Everyone Panic! ColdCard Bitcoin-only wallet HACKED!
I really should have written this right when it happened: my bad
Coldcard's Bitcoin-only wallet got cracked by (presumably) an exploit detected by AI a couple days ago. Apparently the old firmware in the MK2 MK3 versions had piss poor entropy (randomness). Instead of being 128 bit security it was something like 32 bit, which is very easy to brute force with modern technology. This is a colossal fuckup of epic magnitude coming from a cold storage solution that has been touted as one of the best options for years by hardcore Bitcoiners.
My Crypto Twitter feed is basically just filled with people talking about this issue, freaking out, and taking a break from the tired BIP-110 talking points. Because it's such a niche echo-chamber being affected many of these hardcore Bitcoiners feel as though this is an apocalyptic moment even though only 600 BTC were stolen in the first wave. The total amount stolen is estimated around 1000 BTC, perhaps a bit more but it's hard to tell because Bitcoin isn't actually as easy to track as most people assume. In fact the initial attack itself may have gone unnoticed for a long time if the attacker hadn't consolidated all the stolen funds (600 BTC) into a single wallet.
It's honestly kind of insane that an exploit like this could ever exist in the first place. Basically anyone who didn't use multisig or do dice rolls to create a seed is vulnerable to this weakness. Coldcards are pretty expensive as well. I bought a Coldcard Q for like $200. And while I'm hearing rumors that MK4/MK5 and Q all have lower entropy than they should have... it doesn't matter much to me because I NEVER use RNG (random number generation) on the devices that I buy. This is a hard lesson and reminder that just because you buy a hardware wallet doesn't mean everything is safe. You still have to trust the creator of the wallet. This is something I've discussed at length in the past.
How did this happen?
Apparently Coinkite (the company that makes Coldcard product) decided they weren't going to use the open-source standard technology for their security. Why they would ever do such a thing is quite frankly beyond me but there are stories coming out about what exactly happened there, and I find it all a bit weird. As with anything, many are accusing this of being an inside job. I don't think it is but I certainly understand why people would voice that theory considering these circumstances.
https://x.com/Truthcoin/status/2083211545148858624
Is this a bottom signal?
I would have expected price to decline a bit more than 2% on this news. If something like this happened 6 months ago I'm fairly certain there would have been a flash crash something fierce. It somewhat reminds me of the FTX collapse where it seemed like a cataclysmic world-ending event but the price only went down 20% for a month.
At the same time a hack like this exposed very little Bitcoin on the grand scale of things. Whereas to those affected it seems like a failure of decentralization, the actual truth of the matter is the opposite. There are many hardware wallet providers and only one small company was affected by this. Ironically, if that company had just used the code that all the other companies use... there would have been no problem.
Loss of trust
Seeing as we are at the tail end of a bear market the demoralization of an event like this hits very hard. Many hardcore Bitcoiners saying they are thinking about cashing out and giving up (or just giving up if they were one of the victims). After something like this happens many come out of the woodwork saying it's safer to put your money into Coinbase or Blackrock, which is obviously not true. A hack like this could happen 10 times in a row and it would still be less devastating than a big exchange hack. Thus proving once again that people really have the memory of a goldfish and only think about the last event that happened in order to make long-term strategies for the future.
Other more rational people point out that hardware wallets are probably going to become a lot more secure in a short amount of time because all of them are likely racing to audit all their code after something like this happens. The emotional tilt that comes with losing money is going to make people do stupid things as is always the case.
Conclusion
I will probably continue to use my Coldcard because it's airgapped and the only way my private key could get leaked to an attacker is if the data was purposefully fed through the QR code to the internet. Seems unlikely, but again people are very irrational about this situation and don't really want anything to do with the company ever again. Personally I can't blame them.
Leave Everyone Panic! ColdCard Bitcoin-only wallet HACKED! to:
Read more #bitcion posts
Best Posts From edicted
We have not curated any of edicted's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.
More Posts From edicted
- Everyone Panic! ColdCard Bitcoin-only wallet HACKED!
- Bitcoin Uptrend: Summer Relief Rally
- USV: Max Achievement Scholarship
- How Long Till BTC Hardforks?
- The $58k Grind Appears on Radar
- Bitcoin Chain Split and Potential Airdrop Draw Closer
- Lingering Quantum Threat Lingers
- Dealing with Tragedy and Loss
- Did you sell in May, Anon?
- Scrutiny Layer?