Bitcoin Forum
July 31, 2026, 06:16:48 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 5 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1082.65 BTC stolen so far)  (Read 1071 times)
flatfly (OP)
Legendary
*
Online Online

Activity: 1288
Merit: 1208

Joined: 2012


View Profile
July 30, 2026, 08:44:17 PM
Last edit: Today at 03:08:15 PM by flatfly
Merited by theymos (30), pooya87 (30), NotATether (20), OmegaStarScream (10), mprep (10), hosemary (10), d5000 (8), LoyceV (8), bitmover (6), Mitchell (5), BlackHatCoiner (4), philipma1957 (3), ABCbits (2), DdmrDdmr (2), decodx (2), Lucius (1), Welsh (1), tabas (1), nc50lc (1), julerz12 (1), goldkingcoiner (1), AakZaki (1), Zwei (1), Cookdata (1), EL MOHA (1), stwenhao (1)
 #1

https://x.com/Rob1Ham/status/2082896614218203616

[EDIT]

Vendor advisory post:
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Technical deep dive:
https://blog.coinkite.com/entropy-technical-backgrounder/


From Reddit:

Quote
Hoax__

It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.

The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.

Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.

Did you know? Counterparty is still alive! It's the Bitcoin-native DEX with a fascinating history, running with zero downtime since 2014.
Charles-Tim
Legendary
*
Offline

Activity: 2352
Merit: 6465


Leading Crypto Sports Betting & Casino Platform


View Profile
July 30, 2026, 08:53:07 PM
 #2

Have you read about what people are discussing about on this thread? Ill Bloom reports made me remember bx

Who knows if it has something to do with it.

Just use an open source reputed wallet.

Right now not much is known about the exact vulnerability.
So why did you mention Coldcard in the topic title?

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
OmegaStarScream
Staff
Legendary
*
Offline

Activity: 4284
Merit: 7489



View Profile
July 30, 2026, 08:58:06 PM
 #3

So why did you mention Coldcard in the topic title?

Looking at the replies of the tweet, it looks like the post is related to this:

https://x.com/i/status/2082919505819304343
https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/

But nothing is confirmed yet.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
OgNasty
Donator
Legendary
*
Offline

Activity: 5544
Merit: 6432


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
July 30, 2026, 09:09:17 PM
 #4

Very concerning. I’ve never touched a coldcard but I’ve seen them mentioned enough around these forums to where I’m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I’ll have to do some reading up about this one.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
flatfly (OP)
Legendary
*
Online Online

Activity: 1288
Merit: 1208

Joined: 2012


View Profile
July 30, 2026, 09:13:43 PM
Last edit: Today at 10:26:53 AM by flatfly
 #5

True, details are still unclear - I've updated the OP - but there's a growing amount of evidence (on twitter and reddit) seemingly pointing to coldcard.

Did you know? Counterparty is still alive! It's the Bitcoin-native DEX with a fascinating history, running with zero downtime since 2014.
knuckey
Sr. Member
****
Offline

Activity: 1610
Merit: 273



View Profile
July 30, 2026, 09:58:46 PM
 #6

It seems that Coldcard users have not been fully proven to be affected by the Ill Bloom vulnerability, but because there are several users affected, Coldcard's name is dragged, however, anyone who uses Coldcard here, especially those who use it before 2026, must remain vigilant, for the sake of bitcoin security, it is better to move everything to a new wallet until the origin of this theft problem is known.

