Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken (nerds.xyz) 45
"A hardware wallet is supposed to be the safest place to keep Bitcoin," writes The Street, since it never connects to the internet, its keys never leave the device, and "the whole point is that an attacker would need to physically hold it to steal anything."
The problem is that anyone who can reproduce the recovery seed doesn't need to possess the COLDCARD, Nerds.xyz points out. More from The Street: [The recovery seed] is supposed to come from a hardware random number generator producing 128 bits of entropy, a number so large that guessing it is computationally impossible. It wasn't. According to Block's engineering team a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure and called it preliminary. The gap between 128 bits and 40 bits is not a matter of degree. It is the difference between a lock that cannot be picked and one that can be brute-forced by anyone with rented cloud computing....
Chainalysis found the attacker went after the largest balances first, pulling more than $30 million in the opening ten minutes. Within about 25 minutes, roughly 594 BTC had moved out of some 500 single-signature wallets. One victim lost around $1.8 million... Coinkite has shipped fixed firmware, but with a warning that matters more than the patch itself. Updating does not repair an existing seed. A seed created with weak entropy stays weak forever. Affected users have to generate an entirely new wallet on updated hardware and move their coins to it.
By Saturday morning Galaxy research was tracking 1,158.66 BTC, worth roughly $75.1 million, taken from 2,673 addresses, according to the article. And "The Coldcard exploit is ONGOING," Galaxy Research posted an hour ago on X.com. "Move Coldcard single-sig funds to safe locations immediately!" We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators.
Thanks to Slashdot reader BrianFagioli for sharing the news.
The problem is that anyone who can reproduce the recovery seed doesn't need to possess the COLDCARD, Nerds.xyz points out. More from The Street: [The recovery seed] is supposed to come from a hardware random number generator producing 128 bits of entropy, a number so large that guessing it is computationally impossible. It wasn't. According to Block's engineering team a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure and called it preliminary. The gap between 128 bits and 40 bits is not a matter of degree. It is the difference between a lock that cannot be picked and one that can be brute-forced by anyone with rented cloud computing....
Chainalysis found the attacker went after the largest balances first, pulling more than $30 million in the opening ten minutes. Within about 25 minutes, roughly 594 BTC had moved out of some 500 single-signature wallets. One victim lost around $1.8 million... Coinkite has shipped fixed firmware, but with a warning that matters more than the patch itself. Updating does not repair an existing seed. A seed created with weak entropy stays weak forever. Affected users have to generate an entirely new wallet on updated hardware and move their coins to it.
By Saturday morning Galaxy research was tracking 1,158.66 BTC, worth roughly $75.1 million, taken from 2,673 addresses, according to the article. And "The Coldcard exploit is ONGOING," Galaxy Research posted an hour ago on X.com. "Move Coldcard single-sig funds to safe locations immediately!" We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators.
Thanks to Slashdot reader BrianFagioli for sharing the news.
Criminal activity in the crapto space. Who cares? (Score:4, Insightful)
Seriously, this abysmally bad idea has no place in the news. Only blithering idiots are still in there.
Re: (Score:2)
We get it, you're a five-digit ID who dismissed bitcoin when it was originally making noise on /. in 2009/2010 and you're mad you missed out on life-changing wealth.
Sour grapes are a real thing for a lot of slashdotters, but if this were a hack of a github repo that resulted in your PII being stolen, you wouldn't be so dismissive.
Re: (Score:2)
Hahahaha, no. I am a bit more sophisticated than you are. Stop projecting.
Re: (Score:2)
What exactly are you claiming as projection? Please be specific.
Slashdot has obviously declined dramatically over the years, but it's sad to see the graybeards resorting to ad hominem.
Re:Criminal activity in the crapto space. Who care (Score:4, Funny)
So you're claiming you have life changing wealth from Bitcoin? What island did you buy?
Re: Criminal activity in the crapto space. Who car (Score:2)
What do you think ad hominem means? It doesn't mean someone made you feel bad.
Re: (Score:2)
implying that someone is unsophisticated is an ad hominem
When you say that someone's argument is bad because they are allegedly unsophisticated, that is ad hominem. When you say that someone is clearly unsophisticated because of their foolish argument, that is not ad hominem. This is probably the most widely misunderstood logical fallacy, if only because it's the most familiar — if not well-known, in that it is not well-understood. It means argument from a person, and if you are not arguing that someone's argument is bad because of some thing about them whi
Re: (Score:2)
That statement is not about someone's argument, it is about someone's person.
If you read what I wrote, you didn't understand it.
Feel free to ask for clarification, or simply to point out any parts of what I wrote that you find unclear. I'm looking for ways to better explain this.
Re: (Score:2)
That statement is not about someone's argument, it is about someone's person.
If you read what I wrote, you didn't understand it.
Well, that basically proves my claim of lack of sophistication, does it? Although somebody valuing money very highly ("life-changing") does already amply proves non-sophistication.
Re: Criminal activity in the crapto space. Who car (Score:2)
Forget 5 digit /. User ID, I'm old enough to remember the phone company use to mail books with PII called phone books to everyone.
