Record theft from Coldcard wallets: $70 million in Bitcoin stolen due to a critical vulnerability
An unprecedented cyber attack hit Coldcard Mk3 devices, resulting in the theft of over $70 million in Bitcoin. The incident, which emerged on Thursday, was made possible by a bug in the firmware that compromised the generation of seeds, crucial elements for cryptocurrency security.
Quick Response
- The theft affected Coldcard Mk3 wallets with firmware starting from version 4.0.1, released in March 2021
- The bug made the private keys of many single-signature wallets predictable
- The attacker used a blockchain service to facilitate the transfer of funds
- Coinkite, the manufacturing company, admitted that all Coldcard models are vulnerable
- Experts advise transferring funds to secure custody
The technical analysis of the attack
Engineer Clay Garrett of Block revealed on X that the movements on the blockchain corresponded to a "suspicious flow" associated with the attacker. During the investigations, it emerged that the thief used a paid account with a well-known blockchain service provider to query the source addresses and perform other related activities. The authorities were immediately informed.
Galaxy Digital, through its research arm, confirmed that the thief followed an unusual pattern in the movement of coins. This pattern allowed identifying that all transfers were the work of the same attacker. However, the attack itself left no obvious traces, making it indistinguishable from a normal transfer of funds.
The firmware vulnerability
Coinkite, the manufacturer of the Coldcard devices, explained that the bug in the firmware caused a malfunction in the generation of seeds. Instead of using the hardware random number generator (True Random Number Generator), the system fell back on a software generator (Pseudorandom Number Generator), much less secure. This made the private keys of many single-signature wallets predictable, especially those created without the use of dice rolls or a robust BIP-39 passphrase.
The expansion of risk
Initially, the problem was identified only in Coldcard Mk3 devices with firmware starting from version 4.0.1. However, further investigations revealed that all Coldcard models are vulnerable. This led to a significant increase in risk for users, with potential further thefts underway.
Recommendations for users
Security experts advise users to immediately transfer funds from Coldcard single-signature wallets to more secure custody solutions. This includes the use of multi-signature wallets or crypto institutional custody services, which offer a higher level of protection against attacks.
For those still using Coldcard devices, it is crucial to update the firmware to the latest version and adopt additional security measures, such as the use of robust BIP-39 passphrases and dice rolls for seed generation. Additionally, it is advisable to carefully monitor fund movements and report any suspicious activity to the competent authorities.
The importance of security in cryptocurrencies
This incident underscores the importance of adopting rigorous security measures when managing cryptocurrencies. The vulnerability in Coldcard devices demonstrates that even systems considered secure can be compromised. Therefore, it is essential to stay updated on the latest threats and adopt advanced security practices to protect your digital assets.
For further technical details and updates, you can consult the official Coinkite website and blockchain analysis platforms such as Bitcoin Magazine.
The impact on the cryptocurrency market
The attack on Coldcard devices had significant repercussions on the cryptocurrency market. The theft of $70 million in Bitcoin sparked a wave of concern among investors, leading to temporary price volatility. Analysts observed an immediate drop in the value of Bitcoin, although the cryptocurrency quickly recovered part of the losses thanks to the long-term confidence of institutional investors.
The case also sparked a debate on the security of hardware wallets. Many industry experts emphasized the importance of adopting multi-signature custody solutions, which require multiple signatures to authorize transactions and offer a higher level of security compared to single-signature wallets. This incident could accelerate the adoption of such solutions among security-conscious users.
The implications for regulation
The episode raised new questions regarding the regulation of cryptocurrencies. Regulatory authorities may be pushed to scrutinize more closely the security of hardware devices used for cryptocurrency custody. This could lead to new regulations requiring stricter security standards for wallet manufacturers to prevent future attacks.
Additionally, the use of paid blockchain services to facilitate the transfer of stolen funds has raised questions about the accountability of these providers. Authorities may require greater controls and transparency from blockchain services to prevent the abuse of their platforms.
The industry's responses
Coinkite, the manufacturer of the Coldcard devices, responded quickly to the attack, releasing firmware updates and advising users to adopt additional security measures. However, the discovery that all Coldcard models are vulnerable has raised questions about the company's ability to ensure the security of its products.
Other hardware wallet manufacturers have seized the opportunity to highlight the security of their devices. Ledger and Trezor, two of Coldcard's main competitors, stated that their products are not affected by similar vulnerabilities and invited users to consider their solutions as safer alternatives.
The challenges for users
For Coldcard users, the attack represented a significant challenge. Transferring funds to secure custody requires time and technical skills, which can be an obstacle for less experienced users. Additionally, the need to update the firmware and adopt additional security measures can be complex and time-consuming.
Experts advise users to carefully follow the instructions provided by Coinkite and consider using crypto institutional custody services. These services offer a higher level of security and can be a more convenient solution for users who do not have the necessary technical skills to manage the security of their cryptocurrencies independently.
The outlook for the market
Despite the immediate impact of the attack, analysts predict that the cryptocurrency market will continue to grow. The long-term confidence of institutional investors and the increasing adoption of cryptocurrencies by businesses suggest that the sector is well-positioned to address security challenges.
However, the incident underscores the importance of remaining vigilant and adopting rigorous security measures. Users and companies in the sector must collaborate to create a safer and more resilient ecosystem, capable of addressing emerging threats.
The record theft from Coldcard wallets serves as a crucial reminder of the importance of security in cryptocurrencies. As the sector continues to evolve, it is essential that users and companies adopt advanced security measures to protect their digital assets. With the adoption of more secure custody solutions and advanced security practices, the cryptocurrency market can continue to grow in a safe and sustainable manner.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.