Coldcard Exploit Expands as Attackers Steal Up to $130M in Bitcoin

Blockonomics
Ledger


  • Galaxy Research raised its confirmed tally to 1,596 BTC, more than US$100 million, taken from about 7,300 addresses as of Tuesday.
  • A suspected fourth wave, which Galaxy holds with medium-high confidence and has not been confirmed through victim reports, would lift the total to about 2,055 BTC, or roughly US$130 million (AU$184.6 million).
  • Coinkite’s advisory has not been updated since August 1 and still carries no loss figure, no victim count and no apology.

At least 15 separate attackers are draining Bitcoin from wallets built with defective Coldcard firmware, Galaxy Research said Tuesday, lifting its confirmed tally to 1,596 BTC, more than US$100 million (AU$142 million), from about 7,300 addresses.

Two days earlier, the same tally stood at 1,367 BTC across 4,585 addresses. The coin total rose about 17% over those two days while the number of drained addresses rose about 59%.

Galaxy Research head of research Alex Thorn said there are “now NUMEROUS different attackers exploiting the Coldcard vulnerability”, estimating at least 15 of them working through the remaining exposed wallets. 

Galaxy had already cautioned that later waves should not be assumed to involve the same attacker.

okex

Read more: Russia Bans Crypto Mining in Moscow Region Until 2032 Over Power Concerns

Coinkite Faces Questions as Coldcard Exploit Grows 

Galaxy identified a further suspected sweep that would carry the total to about 2,055 BTC, roughly US$130 million (AU$184.6 million), across more than 7,700 addresses. It holds that wave with medium-high confidence and has not confirmed it through victim reports.

Coinkite acknowledged the underlying defect on July 31 and shipped emergency firmware for every affected model. Seeds generated on Mk2 and Mk3 devices without dice rolls carried roughly 40 bits of entropy, and those on the Mk4, Mk5 and Q about 72 bits, against the 128 the devices were meant to produce. 

Galaxy traced the fault to a silent March 2021 change to the random number generator. Installing the update does not repair a seed already created.

Coinkite’s advisory has not changed since August 1 and names no loss figure, no victim count and no number of attackers. “Our investigation is ongoing, and a formal technical review will be released as soon as possible,” it says. That review has not appeared.

Dragonfly managing partner Haseeb Qureshi argued that about US$2 (AU$2.84) of what he called AI hardening could have caught the flaw, citing a test in which the model GLM 5.2 ran for 20 minutes at roughly that cost. 

Qureshi proposed a “Cost of Discovery” measure for how cheaply a frontier model can reproduce a vulnerability, and said there is no evidence the thieves used AI.

Read more: Telegram Under Fire: Australia Sues as Russia Targets Founder Pavel Durov



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*