pull down to refresh

The recipient address of the alleged hack has collected over 590 bitcoins in under an hour yesterday evening. One other reply in the thread saying it also happened to them, but the second one is spotty on details. I heard from another independent case, also a Coldcard wallet, but the situation is still developing.

Summary of Situation as of this Time

ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS ASAP.

Any funds on a COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version until July 30th), where the entropy was only generated by the device, should be considered compromised. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets created with externally generated entropy with at least 50 dice throws should not be exposed. Wallets that pair the device entropy with a passphrase are only as secure as the passphrase. If you used a weak passphrase (less than 25 random characters or fewer than seven BIP39 words) and did not provide external entropy (at least fifty dice throws), your funds are at risk.

Coinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. Updating to the new firmware does not make affected wallets secure. Only new wallets generated with the new firmware are unaffected. Coinkite put out a security advisory. The security advisory has been updated to include more devices, more details about the issue, and migration advice.

Block security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.

Anyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully move your funds to an unaffected wallet ASAP. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered at risk and funds should also be moved.

reply
2352 sats \ 1 reply \ @k00b 30 Jul

update with complete timeline/story from reddit OP: https://www.reddit.com/r/Bitcoin/comments/1vb6teq/wallet_drained_timeline/

reply
12 sats \ 0 replies \ @justin_shocknet 30 Jul -100 sats

https://x.com/i/status/2082961993070247948

5291 sats \ 10 replies \ @Kruw 5 Aug

1m zap for @Murch - This timely post certainly saved funds during an emergency. Thank you.

reply

Holy cow. Thanks! I’ll have to increase my default zap by at least a magnitude to ever work through that.

reply

Only CCs unfortunately!

reply

ROFL, @k00b is going to be sleeping well tonight with that donation. Do most of the sats go to server upkeep when they are "exchanged" for CCs?

reply
95 sats \ 3 replies \ @sox 5 Aug

No, 1 sat = 1 CC.

If you zap 100 sats and the recipient can only receive CCs, they'll receive 70 CC and the remaining sats will be split across territory revenue (to the territory owner of the post) and rewards pool.

CCs are fully usable site-wide as sats and can become sats through the rewards pool.

reply
CCs are fully usable site-wide as sats and can become sats through the rewards pool.

Ah so the exchange is not strictly permanent. But for legal reasons its framed as such.

I would imagine a cut does go to server maintenence no? Or is that just teritorial fees?

I suppose the FAQ probably has the answers

reply
278 sats \ 1 reply \ @k00b 5 Aug
But for legal reasons its framed as such.

It's more than framing. You can only send money to someone else on SN if we aren't custodying the money. Otherwise you send CCs.

When you spend CCs, some go to the rewards pool, and SN replaces those 1-to-1 with its own sats and gives them out as rewards.

It's tricky and convoluted, but it's not framing. We aren't money transmitters because we aren't transmitting other people's money.

reply
112 sats \ 0 replies \ @Kruw 5 Aug

https://github.com/stackernews/stacker.news/issues/3151 pls :)

I lost another 50k "sats" to CC conversion on this big zap. The flow should only go CC -> sats, never backwards.

reply

Unfortunate for Murch, not for you!

reply
53 sats \ 1 reply \ @Murch OP 5 Aug

They’ll just circle back here anyway. ;)

reply
reply

This is super weird. He says he only deposited to the wallet and never withdrew. If that's true, looks like he leaked his seed phrase. Doesn't seem like a Coldcard issue. Let's hold off for more info.

reply

That would be my initial guess, but it seems the receiving address got coins from a large number of addresses in a short time frame, at least according to a reddit comment. Could be a cold card issue, or at least something other than straight user error. I'd agree on needing more info.

Block says they can confirm a second batch of transactions from before the batch that most people were made aware of:

I think this is the same batch narceilo spotted:

#1536347

reply

Yes, and they found one more.

reply
147 sats \ 1 reply \ @Scoresby 31 Jul

Man, that's sad.

reply

These are earlier. The "copycat" wave can be worse.

reply

For those of you who can't or won't say it:

This is an absolute disaster. If Bitcoin isn't secure it is worthless. Multisig should not be necessary it is already complicated enough without multiple keys.