Re: (Score:2)
Check your player's handbook, it's definitely an upgrade from studded leather.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Their value has already peaked. Get out now while they still have some value.
Slashdot introduced me to bitcoin in 2010 and, as a result, I turned a few hundred dollars into a few hundred thousands.
Umm.. Unlikely. $100 worth of bitcoin in 2010 (0.39) would be worth over $15M today. It would have been over $30M last October. Your claim of "a few hundred" multiplies that by some unknown amount. If you actually had $90M in bitcoin last year you wouldn't be bragging about it here.
It looks like the GP did exactly as you suggested: he got out early while he was sure the coin still had some value. Maybe he needed the money for something at the time — something he values more than money. I personally sold a considerable amount of bitcoin in the mid 2010s to buy my own apartment. I know I could have made more money by holding it, but that would have meant renting someone else's apartment, which means higher running costs and less control over my life. So I remain quite happy with
Those idiots will drag you down with them (Score:2)
You can't just wash your hands of things. Not in a modern economy. Everything is interconnected and sooner or later shit rains down on everybody.
Re: (Score:2)
It's being promoted by the President of the United States and by Federal agencies. It's mainstream and something that lay people will be interacting with. You can justifiably call them blithering idiots for trusting anything POTUS says, but it's definitely relevant news.
Randomization AND a software bug! (Score:3)
Are you nuts? This is the most interesting news in quite some time, at least from a nerd perspective.
This story has everything you'd want- an insufficient randomization problem, a software bug that makes it subtlety fail and take the wrong path that makes a lot of keys guessable, and then, years later, an eventual exploit where someone, offline, reproduced a ton of these failed key creations, checked the blockchain to see which ones had stuff, set up a burst of activity that would move all the bitcoin at e
Re: (Score:2)
Wonder if the police will start treating it as flippantly as they do "theft during a drug deal".
seriously - who certified or tested this (Score:3)
And one entity, the US government, had a non-standard random number generator, that they couldn't explain in the original version of Open SSL (yes the US government paid for it). It did pass all the randomness tests I tried but it wasn't the algorithm they claimed. With random number generators you "merge" in entropy from a physical source into your entropy pool because your physical source could have a "bias" or uneven distribution to its bits.
Re:seriously - who certified or tested this (Score:4, Interesting)
40 bit is within reach of practical guessing attacks. 128 bit is not, but just barely (the limit where it becomes reliably unguessable is somewhere in the 80...100 bit range). If you are serious about things you use at the very least 256 bit. And, obviously, you do independent expert review on any major change. This one is so abysmally insightless and bad, it may well have been an intentionally placed backdoor. I wonder whether they can still reliably say who did the change.
As to who certified that, this is the crapto space. Where everything is easy, nothing needs to be certified and stupid is the name of the game.
Re: (Score:3)
Re: (Score:2)
I do wonder about the hardware RNG on the STM32. They say it passes various randomness tests, and I'm sure they are right, but those tests aren't the be-all and end-all. I'd want to mix it with other sources of entropy.
Re: (Score:2)
silently? (Score:4, Insightful)
Does that mean they have never run their code changes in a test environment to see what they do? Perhaps under a debugger? Also, why was it even possible to fall back to such a weak keylength?
Re: (Score:3)
> Also, why was it even possible to fall back to such a weak keylength?
Key length is likely something perfectly normal, What this article is talking about is entropy, which is a measure of how truly random your RNG is.
https://en.wikipedia.org/wiki/... [wikipedia.org]
Basically everyone uses predictable RNG generators that always output same numbers for a given seed. The security of this depends on providing truly random seed that cannot be predicted. Im guessing hardware wallet has not enough external inputs to generate
Fuck you for posting this (Score:3)
The magic 8-ball says lawsuits incoming.... (Score:2)
So one should probably wonder (Score:5, Interesting)
What are the odds that a COLDCARD insider has been playing the long game, and it just payed off?
Re: (Score:2)
What are the odds that a COLDCARD insider has been playing the long game, and it just payed off?
What are the odds a predictive market would be legalized in time to bet on those odds?
Corruption seeded long ago. From the (Congressional) Inside (Trader) Out..
Re: (Score:2)
It hasn't paid out yet, he still needs to withdraw it to spend it. FTA: "the operator is waiting for scrutiny to fade, or has no viable way to launder a sum this visible."
Re: (Score:2)
There are more subtle ways to make a compromised RNG. One that can only be cracked by you, not everybody on the planet.
Unsurprising (Score:2)
Crypto kids: Code is Law!
Computer grey hairs: That's a fucking stupid idea.
Re: Unsurprising (Score:3)
What's with the reporting? (Score:2)
We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators.
Why? Isn't bitcoin perfectly self-policing? People should have done their due diligence on how they stored their keys, and if they didn't that is just the invisible hand of the market at work.
I'm so hard right now (Score:1)
This smells like an inside attack (Score:2)
Re: (Score:2)
Except that they would know exactly who committed that change, I don't see that person getting away with it.
This has happened before, Bitcoin isn't safe ! (Score:2)