Coldcard Hack Tops $100M as Galaxy Flags Possible 4th Wave
CMC Crypto News

Coldcard Hack Tops $100M as Galaxy Flags Possible 4th Wave

2ในการอ่าน
2 hours ago

Galaxy Research confirms 1,596 BTC stolen from ~7,300 Coldcard addresses across 3 waves. A suspected 4th wave could push total losses to 2,055 BTC, or ~$130M.

Coldcard Hack Tops $100M as Galaxy Flags Possible 4th Wave

สารบัญ

Galaxy Research has confirmed that hackers have stolen 1,596 Bitcoin (BTC), worth more than $100 million, from approximately 7,300 Coldcard hardware wallet addresses across three coordinated attack waves and 14 smaller incidents.

Source: X

Galaxy also flagged a suspected fourth wave that, if confirmed through victim reports, would push the total to 2,055 BTC, or roughly $130 million. The firm holds the fourth wave with "medium-high" confidence but has kept it out of its confirmed figures as no victims have yet reported being part of it.

What Caused the Vulnerability

The flaw traces to a single code change made on March 1, 2021, in Coldcard firmware developed by Canadian manufacturer Coinkite. That change caused seed generation to fall back to a software-based pseudorandom number generator instead of the device's hardware random number generator.

Seeds generated under the affected firmware were produced with far less entropy than intended, making them searchable offline without physical access to the device.

Block's engineering team, which analyzed the flaw, estimated that the effective search space for Mk3 devices collapsed to roughly 40 bits under some conditions. For Mk4, Mk5, and Coldcard Q devices, the ceiling remained below 73.3 bits, well short of the intended 128-bit security level.

An attacker who can constrain a device's unique identifier, timer state, and prior random number call history can reproduce candidate seeds and check them against public blockchain data.

The affected firmware versions span Coldcard Mk2 and Mk3 devices running versions before 4.2.0, Mk4 and Mk5 devices before 5.6.0, Coldcard Q before version 1.5.0Q, and Edge builds before 6.6.0X on Mk4/Mk5 and 6.6.0QX on the Q model.

Coinkite has released emergency firmware updates for all affected models and said it destroyed remaining inventory manufactured with vulnerable firmware. Updating firmware does not secure an already-generated seed. Users must create a new seed on patched or unaffected hardware and transfer their BTC to addresses controlled by that new seed.

Related Article:Coldcard Firmware Flaw Drains $89M From 4,500 Bitcoin Wallets in 3 Waves

How the Attacks Unfolded

The first sweep occurred on July 30 when an attacker drained 1,082.65 BTC from 1,196 addresses in 41 minutes. Subsequent waves followed at roughly 27-hour intervals, with each sweep showing similar patterns of address aggregation.

Galaxy said it has not confirmed whether the same actor is behind all three waves. The 14 smaller incidents identified alongside the three main waves may represent separate, opportunistic attackers exploiting the now-public vulnerability.

Galaxy Head of Firmwide Research Alex Thorn flagged the possible fourth wave on Aug. 3, noting the transaction pattern in the mempool matched that of previous sweeps. Galaxy said 73 individual victims have contacted the firm directly, and their reports helped researchers identify victim and attacker addresses to share with federal law enforcement, crypto exchanges, and cybersecurity investigators.

This article contains links to third-party websites or other content for information purposes only (“Third-Party Sites”). The Third-Party Sites are not under the control of CoinMarketCap, and CoinMarketCap is not responsible for the content of any Third-Party Site, including without limitation any link contained in a Third-Party Site, or any changes or updates to a Third-Party Site. CoinMarketCap is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement, approval or recommendation by CoinMarketCap of the site or any association with its operators. This article is intended to be used and must be used for informational purposes only. It is important to do your own research and analysis before making any material decisions related to any of the products or services described. This article is not intended as, and shall not be construed as, financial advice. The views and opinions expressed in this article are the author’s [company’s] own and do not necessarily reflect those of CoinMarketCap.
0 people liked this article