Coldcard’s RNG Bug Has Reportedly Compromised More Than 1,750 BTC

fiverr
Ledger


A five-year-old firmware flaw in Coinkite’s Coldcard hardware wallets has let attackers reconstruct Bitcoin Bitcoin L1Bitcoin is the first and most well-known cryptocurrency introducing a new payment network and a kind of money. View Profile” class=”stubHighlight”>Bitcoin Bitcoin private keys entirely offline, and the toll keeps climbing.

Coinkite confirmed the bug traces back to a March 2021 firmware error, and Galaxy Research has estimated that the vector has led to +1,750 BTC (well over $100M) drained from ~5,000 addresses across multiple attack waves since July 30th.

What’s the Scoop?

  • The bug: A 2021 build error meant Coldcard’s firmware only checked whether a hardware-RNG flag existed rather than whether it was actually enabled, silently routing seed generation through MicroPython’s deterministic Yasmarang fallback instead of the true hardware random number generator (RNG).
  • Big problem: Because of the RNG flaw, effective entropy collapsed from a targeted 128 bits to roughly 40 bits on Coinkite’s Mk2/Mk3 devices and about 72 bits on Mk4/Mk5/Q devices. This narrowing was enough for an attacker to brute-force candidate seeds offline and match them against public blockchain addresses.
  • Four waves & counting: The first sweep hit July 30th, draining +1,082 BTC from nearly 1,200 addresses in under an hour. The second and third waves followed through August 1st, pushing the confirmed total to 1,367 BTC (~$89M) from 4,585 addresses. A suspected fourth wave began yesterday, August 2nd, and added roughly 449 more BTC from about 700 addresses. That is Galaxy Research’s running tally, though, and unconfirmed by Coinkite for now.
  • Fix risks: Coinkite shipped patched firmware for every model line within two days, but updating does nothing to repair a seed already generated under the flaw, so funds still have to migrate to a brand new address. Complicating that, users and Casa co-founder Jameson Lopp have reported devices bricking during Coinkite’s new update, leading Lopp to recommend moving funds off a weak seed before touching the firmware at all.
  • Zooming out: Crypto’s scramble to reckon with AI as a weapon and a shield continues. The new paradigm means hackers can use frontier models to find years-old flaws for a couple of dollars of compute, while builders can now prep their defenses just as cheaply. Expect more cat-and-mouse dynamics as the race for supremacy here continues. For example, the Bitcoin bridge Boltz just temporarily disabled swaps, citing a sharp rise in AI-assisted probing that its small team couldn’t keep pace with.





Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*