The Coldcard wallet attack spreads, with losses nearing $89 million. A vulnerability in the Coldcard firmware version released in March 2021 has led to the theft of 1,367 BTC, worth nearly $89 million, from 4,585 wallet addresses. Galaxy Research recorded a third wave of attacks that withdrew approximately 208 BTC from 1,912 addresses between Friday noon and Saturday morning UTC. Unlike the initial wave, which primarily targeted wallets with large balances, the attackers have now shifted to scanning wallets holding only a few thousand dollars. The method of fund aggregation has also changed. Bitcoin from each victim is transferred to separate addresses, with each transaction typically processing around six wallets. This may indicate that the attackers modified their tactics after previous aggregation addresses were publicly tracked, but it also cannot be ruled out that another group is exploiting the same vulnerability. The security flaw is believed to have caused certain Coldcard devices to generate seeds using a predictable software-based random number generator instead of a secure hardware-based source. This allowed attackers to offline-reconstruct private keys without physical access to the devices.
CoinPhotonShare
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.