Skip to content
View in the app

A better way to browse. Learn more.

ASEAN NOW

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Air gapped bitcoin hardware wallet hacked. $75M gone so far

Featured Replies

Sure glad I'm not investing gambling in this crypto stuff.


Coldcard hack just grew to $75M

https://www.thestreet.com/crypto/markets/coldcard-hack-just-grew-to-75m-call-your-friends

A five-year-old firmware bug let an attacker guess private keys without ever touching a device.

A hardware wallet is supposed to be the safest place to keep Bitcoin. The device never connects to the internet, the private keys never leave it, and the whole point is that an attacker would need to physically hold it to steal anything.

On August 1, Galaxy Research said it had identified a second wave of thefts tied to the same attacker who drained hundreds of Coldcard wallets days earlier. The firm is now tracking 1,158.66 BTC, worth roughly $75.1 million, taken from 2,673 addresses. Its earlier count on July 31 stood at 1,082.65 BTC from 1,196 addresses, which was already double the initial estimate of 594 BTC.

The attacker never touched a single device.

What actually went wrong

The flaw sits in the firmware of Coldcard wallets built by Canadian manufacturer Coinkite. When you set up a hardware wallet, the device generates a recovery seed, the string of words that controls your Bitcoin. That seed is supposed to come from a hardware random number generator producing 128 bits of entropy, a number so large that guessing it is computationally impossible.

It wasn't. According to Block's engineering team, a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure and called it preliminary.

The gap between 128 bits and 40 bits is not a matter of degree. It is the difference between a lock that cannot be picked and one that can be brute-forced by anyone with rented cloud computing. The attacker did not need to breach anything. They regenerated the likely seeds offline, derived the addresses, and checked which ones held Bitcoin.

How the theft ran

Chainalysis found the attacker went after the largest balances first, pulling more than $30 million in the opening ten minutes. Within about 25 minutes, roughly 594 BTC had moved out of some 500 single-signature wallets. One victim lost around $1.8 million.

Galaxy traced the sweeps to a 41-minute window between 1:10 and 1:51 UTC on July 30, spread across nine blocks. Coinkite's first public advisory came about 30 hours later. Every coin taken in both waves came from a wallet created after March 17, 2021, which is the strongest evidence linking the thefts to the firmware release.

3 hours ago, gargamon said:

Sure glad I'm not investing gambling in this crypto stuff.

You don't have to use a cold/hot wallet. You can safely invest in BTC via any spot Bitcoin ETF from your favorite high-street bank or stock broker.

4 hours ago, gargamon said:

Sure glad I'm not investing gambling in this crypto stuff.

That's exactly what people said to me back in 2012 when I bought a load of it.

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.