Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds

Crypto’s favorite maxim, “don’t trust, verify” wasn’t followed in the case of Coldcard’s code.

How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds

Jonathan Goodman, a Toronto entrepreneur, learned the hard way that even following strict security protocols for his bitcoin can be insufficient. In July 2023, Goodman reported that all 18.25 bitcoin in his hardware wallet, a Coldcard, had been stolen—an amount worth nearly $1.17 million at the time. Goodman had stored his seed phrase, which unlocks access to the bitcoins, in a separate safe deposit box, keeping the wallet itself offline and disconnected from the internet.

Despite his best efforts, Goodman's wallet was emptied by attackers exploiting a vulnerability in the Coldcard's seed generation process.

The vulnerability went unnoticed for years within Coinkite, the company behind the Coldcard hardware wallet. Coinkite's decision to shift from a hot wallet to a decentralized hardware wallet was driven by the need to address persistent online attacks and legal complications. In 2016, Coinkite released the Coldcard, designed to create private keys securely without relying on internet-connected components or proprietary software.

Users could manually manage seed phrases and transactions, providing a sense of security against online threats.

However, the seed generation flaw entered the Coldcard's firmware during a major software overhaul in 2021. The flaw went undiscovered because users were primarily focused on Coldcard's advanced features, such as support for multisignature transactions, encrypted backups, and duress PINs. Bitcoin developer James O’Beirne later identified the flaw as stemming from code changes authored by Coinkite co-founder Peter Gray under the pseudonym "switck," which was not thoroughly scrutinized by the broader community.

Galaxy Research estimated that the flaw enabled at least 15 different attackers to siphon a total of 1,596 bitcoin—equivalent to over $100 million—from approximately 7,300 addresses. The stolen funds were dispersed across multiple wallets, making it difficult to trace and recover the assets. Goodman's experience underscores the importance of scrutinizing even the most secure hardware wallets, as vulnerabilities can still exist in the most well-intentioned systems.

Written by urgent.news from CoinDesk's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at coindesk.com →

More in Tech

Ask HN: Alternatives to GitHub

Github has been down consistently over the last few months - does it make sense to switch to alternatives? Comments URL: https://news.ycombinator.com/item?id=49331033 Points: 240 # Comments: 146

More from Monday 17 August →