Urgent.News

What's breaking now, across thousands of outlets.

Tech

Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken

"A hardware wallet is supposed to be the safest place to keep Bitcoin," writes The Street, since it never connects to the internet, its keys never leave the device, and "the whole point is that an attacker would need to physically hold it to steal anything." The problem is that anyone who can reproduce the recovery seed doesn't need to possess the COLDCAR, Nerds.xyz points out. More from The…

Abstract editorial illustration

A security breach has been uncovered in Coldcard hardware Bitcoin wallets, resulting in the theft of $75 million. Hardware wallets are typically considered the most secure method for storing Bitcoin, as they are not connected to the internet and all keys remain on the device. However, a flaw in Coldcard's firmware, which was introduced on March 1, 2021, allowed attackers to easily guess the recovery seed used to secure these wallets.

The recovery seed is intended to be generated by a hardware random number generator, providing 128 bits of entropy, making it nearly impossible to guess. However, due to a single code change, the firmware on Coldcard Mk3 devices fell back to a software-based generator, collapsing the search space to just 40 bits. This significant reduction in entropy makes it feasible for attackers to brute-force the recovery seed, effectively turning the hardware wallet into a vulnerable point.

Within minutes of discovering the vulnerability, the attacker began targeting wallets with the largest balances, moving over $30 million in the first ten minutes alone. By 25 minutes, approximately 594 BTC had been transferred from around 500 single-signature wallets. One victim reportedly lost $1.8 million worth of Bitcoin.

To address the issue, Coinkite, the manufacturer of Coldcard, released a fixed firmware update. However, it is crucial to note that updating the hardware does not repair existing weak seeds. Affected users must generate new wallets on updated hardware and transfer their funds to these secure wallets. As of Saturday morning, Galaxy Research had tracked a total of 1,158.66 BTC (about $75.1 million) stolen from 2,673 addresses.

The security breach is ongoing, and users are strongly advised to immediately move their Coldcard single-signature funds to safer locations. Investigators have been alerted to nearly 600 addresses believed to be holding stolen funds, and they urge federal investigators, industry compliance firms, and cross-industry cyber investigators to closely monitor these funds.

Written by urgent.news from Slashdot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 3 other outlets

Read the original at it.slashdot.org →

More in Tech

More from Sunday 2 August →