Bitcoin community responds swiftly to Coldcard exploit as 1,367 BTC drained from vulnerable wallets

1 hour ago 2



A vulnerability in Coldcard hardware wallets has led to the theft of approximately 1,367 BTC, worth around $89 million, from over 4,500 addresses since coordinated attacks began on July 30. The bug, quietly sitting in firmware since March 2021, weakened the randomness used to generate wallet seeds so severely that attackers were eventually able to crack them. Foundation Devices CEO Zach Herbert pointed to the open-source nature of Bitcoin wallet code as the reason the community was able to detect the issue and respond as quickly as it did. His argument: proprietary firmware would have made the problem harder to find and even harder to fix. What went wrong inside Coldcard’s firmware When you set up a hardware wallet, the device generates a “seed,” which is essentially the master key to all your Bitcoin. That seed needs to be random. The industry standard is 128 bits of entropy, which in practical terms means the number of possible seeds is so astronomically large that brute-forcing your way to the right one would take longer than the age of the universe. Coldcard’s firmware version 4.0.1, released in March 2021 by Canadian manufacturer Coinkite, introduced a bug during a significant...

Read Entire Article