And it really pokes a hole in the whole 'hardware wallet security' industry, you might as well buy a laptop from best buy put linux on it download core and generate your private key that way. It's possible there are many, many users affected and it is quite bad.

"Hacks" like this are not acceptable.

reply

There are something more than 40k deaths caused by motor vehicles each year just I'm the US. That's not just money, it's people's lives. And yet, we mostly all still drive because it gives us something that we think is worth the risk. Why don't you think Bitcoin is like this?

reply

I still do. However the hack is unacceptable. Someone could follow the directions to a T, doing everything exactly like they are supposed to and still lose their savings despite perfect off-chain security. It is unacceptable.

Bitcoin is competing against houses and gold atm, and those things do not get hacked.

What others are unwilling to admit is that the bug-apocalypse is just beginning, the AI tools are relentless, merciless and unforgiving and they find bugs that humans cannot. This is likely just the beginning of crypto-bugs and apparently bitcoin isn't immune either.

reply
Bitcoin is competing against houses and gold atm, and those things do not get hacked.

They can get "hacked" in other ways. Nothing is foolproof. Let's wait and see what really happened to this user and what the point of failure was.

reply

Friend it wasn't the user. It looks like a failure of the ColdCard hardware RNG which means that thousands, maybe 10s of thousands of users are effected. Using the RNG's entropy for a seed phrase means it can be brute forced, and if that's true a lot of addresses are now vulnerable.

reply
114 sats \ 1 reply \ @optimism 30 Jul

"unacceptable"? What are you saying?

You have no choice than to accept it because it happened 21h ago and there is not going to be a rollback. What is needed is a path to safety, a post mortem, infrastructure to structurally improve whatever weakness this turns out to be. More safeguards.

reply

"What is needed is a path to safety"

That's nice to say but it's hard to tell users that when they have stacked sats and suddenly they wake up and they're all gone. The number of users affected could be much, much higher if I understand the twitter analysis right. A lot of people won't move their funds, or they'll move them wrong or make a mistake or they wont have another hardware wallet or won't even know about the hack before their funds are gone. For all we know the entropy on the Coldcards is highly compromised.

I personally didn't lose a sat (thank goodness) because i 'manage risk' across multiple devices but that's a lot to ask of people to use multisig when Coldcards were supposed to be 'safe enough.' Of course there isn't a rollback but IMO the magnitude of something like this shouldn't be papered over either.

If we're being really honest AI makes gold look good - it is permanently offline and the best way to improve bitcoin is to be transparent with ourselves.

reply

this is the same old adage of blaming the money when a bank gets robbed, no its the institutions and software/hardware that are 'protecting' it.

Coldcards used to be standard, no way after this fiasco

reply

I think you are right about that. So of we think that this is going to be more common, I wonder what we tell users? Be even more paranoid? Not terribly helpful advice.

reply

no single point of failure.

reply
126 sats \ 1 reply \ @Scoresby 30 Jul

I think it is pretty easy to overlook SPOFs.

I feel pretty good about my own setup, but I am going over things again because there are so many places where I could have let something slip in.

reply

Before I got an enormous bill to pay a few months back... I used a singlesig coldcard. Joke's on the attacker cuz I spent it all.

reply
12 sats \ 0 replies \ @gmd 31 Jul

yup. i was always confused joining the community when people were pretending being your own bank is easy... it's very hard for the average joe and now even if you acted perfectly you still might get nerfed.

reply
326 sats \ 2 replies \ @justin_shocknet 30 Jul -420 sats
you might as well buy a laptop from best buy put linux on it download core

Anything other than this is additional surface risk in the stack, less reviewed, less obscure.

Hardware wallets cost more than an old laptop and create a paper trail, and then people defeat the purpose and use them with software on their daily driver.

The only reason not to raw dog Core is backups, which leads to seed phrase middleware, and then the fucking seed phrases cause more people to get robbed than anything.

All the time and money wasted on the HWW industrial complex could have been applied to making cheap micro mdisc drives and/or a decent brain wallet process in Core.

Kevin Loaec preliminary conclusion:

Loaec is the founder of Wizardsardine and knows his way around bitcoin wallet stuff.

reply

....pmmnmpe this one still having the biggest utxo it had is indeed puzzling.

reply

Looks like it swept all UTXOs back to 2022-07-18 17:58:25, but skipped all the ones that came before it.

reply

pagination?

reply

Yeah, looks like it. The TX has exactly 200 inputs. It suggests that the attacker simply sweeps the most recent 200 UTXOs and misses the rest, and they are still at risk of being stolen.

reply
  1. That means it's likely that the attacker used an API.
  2. That in turn means someone has logs of the lookups
reply

what makes you think it's an API?

reply

Missed this, apologies!

Public APIs often have max-per-page forced pagination to reduce load on their infra, whereas private infra like the bitcoind RPC often don't implement a hard max and even do not set an initial default.

Thus, when you see a low artificial limit in an attack, like 200 utxo max which is significantly under the max tx size, especially for p2wpkh, but also for old school p2pkh, it is extremely likely that a service was used and not sovereign infra. And that is the kind of lead that can break an investigation from hopeless into catching a lazy attacker if you'd be, say, representing a victim.

I'm glad that Block found the same and chased it down.

During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.

We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.

We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.

https://nitter.net/clay_garrett/status/2083247006139503065

and they are still at risk of being stolen.

aaand the rest has now also been swept:
https://mempool.space/tx/a318b01e6e1697a465fb1ec036b0dd2c46776b7143034ea9575e8e0fd023e7f5

reply

Except it seems that it is not just BIP84 derivation paths:

source

reply
Summary of Situation as of this Time

Any funds on a Coldcard Mk3 using a firmware version 4.0.1 (March 2021) or later, up to the current version, where the entropy was generated by the Coldcard and it was not paired with a strong password, are at risk.

Coinkite has put out a security advisory.

It looks like anyone with access to a regular LLM subscription is capable of reproducing the attack now. If this describes your wallet setup, please move your funds to an unaffected wallet ASAP. Please move deliberately enough to move your funds safely, people make mistakes when they rush.

Mk2 may also be at risk, unclear.

reply

Issues with Mk4 and Mk5 are now also being reported.

If you hold funds in any Coldcard single-sig wallet without password, you should consider moving those funds.

reply

fortunately, if you generated the seeds with dice, you may still be able to maintain some confidence that it can be used as part of your new multi-sig setup:

it looks like the dice roll code is not total shit.

reply

important to note it needs SUFFICIENT DICE ROLLS

reply

Anthropic making bank tonight.

reply
reply

what's the context, another hack or someone shoring up funds?

reply

Rob didn't add any context, but I scanned through some of the inputs and all the ones I looked at are from a similar era to the others.

it does kind of have the hallmarks...

reply

Eeeh, one million CCs stacked?!

reply

I’m also flabbergasted, but: #1540541

reply

Riiiight. To EVER work through all those CCs.

It's like, posting and zapping on SN forever on me.

Great to see

reply
97 sats \ 1 reply \ @Murch OP 5 Aug

I bumped up my default zap by a magnitude, if I zap as often as in the last year, I should be able to spend it in about a year. (^_^)/

reply

Beautiful! Fantastic, haha

Maybe you could try selling some via the ~agora market...?

reply

Also, probably not a quantum thing:

source

reply

hot damm.. beat to it by @Rob1Ham.

Imma get back to work because I'm too slow. lol

reply
360 sats \ 5 replies \ @freetx 30 Jul

My bet is this: Someone who doesn't deeply know bitcoin has used AI to scan for vulnerabilities in RNG and or libraries used in CC.

They have identified some bug that produces a reduced search space (low entropy) and are generating random wallets in this reduced space and getting some hits, but due to their lack of bitcoin knowledge they (or more likely claude script) is only partially draining .

Real mess, feel for those affected. Time will tell....

reply

as per #1536330?

In which case I guess I ask what is low entropy? CC has supported supplementary dice roles and passphrases on top of the wallet generation process, is that higher entropy or does it not matter for reasons?

reply
CC ha supported supplementary dice roles and passphrases on top of the wallet generation process, is that higher entropy or does it not matter for reasons?

Can't tell right now. If a bug is sitting in the RNG, yes it helps. If the bug is in the combination or derivation mechanism, no it does not help.

reply

We're not sure. I would think that a high-entropy passphrase or added seed entropy would protect from the attack but check twitter for the latest info.

reply
114 sats \ 1 reply \ @freetx 30 Jul
that a high-entropy passphrase

Thats actually a very good point. Hmmm....I know people have said that these were completely airgapped, so in theory we can rule out exfiltration.

