Nearly 1,000 Bitcoins Worth $70 Million Drained in 41 Minutes: Here’s How Hackers Compromised an Offline System | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Nearly $70 million in Bitcoin was stolen after attackers exploited a flaw in Coldcard hardware wallets’ offline key generation.

Close to 1,000 bitcoins, worth about $70 million, were drained within a 41-minute window from a group of 1,196 wallets. What further complicates the heist is the fact that it was carried out through a group of devices that never connect to the internet. Here’s what went wrong.

According to a mapping by Galaxy Research, about 1,082.65 BTC were swept away between 01:10 and 01:51 UTC across six blocks, with three intervening blocks containing nothing. This suggests the transactions were broadcast in batches rather than as one continuous stream of attacks. What made these attacks harder to recognize was that the amount stolen was much smaller than some of the larger crypto thefts seen this year, but the mechanism used is what makes this attack highly unusual.

Here’s why the Coldcard exploit is a bigger concern than many think

In most cybercrimes, an exchange is breached, a smart contract is exploited, or a private key or access node is compromised. But what if the devices handling those keys could not connect to the internet, meaning an attacker theoretically should not be able to reach them?

Whenever a wallet is created, the device is supposed to generate a number so large and unpredictable that it cannot be guessed. This number is known as the seed, and every address and private key is derived from it using fixed public rules. Coldcard’s firmware was designed to generate that number using a dedicated hardware random number generator.

More from Tech

However, an internal build setting instructed the firmware to skip the hardware generator. As a result, key generation fell back to a basic software substitute that was seeded using the chip’s serial number and its clock registers. The serial number is fixed factory metadata, while the clock values represent timing states that an attacker could potentially narrow down or reproduce using their own device.

This meant that the range of possible keys, which should have been astronomically large, became countable. Investigators found that key generation could be predicted on the older MK2 and MK3 Coldcard models.

The attacker likely generated candidate seeds on their own hardware, derived the addresses each seed would produce, and then checked those addresses against the public blockchain, which anyone can download.

According to a CoinDesk report citing the investigation, Galaxy’s breakdown illustrates how the process unfolded. Of the drained wallets, 1,183 used the modern native SegWit address format, seven used an older legacy format, and six used an even older address type.

Since owners have no reliable way of determining whether they are affected, there is currently no test that can confirm whether a wallet is vulnerable. An identity seed generated from a reproducible range leaves users susceptible to attack from multiple directions.

Is the attack over, or does the risk remain?

While Coldcard’s maker has warned that only MK3 owners are affected and that newer devices remain safe, the investigation reportedly places the MK2, MK4, Q, and MK5 models within the scope of the issue as well.

The attacker reportedly used a well-known blockchain data provider to query the source addresses during the theft. The provider’s internal logs matched the suspected workflow with what investigators described as “extraordinary specificity.” According to reports, the provider had simply been supplying routine blockchain services to requests that gave no indication of their malicious purpose.

The attacks highlight how rapidly the cybersecurity landscape is evolving. Just recently, a quantum-resistant algorithm that had passed expert review for two years was heavily compromised by Anthropic AI models in just 60 hours.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW