Bullish
ColdCard Private Key Vulnerability Leads to 1,719 BTC Loss
15:26
Configuration error disabled hardware RNG in ColdCard wallets, enabling private key deduction and resulting in the theft of approximately 1,719 BTC from affected users.
Woofun AI reports that a critical private key vulnerability in ColdCard hardware wallets resulted in the loss of approximately 1,719 BTC. SlowMist's security team reconstructed the attack chain using Mk3 firmware version 4.1.9, identifying the root cause as an incorrect configuration setting 'MICROPY_HW_ENABLE_RNG' to 0. This error disabled the STM32 hardware true random number generator, forcing the system to rely on the non-cryptographically secure Yasmarang software pseudo-random number generator. The predictable output reduced effective entropy to roughly 40 bits for Mk2/Mk3 models and 72 bits for Mk4/Mk5/Q models. Attackers modeled keypress patterns and used GPU clusters for brute-force enumeration to deduce private keys, subsequently draining funds from P2WPKH addresses. SlowMist advises affected users to upgrade to the fixed firmware, generate a new seed phrase, and verify new address functionality before transferring assets.
WOOFUN AI
Impact Assessment · Quick Read
The incident highlights significant risks associated with hardware wallet firmware configurations, particularly regarding random number generation integrity. With 1,719 BTC lost, the breach underscores the importance of cryptographic entropy in cold storage security. Users of ColdCard devices may face heightened scrutiny regarding their firmware versions, potentially impacting trust in the brand. The technical details provided by SlowMist serve as a critical warning for other hardware wallet manufacturers to audit their RNG implementations.
Generated by WOOFUN AI · For reference only, not investment advice
Comments
No comments yet.