source avatarCrypto's Sherlock

Share

🚨 41 minutes. 1,196 wallets. 1,082 BTC. Approximately $70 million vanished from devices known as hardware wallets 😳 And the attacker didn’t touch a single device 👇 🧊 Coldcard is one of Bitcoin’s most trusted hardware wallets. Hundreds of wallets were swept sequentially between 01:10 and 01:51 UTC on July 30, according to Galaxy Research’s findings. Most had been dormant since 2021 — completely inactive 💀 🔍 So why? The most critical moment for any hardware wallet is when the seed is first generated. At that moment, the device must draw numbers from its true hardware random number generator — a physical, unpredictable source. ⚠️ In March 2021, a single-line firmware change caused the device to stop using that hardware source. It was replaced by a far weaker, software-based generator. And where did that generator get its randomness from? The device’s serial number, internal clock, and keypresses 🤯 📉 Result: The 128-bit security expected behind a 12-word seed dropped to roughly 40 bits. Meaning: Astronomical odds became a range brute-forceable by a computer. The wallets weren’t hacked — they were recalculated 🧮 🧨 Coinkite first issued a warning for the Mk3, then expanded its scope. Affected range: Seeds generated on Mk3 firmware 4.0.1 and later; Mk4 and Mk5 below version 5.6.0; Q below version 1.5.0Q. CEO Rodolfo Novak openly apologized and accepted full responsibility. ✅ Who was saved? Those who added their own randomness during setup by rolling 50+ dice. And those who added a strong BIP39 passphrase — their risk remained significantly limited. 🛑 This is critical: Updating the firmware does not fix existing seeds. Updates only protect future generations. A weak seed already generated cannot be strengthened by an update. What must be done: Generate a new seed on the patched firmware and move your funds there. Stay calm — first test with a small transfer 🐢 📊 And it’s not over. Galaxy Research detected a second wave. Total tracked funds exceeded 1,158 BTC — around $75 million. Funds are sitting at seven addresses — still untouched. An unusually passive behavior for such a massive theft 👀 🧠 The lesson here? For years we’ve interpreted “cold wallet” as “untouchable.” But true vulnerability isn’t where the key is stored — it’s where it’s born 🔑 And as a user, you have no way to audit that moment afterward. You simply trust the device. 🐾 Sherlock note: This incident is the third-largest of its kind since Milk Sad. The only recurring theme in crypto history? The most trusted places are where breaches emerge. So what happens next? 🤔 Do we keep trusting closed-box hardware wallets — or should rolling dice to generate your own randomness become standard practice? Let’s discuss in the comments 👇 This content is for informational purposes only; it is not investment advice or financial guidance.

No.0 picture
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.