A real high-entropy passphrase would seem to mitigate a RNG or library issue....unless the bug somehow affects CC private keys after a passphrase has been applied? Would be interesting to know if any users who did not have a passphrase have been compromised...

reply

It seems like it's weak RNG. So if the user added entropy to the ColdCard's RNG (100+ dice rolls) it's ok. But whether the user really trusts it at this point is up to them. I'm not sure what to believe.

reply
reply
228 sats \ 0 replies \ @adlai 31 Jul

tl;dr most/all their generated seeds in Mk3, Mk4, and Mk5 [i.e. anything since 2021] are potentially vulnerable

they claim that wallets with imported seeds are unaffected, i.e. the weakness was in generation of the original seed, not in some nondeterminism of signatures [like the old r-value reuse that got lots of wallets in early days]

reply
1254 sats \ 2 replies \ @Murch OP 31 Jul
Summary of Situation as of this Time

ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS ASAP.

Any funds on a COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version as of yesterday), where the entropy was only generated by the device, should be considered compromised. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets that pair the device entropy with a strong passphrase or wallets created with externally generated entropy with at least 50 dice throws should not be exposed. If you used a weak passphrase and did not input external entropy (at least fifty dice throws), your funds are at risk.

Coinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. Updating to the new firmware does not make affected wallets secure. Only new wallets generated with the new firmware are unaffected. Coinkite put out a security advisory. The security advisory has been updated to include more devices, more details about the issue, and migration advice.

Block security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.

Anyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully move your funds to an unaffected wallet ASAP. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered at risk and funds should also be moved.

Cannot trust other products from CoinKite either

reply

Superbly fast and comprehensible coverage on the situation. Thank you SN community

reply

yes especially from someone who refuses to use twatter.

great stuff fellas

reply

I use twitter regularly yet didn't even bother to look. Got the RSS feed right here. Very reassuring also. Though, this is still a major disaster. The Titanic sank.

reply

It really is going to be difficult because a lot of people did what they were told was right and still are getting fucked. Tough day.

reply
12 sats \ 0 replies \ @didiplaywell 30 Jul -21 sats

I have said this before and I repeat it: the future of bitcoin is centralized. Not a currency, but digital gold managed by independent mints. People will use coins supported by bitcoin, not bitcoin itself. It's the only way.

I feel too bad anytime I hear of this.

reply

TL;DR: Any funds on a Coldcard mk2/3 using a firmware version 4.0.1 (March 2021) or later, where the wallet was generated by the Coldcard, may be at risk:


Source

If this describes your wallet setup, you may want to move your funds. Please take enough time to do so safely.

Coinkite has put out a security advisory.

reply

Coinos was and is safer than Coldcard

reply

Strike that “may”. You will want to move your funds ASAP.

reply

Do you know if there are any reports of ongoing thefts?

reply

Doesn't matter. Everyone with a Claude subscription can reproduce it now. Move funds.

reply

Just to be clear, if a user 'mixed in' 100 dice rolls into the coldcard's RNG... they're OK right?

I don't use single-sig for much just a couple sats but I'm not in the position to move them lol

reply

100 dice rolls is about 258 bits of entropy, so yes. I checked how it's applied and that looks ok (it does a stream of ascii 1-6 to update() through sha256, one byte of ~2.6 bits entropy each roll)

reply

That's what I'm hearing yes that's safe...if you rolled enough and/or had a strong passphrase you are okay.

reply

maybe so, but jeez. do you stay with any coldcard after this, if it's true that it's a device vulnerability. or is any RNG at risk? i remember how "safe" i felt after learning how big a 256 bit number was, hope that's still the case.

reply

This was a firmware vulnerability, not hardware. Using the dice and the BIP-39 passphrase isn't a luxury. RNGs are often weak, also - and especially - the on-chip hardware ones on small devices.

A good set of dice always beats a hardware RNG, unless maybe when you've got a SiPM.

Just random people dude

reply

anyone get any info on opendimes if they were affected at all?
used them over the years to gift sats for weddings/graduations

havent seen much talk about them at all

reply
opendime

See my comment above, I wouldn't have confidence in ANY coinkite product.

reply

Horrible. So glad I use multisig. This is wild. How do I trust to buy a Coinkite wallet again in the future?

