source avatarCrypto's Sherlock

I-share

🚨 41 dakika. 1.196 wallet. 1.082 BTC. Approximately $70 million in assets vaporized from devices known as cold wallets 😳 And the attacker didn’t even touch a single device 👇 🧊 Coldcard is one of the most trusted hardware wallets in the Bitcoin world. Hundreds of wallets were swept sequentially between 01:10 and 01:51 UTC on July 30, according to Galaxy Research’s findings. Most were dormant wallets that hadn’t moved since 2021 💀 🔍 So why? The most critical moment for a hardware wallet is when the seed is first generated. At that moment, the device must pull numbers from its internal true random number generator—a physical, unpredictable source. ⚠️ In March 2021, a single-line firmware change caused the device to stop using that hardware source. It was replaced with a much weaker, software-based generator. And where did that generator get its randomness from? The device’s serial number, internal clock, and keypresses 🤯 📉 Result: The 128-bit security expected behind a 12-word seed dropped to approximately 40 bits. Meaning, the odds shifted from astronomical to within range of brute-force computation by a computer. The wallets weren’t broken—they were recalculated 🧮 🧨 Coinkite first issued a warning for the Mk3, then expanded its scope. Affected range: Seeds generated on Mk3 firmware 4.0.1 and later, Mk4 and Mk5 below version 5.6.0, and Q below version 1.5.0Q. CEO Rodolfo Novak openly apologized and accepted responsibility. ✅ Who was saved? Those who added their own randomness during setup by rolling 50 or more dice. And those who added a strong BIP39 passphrase. Their risk remained significantly limited. 🛑 This is critical: Updating firmware does not fix an existing seed. The update only protects future seeds. A weak seed already generated cannot be strengthened by an update. What must be done: Generate a new seed on the patched firmware and move your funds there. Take it slow—start with a small test transfer 🐢 📊 And it’s not over yet. Galaxy Research detected a second wave. Total tracked BTC exceeded 1.158 BTC—around $75 million. Funds are sitting at seven addresses and still haven’t moved. An unusually passive behavior for such a massive theft 👀 🧠 The lesson here: For years, we’ve interpreted “cold wallet” as “untouchable.” But the real vulnerability isn’t where the key is stored—it’s where it’s born 🔑 And as a user, you have no way to audit that moment afterward. You simply trust the device. 🐾 Sherlock note: This incident is the third largest case of its kind since Milk Sad. The only recurring theme in crypto history: vulnerabilities always emerge where people trust the most. So what happens next? 🤔 Do we keep trusting closed-box hardware wallets—or should rolling dice to generate our own randomness become standard practice? Let’s discuss in the comments 👇 This content is for informational purposes only; it is not investment advice or investment counseling.

No.0 picture
Disclaimer: Ang information sa page na ito ay maaaring nakuha mula sa mga third party at hindi necessary na nagre-reflect sa mga pananaw o opinyon ng KuCoin. Ibinigay ang content na ito para sa mga pangkalahatang informational purpose lang, nang walang anumang representation o warranty ng anumang uri, at hindi rin ito dapat ipakahulugan bilang financial o investment advice. Hindi mananagot ang KuCoin para sa anumang error o omission, o para sa anumang outcome na magreresulta mula sa paggamit ng information na ito. Maaaring maging risky ang mga investment sa mga digital asset. Pakisuri nang maigi ang mga risk ng isang produkto at ang risk tolerance mo batay sa iyong sariling kalagayang pinansyal. Para sa higit pang information, mag-refer sa aming Terms ng Paggamit at Disclosure ng Risk.