A firmware flaw in Coldcard hardware wallets, a Bitcoin-only device, has been linked to the draining of 1,196 Bitcoin addresses in just 41 minutes on July 30, resulting in the theft of approximately $70.2 million worth of Bitcoin. The issue stems from a March 2021 firmware integration error that incorrectly routed seed generation, as reported by The Hacker News.The vulnerability, identified by Block and detailed by Galaxy Research, occurred because a deterministic software pseudorandom number generator (PRNG) was used instead of the intended hardware random number generator (RNG) for seed generation. This error allowed an attacker, under specific conditions, to reproduce candidate output streams offline. By checking these candidate seeds against public blockchain data, the attacker could identify and drain vulnerable addresses. Coinkite, the manufacturer of Coldcard, has released emergency firmware updates for all affected models and release tracks. However, installing the new firmware does not repair seeds already exposed by the flaw.Coinkite advises users whose seeds may have been compromised to generate a new seed on the patched firmware and move their funds immediately. Restoring an old seed, even to updated firmware, carries the weakness forward. The extent of the vulnerability depends on the firmware version running when the seed was created, with specific versions of Mk2, Mk3, Mk4, Mk5, and Q models being affected. While no attacker has been publicly named, the pattern of the sweep has been mapped, though it mimics legitimate coin movement.Source: The Hacker News
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