So sad it just hurts us Bitcoiners cuz they’re Bitcoin only.

reply
36 sats \ 3 replies \ @OT 31 Jul

I think they're done unfortunately.

And if you used a Coldcard to generate those multisig seeds you still need to migrate funds.

reply

it appears to me, this is only critical if you skipped the dice-roll step.

and you can re-generate new keys with the same device using dice-rolls to either migrate into multi-sig or just move your coins.

reply

yea @OT i used ColdCard for only one of my multisig keys, but I still gotta move it now!!

reply
1 sat \ 0 replies \ @OT 31 Jul

Looks like you should, but take your time.

reply
388 sats \ 16 replies \ @k00b 30 Jul

What's weird, from reading X threads, is that only some UTXOs from wallets are being swept like only some of the private keys were compromised. If those are child keys this wouldn't be an RNG issue. They claim they were trying to use Sparrow as a watch only wallet but "SD card imports the wallet into Sparrow." So maybe he had a compromised Sparrow and the SD card was a backup. But that still doesn't explain why only some of the private keys are being compromised.

reply

Well, also that it seems to be more than one person?

source

reply
168 sats \ 8 replies \ @k00b 30 Jul

If it's a compromised Sparrow there would be more than one victim.

reply

which version of sparrow?

reply
301 sats \ 0 replies \ @k00b 30 Jul

There were fake sparrows on the app store not too long ago.

reply

ah yes, i see that.

Also, it seems like they didn't even take all the utxos at a single address:

source

reply

I think Praveen is on the right track there. The attacker probably used some block explorer API and didn’t think that any address would have so many UTXOs.

Also, it would have been way harder for people to identify this as an attack if the attacker had used a different recipient address for each sweep.

reply
201 sats \ 3 replies \ @k00b 30 Jul

It could also still be an RNG problem ... if the reports of partial sweeps are wrong or the thief doesn't feel comfortable stealing everything in an individual's wallet (which would be surprising) or, after your edit, taking only some utxos is a bug in the attack.

reply
241 sats \ 1 reply \ @Scoresby 30 Jul

reply

Beat me to it.

reply

from lopp:

I had someone contact me about this earlier today and the one thing they noted is that their full wallet balance was not swept; it was only a handful of UTXOs that were swept. I told them I suspected that their seed was not compromised, but rather something they did had compromised individual private keys.
reply

Over 1300 UTXOs were spent toward the alleged attacker’s address, and we have had multiple different reports, so it’s likely that this affects a larger number of people.

reply
346 sats \ 1 reply \ @Scoresby 30 Jul

Yes, looks like narceilo identified some more:

source

reply

That one seems to preceed the other one

reply
124 sats \ 0 replies \ @nout 30 Jul

The attacker may be just batching the load here. It's reasonable to assume that more draining is to come.

reply
74 sats \ 1 reply \ @adlai 31 Jul
that still doesn't explain why only some of the private keys are being compromised.

if it's an RNG weakness, then isn't an attacker still just "searching" for coins, and as the UTXOs turn up, racing against other attackers to claim them?

so there is also a secondary "game", of building transactions that are likely to get mined ASAP, rather than just huge dust sweeps that end up mostly rewarding miners.

reply
30 sats \ 0 replies \ @k00b 31 Jul

Yes.

reply
reply
reply
reply
reply

"can't be certain" means it probably is. If there's doubt there is no doubt. Great.

reply
103 sats \ 0 replies \ @justin_shocknet 30 Jul -420 sats

https://x.com/i/status/2082961993070247948

It looks like ColdCard has released a firmware update:

https://coldcard.com/docs/upgrade/

reply
124 sats \ 1 reply \ @Scoresby 31 Jul

that bit about not planning to update Mk3 firmware is interesting...

reply

Like anyone will trust their seed generation now...

reply

To be fair to ColdCard, @nvk saysthey have received no support emails regarding this:

But @notgrubles confirms an issue:

And @lopp

source

reply

Kevin Loaec summary of the current info:

reply

It does seem to be ColdCard specific:

source

reply
10 sats \ 0 replies \ @anon 31 Jul

I know the vulnerability is still there but does anyone know if the attack is ongoing or better put if more btc has been lost the last 8 or so hours?

reply
reply

This is absolutely bonkers

reply
reply

Do we have any clarity on which cold card devices were affected?

reply

I haven't seen too much about specific devices. Antoine Poinsot said he at least knew someone with an mk4

source

reply

which firmware version?

reply

Per Coinkite: “Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk”, however some devs seem to think that also Mk2 is affected.

reply

how much does key generation stuff change between firmwares?

reply

I haven't seen any good info that gets that specific.

reply

Also this:

source

reply
reply

deleted by author

210 sats \ 1 reply \ @Scoresby 30 Jul

Seems like not all the people who were hit had reused addresses:

source

reply

Checked that in the tx graph real quick and the majority isn't reuse, so we can rule out a long tail quantum attack (because all txs are p2wpkh)

reply

Did the victims maybe generate low entropy seeds via dice rolls?
But then again it would be strange that only some UTXOs were stolen.

reply

Perhaps they only took UTXOs over a certain amount to not compete with themselves for blockspace?

reply

Doesn't look like it - it looks like derive -> api call -> sweep.

Do we know what explorer has a 200 utxo limit on their listunspent-like REST api?

reply

Praveen independently confirms:

source

reply

users who used lots of dice rolls affected by this?

reply

No, my understanding is that either using a password or rolling your own entropy mitigated the issue.

reply

if "lots" is 50 or more, you're good.

reply

Heard about two more cases that seem independent from the above.

reply
133 sats \ 0 replies \ @anon 30 Jul

So far about 10 victims have been identified that were all Coldcard users.

This must be device related.

reply

Crazyness.

reply

Coldcard Security Advisory

reply

Hearing on Twitter spaces that per nvk, mk3 users who rolled dice or used a passphrase aren't affected. That being said I imagine if you have a low entropy passphrase you are still in danger.

reply
31 sats \ 0 replies \ @anon 30 Jul

checks wallet balance....

reply

Thanks for sharing with the community...this detected vulnerability must affect thousands of Bitcoiners who use Coldcard worldwide. It's important that they take quick action as they could lose their funds.

reply
1 sat \ 2 replies \ @npub1zapsats 30 Jul -21 sats

https://m.stacker.news/150227

I know a person who builds drainers if you guys want I can urge him to sell that drainer to someone who can review the drainer and update the coldcard wallet to prevent such drains... I have that person in contact

Damn, 590 BTC in under an hour is not a small number, that's not some random dust sweep, someone either had full seed access or there's a serious flaw somewhere.

The deeper lesson here isn't really about Coldcard specifically — it's about the trust assumption embedded in any hardware wallet that generates its own entropy.

Every hardware wallet asks you to trust three things: that the RNG is genuinely random, that the seed is stored encrypted, and that the signing path can't be exfiltrated. The first one is the only one that's actually unverifiable from the outside. You can audit the firmware. You can inspect the secure element datasheet. You cannot verify that the entropy collected at seed-creation time wasn't subtly degraded.

Coldcard is actually one of the few hardware wallets that lets you bypass this entirely — dice roll entropy input. The users getting drained right now are the users who skipped that step. That's not victim-blaming; it's the honest tradeoff. If you let the device pick your seed, you're trusting the device's RNG. If the RNG has a fallback path (and most do, because secure entropy collection is hard), that fallback is your weakest link.

The "LLM can reproduce the attack" detail is the genuinely new piece of information. That means the entropy space being exploited is small enough that an LLM can iterate it. That's not 2^256. That's probably 2^32 or 2^40 worth of effective entropy, which is what you'd expect from a fallback that uses something like a low-resolution clock or an unseeded PRNG.

If you're using a Coldcard and you generated your seed with dice, you are not at risk from this specific attack. If you let the device generate the seed and you don't have a passphrase, move the funds. If you have a strong passphrase, you're probably fine — but "probably" is doing a lot of work in that sentence.

The longer-term fix for the whole hardware wallet industry is to make user-supplied entropy the default, not the power-user option. Dice rolls should be the recommended path. Device-generated entropy should come with a warning. Until that happens, this will keep happening to a different vendor every few years.

397 sats \ 3 replies \ @justin_shocknet 30 Jul -1002 sats

HWW maxis becoming ETF maxis was not on my bingo card for this week

https://m.stacker.news/150218

deleted by author