Coldcard Hack: $116 Million Bitcoin Stolen Via Firmware Flaw | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


“Perhaps the hardest part about this is that I did everything right,” Jonathan Goodman wrote on X.

“I never shared my seed phrase with anybody. My devices never touched the internet,” the Canadian entrepreneur wrote. His Coldcard hardware wallet sat in a safety deposit box. On the night of July 29, 18.25245043 bitcoin, worth about C$1.6 million, left his addresses. His post has been viewed roughly 7.6 million times.

“If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further,” Rodolfo Novak, chief executive of Coldcard’s maker Coinkite, wrote on July 31.

Since July 30 an attacker has moved about 1,816 bitcoin, roughly $116 million, out of more than 5,200 addresses generated on Coldcard devices. Galaxy Research counted the largest sweep at 1,082 bitcoin from 1,196 wallets, broadcast inside 41 minutes. A fourth wave emptied another 709 addresses on Monday. Bitcoin traded near $64,300 through all of it.

“Please treat this as urgent,” Coinkite said in its advisory. “Migrate your funds.”

‘Systems Users Interact With But Never See’

“A hardware wallet’s security ultimately comes down to the firmware and systems users interact with but never see,” said Ido Ben-Natan, co-founder and chief executive of Blockaid.

Nobody was phished. No device was stolen. Coldcard firmware version 4.0.0, shipped in March 2021, carried a build setting telling the device to skip its dedicated hardware randomness chip. A supporting library checked whether the setting existed. It did not check whether the setting was switched on. Key generation fell through to a software substitute seeded from the chip’s serial number and its clock registers.

Seeds made that way can be enumerated. On Mk4, Mk5 and Q devices, researchers put the reproducible search space at roughly four billion possibilities, which runs on ordinary hardware. On the older Mk3, effective randomness dropped from 128 bits to about 40. Owners who generated their seed with at least 50 private dice rolls, or who used a strong passphrase, were unaffected. Almost nobody does that.

“Every wallet ultimately depends on a root secret generated from high-quality entropy,” said Vincent Bouzon, a cybersecurity expert at rival manufacturer Ledger. Generation, he said, “must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.”

‘Already Being Read By Attackers’

“I’m sorry and I’m devastated,” Novak, who posts as NVK, wrote in his apology. “Our team is heartbroken about yesterday’s news.” A follow-up letter called the previous three days “some of the hardest in this company’s history.”

Then Coinkite named a suspect that was not a person.

“To every other developer: we believe this is a sober reality of the new AI paradigm,” Novak wrote. “AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts.” He added: “If your firmware is open-source or has ever been public, assume it’s already being read by attackers and defenders alike.”

Security specialists have pushed back. A build flag that disables a hardware random number generator is a human engineering failure, they argue, and conventional review should have caught it years before any model read the repository. Andrew Lazutkin, chief technology officer at Tangem, drew a different lesson: “This incident is a good example of why open-source firmware should not automatically be equated with better security.”

Bitcoin holders have spent two years worrying about quantum computers reaching into cold storage, a fear Coinbase’s Brian Armstrong amplified in April. What got there first was a build flag.

“I think we’re four years away from Bitcoin going away,” David McAlvany, chief executive of Vaulted, said on the On The Margin podcast, predicting quantum computing will eventually break the chain. He expects machines to compress the schedule. “If I extrapolate that out and see the compound effect of technology and AI, what might have taken twenty years to get to effective quantum computing, I think is going to shrink dramatically,” he said.

‘The Worst Hit In Bitcoin History’

“This is the worst hit in bitcoin history to the most knowledgeable and ‘properly secured’ bitcoiners,” said bitcoin commentator Guy Swann.

Lorenzo Valente, director of digital asset research at ARK Invest, was harsher. “The self-custodial hardware space is a disaster at this point and creates more bad rep for the industry than anything else,” he said. Taproot developer Udi Wertheimer wrote that “the idea of your bitcoin resting easy in some secret location while you enjoy life not worrying about it is currently unrealistic.”

Casa chief executive Nick Neuman went after the dice-roll escape hatch. “You just can’t ask people to roll dice to be secure with your self custody,” he said. “It’s a non-starter for 99% of people.” David Lawrence, co-founder of Amicus, put the damage in doctrinal terms: “This is hugely damaging to the people who believe that 8 billion people will hold their Bitcoin in cold storage in the future.”

Institutional custodians made their pitch within days. Joe Burnett, vice president of bitcoin strategy at Strive, which holds about 20,000 bitcoin, argued that regulated custodians such as Fidelity and BitGo suit large balances better than a hardware wallet with one point of failure.

“Self-custody asks individuals to carry every operational risk themselves: hardware defects, key loss, inheritance, recovery,” Metaplanet chief executive Simon Gerovich wrote on X. “Even careful people doing everything right can be exposed by a flaw they had no way to see.”

Binance founder Changpeng Zhao answered with a precedent. “You may or may not know, @TrustWallet faced this exact same bug years ago, a pseudo-random number generator, ie, not truly random, $12m in losses,” he wrote. “They covered every user. Software will always have bugs. What matters is who’s behind it.” Zhao has also said he remains “a believer in self-custody, but it puts the burden on you.”

Coinkite says its investigation is ongoing and that a technical review will follow. It is helping users file police reports and insurance claims. It has not offered to make anyone whole.

Bitcoin has absorbed this kind of week before, most recently when DeFi’s yield layer was rebuilt after last November’s hacks. The timing is worse than usual. Strategy, the largest corporate holder, sold 1,638 bitcoin for $104.7 million between July 27 and August 2 to fund preferred dividends and buybacks.

“What’s a bit unfortunate about it is that attackers understood that before infrastructure teams and before security teams,” Ido Sofer, founder of Sodot, said on the On The Margin podcast. Crypto, he added, is “meeting every new attack vector first.”

Sofer’s advice to companies now applies to anyone holding one device. “So yeah, there will be hacks,” he said. “The question is, is it gonna be in your company or not?”



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW