Web3: Coldcard key vulnerability leads to the theft of approximately 594 bitcoins.
Decrypt
Ai 注目
Coinkite claims that the Coldcard seed generation vulnerability has resulted in the theft of approximately 594 bitcoins, and attackers may have used AI to discover the problem.
役立つ
No.ヘルプ

Hardware wallet manufacturer Coinkite disclosed that some Coldcard devices used an incorrect random number source when generating seeds, resulting in insufficient randomness in the mnemonic phrase. The company estimates that this issue has been exploited, with approximately 594 bitcoins being transferred from about 500 wallets within 25 minutes.

The vulnerability lies in the random number call.

Coinkite stated that the firmware was supposed to call the hardware random number generator, but a software fallback implementation from MicroPython also existed in the codebase, and both had the same function signature. Because the preprocessing checks during the build only checked whether the setting existed and did not verify the value, the device ultimately went to the software fallback path without reporting an error.

The company stated that this issue has existed since a migration in March 2021. As a result, the seed entropy generated by the device is lower than the design target, making it easier for attackers to guess the private key through brute force.

Mk3 has the highest risk

Coinkite states that all current Coldcard devices are affected to varying degrees. Mk3's effective search space is approximately 40 bits, significantly lower than the required 128-bit strength for a seed. Mk4, Q, and Mk5, due to the added entropy from the secure element, can achieve a strength of approximately 72 bits, but still fall short of the target level.

  • Mk3: Effective strength approximately 40 bits
  • Mk4, Q, Mk5: Approximately 72 bits
  • Tapsigner, OpenDime, and Satscard were unaffected.

You still need to change the seed after upgrading.

Coinkite has released an emergency hotfix, including version 5.6.0 for Mk4 and Mk5, and version 1.5.0Q for the Q model. However, the company emphasizes that upgrading the firmware will not fix previously generated torrents, and affected users will still need to regenerate new mnemonic phrases.

The company recommends that users migrate their funds after patching, and in conjunction with using a stronger BIP-39 passphrase, introducing additional entropy through at least 99 dice rolls, or both. Mk3, being no longer supported, requires a separate migration path.

The manufacturer mentioned that AI may be involved in discovering vulnerabilities.

Coinkite stated that the company can currently only assume that attackers discovered the issue by using AI to review its past open-source firmware versions. The company said it had also used a leading model to examine the same code a few weeks ago, but did not detect the vulnerability at that time.

Trezor subsequently reminded users that its products were unaffected, noting that even after restoring weak seeds generated on affected Coldcards to other brands of devices, the seeds themselves remained fragile. Block, after independent analysis, also stated that its products were unaffected by this incident.

チップ
$0
いいね
0
保存
0
閲覧数 854
HQYCは、読者の皆様にブロックチェーンを理性的に捉え、リスク意識を高め、各種仮想トークンの発行と投機に注意を払うようお願いします。サイト内のすべてのコンテンツは市場情報または関連する見解のみであり、いかなる形式の投資アドバイスも構成しません。機密情報を含むコンテンツを発見した場合は、“報告”,をクリックしてください。すぐに対処します。
送信
コメント 0
人気
最新
まだコメントがありません。最初のコメントを投稿しましょう!
関連
Web3: Coldcard wallet vulnerability leads to the theft of 594 bitcoins.
Coldcard hardware wallets were found to have a key generation flaw, allowing attackers to steal approximately 594 bitcoins within 25 minutes.
CoinDesk
·2026-07-31 13:25:06
971
Web3: Poolin files for bankruptcy with liabilities of approximately $173 million.
Bitcoin mining company Poolin has filed for bankruptcy protection in the United States, with liabilities of approximately $173 million, and is seeking to sell two of its Texas mining farms.
CoinDesk
·2026-07-24 19:18:53
606
Web3: The Thai Securities and Exchange Commission accuses Bitkub of concealing a $50 million theft.
The Thai Securities and Exchange Commission has accused Bitkub of concealing a 2021 cyberattack that resulted in approximately $50 million in losses. The case has been transferred to the police for investigation.
CoinDesk
·2026-07-27 21:41:55
537
web3: Strategy adjusts the definition of key financial metrics
Strategy adjusted its financial metrics in an attempt to restore investor confidence amid a weakening stock price and declining debt instruments.
U.Today
·2026-07-29 21:33:52
566
Web3: XRP approaches key support level of $1.08
XRP is testing key support around $1.08, with the market watching to see if it can return above $1.11 to $1.12.
Coinpaper
·2026-07-26 19:52:01
700