████
██









██
████



███████████████▄▄███████████████▄███████████████▄█████████████████████████████▄
███████████████████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████▄█████▄█████▄███████▄
███████████████████████████████████████████████████████████████████████████████████████████████████████
███████████████▀▀███████████████▀███████████████▀████████████████████████████████▀█████▀█████▀██████
████
██









██
████
████
██









██
████

🍒
████
██









██
████
████
██









██
████

⚽️
████
██









██
████
████
██









██
████
 
 IIIIIFASTEST GROWING CASINO & SPORTSBOOK  [ Play Now ]
████
██









██
████
Kruw
Sr. Member
****
Offline

Activity: 1190
Merit: 284


Use Bitcoin anonymously - wasabiwallet.io


View Profile WWW
Today at 01:00:18 AM
Merited by mprep (10), BlackHatCoiner (4), philipma1957 (2)
 #7

It seems that Coldcard users have not been fully proven to be affected by the Ill Bloom vulnerability, but because there are several users affected, Coldcard's name is dragged, however, anyone who uses Coldcard here, especially those who use it before 2026, must remain vigilant, for the sake of bitcoin security, it is better to move everything to a new wallet until the origin of this theft problem is known.

Coldcard confirmed the vulnerability: https://x.com/COLDCARDwallet/status/2082961993070247948

Protect your privacy - Coinjoin with Wasabi Wallet
Code:
https://coinjoin.kruw.io/
Rymaster
Member
**
Offline

Activity: 468
Merit: 38

-Squidster-


View Profile
Today at 01:01:04 AM
 #8

It seems that Coldcard users have not been fully proven to be affected by the Ill Bloom vulnerability, but because there are several users affected, Coldcard's name is dragged, however, anyone who uses Coldcard here, especially those who use it before 2026, must remain vigilant, for the sake of bitcoin security, it is better to move everything to a new wallet until the origin of this theft problem is known.

Well it seems even ColdCard is now convinced it is an issue for them, as they have now posted about it on their blog site, Coinkite, and also their subreddit.

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

https://www.reddit.com/r/coldcard/s/M6ZjLrB7yx

Join us over in the Reddit group!  www.reddit.com/r/CryptoCollectibles
rdluffy
Legendary
*
Online Online

Activity: 3038
Merit: 2019



View Profile WWW
Today at 01:05:16 AM
 #9

I also just saw the news on the local website I usually visit
https://livecoins.com.br/usuarios-relatam-perdas-de-us-385-milhoes-em-bitcoin-em-possiveis-ataques-ligados-a-coldcard/

Coldcard has confirmed the vulnerability
I don't know if anyone here is using this wallet (but chances are, yes)

I believe the safest course of action is to move your funds to another wallet as soon as possible
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 9997


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 01:28:38 AM
Last edit: Today at 04:51:08 AM by NotATether
Merited by pooya87 (5), Welsh (3), philipma1957 (1), Zwei (1)
 #10

If you have Coldcard Mk3 with firmware dated after version 4.0.1, I would transfer the funds elsewhere, take a hammer and smash the device.

Edit: smash your Mk2 too

Mk4, Q, and Mk5 seem to be OK according to this tweet

COLDCARD Mk3 Security Advisory

If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.

Mk4, Q and Mk5 are not affected based on our early analysis.

Read the advisory and migrate carefully:

Always generate your seed phrases yourself. Do not use seed phrases generated by hardware wallets under any circumstances.

And always use the BIP39 passphrase. Even if it's just a single extra word.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Kruw
Sr. Member
****
Offline

Activity: 1190
Merit: 284


Use Bitcoin anonymously - wasabiwallet.io


View Profile WWW
Today at 01:36:38 AM
Merited by BlackHatCoiner (4), NotATether (1)
 #11

Mk4, Q, and Mk5 seem to be OK according to this tweet

Other models are partially affected: https://x.com/Nneuman/status/2082977839654093290

Protect your privacy - Coinjoin with Wasabi Wallet
Code:
https://coinjoin.kruw.io/
Meuserna
Sr. Member
****
Offline

Activity: 319
Merit: 488


View Profile WWW
Today at 02:27:47 AM
Merited by mprep (10), theymos (5), LoyceV (4), hosemary (2), Zwei (1), stwenhao (1)
 #12

Always generate your seed phrases yourself. Do not use seed phrases generated by hardware wallets under any circumstances.

And always use the BIP39 passphrase. Even if it's just a single extra word.

