A roundup of the week's secondary security items that did not warrant standalone coverage, with verification status noted for each.
Harmony: A Rollback That Is Decided but Not Demonstrated
Three weeks after an attacker exploited flaws in Harmony's legacy cross-shard verification path to mint unbacked ONE tokens, the protocol's remediation plan remains in a peculiar state: published, but with no confirmed execution.
An incident analysis published by Rekt reconstructs the scale of the August 12 incident: an initial 4 billion ONE mint flagged within the hour was later reconciled by Harmony's own August 17 trace to a revised flow model approaching 3 trillion ONE, including one wallet that attempted 534 transfers of 5 billion ONE each in 106 seconds — 477 of which succeeded. SlowMist's public tracker carries a $3.2 million estimate, which represents third-party cash-out value rather than the dilution cost to every other holder. The rollback plan holds Shard 0 at block 92,730,034 and Shard 1 at block 94,978,278, both to be restored from replacement databases.
Whether that rollback has actually executed — and whether the final mint total has been fully reconciled — remains unconfirmed as of August 30. The incident is Harmony's third major security failure in four years, following the 2022 Horizon bridge key theft and a 2023 staking exploit.
Coldcard: The Story Shifts From Sweeps to Structure
No new large-scale Coldcard sweep was reported this week, but the $130-million-plus firmware exploitation — in which a vulnerable random number generator let at least 15 separate attackers brute-force seeds offline — continued to reshape the custody conversation.
Bloomberg published an opinion piece arguing the fallout shows crypto's self-custody elite "can't be their own banks forever," while industry commentary converged on a more technical consensus: single-vendor single-signature setups are no longer an acceptable baseline for significant holdings, and multi-vendor multi-signature configurations — where no single device or firmware vendor is a single point of failure — are the emerging standard. That consensus matters more than any individual loss figure, because it changes default behavior going forward rather than only assigning blame backward.
Sparrow: AI-Assisted Review Flags Fixes in Bitcoin Privacy Wallet
Cryptonews.net reported that Sparrow, the widely used Bitcoin privacy wallet, shipped an update addressing issues surfaced during an AI-assisted code review. The report credits the machine-assisted review with flagging the fixes that made it into the release.
The item is worth noting for what it signals rather than for severity — no exploitation was reported, and the wallet's maintainers have a strong disclosure track record. But it is another data point in a trend this publication is tracking closely: machine-assisted scanning moving from research curiosity to routine part of the maintenance loop in Bitcoin tooling. The distinction between such scans and human-reviewed audits remains worth preserving even — especially — as the tools improve.
Items in this digest are attributed to the sources named. Incidents without independent confirmation in at least two sources are excluded. TrustGrade Code Scoring, launching December 2026, will bring automated security scans with verified, registry-backed scores to smart contracts — details at trustgrade.ai.