Announcing CommitWatch: Every Patch Tells a Story

A patch is not the same as disclosure. CommitWatch reads security-critical commits so the rest of us don't have to — and keeps a public record of what was fixed, how clearly it was explained, and whether anyone told the users.

Read More
Full Disclosure: Coldcard v5.6.0 Post-Hotfix Analysis and 39 Unpatched Findings

On July 31, 2026, Coinkite released Coldcard firmware v5.6.0 as an urgent hotfix for a "limited entropy bug" that produced roughly $90M in user losses. This post presents a technical analysis of what that hotfix actually addresses, what it does not, and additional security findings that users need to know about when deciding how to proceed.

Read More
The $38 Million Random Number

Coldcard's five-year RNG failure let attackers sweep $38M from wallets this week — but seeds protected by a strong BIP39 passphrase survived. Here's why, and how TimeCapsule makes that layer practical.

Read More
Important Security Advisory: pfSense Captive Portal Vulnerability

An important security vulnerability has been discovered in pfSense that affects installations with captive portal enabled with certain configurations. This vulnerability requires NO AUTHENTICATION to exploit.

Read More
(Updated) Coldcard Delta PIN Bitcoin Private Key Recovery Vulnerability

The Karma-X Security Research Team discovered a critical cryptographic vulnerability in the Coldcard hardware wallet's Delta PIN feature that allowed full private key recovery with just two transaction signatures.

Read More
Critical Vulnerability in Coldcard Hardware Wallets

Karma-X has discovered a critical vulnerability in the ColdCard wallet which could compromise user funds. Traveling with a ColdCard device could present significant risk to user funds and it is advised to use caution until patches are released.

Read More
Multiple Critical Security Vulnerabilities in Nvidia TensorRT Library

Karma-X Research Team has discovered multiple critical vulnerabilities in NVIDIA TensorRT

Read More
Multiple Critical Security Vulnerabilities in Ollama

Karma-X Research Team has discovered multiple critical security vulnerabilities in Ollama, the popular open-source AI framework.

Read More
Template Injection in LangChain Mustache Callable Scopes Leading to Remote Code Execution: CVE Pending

A template injection vulnerability exists in LangChain's Mustache template processing engine that allows attackers to execute arbitrary Python code through user-controlled callable scopes

Read More
💬 Ask our AI Assistant Kali