This.

When Ledger added internet key extraction to their firmware, it shook me. I stopped using my Ledgers immediately and I spent quite a while coming up with a better solution, which boils down to what you just said.

I generated my seed phrase myself. I did this by printing the BIP85 word list and using scissors to cut it into pieces with 1 word on each piece. I put the pile of paper in a huge popcorn bowl and I pulled out 23 words. Actually I pulled a word, wrote it down, and put the paper back in the bowl... shuffled the paper and picked again. Totally random.

I got a fully open source hardware wallet: Krux (sort of like a SeedSigner) and I entered the words, letting it find the 24th word checksum. For a 24 word seed, there are usually only 7 or 8 possible checksum words for the 24th word, so I felt comfortable letting the device choose the final word for the seed.

I did the same thing to choose a 7 word passphrase. 7 random words. All lowercase with a space between each word. That was how I built my first post-Ledger wallet.

Obviously, the exploit we're all following today has nothing to do with Ledger (presumably). It's a ColdCard issue. But it just reinforces my belief in choosing my own random entropy.

For anybody who doesn't want to go through the hassle of printing and cutting... BTC Hardware Solutions sells what they call Entropia Seed Tablets. They're seed words in a jar:

Quote
Choose 11 or 23 words at random, and then use a bitcoin signing device like SeedSigner to calculate the final checksum word that completes your seed phrase.

Here's a link.

gmaxwell
Staff
Legendary
*
Offline

Activity: 4816
Merit: 11165



View Profile WWW
Today at 05:01:13 AM
Merited by theymos (5), LoyceV (4), philipma1957 (2), hosemary (2), bitmover (2), goldkingcoiner (1), NotATether (1), stwenhao (1)
 #13

Mk4, Q, and Mk5 seem to be OK according to this tweet

This disagrees with my analysis.  I believe the attack is ~32-bits harder on Mk4+ but they're still vulnerable.
crwth
Copper Member
Legendary
*
Offline

Activity: 3570
Merit: 1610


Crypto Casino with No KYC on routine deposits


View Profile
Today at 05:23:28 AM
 #14

Is there an actual or exact failure in what has happened? To correctly do something about it, there should be something definitive to understand the root cause of it.

If somebody has their funds in this method, I feel like migrating them to a newly generated wallet is a safe approach.

▄▄▄▀▀▀▀▀▄▄▄
▄█▀████▄▄▄████▀█▄
▄████▄▄▄▄▄▄▄▄▄████▄
████▄█████▄▄▄█████▄████
██▀▀▀███▄▄█████▄▄███▀▀▀██
█▌█████▀█████████▀███▐█
████████▀█████▀▄██▀████
████▀▄█████▄██████
██▀▄▀▄▐█▌█████████
█████████▐█▌█████████
▀█▄██████▐█▌▄█▀▀▄█▀
▀██▄▄▄▄███▄▄▄▄██▀
▀▀▀█████▀▀▀
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
100
FREE SPINS

 
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
 
  CLAIM BONUS  
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 9997


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 05:34:23 AM
 #15

Mk4, Q, and Mk5 seem to be OK according to this tweet

This disagrees with my analysis.  I believe the attack is ~32-bits harder on Mk4+ but they're still vulnerable.


Yes, you are correct. Someone posted on X about this and I just found it.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
dkbit98
Legendary
*
Offline

Activity: 3038
Merit: 8776



View Profile WWW
Today at 05:38:50 AM
 #16

Surpise, surpise... total collapse of stupid c0ldcard crap and final mental meltdown of NKV nutcase  Cool
Looks like dkbit98 was right once again when I warned everyone to stop using c0oldcard devices.
It's impossible foe egoistic lunatic to create something good, and it is safe to assume that ALL their devices are affected.
This is so bad, and a lesson for everyone who supported this company and their non-open source code.

