Security Flaw in Coldcard's Key Generation Exposes 594 Bitcoins to Theft

Deep News
07/31

Approximately 594 bitcoins, valued at around $38 million, were stolen from about 500 Coldcard hardware wallets in a 25-minute window Friday morning Beijing time due to a vulnerability in the key generation process. The theft occurred between 01:31 and 01:56, with the attacker moving 1,324 Bitcoin fragments across 500 transactions and then consolidating 562 of them into a single address, where the funds have remained idle.

All compromised wallets were single-signature setups, each holding more than 0.15 bitcoins. The majority had been inactive for an extended period, with their creation dates spanning from 2021 to 2026, closely matching the lifespan of the vulnerability.

Coldcard, a hardware wallet produced by the Canadian company Coinkite, is designed for offline storage of Bitcoin private keys. The flaw impacts multiple product generations, including the Mk2, Mk3, Mk4, Q, and Mk5 models. According to a report from Block Inc.'s Bitcoin engineering and security team, the root cause was a misconfiguration in the firmware build that caused the device to bypass its own hardware random number generator. Instead, it relied on a weak software-based random number generator using the chip's serial number and clock registers—data that is not secret and could be easily obtained or calculated by attackers.

The issue can be traced back to a code commit from March 1, 2021, and was released with firmware version 4.0.0 that same month. The degree of risk depends on the firmware version running on the device when the wallet seed was created, not the time of purchase. Coinkite has warned that users who generated seeds on Mk3 devices running firmware version 4.0.1 or later are at risk, while it has preliminarily confirmed that Mk4, Q, and Mk5 models are unaffected. Block stated that it has disclosed its findings to Coinkite, which has acknowledged them. Both companies emphasize that the analysis is preliminary, with Block noting it issued the report without completing a full test cycle, as the attack was already in progress.

Beyond wallet seeds, the same random number generator also compromised the security of Coldcard paper wallet private keys, seed split masks, device cloning keys, and the Key Teleport transfer function. The price of Bitcoin remained above $64,000 during Asian morning trading, with the large-scale theft having no significant impact on the market.

免責聲明:投資有風險,本文並非投資建議,以上內容不應被視為任何金融產品的購買或出售要約、建議或邀請,作者或其他用戶的任何相關討論、評論或帖子也不應被視為此類內容。本文僅供一般參考,不考慮您的個人投資目標、財務狀況或需求。TTM對信息的準確性和完整性不承擔任何責任或保證,投資者應自行研究並在投資前尋求專業建議。

熱議股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10