#Coldcard助记词缺陷致BTC被盗

赛道趋势narrativeLIVE 实时同步

Coldcard Mk3因助记词生成缺陷导致594枚BTC被盗,引发安全恐慌。

相关文章6
KOL 观点7
关键事件2
#Coldcard助记词缺陷致BTC被盗 资讯
实时同步
资讯

1000枚BTC被盗:Coldcard密钥漏洞致7000万美元损失

Galaxy Research披露Coldcard因密钥生成缺陷遭长期攻击,超1200地址失守,1000枚BTC被盗。尽管已发布补丁,但7000万美元损失警示硬件钱包并非绝对安全,用户需立即升级固件并审视多签方案。

WOOFUN Research11 小时前243资讯
资讯

Coldcard种子缺陷曝光:按下按钮即可重置私钥

Coinkite警告Coldcard Mk3/Mk4/Mk5/Q系列种子生成存在缺陷,受固件版本限制,用户需迁移资金以规避私钥泄露风险。

WOOFUN Research1 天前69资讯
资讯

594枚BTC被盗警示:Blockstream澄清Jade安全

Blockstream确认Jade系列未受RNG漏洞波及,区别于Coldcard 594枚BTC被盗案。公司强调技术差异,建议用户遵循最佳实践转移资产,并重申开源透明原则以应对LLM辅助检测的新常态。

