GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Community users used AI to audit Coldcard code, discovering a critical vulnerability in just 8 minutes

Developers on Reddit used Claude Code to scan the Coldcard open-source firmware for vulnerabilities, pinpointing the core issue within 8 minutes: When generating private keys, the firmware invoked a software pseudo-random number generator instead of a hardware true random number generator, and it was this vulnerability that led to the theft of approximately $70 million in BTC from 1,196 wallets. Meanwhile, community users also reported that using Zhipu GLM 5.2 (trained on June 16, offline) for an independent scan similarly discovered this vulnerability. This bug has existed in the open-source wallet code for over five years.

Stacks Co-founder Shares Lessons from Coldcard Security Incident: Don't Put All Your BTC in One Basket

Odaily News, Stacks co-founder Muneeb shared his views on the Coldcard wallet incident, summarizing lessons learned in three areas: Bitcoin storage strategy, quantum computing threats, and ecosystem security building. Regarding Bitcoin storage strategy, he noted that many industry security experts are not even familiar with Coldcard, and top-tier security research institutions may not have conducted thorough audits of its code. Muneeb believes the best approach going forward should be asset diversification rather than concentrating all funds in a single solution, and suggested:1. Allocate 20%-30% of BTC to ETFs, such as BlackRock's Bitcoin ETF IBIT, for professional custody and regulatory protection;2. Allocate 40%-50% of BTC to multisignature solutions like Casa, such as the three-key model, spreading keys across security companies, mobile devices, and hardware wallets;3. Allocate 20%-30% of BTC to more advanced self-custody approaches, combining different hardware wallets and diverse entropy sources.On the quantum computing threat, Muneeb stated that once quantum computers break through existing encryption systems in the future, Bitcoin users may experience a shock similar to "BTC suddenly being transferred out of cold wallets." The quantum threat is real, and the industry should prepare in advance rather than underestimate technological progress, especially against the backdrop of large language models accelerating scientific research breakthroughs.

Bloomberg ETF Analyst Questions Coldcard Team Size: Approximately 5-Person Team Undertaking Critical Wallet Security Responsibilities Poses Risk

Bloomberg Senior ETF Analyst Eric Balchunas commented on the Coldcard wallet security incident, questioning whether a company with only about 5 employees is suitable to undertake such critical Bitcoin storage responsibilities. He stated that the number of employees behind Coldcard "seems unbelievably low," asking whether people would be willing to store their life savings in a bank with only 5 employees headquartered in Canada. In the crypto industry, this might be viewed as a feature, but from a traditional finance perspective, it becomes a clear risk signal. Balchunas further stated that, in comparison, institutions with larger teams such as Coinbase and Ledger may hold advantages in security investment and operational capabilities, even if users need to bear higher transaction costs. Bitcoin ETFs offer another option: investors can obtain the security guarantees provided by large, professional, regulated financial institutions while also enjoying lower management fees.

Bitcoin Small-Value Transfers Hit New High Since FTX Collapse, Coldcard Security Incident Sparks Self-Custody Debate

as the suspected hacking incident involving Coldcard wallets continues to unfold, Bitcoin small-value transfers have surged significantly, reaching their highest level since the FTX exchange collapse, reigniting market discussions on Bitcoin self-custody security.Julio Moreno, Head of Research at CryptoQuant, disclosed data on X platform showing that the number of on-chain Bitcoin transfers below 1 BTC has risen to its highest level since November 2022, with approximately 39,600 BTC transferred in a single day—only about 300 BTC below the record of 39,900 BTC set on November 16, 2022, just days after FTX filed for bankruptcy. He believes that users proactively taking action to address risks is a positive signal. Additionally, Eric Balchunas, Senior ETF Analyst at Bloomberg, noted that Bitcoin ETFs, backed by a mature regulatory framework and convenience, may offer some users a safer investment approach.However, industry insiders point out that the Coldcard incident more likely reflects issues with a single wallet provider or specific security processes, rather than indicating a failure of the entire Bitcoin self-custody system. This event once again highlights the importance of security awareness, risk diversification, and wallet usage habits in personal asset management.

$282 Million in Bitcoin and Litecoin Stolen in Trezor Impersonation Support Scam

Odaily News, January 10 - A Bitcoin and Litecoin holder provided a 12-word recovery phrase to attackers impersonating Trezor support personnel, resulting in the theft of approximately $282 million in assets, including about $139 million in Bitcoin and $153 million in Litecoin. Blockchain forensics firm ZeroShadow stated that the incident stemmed from a social engineering attack, not a compromise of wallet software or private key infrastructure. The stolen funds were split via the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze approximately $700,000 in funds within 20 minutes. Under the BIP39 standard, a 12-word recovery phrase contains approximately 128 bits of entropy, while a 24-word phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of all mined Bitcoin is permanently inaccessible due to lost keys, involving millions of BTC, with causes including forgotten recovery phrases, damaged backups, and a lack of inheritance planning.

