#Coldcard助記詞缺陷致BTC被盜

賽道趨勢narrativeLIVE 即時同步

Coldcard Mk3因助記詞生成缺陷導致594枚BTC被盜,引發安全恐慌。

相關文章5
KOL 觀點6
關鍵事件1
#Coldcard助記詞缺陷致BTC被盜 資訊
即時同步
顯示 5 條資訊
KOL 觀點
WU
Wu Blockchain
1 天前
中立
Coldcard issues Mk3 seed warning after 594 BTC theft raises security concerns Coinkite warned that wallets created on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 may be at risk due to a seed generation flaw. Users are advised to migrate funds immediately. The warning comes as investigators continue probing the recent theft of 594 BTC from hundreds of single-signature wallets, though no evidence has confirmed a link between the two incidents.
6009
EV
evankaloudis
1 天前
中立
TL;DR on the Coldcard vulnerability: If you didn't provide the entropy for your seed (didn't roll a dice 100+ times and/or add a solid '25th-word' passphrase) you need to be moving your funds ASAP. The MK3 is most vulnerable, but the MK4, MK5, and Q are also affected.
4908
NU
nunchuk_io
1 天前
中立
Coldcard Mk3 users: if your seed was generated on-device (firmware 4.0.1+, ~2021 onward) without dice rolls or a passphrase, your funds may be at risk. Migrate ASAP. Multisig users are protected by design: even a fully compromised key can’t move funds on its own. This is exactly the failure mode multisig exists for. No emergency migration needed, just rotate the affected Mk3 key at your convenience.
66012
UN
Unchained
1 天前
中立
Coldcard has disclosed a vulnerability in how their devices generate random numbers for seeds, and outside researchers have corroborated the issue. While the issue originated in Coldcard’s firmware and not Unchained tech stack, at this time, and out of an abundance of caution, our recommendation is to rotate any Coldcard-generated key to a key generated on a different device. This issue is most severe if you use two Coldcard-generated keys for your Unchained 2-of-3 multisig vault. Within any standard 2-of-3 configuration, if only one key is compromised, funds are generally considered safe. However, clients should still replace their key as soon as practicable. Moving too quickly or panicking can lead to mistakes. Scammers target people who are fearful. When communicating with our team, always verify your Unchained representative using Support PINs: https://t.co/stNEGfqfWA
194045
QU
Quit
1 天前
中立
Today it appears that the entropy (or lack thereof) behind Cold Card seed generation was exploited. The tl;dr is that bad randomness in Mk3 seed generation for Cold Card hardware wallets led cluster of roughly 594 BTC being swept from about 500 addresses in a short window. Coinkite warns that seeds generated on Mk3 firmware 4.0.1 through 5.0.3 may be at risk. However there's evidence that Mk4, Q, and Mk5 could also be affected, though would require much more compute. The proposed mechanism is: 1. The Mk3’s seed-generation path produced insufficiently unpredictable entropy for some setups. 2. Instead of a truly 128/256-bit secret, the output may have been drawn from a much smaller or structured state space. 3. An attacker can reproduce the candidate seeds offline, derive standard BIP-32/BIP-44 address paths, and scan the blockchain for funded matches. 4. Once a candidate matches a known address, the attacker has the corresponding private key and can sweep it. The device PIN, air gap, and secure element do not help at that point. no reason to believe that Ledger, GridPlus, or Trezor devices share similar shortcomings, but this DOES highlight something: trust is everywhere in crypto. We want things to be trustless, but you have to trust that: - your exchange won't ban you - your wallet software won't act maliciously - your hardware wallet firmware won't export your private keys to the feds - your seed is generated with sufficient entropy It seems like nothing is safe. At this point I have to recommend multi-device multisigs for anything of significant value to you. Generate at least two seeds using at least two different vendors (say GridPlus and Ledger) and then configure a multisig using wallets from each seed. Write the seeds only on paper, split them via shamir secret sharing and distribute them geographically, among family etc. Or just give up the dream and buy crypto ETFs.
365044
CO
Cointelegraph
1 天前
中立
🚨 ALERT: Coinkite warns that funds on Coldcard Mk3 devices running firmware from 4.0.1 through 5.0.3 may be at risk. Users are urged to migrate to an unaffected model or set a BIP-39 passphrase immediately. https://t.co/1Qd1dhYctf
75014
研究報告
暫無資料
關鍵事件時間線
2026-07-31
Coldcard Mk3助記詞缺陷致594枚BTC被盜
週五凌晨,Coldcard Mk3等硬件錢包因固件熵值生成缺陷,導致594.48枚BTC在25分鐘內被盜。Coinkite緊急警告用戶私鑰可被預測,建議立即遷移資產。該漏洞波及Mk2至Mk5等多款型號,引發市場恐慌,專家推薦改用BIP-39密碼短語避險。

評論

回覆 @用戶
0/800

暫無評論

消息提醒

登入後查看消息
查看全部消息管理訂閱