Update about @COLDCARDwallet for my followers that might not have seen the news yet: 👇 If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9 (This would have likely been between 2021 to 2023). If you have a newer ColdCard you are also likely affected but to a lesser extent. Read their statement: https://t.co/rbC81X6wOz Additional thoughts: - The problem is not the security of your private key on a hardware wallet. The bug was in the creation of that private key (12-24 word seed) which was discovered to NOT be very random. Even if your you set up was air gapped it did not matter in this case. - ColdCard is one of the few devices that allows you to generate your seed (by tossing dice), if you generated the private key yourself, your funds are safe and ColdCard remains a secure device to protect that key. However, since we don't know if the company will survive this unfortunate event. Make sure you have another hardware signing device in case there are no longer firmware updates. - If you let the ColdCard generate the 'not so random' private key for you, but you protected your coins with a Passphrase on top of the 12-24 words. Here is what you should do: * Move the funds to another wallet ASAP. The stronger the Passphrase (at least 6 words or maybe 15+ random alphanumeric characters) the more time you have before it's cracked, but assume it will be cracked as that's the ONLY thing protecting your coins at the moment. But unlike your bank account password that locks after 5 incorrect attempts, a computer is guessing this at millions combinations a second as we speak! - If you are using the compromised key(s) generated by ColdCard as an X of Y MultiSig, then you may or may not be in immediate danger. It depends on how many of those keys are compromised. If it's or = to X then your funds are at risk and immediately move the funds to another wallet and redo your multisig set up. - If you did not have a passphrase nor tossed dice, your funds are probably already gone 😰 but drop everything and go check! Final NOTE: I feel terrible for all the people who lost their coins as many of us have trusted ColdCard with the highest of security assumptions. I really do believe that incidents like this are the unfortunate lessons we go though that ultimately makes bitcoin stronger and more valuable. If Bitcoin wasn't this unstoppable asset, hackers would not be trying this hard to steel it from you exploiting every possible mistake in the code. In our current LLM word, this is more true than ever. - Be your own Random Number Generator and start creating your own RANDOM seed. - Protect that Seed with a Passphrase - Use the device in an X of Y MultiSig!
Tone VaysShare
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.