Quote
Regarding the implications:
- If you generated using dice or wordlist or another method that included non-Coldcard entropy, you are fine.
- If you generated on a non-Coldcard device, you are fine.
- If not, your funds are at risk. A passphrase will help slow it down but the main seed is still compromised.
https://nostr.at/nevent1qqsxt6lahxeq8h69ne78w6ls394ez5pqycguwrsp89tacwteh7878ccpp4mhxue69uhkummn9ekx7mqpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgq3q2262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7sl2jl2z

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
Outhue
Hero Member
*****
Offline

Activity: 1638
Merit: 677



View Profile WWW
Today at 05:39:49 AM
Last edit: Today at 07:52:03 AM by Outhue
 #17

If you have Coldcard Mk3 with firmware dated after version 4.0.1, I would transfer the funds elsewhere, take a hammer and smash the device.

Edit: smash your Mk2 too

Mk4, Q, and Mk5 seem to be OK according to this tweet

COLDCARD Mk3 Security Advisory

If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.

Mk4, Q and Mk5 are not affected based on our early analysis.

Read the advisory and migrate carefully:

Always generate your seed phrases yourself. Do not use seed phrases generated by hardware wallets under any circumstances.

And always use the BIP39 passphrase. Even if it's just a single extra word.

Haa! NotATether. You must have some explanation to make about this comment, like what do you mean by saying people should not use their hardware wallet to generate seed phrases? This is the first time I would ever heard such, I've been using my seed phrases that was generated with an airgapped hardware wallet, how is this not safe?

I am using Keystone 3 to be precise and what you just said scares the shit out of me, I have no bitcoin elsewhere than in my Keystone and it's been over 4 years of usage already, can you be more clearing about what you are trying to teach us with this statement of yours? I've never ever heard this before, this is scary.

Meuserna
Sr. Member
****
Offline

Activity: 319
Merit: 488


View Profile WWW
Today at 05:42:27 AM
Merited by bitmover (3)
 #18

Mk4, Q, and Mk5 seem to be OK according to this tweet

This disagrees with my analysis.  I believe the attack is ~32-bits harder on Mk4+ but they're still vulnerable.


I agree. Absolutely.

It's very likely the hackers spent months pulling off this attack. Maybe even longer. I can't even imagine how many billions of seed phrases they searched, but it isn't nearly as hard as people think to do so if - and this is the point - if an exploit limits the number of wallets to search, which is surely the case in this instance.

They probably searched for months and built up a pool of wallets to hit. Then, they wiped them all out at once in order to prevent anyone from figuring out where the vulnerability was until it's too late.

I have to assume this isn't the last attack like this we'll see.

Four things I assume. Two good, two bad:

1. I assume wallets that use a passphrase are safe from these attacks because seed-phrase-hunters have no way of knowing a seed phrase generating an empty wallet has coins in a wallet using that seed with a passphrase.

2. I assume multisig wallets are safe for the same reason. Seed-phrase-hunters have no way of knowing a seed phrase generating an empty wallet has coins in a wallet generated using multiple seeds.

3. I assume it's only a matter of time before Ledger's key extraction scheme gets hacked, presumably at the firmware level. That'll be a much more difficult hack to pull off, but it'll be much worse than this ColdCard hack because Ledger is a huge honeypot.

4. I assume it's only a matter of time before exploits are found for smaller commercial wallets, leading to similar thefts.

Now, more than ever, I think it's time for people to start thinking about how to do self custody right. Generate your own random seed phrases. It's not hard, but do it right. Use a passphrase or do multisig. Learn how to document your wallet setup and store that documentation securely.

Too many people in Bitcoin are chasing brand-name cool-factor. "Yo, bro! You seen the new [insert brand-name hardware wallet here]? They're the sh!t bro!" Those people are idiots who should be buying an ETF instead because they're not ready to take self custody seriously.

