đš 41 minutes. 1,196 wallets. 1,082 BTC. Approximately $70 million evaporated from devices known as cold wallets đł And the attacker didnât touch a single device đ đ§ Coldcard is one of the most trusted hardware wallets in the bitcoin world. Hundreds of wallets were swept in sequence between 01:10 and 01:51 UTC on July 30, according to Galaxy Researchâs findings. Most were dormant wallets that hadnât moved since 2021 đ đ So why? The most critical moment for a hardware wallet is the instant the seed is first generated. At that moment, the device must pull numbers from its internal true random number generatorâa physical, unpredictable source. â ïž In March 2021, a single-line firmware change caused the device to stop using that hardware source. It was replaced by a far weaker, software-based generator. And where did that generator get its randomness from? The deviceâs serial number, internal clock, and key presses đ€Ż đ Result: The 128-bit security expected behind a 12-word seed dropped to approximately 40 bits. Meaning: Astronomical odds became a range brute-forceable by a computer. The wallets werenât brokenâthey were recalculated đ§ź đ§š Coinkite first issued a warning for the Mk3, then expanded its scope. Affected range: Seeds generated on Mk3 4.0.1 and later, Mk4 and Mk5 below version 5.6.0, and Q below version 1.5.0Q. CEO Rodolfo Novak openly apologized and accepted responsibility. â Who was saved? Those who added their own randomness during setup by rolling 50 or more dice. And those who added a strong BIP39 passphraseârisk remained significantly limited for them. đ This is critical: Updating the firmware does not fix existing seeds. The update only protects future generations. A weak seed already generated cannot be strengthened by an update. What must be done: Generate a new seed on the patched version and move your funds there. Take it slowâstart with a small test transfer đą đ And itâs not over. Galaxy Research detected a second wave. Total tracked funds exceeded 1,158 BTCâaround $75 million. Funds are held at seven addresses and still havenât moved. An unusually passive behavior for such a massive theft đ đ§ The lesson here: For years, weâve interpreted âcold walletâ as âuntouchable.â Yet the real vulnerability isnât where the key is storedâitâs where itâs born đ And as a user, you have no way to audit that moment afterward. You simply trust the device. đŸ Sherlock note: This incident is the third-largest case of its class since Milk Sad. The only recurring theme in crypto history: vulnerabilities emerge precisely where people trust the most. So what happens next? đ€ Do we continue trusting closed-box hardware walletsâor should rolling dice to generate our own randomness become standard? Letâs discuss in the comments đ This content is for informational purposes only; it is not investment advice or investment counseling.
Crypto's SherlockPartager

Source:Afficher l'original
Clause de non-responsabilitĂ© : les informations sur cette page peuvent avoir Ă©tĂ© obtenues auprĂšs de tiers et ne reflĂštent pas nĂ©cessairement les points de vue ou opinions de KuCoin. Ce contenu est fourni Ă titre informatif uniquement, sans aucune reprĂ©sentation ou garantie dâaucune sorte, et ne doit pas ĂȘtre interprĂ©tĂ© comme un conseil en investissement. KuCoin ne sera pas responsable des erreurs ou omissions, ni des rĂ©sultats rĂ©sultant de lâutilisation de ces informations.
Les investissements dans les actifs numĂ©riques peuvent ĂȘtre risquĂ©s. Veuillez Ă©valuer soigneusement les risques dâun produit et votre tolĂ©rance au risque en fonction de votre propre situation financiĂšre. Pour plus dâinformations, veuillez consulter nos conditions dâutilisation et divulgation des risques.