Ledger and Trezor Assure Users After Coldcard's $38M Bitcoin Exploit

iconAMBCrypto
Share
AI summary iconSummary
Bitcoin news broke as Ledger and Trezor confirmed their hardware wallets were unaffected by Coldcard’s $38 million exploit. Coldcard’s flaw reduced entropy to 40 bits, enabling brute-force attacks. Ledger uses 256-bit entropy, while Trezor confirmed no shared code with Coldcard. The incident raised concerns, pushing the fear and greed index lower and causing Bitcoin to drop 3% to $62.4K, a two-week low.

Bitcoin hardware wallet providers Ledger and Trezor have distanced themselves from Coinkite’s Coldcard $38M exploit.

An unfortunate code flaw within Coldcard’s firmware allowed an attacker to steal 38M worth of BTC or more from the hardware wallet.

Since Coldcard shares part of the hardware design involving the True Random Number Generator (TRNG) with other providers, investors were worried that other wallets could also be at risk.

AD

However, Ledger clarified that it uses a slightly more secure design, maintaining that their Bitcoin hardware wallets were “not affected” by Coldcard’s flaw.

Ledger Trezor Coolcard
Source: X

The firm added that it uses a 256-bit mathematical complexity system (entropy), which makes seed phrases difficult to crack.

On the contrary, Coldcard’s flaw downgraded Coinkite’s system from a 128-bit to a guessable 40-bit system, which could easily be cracked using brute force.

Trezor, another Bitcoin hardware provider, also assured its users that they should not be alarmed about the Coldcard incident.

Trezor users: your funds are safe. The recent Coldcard issue is limited to their own custom firmware and how some of their devices generated randomness. Trezor does not share that code.

BTC dumps 3% to 2-week low after Coldcard exploit

Despite the assurance, the Coldcard exploit sparked broader fear about safety on hardware wallets and self-custody.

According to TaprootWizards’ Udi Wertheimer, self-custody is now “worryingly unrealistic,” warning that AI models with cybersecurity attack capabilities will intensify the hacks.

For his part, Coinbase CEO Brian Armstrong said the best way to improve physical security is by “air-gapping keys,” citing his firm’s operational standard for crypto ETF custody.

Ledger, Trezor Coolcards
Source: X

As the community discussed Bitcoin self-custody threats, BTC’s sentiment dropped to a four-month low. According to Santiment data, the soured sentiment mirrored the market caution seen as the West Asia crisis intensified in April.

As a result, Bitcoin [BTC] price dropped sharply by nearly 3%, tagging a 2-week low of $62.4K. But the crypto asset slightly recovered back above $63K as of writing.

Ledger Trezor Coolcards
Source: Santiment

Others projected that the overwhelming effort to handle self-custody amid the ongoing risks would force investors to opt for U.S. Spot ETFs.

However, the ETF demand was also impacted by the weak sentiment on Friday. The products recorded a daily net outflow of $265. It remains to be seen whether the spot BTC ETFs will attract new investors worried by self-custody risks and upcoming quantum attack vectors.


Final Summary

  • Ledger and Trezor said they were “not affected” by the Coldcard flaw as they operate different systems for their hardware wallets.
  • Coinbase CEO said “air-gapping keys” can help reduce some threats.
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.