Coldcard Firmware RNG Flaw Tied to $88.6M BTC Theft; Users Told to Migrate Seeds

AI مارکیٹ کا خلاصہ
On-chain research links an estimated 1,367 BTC ($88.6M) theft to weak seeds generated by vulnerable Coldcard firmware that used a deterministic RNG fallback. Users are urged to migrate funds to new, freshly generated seeds on patched firmware, as fixes cannot restore entropy to old seeds. The incident may pressure near-term sentiment around self-custody security, while underscoring that Bitcoin's protocol was not compromised.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-1.22%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Coldcard hardware-wallet users were put on high alert Aug. 1 after on-chain investigators linked multiple theft waves to wallet seeds generated by vulnerable Coldcard firmware. Dogecoin contributor Mishaboar urged anyone who has ever used a Coldcard to "migrate your funds to a new wallet immediately," warning users not to reuse the old seed and never to enter recovery words on an internet-connected computer. Galaxy Research said its latest on-chain review points to three suspected attack waves that collectively moved 1,367.05 BTC (about $88.6 million) from 4,585 addresses. Galaxy stressed the total is an observed on-chain estimate and has not been confirmed by Coinkite, law enforcement, or all affected users. The largest wave drained 1,082.65 BTC from 1,196 addresses in roughly 41 minutes on July 30. A subsequent wave swept about 208 BTC from 1,912 addresses; the average balance per address fell to just over 0.1 BTC, suggesting a shift from larger targets to many smaller wallets. Galaxy said each wave appears consistent with a single operator, though it cannot prove the same actor ran all of them. The third wave showed different collection behavior, including separate destination addresses, batching multiple victims into single transactions, and checking only the default derivation path. Galaxy also cautioned that its identified patterns will not capture every theft, since attackers could construct valid transactions without repeating the same fees, destination formats, or collection methods. Coinkite's advisory says the issue is limited to seeds created on: - Mk2 and Mk3 devices running firmware v4.0.1 through v4.1.9 - Mk4 and Mk5 devices with firmware earlier than standard v5.6.0 or Edge v6.6.0X - Coldcard Q, fixed in standard v1.5.0Q and Edge v6.6.0QX Mk1 devices are outside the identified firmware regression. Coinkite said TAPSIGNER, OPENDIME and SATSCARD are unaffected because they rely on different codebases. The company said its investigation is ongoing and that it will publish a formal technical report. Block's Bitcoin engineering and security team attributed the problem to a firmware integration error: when generating seeds, affected builds used a deterministic MicroPython fallback instead of the STM32 hardware random-number generator. On Mk2 and Mk3 v4 firmware, this fallback added essentially no cryptographic entropy. Later models received a limited secure-element reseed, but seeds created earlier remained weak. Block said this reflects its current technical assessment and that it has not empirically tested every device. Coinkite and researchers recommend users take the following steps: - Do not reuse any old Coldcard seed. - Generate a completely new seed on a patched Coldcard or a different wallet. - Install Coinkite's fixed firmware for your model before creating any replacement seed. - Record and verify the new backup, confirm the receiving address on the device screen, and send a small test transaction first. - Move the remaining balance only after the test funds arrive. - Keep the old backup until the full migration is confirmed. - Never type a seed phrase on an internet-connected computer; store offline copies in separate secure locations to reduce exposure to phishing, malware, and cloud-sync mistakes. Mishaboar also pointed to the added protection of a BIP-39 passphrase (the Coldcard "25th/13th word") and strong passphrases. Coinkite noted a passphrase cannot "fix" a seed that is already compromised, and short or reused passphrases still carry risk. Coinkite said a narrow exception may apply to users who added at least 50 fair, independent, private dice rolls before the final seed words were produced, contributing at least 128 bits of independent entropy. Users who entered fewer than 50 rolls, can't recall the number, or exposed the roll sequence are advised to migrate. Firmware patches protect future seed generation but cannot retroactively add entropy to seeds that were already created, and importing a weak seed into another wallet preserves the weakness. Bitcoin investor Anthony Pompliano said the incident underscores how technically demanding secure self-custody can be, while noting the Bitcoin protocol itself was not compromised because attackers reproduced private keys rather than exploiting the network. The losses have also renewed debate about institutional custody and spot-Bitcoin ETFs for investors who prefer not to manage private keys directly. Coinkite has released firmware fixes for affected models and continues investigating. Galaxy and other researchers may update address tracking as additional victims are identified. Until inquiries conclude, the $88.6 million figure remains an on-chain estimate rather than a confirmed total. Coldcard owners are advised to consult Coinkite's official model-specific advisory and update firmware before generating any new seed.