■ RECOMMENDED ACTIONS TODAY 1 [P1] Patch Adobe Campaign Classic immediately to address the CVSS 10.0 vulnerability (CVE-2026-484) to prevent zero-interaction arbitrary code execution. 2 [P1] Update Ruby on Rails installations to the latest patched version to mitigate the critical Active Storage file read and RCE vulnerability. 3 [P1] Update Coinkite Coldcard hardware wallet firmware to the latest secure version to protect against the critical wallet-draining vulnerability. 4 [P2] Implement robust endpoint protection on macOS devices to detect and block Atomic MacOS Stealer (AMOS) infections. 5 [P2] Enforce VPN usage on public and hotel Wi-Fi networks to mitigate Adversary-in-the-Middle attacks distributing the CornFlake RAT. LIVE IOC FEED C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 PORT 8080 STATUS OFFLINE MALWARE Emotet COUNTRY US IP ADDRESS 50.16.16.211 PORT 443 STATUS ONLINE MALWARE QakBot COUNTRY US IP ADDRESS 34.204.119.63 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY US IP ADDRESS 178.62.3.223 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY GB IP ADDRESS 27.133.154.218 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY JP FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
SECURITYINTEL DAILY BRIEF
Sunday, August 02, 2026
Coldcard Wallet Flaw Leads to $70M Theft
Today's threat landscape is highlighted by critical vulnerabilities and sophisticated delivery vectors, including a maximum-severity CVSS 10.0 flaw in Adobe Campaign Classic and a critical RCE vulnerability in the Ruby on Rails Active Storage framework. Additionally, threat actors are actively exploiting hardware wallet firmware flaws and hijacking hotel Wi-Fi networks to deliver surveillance malware like the CornFlake RAT. Organizations must prioritize patching web frameworks and enterprise software while enforcing strict network access controls for remote workers.
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft
A firmware vulnerability in Coldcard hardware wallets allowed attackers to drain $70.2 million across 1,196 Bitcoin addresses in just 41 minutes, highlighting severe risks in hardware-based crypto storage.
Adobe Campaign Classic CVSS 10.0 Flaw Allows Zero-Interaction RCE
A maximum-severity vulnerability (CVE-2026-484) in Adobe Campaign Classic enables unauthenticated arbitrary code execution without any user interaction, posing a severe threat to enterprise marketing platforms.
Ruby on Rails Patches Critical Active Storage Flaw with RCE Potential
A critical vulnerability in the Rails Active Storage framework allows unauthenticated attackers to read arbitrary files and potentially escalate to remote code execution (RCE).
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver CornFlake RAT
Threat actors are hijacking hotel Wi-Fi networks to serve fake browser updates that install 'CornFlake' surveillance malware, capable of capturing keystrokes, webcam, and microphone data.
Adobe Campaign Classic (ACC) — Arbitrary code execution without user interaction
Ruby on Rails (Active Storage) — Unauthenticated arbitrary file read and potential remote code execution (RCE)
Coinkite Coldcard Firmware — Firmware flaw allowing unauthorized draining of cryptocurrency wallets
Adform JavaScript — Script poisoning leading to cryptocurrency wallet address swapping
Hijacked hotel Wi-Fi to distribute CornFlake RAT via fake browser updates
Exploited Coldcard firmware flaw to steal $70.2 million in Bitcoin
Poisoned Adform JavaScript to swap cryptocurrency wallet addresses
CRITICAL — Adobe Campaign Classic (ACC) — Zero-interaction arbitrary code execution vulnerability (CVE-2026-484) — [THN]
CRITICAL — Ruby on Rails (Active Storage) — Unauthenticated arbitrary file read and potential RCE — [BC] / [SW]
CRITICAL — Coinkite Coldcard — Firmware flaw leading to massive cryptocurrency theft — [THN]
■ RECOMMENDED ACTIONS TODAY
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5
FULL IOC EXPORT — GOOGLE SHEET
All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
