source avatarCrypto's Sherlock

Partager

🚹 41 minutes. 1,196 wallets. 1,082 BTC. Approximately $70 million evaporated from devices known as cold wallets 😳 And the attacker didn’t touch a single device 👇 🧊 Coldcard is one of the most trusted hardware wallets in the bitcoin world. Hundreds of wallets were swept in sequence between 01:10 and 01:51 UTC on July 30, according to Galaxy Research’s findings. Most were dormant wallets that hadn’t moved since 2021 💀 🔍 So why? The most critical moment for a hardware wallet is the instant the seed is first generated. At that moment, the device must pull numbers from its internal true random number generator—a physical, unpredictable source. ⚠ In March 2021, a single-line firmware change caused the device to stop using that hardware source. It was replaced by a far weaker, software-based generator. And where did that generator get its randomness from? The device’s serial number, internal clock, and key presses đŸ€Ż 📉 Result: The 128-bit security expected behind a 12-word seed dropped to approximately 40 bits. Meaning: Astronomical odds became a range brute-forceable by a computer. The wallets weren’t broken—they were recalculated 🧼 🧹 Coinkite first issued a warning for the Mk3, then expanded its scope. Affected range: Seeds generated on Mk3 4.0.1 and later, Mk4 and Mk5 below version 5.6.0, and Q below version 1.5.0Q. CEO Rodolfo Novak openly apologized and accepted responsibility. ✅ Who was saved? Those who added their own randomness during setup by rolling 50 or more dice. And those who added a strong BIP39 passphrase—risk remained significantly limited for them. 🛑 This is critical: Updating the firmware does not fix existing seeds. The update only protects future generations. A weak seed already generated cannot be strengthened by an update. What must be done: Generate a new seed on the patched version and move your funds there. Take it slow—start with a small test transfer 🐱 📊 And it’s not over. Galaxy Research detected a second wave. Total tracked funds exceeded 1,158 BTC—around $75 million. Funds are held at seven addresses and still haven’t moved. An unusually passive behavior for such a massive theft 👀 🧠 The lesson here: For years, we’ve interpreted “cold wallet” as “untouchable.” Yet the real vulnerability isn’t where the key is stored—it’s where it’s born 🔑 And as a user, you have no way to audit that moment afterward. You simply trust the device. đŸŸ Sherlock note: This incident is the third-largest case of its class since Milk Sad. The only recurring theme in crypto history: vulnerabilities emerge precisely where people trust the most. So what happens next? đŸ€” Do we continue trusting closed-box hardware wallets—or should rolling dice to generate our own randomness become standard? Let’s discuss in the comments 👇 This content is for informational purposes only; it is not investment advice or investment counseling.

No.0 picture
Clause de non-responsabilitĂ© : les informations sur cette page peuvent avoir Ă©tĂ© obtenues auprĂšs de tiers et ne reflĂštent pas nĂ©cessairement les points de vue ou opinions de KuCoin. Ce contenu est fourni Ă  titre informatif uniquement, sans aucune reprĂ©sentation ou garantie d’aucune sorte, et ne doit pas ĂȘtre interprĂ©tĂ© comme un conseil en investissement. KuCoin ne sera pas responsable des erreurs ou omissions, ni des rĂ©sultats rĂ©sultant de l’utilisation de ces informations. Les investissements dans les actifs numĂ©riques peuvent ĂȘtre risquĂ©s. Veuillez Ă©valuer soigneusement les risques d’un produit et votre tolĂ©rance au risque en fonction de votre propre situation financiĂšre. Pour plus d’informations, veuillez consulter nos conditions d’utilisation et divulgation des risques.