Hacker Deposits 229.72 ETH, Valued at $445,000, from Coldcard Attack Involving Approximately 30 BTC into Duel.comcasino

Odaily News: According to monitoring by Galaxy's Head of Research, a victim's Coldcard wallet was compromised in a hacker attack involving nearly 30 BTC, of which 17 BTC were swapped for ETH via THORChain and subsequently deposited into Duel.comcasino. The victim and a researcher have sent emails to all known addresses associated with Duel.comcasino, requesting that the relevant funds be frozen, and provided all transaction and deposit information. The hacker deposited 229.72497255 ETH, valued at $445,000, into Duel.comcasino—funds originating from the Coldcard attack involving approximately 30 BTC. The victim stated that Duel.comcasino responded by saying that the police would need to contact their team. Duel.comcasino's anti-money laundering policy claims it enforces Know Your Customer (KYC) procedures and complies with all applicable laws. Duel.comcasino was notified within minutes of the deposit being completed. To date, Duel.comcasino has not frozen the relevant funds. Since most of the Western world had already passed midnight at the time of the incident, police reports cannot be filed until at least Monday. If Duel.comcasino fails to freeze the funds, the victim will pursue legal action against them. Duel.comcasino's X account has been suspended, and Galaxy's Head of Research has also flagged individuals on X suspected of being associated with the platform, including team members and dealers: @korraflow, @atrois7, @MiaMalkova.

Coldcard Hacked Triggers Massive Bitcoin Transfer, Daily Active Addresses Hit Nearly 8-Month High

According to CryptoQuant Head of Research Julio Moreno (@jjcmoreno), following the hack of Coldcard hardware wallets, users transferred Bitcoin on a large scale due to security concerns. On-chain data shows that Bitcoin daily active addresses surged from 645,000 on July 30 to nearly 1 million on July 31, marking the highest single-day level since December 10, 2024, with active sending addresses rising significantly while receiving addresses saw relatively limited growth. Meanwhile, daily exchange deposit volume for single transactions under 10 BTC soared to 7,300 BTC, the highest since February 6 this year.

Galaxy Research Head: Coldcard attack ongoing, will update affected address count statistics

Odaily News, Galaxy Research Head Alex Thorn posted on X platform, stating that the attack targeting wallet addresses with weak random numbers generated by Coldcard is still ongoing. Users who still hold funds in Coldcard single-signature wallets should immediately migrate to secure addresses. New victim addresses and attacker addresses are continuously being added to the investigation database, and Galaxy Research plans to release updated statistics on the number of affected addresses.He noted that the previously identified waves 1, 2, and 3 of the attack exhibit clear programmatic characteristics, and the stolen BTC currently remains in the attacker's addresses without any transfers. However, in recent times, smaller-scale attackers have begun exploiting the vulnerability to steal funds and move them through peeling chains, cross-chain services, and other methods. It is certain that single-signature wallet addresses generated by Coldcard after the March 2021 firmware upgrade are all potentially at risk, and users should migrate funds as soon as possible.Previously reported, Galaxy Research has disclosed that the Coldcard vulnerability attack has affected approximately 1,367.05 BTC (approximately $88.6 million), involving around 4,585 addresses.

Galaxy Research: Approximately 600 Suspected Coldcard Attacker Addresses Submitted

Galaxy Research stated in a post on X that the attack targeting wallet addresses generated with weak randomness by Coldcard is still ongoing. The team urges users to immediately migrate funds from affected Coldcard single-signature wallets to secure addresses.They stated that approximately 600 suspected attacker addresses have been submitted to federal investigators, industry compliance bodies, and cross-industry cybersecurity investigators. These addresses are believed to hold funds stolen from Coldcard wallets with weak randomness.The team also noted that victims have proactively shared wallet addresses and transaction hashes, helping researchers establish on-chain attack patterns and further identify more affected wallets and attack addresses. Currently, multiple parties within the Bitcoin and crypto industry are assisting in user asset protection and attack tracing efforts.Galaxy Research previously stated in a post on X that a third wave of attacks suspected to target Coldcard-generated addresses has emerged, with 207.7294 BTC already transferred out. According to on-chain tracking data, the Coldcard wallet attack incident has so far involved approximately 1,367.05 BTC, valued at approximately $88.6 million, affecting 4,585 addresses.