I hate saying it like that... but even on a forum like this, it's shocking how many people don't take self custody seriously. They get caught up in fanboyism for brands and gadgets. And they set themselves up for disaster.

gmaxwell
Staff
Legendary
*
Offline

Activity: 4816
Merit: 11165



View Profile WWW
Today at 05:53:52 AM
Last edit: Today at 07:28:12 AM by gmaxwell
Merited by pooya87 (30), hosemary (12), theymos (10), mprep (10), ABCbits (8), LoyceV (6), BlackHatCoiner (4), philipma1957 (3), Pmalek (3), crwth (1), Zwei (1), stwenhao (1)
 #19

Is there an actual or exact failure in what has happened? To correctly do something about it, there should be something definitive to understand the root cause of it.

The coldcard source code attempts to disable the hardware RNG support in micropython because they provide their own implementation, but the handling of the the disable flag is inconsistent.

To disable it they #define MICROPY_HW_ENABLE_RNG (0)   and this successfully disables it.

But to enable their replacement they check #ifndef MICROPY_HW_ENABLE_RNG   ---   and this is ineffective because the if(n)def directive checks only if the flag MICROPY_HW_ENABLE_RNG is defined, its value "(0)" is irrelevant and counts as defined just as any other value would.  Probably any sufficiently long-expirenced C programmer has encountered a form of this #if vs #ifdef confusion.

This inconsistency makes the coldcard firmware not use its own HWRNG support code but instead call the micropython random function.  But the micropython function has its hardware support disabled and when it is disabled it replaces it with a placebo insecure PRNG function which is seeded with part of the devices hardware id and a timer.  "Micropython: We've replaced this users randomness with Folgers Crystals, lets see if they notice".

The replacement function *looks* like good random numbers... but they're not random at all, and provide essentially no security.  However, if you were to try to judge their quality with tools like diehard you would probably get a result that they were high quality -- this the reason RNGs are such a risky part: the quality of a random stream depends on how it was created and can't be detected purely from the random values itself.

So for mk3 the attacker just needs to search the likely hwids and timer values for wallets.

For mk4+ the not-random random value from above gets xored with another instance of the same placebo function (more Folgers Crystals), initialized with a 32-bit presumably secure random value that ultimately comes from another chip inside the wallet.  The 32-bits of extra security is not enough to make it secure, but it may delay attacks by speak-and-spell wielding toddlers.

The use of "fallback" and no-security providing PRNG "whiteners" is a practice that some people have previously identified as risky due to the risk of accidentally hiding more serious bugs.  Unfortunately both the authors of micropython and coldcard itself engaged in this particular sin, and fixing either one alone wouldn't have made the error immediately obvious.  I wouldn't say that belt-and-suspenders like these are unconditionally bad, but incredible care must be taken to be sure that they aren't covering up other issues.

Take my analysis with a grain of salt: it's purely a product of personally reading the source code.  I do understand that expert AI users also independently reached the same conclusion including with validation against a disassembled firmware image, which is why I feel confident enough sharing it.

Edit: This post is also consistent with the new coldcard blogpost: https://blog.coinkite.com/entropy-technical-backgrounder/
flatfly (OP)
Legendary
*
Online Online

Activity: 1288
Merit: 1208

Joined: 2012


View Profile
Today at 06:10:25 AM
 #20

https://x.com/clay_garrett/status/2082980440525132245

clay_garrett:
Quote
There are 695 earlier transactions with the same full fingerprint that transactions in the known set had. These transactions moved another 488.10957948 BTC. If this is part of the same attack, it’d bring the total to 1,082.58680432 BTC.

[...]

We scanned all 888,661 transactions in blocks 960050–960230. Each match in the original wave had these shared properties: version 2, locktime 0, final sequence on every input, one output and inputs from one source address, a P2WPKH destination, one homogeneous supported input type and a 30 sat/vB pre-signing fee estimate.

Did you know? Counterparty is still alive! It's the Bitcoin-native DEX with a fascinating history, running with zero downtime since 2014.
Pages: [1] 2 3 4 5 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!