Coldcard 2021 年固件漏洞致逾 1 亿美元比特币被盗

链捕手
5 hours ago

ChainCatcher 消息,硬件钱包 Coldcard 的 2021 年固件漏洞导致部分恢复种子随机性不足。自 7 月 30 日起,攻击者从受影响钱包转走约 1,600 至 1,800 枚 Bitcoin,涉及数千个地址,估值超过 1 亿美元。Coldcard 制造商 Coinkite 表示,需假设有人利用 AI 审查其公开固件。该漏洞已存在约五年,AI 是否参与相关攻击尚未得到确认。

Shielded Labs 研究员 Taylor Hornby 使用 Claude Opus 4.8 审计代理,发现 Zcash Orchard 屏蔽池电路一项始于 2022 年的漏洞,测试中可无痕生成无限量伪造 ZEC。开发者在数日内完成修复,未确认发生盗币。

区块链分析公司 Chainalysis 统计显示,携带恶意软件指令及命令控制信息的链上写入量,日均从约 2.06 次升至 11.1 次,增幅 440%。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10