Web3: Coldcard wallet vulnerability leads to the theft of 594 bitcoins.
CoinDesk
Ai 注目
Coldcard hardware wallets were found to have a key generation flaw, allowing attackers to steal approximately 594 bitcoins within 25 minutes.
役立つ
No.ヘルプ

Canadian hardware wallet maker Coinkite's Coldcard has been found to have a key generation flaw. Attackers exploited this vulnerability to transfer 594 bitcoins in approximately 25 minutes, estimated at around $38 million based on the price mentioned in the article. About 500 addresses were affected, all of which are single-signature wallets.

Transfer out within 25 minutes

On-chain records show that the funds were rapidly transferred out between 01:31 and 01:56 UTC on Friday. The relevant transfers were distributed across 3 blocks, involving a total of 500 transactions and 1324 Bitcoins.

Of these, 562 bitcoins were subsequently consolidated into a single address and had not been transferred further as of the time of this report. The emptied wallets all shared a common characteristic: they were all single-signature addresses, and each wallet held more than 0.15 bitcoins.

Many of the addresses have not been used for many years, and the funds were formed between 2021 and 2026, a timeframe that largely coincides with the period when the vulnerability existed.

The vulnerability stems from a failure in random number generation.

The problem lies in Coldcard's random number generation process when generating wallet seeds. By design, wallet seeds should come from a highly random source that is difficult to predict, but a report released by Block's Bitcoin Engineering and Security team states that some Coldcard firmware versions skip the hardware random number generator when generating keys.

The report states that the device's configuration allows it to bypass a hardware random source and instead generate keys using software. This process relies on non-confidential data such as chip serial numbers and clock registers. Because this information is not secret, attackers can use it to narrow down their guesses and potentially recover the wallet seed.

Block traced this change back to a code commit on March 1, 2021, and said the issue was subsequently incorporated into the 4.0.0 firmware released that month.

The affected area refers to Mk3 devices.

Coinkite has advised users to carefully check wallet seeds created on Mk3 devices using firmware version 4.0.1 or later. The company initially stated that Mk4, Q, and Mk5 models do not appear to be affected at present.

The report also mentioned that the risks are not limited to ordinary wallet seeds. Paper wallet private keys, seed split masks, device cloning keys, and Key Teleport transfer functions that use the same generation logic may also be affected.

Block stated that it has notified Coinkite of its findings, and the latter has confirmed receipt of the information. Both parties acknowledge that the current analysis is still in its preliminary stages, but Block believes that given the attack has already occurred, it is disclosing the findings before completing all exploitability testing.

Additional information:From a market perspective, this large-scale transfer has not yet had a significant impact on the price of Bitcoin. At the time the report was published, Bitcoin was still above $64,000 in early Asian trading.

チップ
$0
いいね
0
保存
0
閲覧数 964
HQYCは、読者の皆様にブロックチェーンを理性的に捉え、リスク意識を高め、各種仮想トークンの発行と投機に注意を払うようお願いします。サイト内のすべてのコンテンツは市場情報または関連する見解のみであり、いかなる形式の投資アドバイスも構成しません。機密情報を含むコンテンツを発見した場合は、“報告”,をクリックしてください。すぐに対処します。
送信
コメント 0
人気
最新
まだコメントがありません。最初のコメントを投稿しましょう!
関連
Web3: Zhibao Technology plans to complete PIPE financing with 3,500 bitcoins.
Zhibao Technology plans to establish a Bitcoin treasury through PIPE financing, settled in the form of approximately 3,500 bitcoins. After the transaction is completed, the investors will obtain a majority of seats on the board of directors.
crypto.news
·2026-07-24 16:38:21
625
web3: BitMEX sued for 623 bitcoins before shutting down
As BitMEX announced its shutdown in September, it was hit by a proposed class-action lawsuit, accusing it of unfairly liquidating and withholding 622.66 Bitcoins as collateral.
CoinDesk
·2026-07-24 17:58:01
1034
Web3: The Thai Securities and Exchange Commission accuses Bitkub of concealing a $50 million theft.
The Thai Securities and Exchange Commission has accused Bitkub of concealing a 2021 cyberattack that resulted in approximately $50 million in losses. The case has been transferred to the police for investigation.
CoinDesk
·2026-07-27 21:41:55
535
Web3: Phishing emails impersonating Ledger updates lead to the theft of 400,000 XRP.
Phishing emails impersonating Ledger updates resulted in the theft of approximately 400,000 XRP from one holder.
Coinpedia
·2026-07-28 02:33:07
331
Web3: Samsung Wallet plans to add stablecoin functionality.
Samsung plans to add stablecoin support to Samsung Wallet, but has not yet disclosed the currency, timeline, or partners.
crypto.news
·2026-07-24 19:18:54
453