Coldcard Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Cybersecurity

Coldcard Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Published:
Updated:

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth approximately $70.2 million at the time. Galaxy Research mapped the sweep and linked it to a firmware flaw in Coldcard, a Bitcoin-only hardware wallet made by Canadian company Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (RNG). According to Block, an attacker who can determine or sufficiently constrain the device UID, timer state and history of prior RNG calls can reproduce candidate output streams offline without accessing the device. Candidate seeds can then be tested by deriving their addresses and comparing them with public blockchain data. The incident gives Somali Bitcoin users a concrete reason to scrutinise wallet firmware: keeping funds on dedicated hardware does not protect them when the device’s secret-generation process is flawed.

Source: Thehackernews

Read our sourcing and corrections policy

Share:

Comments

Be the first to comment on this story!