Coldcard Issues New Security Alert Over Bitcoin Hack Vulnerability

iconBitcoinsistemi
Share
AI summary iconSummary
Coldcard has issued a new security breach alert over a Bitcoin wallet flaw linked to $40 million in losses. Users are urged to transfer funds and create new recovery phrases. The flaw affects key generation and outdated address derivation methods. Coldcard denied firmware permanently disables devices, saying a TRNG error can be fixed by restarting. A new patch is in development with seed error detection and retry limits. The alert comes amid ongoing concerns over new token listings and wallet security.

Hardware wallet manufacturer Coldcard has issued a new high-priority security alert, stating that the cryptographic threat affecting its users is far from over. The company advises all users to move their Bitcoin assets to newly created wallets and generate entirely new recovery words (seed phrases).

According to Coldcard, the risk posed by the security vulnerability affecting the key generation process, which is associated with losses of approximately $40 million, persists. Users are advised to update their firmware and stop using addresses generated via outdated derivation methods to prevent unauthorized asset transfers.

The company also denied claims that the current firmware permanently rendered Coldcard devices unusable. Coldcard stated that in the event of a temporary random number generator (TRNG) error, disconnecting and restarting the device from all power sources should resolve the issue under normal hardware conditions.

The statement released by Coldcard included the following:

“Claims that the latest software permanently renders Coldcard devices unusable are incorrect. In the event of a TRNG error, completely disconnect the device and restart it. The situation is temporary; no data will be written to the flash memory, and the system is designed to shut down safely.”

Related News: Why Has Bitcoin Been Unable to Make the Expected Surge? There Is Both Positive and Negative Data

Developers also stated that there is no evidence that the current TRNG fix permanently breaks devices. They explained that if a temporary TRNG seed error occurs, completely shutting down and restarting the device is expected to restore normal operation.

However, developers are working on a new patch to make the post-error recovery process of the random number generation system more secure. The proposed update will follow the documented recovery procedure of chip manufacturer STMicroelectronics and will include additional safety measures such as a limited number of retries, seed error detection, and the deletion of old RNG outputs after recovery.

It was announced that support for Coldcard Mk3 devices will be addressed in a separate software update.

*This is not investment advice.

Continue Reading: Coldcard Issues New Statement Regarding the Major Bitcoin Hack

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.