COLDCARD vulnerability may have originated from compiler bypass handling

Odaily News: Bitcoin News posted on X platform that a new technical analysis by Core-Lightning developer ddustin shows that the 2021 COLDCARD vulnerability may have originated when developers attempted to connect the wallet using Python code, MicroPython's C code, and the STM32 hardware random number generator. The custom code appears to have conflicted with MicroPython's existing implementation, potentially triggering a compiler error. Evidence suggests that developers subsequently set MICROPY_HW_ENABLE_RNG to 0, allowing the firmware to compile successfully. This change led to unintended consequences: when users created new wallets, the firmware no longer used the hardware random number generator, instead falling back to MicroPython's weaker Yasmarang software random number generator. The commit message left by the developers was only "runs." The analysis states that this serves as a reminder to developers not to release security-critical code they do not fully understand, especially when it protects billions of dollars in Bitcoin.

Galaxy Research: ColdCard Wallet Hacker Attack Scale Continues to Expand, Three Waves of Attacks Stole a Total of Approximately $88.6 Million Worth of BTC

According to monitoring by on-chain analysis firm Galaxy Research (@glxyresearch), the ColdCard wallet hacking incident has developed into a third wave, with an additional 207.73 BTC stolen. Currently, the three waves of attacks have cumulatively stolen 1,367.05 BTC (approximately $88.6 million), involving 4,585 addresses. On-chain data shows that the three waves of attacks exhibit highly similar characteristics: identical fund consolidation topology, identical P2WPKH target addresses, and mixed derivation paths. Each wave occurred approximately 27 hours apart, suggesting they were carried out by the same attacker, but there is currently no direct evidence to confirm this. Currently, all terminal addresses controlled by the hackers hold a total of 1,366.39 BTC (approximately $88.6 million), all of which are in an unspent state on-chain. Galaxy Research noted that the above data is based solely on Bitcoin block data and UTXO set analysis, and has not yet computationally verified whether the victim addresses have vulnerabilities due to low-entropy generation.

CZ: Software always has vulnerabilities; what matters is how the team behind it handles the issues

Odaily News: Binance founder CZ reposted on X platform about a user's encounter with a Coldcard wallet attack and stated that software will always have vulnerabilities; the key lies in how the team behind it handles the problems.CZ added that Trust Wallet faced a similar issue years ago, when a non-truly random pseudo-random number generator led to losses of approximately $12 million, but the team ultimately covered the user losses.Previous report: A third wave of attacks suspected to target addresses generated by Coldcard has emerged, with the attacker transferring approximately 207.7294 BTC again. Data shows that the scale of Coldcard-related attacks observed so far has expanded to about 1,367.05 BTC, involving approximately 4,585 addresses, valued at around $88.6 million at current prices.

Stealing $72.71 Million in Bitcoin, Coldcard RNG Vulnerability Exploit Cluster Begins Moving Funds

Odaily News: The Coldcard RNG vulnerability exploit cluster has stolen 1,159.42 BTC, approximately $72.71 million, from 870 exploited addresses. The attacker transferred 0.06 BTC to a new address, worth approximately $3,780; the remaining 1,159.35 BTC is still distributed across the original 8 attacker addresses, valued at around $72.7 million.

Dice rolls cannot protect all Coldcard features; multiple features may be affected by Yasmarang PRNG flaw

Odaily News: Bitcoin News posted on X platform, stating that even if the mnemonic remains secure because it was generated via dice rolls or imported from an existing mnemonic, multiple Coldcard features may still be vulnerable due to the Yasmarang PRNG flaw. Affected features include paper wallets, device cloning, USB sessions, Secret Teleport, co-signing keys, password generator, and HSM mode. If the mnemonic was imported or generated through a sufficient number of dice rolls, the mnemonic itself remains secure, but using these features may still expose secret information generated by the flawed random number generator.

