Bitcoin Wallets at Risk After Critical Coldcard Security Bugs Get Exposed

0
1
Bitcoin Wallets at Risk After Critical Coldcard Security Bugs Get Exposed


Bitcoin self-custody users are being urged to move their funds after Block disclosed two critical vulnerabilities in multiple generations of Coldcard hardware wallets. 

Block’s engineering and security teams started getting reports of Bitcoin being remotely stolen from non-Bitkey wallets and began an investigation. 

It turned out that Coldcard Mk2, Mk3, Mk4, Q, and Mk5 devices have security flaws. That said, the company has clarified that none of its products, including Bitkey, were affected. 

Can XRP Overcome Pressure? Zcash (ZEC) Might Bounce to $500, Did Hyperliquid (HYPE) Lose Its Importance? Crypto Market Review

Crypto Is for Crooks, Dem Senator Says

Over 1,000 BTC potentially exposed to theft 

According to Block, the attack initially targeted single-signature wallets and took place over roughly an hour, but researchers warned the campaign is likely still active. 

The company said wallets protected with weak 25th-word passphrases and some multisignature setups could also be at risk.

The first vulnerability affects the Coldcard Mk2 and Mk3 firmware. In this case, a coding error caused wallet generation to rely on predictable values instead of sufficient hardware-generated randomness. 

You Might Also Like

Title news

For newer Mk4, Q, and Mk5 devices, Block said the firmware attempted to improve entropy during boot using secure-element input. However, a flaw reduced that additional randomness to just 32 bits. 

Simply importing an affected seed into another wallet does not eliminate the threat. The compromised seed remains vulnerable if a wallet was created on vulnerable Coldcard firmware.  

Block said it privately disclosed its findings to Coldcard maker Coinkite and later made the findings public. 

“Personally I recommend that anyone affected move funds as soon as they can safely do so,” Block engineer Max Guise wrote on X. 

What is notable is that the attack may be larger than initially believed. Security engineer Clay Garrett said researchers identified 695 earlier transactions that matched the same on-chain fingerprint. These transactions account for an additional 488.11 BTC.

The total amount potentially stolen would rise to 1,082.59 BTC, according to Block’s preliminary analysis. 



Source link