source avatarFrederik Lund

Share

The Coldcard hack is devastating. So far, around 1,370 BTC has been drained. For years, we learned that "not your keys, not your coins". It turned out that "your own keys" was not enough. Explained simply, the Coldcard hack is a firmware bug from 2021. When users create seed phrases, it is supposed to be random. That is what keeps it nearly impossible to guess for an attacker. The twist: it wasn't. The "random" 24 words were basically generated from the device clock and how fast you pressed buttons. In other words, a pattern. And patterns can be guessed. For years we thought that self-custody in a hard wallet was the safest way to keep your Bitcoin. Turns out that is only true as long as the developer has not made any shortcuts. Which, of course, is impossible for the user to know. Where am I supposed to keep my Bitcoin?

No.0 picture
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.