Coldcard Flaw Puts $116 Million in Bitcoin at Risk
Major Flaw in Coldcard Wallet Puts $116 Million in Bitcoin at Risk
A significant security flaw in the Coldcard hardware wallet has potentially exposed $116 million in Bitcoin to theft, renewing concerns over the self-custody of cryptocurrency. This revelation comes from Bobby Gray, the founder of TEXITcoin, who highlighted that a seed-generation failure left approximately 1,816 BTC vulnerable.
Details of the Security Flaw
The issue stemmed from a firmware error in Coldcard hardware wallets, specifically allowing some devices to generate seed phrases with only about 40 bits of entropy instead of the expected 128 bits. This drastic reduction in randomness significantly lowered the security of the seed phrases, making it easier for attackers to target and exploit affected wallets without needing physical access to the devices.
Scope of the Attack
According to reports, over 5,200 addresses were impacted, leading to substantial losses that began surfacing on July 30, 2023. TRM Labs conducted an on-chain analysis and confirmed the estimated loss associated with this exploit. Their investigation indicated that attackers were able to reconstruct the private keys associated with vulnerable wallets without any direct intervention on the hardware.
Coldcard’s Response
In response to this serious vulnerability, Coinkite, the manufacturer of Coldcard, has released patched firmware versions. Users are advised to completely migrate their wallets to new seeds because simply updating the firmware does not rectify the existing flaws in previously generated seeds. This migration involves verifying the integrity of new seeds and conducting small test transactions to ensure security.
Self-Custody Vs. Centralized Custody Debate
Despite the losses, Gray expressed that self-custody itself did not fail; rather, it was the blind trust in the wallet’s ability to generate secure seeds that led to these issues. He remarked, “Blind trust is what failed here, and self-custody is taking the blame it doesn’t deserve.” He emphasized the importance for users to independently verify the methods used in generating their keys, rather than solely relying on advertised security features.
Market Dynamics Post-Incident
Following the disclosure of the Coldcard flaw, there has been a noticeable shift in user behavior. OKX reported record inflows as some cryptocurrency holders opted to transfer their assets from personal wallets to centralized services, illustrating a shift toward custodial solutions, despite the potential risks inherent in those platforms as noted by Gray.
The Way Forward for Affected Users
Users concerned about their Coldcard wallets are encouraged to replace vulnerable seeds by generating new, secure ones through the upgraded firmware. Coinkite’s advisory details the steps needed to ensure funds are safely transferred to a new secure seed, which must be conducted meticulously to avoid additional risks.
This incident serves as a critical reminder of the necessity for vigilance and proactive security measures in managing cryptocurrency assets, particularly for those opting for self-custody solutions.
Source: crypto.news