Exploit Discovered in Bitcoin's "Safest Vault" Leaves Users Ransacked

Deep News08-03 19:28

Criminals have identified a flaw in a Bitcoin "cold wallet" software program, a type of storage once deemed the most secure method for holding cryptocurrency. Attackers are now using this vulnerability to continuously drain wallets, stealing tens of millions of dollars in digital assets.

Canadian firm Coinkite Inc. alerted users of its Coldcard hardware wallet over the weekend that a security flaw in the key generation process protecting their Bitcoin had been compromised, affecting some wallets. Data from Galaxy Research shows that, as of Monday, attackers had siphoned over 1,755 Bitcoin from approximately 5,000 wallets, valued at roughly $110 million at current market prices.

The Coldcard is a hardware device that allows users to store their Bitcoin in a "cold wallet," which is disconnected from the internet. This isolation has long been considered the gold standard for cryptocurrency security.

However, a report from Block Inc.’s engineering team revealed a defect in the Coldcard device's software, leading to the creation of "seed phrases" that were predictable. These seed phrases are a set of words used to recover and access a wallet.

Aneirin Flynn, CEO of cybersecurity firm Failsafe, commented, "This exposes a fallacy – that many people think offline cryptocurrency storage is absolutely safe. In reality, the hardware wallet is just generating your keys. If the underlying algorithm is flawed, attackers can work backward to deduce those keys."

Initially, some users were in disbelief that they could be affected. Jonathan Goodman, one of the victims, said he thought his wallet would be safe but decided to check anyway.

"The moment the wallet loaded, I knew it was over," he stated. "The screen was filled with red transaction records. Between 9:36 PM and 9:43 PM on July 29, all assets from my three wallets were transferred out."

According to Block, the core issue stemmed from Coinkite's implementation of a random number generator when creating seed phrases. True randomness is critical for cryptographic security, but the Coldcard wallet had a backup mechanism that used deterministic values, such as the device's serial number, to generate keys under certain conditions.

This allowed attackers to systematically calculate users' wallet keys and transfer all assets out. A report from last Friday estimated the losses at around $38 million, a figure that escalated rapidly over the weekend.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Comments

We need your insight to fill this gap
Leave a comment