WOOFUN Research1 天前55资讯
资讯

594枚BTC神秘流出,Coldcard熵值缺陷引恐慌

Coinkite警告Mk3设备固件存在熵值生成缺陷,导致约594枚比特币被转走。专家建议采用BIP-39密码短语或骰子投掷法临时避险,切勿轻信第三方检测工具。

WOOFUN Research1 天前28资讯
资讯

25分钟盗594枚BTC,私钥生成机制存致命缺陷

周五凌晨,约594枚比特币因Coldcard硬件钱包固件漏洞在25分钟内被盗。调查揭示其随机数生成器被绕过,导致私钥可被预测,影响Mk3等旧型号及纸质钱包。

WOOFUN Research1 天前118资讯
资讯

Coldcard种子漏洞波及5款型号,盗窃风险极高

Bitkey负责人警告Coldcard Mk2至Mk5等多款硬件钱包存在种子生成缺陷,风险涵盖多签架构,建议用户通过官方渠道获取指引并加强安全审计。

WOOFUN Research1 天前36资讯
显示 6 条资讯
KOL 观点
WU
Wu Blockchain
1 天前
中立
Coldcard issues Mk3 seed warning after 594 BTC theft raises security concerns Coinkite warned that wallets created on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 may be at risk due to a seed generation flaw. Users are advised to migrate funds immediately. The warning comes as investigators continue probing the recent theft of 594 BTC from hundreds of single-signature wallets, though no evidence has confirmed a link between the two incidents.
6009
UN
Unchained
1 天前
中立
Coldcard has disclosed a vulnerability in how their devices generate random numbers for seeds, and outside researchers have corroborated the issue. While the issue originated in Coldcard’s firmware and not Unchained tech stack, at this time, and out of an abundance of caution, our recommendation is to rotate any Coldcard-generated key to a key generated on a different device. This issue is most severe if you use two Coldcard-generated keys for your Unchained 2-of-3 multisig vault. Within any standard 2-of-3 configuration, if only one key is compromised, funds are generally considered safe. However, clients should still replace their key as soon as practicable. Moving too quickly or panicking can lead to mistakes. Scammers target people who are fearful. When communicating with our team, always verify your Unchained representative using Support PINs: https://t.co/stNEGfqfWA
194045
CA
callebtc
1 天前
中立
This is worse than any previous Bitcoin exchange hack. It is arguably one of the worst things that could happen. The popular hardware wallet COLDCARD has a faulty random number generator (RNG). Funds are being drained from ordinary users’ hardware wallets as you read this. Users first reported to Block less than 24 hours ago that funds were moving out of their wallets. The exploit was most likely discovered with the help of AI. Block has confirmed that the RNG is broken. You know what that means. There are likely already multiple attackers competing for the affected BTC. Many more will join very soon. Nobody knows how much BTC is affected. Nobody knows how many users are affected. This attack has only just begun, and it will continue until all affected BTC has been drained unless users secure their funds first. Inevitably, many Bitcoiners will not hear about the incident early enough to respond in time. I am truly saddened for everyone affected, especially those who may have just lost their life savings. The worst part is that they did everything right.
3.0K0414
QU
Quit
1 天前
中立
Today it appears that the entropy (or lack thereof) behind Cold Card seed generation was exploited. The tl;dr is that bad randomness in Mk3 seed generation for Cold Card hardware wallets led cluster of roughly 594 BTC being swept from about 500 addresses in a short window. Coinkite warns that seeds generated on Mk3 firmware 4.0.1 through 5.0.3 may be at risk. However there's evidence that Mk4, Q, and Mk5 could also be affected, though would require much more compute. The proposed mechanism is: 1. The Mk3’s seed-generation path produced insufficiently unpredictable entropy for some setups. 2. Instead of a truly 128/256-bit secret, the output may have been drawn from a much smaller or structured state space. 3. An attacker can reproduce the candidate seeds offline, derive standard BIP-32/BIP-44 address paths, and scan the blockchain for funded matches. 4. Once a candidate matches a known address, the attacker has the corresponding private key and can sweep it. The device PIN, air gap, and secure element do not help at that point. no reason to believe that Ledger, GridPlus, or Trezor devices share similar shortcomings, but this DOES highlight something: trust is everywhere in crypto. We want things to be trustless, but you have to trust that: - your exchange won't ban you - your wallet software won't act maliciously - your hardware wallet firmware won't export your private keys to the feds - your seed is generated with sufficient entropy It seems like nothing is safe. At this point I have to recommend multi-device multisigs for anything of significant value to you. Generate at least two seeds using at least two different vendors (say GridPlus and Ledger) and then configure a multisig using wallets from each seed. Write the seeds only on paper, split them via shamir secret sharing and distribute them geographically, among family etc. Or just give up the dream and buy crypto ETFs.
365044
AS
Ash Crypto
1 天前
中立
THIS IS INSANE. $40,000,000 in $BTC was stolen because of the Coldcard wallet vulnerability. The attacker exploited a flaw in Coldcard's key generation and stole these funds within 25 minutes. Even cold wallets aren't safe now. https://t.co/vULxlMzJ26
1.5K0220
EV
evankaloudis
1 天前
中立
TL;DR on the Coldcard vulnerability: If you didn't provide the entropy for your seed (didn't roll a dice 100+ times and/or add a solid '25th-word' passphrase) you need to be moving your funds ASAP. The MK3 is most vulnerable, but the MK4, MK5, and Q are also affected.
4908
CO
Cointelegraph
1 天前
中立
🚨 ALERT: Coinkite warns that funds on Coldcard Mk3 devices running firmware from 4.0.1 through 5.0.3 may be at risk. Users are urged to migrate to an unaffected model or set a BIP-39 passphrase immediately. https://t.co/1Qd1dhYctf
75014
研究报告
暂无数据
关键事件时间线
2026-08-01
Coldcard漏洞致超 7000 万美元比特币损失
Galaxy Research披露Coldcard因密钥生成缺陷遭长期攻击,导致超1200个地址失守。此次事件造成约1000枚BTC被盗,总损失高达7000万美元。Coinkite已承认全责并发布紧急固件更新,但巨额损失警示硬件钱包并非绝对安全,用户需立即升级并审视多签方案。
2026-07-31
Coldcard Mk3助记词缺陷致594枚BTC被盗
周五凌晨,Coldcard Mk3等硬件钱包因固件熵值生成缺陷,导致594.48枚BTC在25分钟内被盗。Coinkite紧急警告用户私钥可被预测,建议立即迁移资产。该漏洞波及Mk2至Mk5等多款型号,引发市场恐慌,专家推荐改用BIP-39密码短语避险。

评论

回复 @用户
0/800

暂无评论

消息提醒

登录后查看消息
查看全部消息管理订阅