Self-custody confidence permanently changed, Strive VP says Bitcoin custody may enter its next phase

Strive Vice President Joe Burnett posted on X, saying that recent weeks may be among the worst in Bitcoin's history. Many people purchased approved hardware wallets, generated seed phrases offline, and followed established best practices, yet still lost significant amounts of Bitcoin due to a vulnerability affecting seed phrases generated by COLDCARDwallet since March 2021. The vulnerability went undetected for over five years. Joe Burnett stated this will permanently change people's confidence in self-custody. Self-custody will still exist, but it has been permanently changed. For those who want to directly control large amounts of Bitcoin, the standard should be multi-vendor multisignature, with keys independently generated using different hardware and different software, and stored in different physical locations. If they cannot accept this approach, they should use institutional-grade custodians. Joe Burnett noted that the current wave of Bitcoin adoption is occurring through ETFs, treasury companies, and institutional custodians, primarily driven by people who never intended to become experts in private key generation, hardware security, firmware, backups, inheritance planning, and physical storage. A single key generated by one hardware wallet protecting large amounts of Bitcoin carries excessively high concentration risk. Joe Burnett also said that institutional custody may ultimately lead to too much Bitcoin being concentrated in the hands of large companies, creating risks of censorship, seizure, and confiscation. However, Bitcoin's portability and settlement properties provide a critical counterbalance — users can create a wallet and request the custodian to send Bitcoin, shifting from counterparty risk to direct ownership within minutes. Joe Burnett believes that as long as Bitcoin itself remains secure, the failure of one custody method does not negate the underlying monetary system, but rather forces the market to develop better tools, stronger standards, and more resilient custody architectures. This week may ultimately mark the end of one era of Bitcoin custody and the beginning of the next wave of Bitcoin adoption.

Nunchuk Responds to Coldcard Vulnerability: Platform Keys Will Not Be Used Directly

Odaily News, according to Bitcoin News monitoring, Nunchuk stated that some Nunchuk platform keys are generated by Coldcard Mk4, but these keys will not be used directly. Nunchuk derives independent keys through custom logic, making them less susceptible to lookup table attacks based on compromised Coldcard seeds. Nunchuk added that, given enough time, it believes attackers may eventually incorporate these derived keys as well.

Galaxy Research: Bitcoin losses related to the Coldcard vulnerability have risen to $70 million

Galaxy Research stated on Friday that over 1,000 BTC from nearly 1,200 addresses have been moved, valued at approximately $70 million, with the transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets.Earlier, Coldcard manufacturer Coinkite issued a warning on Thursday about an ongoing issue with seed phrases generated by Coldcard Mk3 devices. Out of caution, the company reminded all users who generated seed phrases using Mk3 devices with firmware version 4.0.1, released in March 2021, or later, that their funds may be at risk.Subsequently, Coinkite expanded the scope of its risk alert to include certain firmware versions of Mk4, Mk5, and Coldcard Q, and released emergency firmware updates for all affected models.Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday and stated that the company takes "full responsibility" for the firmware vulnerability, acknowledging that internal review processes failed to identify the issue.Novak also suggested that the vulnerability may have been discovered with the help of artificial intelligence, noting that this incident reflects a "sobering reality under the new AI paradigm." He warned that AI-assisted code review could identify potential vulnerabilities faster than experienced security experts, while also making it easier for attackers to exploit weaknesses in public code.

Approximately $30 million stolen in the first 10 minutes, Coldcard vulnerability attacker prioritized highest-value wallets first

Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.

Reduced randomness: Seeds from some COLDCARD wallets since 2021 are easier to guess

: Bitcoin News posted on X platform stating that Coinkite said the issue is not with Bitcoin's cryptography itself, but with the way COLDCARD generates wallet seeds. During the libNgU migration in March 2021, the wallet unexpectedly used a weaker software random number generator when creating new seed phrases, instead of the device-specific hardware random number generator. This reduced the randomness protection for some wallets, making certain seeds easier to guess than expected. The vulnerability has affected seed generation since March 2021, with Mk3 devices being the most affected. Mk4, Q and Mk5 have incorporated additional hardware-generated randomness, providing stronger protection, but they still rely on the same software component afterward. Coinkite stated that the error occurred because two pieces of software used the same function name, causing the wrong function to be selected during the build process without triggering an error. The company has changed its build process to prevent this from happening again.

Coinkite Issues Coldcard Mk3 Security Warning, Suspected to Be Related to $38 Million Bitcoin Theft Incident

据 Cointelegraph 报道,加拿大比特币硬件钱包制造商 Coinkite 警告 Coldcard Mk3 用户立即迁移资金,受影响固件版本为 2021 年 3 月发布的 4.0.1 至最终版本 5.0.3,Mk4、Q 及 Mk5 不受影响。与此同时,比特币安全专家正在调查一起涉及 594.48 枚 BTC(约 3830 万美元)的异常清仓事件,涉及 1324 个 UTXO 在三个区块内通过 500 笔交易被转移,所有地址均为单签名地址。