GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Galaxy Research Head: Coldcard attack ongoing, will update affected address count statistics

Odaily News, Galaxy Research Head Alex Thorn posted on X platform, stating that the attack targeting wallet addresses with weak random numbers generated by Coldcard is still ongoing. Users who still hold funds in Coldcard single-signature wallets should immediately migrate to secure addresses. New victim addresses and attacker addresses are continuously being added to the investigation database, and Galaxy Research plans to release updated statistics on the number of affected addresses.He noted that the previously identified waves 1, 2, and 3 of the attack exhibit clear programmatic characteristics, and the stolen BTC currently remains in the attacker's addresses without any transfers. However, in recent times, smaller-scale attackers have begun exploiting the vulnerability to steal funds and move them through peeling chains, cross-chain services, and other methods. It is certain that single-signature wallet addresses generated by Coldcard after the March 2021 firmware upgrade are all potentially at risk, and users should migrate funds as soon as possible.Previously reported, Galaxy Research has disclosed that the Coldcard vulnerability attack has affected approximately 1,367.05 BTC (approximately $88.6 million), involving around 4,585 addresses.

Galaxy Research: Approximately 600 Suspected Coldcard Attacker Addresses Submitted

Galaxy Research stated in a post on X that the attack targeting wallet addresses generated with weak randomness by Coldcard is still ongoing. The team urges users to immediately migrate funds from affected Coldcard single-signature wallets to secure addresses.They stated that approximately 600 suspected attacker addresses have been submitted to federal investigators, industry compliance bodies, and cross-industry cybersecurity investigators. These addresses are believed to hold funds stolen from Coldcard wallets with weak randomness.The team also noted that victims have proactively shared wallet addresses and transaction hashes, helping researchers establish on-chain attack patterns and further identify more affected wallets and attack addresses. Currently, multiple parties within the Bitcoin and crypto industry are assisting in user asset protection and attack tracing efforts.Galaxy Research previously stated in a post on X that a third wave of attacks suspected to target Coldcard-generated addresses has emerged, with 207.7294 BTC already transferred out. According to on-chain tracking data, the Coldcard wallet attack incident has so far involved approximately 1,367.05 BTC, valued at approximately $88.6 million, affecting 4,585 addresses.

COLDCARD vulnerability may have originated from compiler bypass handling

Odaily News: Bitcoin News posted on X platform that a new technical analysis by Core-Lightning developer ddustin shows that the 2021 COLDCARD vulnerability may have originated when developers attempted to connect the wallet using Python code, MicroPython's C code, and the STM32 hardware random number generator. The custom code appears to have conflicted with MicroPython's existing implementation, potentially triggering a compiler error. Evidence suggests that developers subsequently set MICROPY_HW_ENABLE_RNG to 0, allowing the firmware to compile successfully. This change led to unintended consequences: when users created new wallets, the firmware no longer used the hardware random number generator, instead falling back to MicroPython's weaker Yasmarang software random number generator. The commit message left by the developers was only "runs." The analysis states that this serves as a reminder to developers not to release security-critical code they do not fully understand, especially when it protects billions of dollars in Bitcoin.

Galaxy Research: ColdCard Wallet Hacker Attack Scale Continues to Expand, Three Waves of Attacks Stole a Total of Approximately $88.6 Million Worth of BTC

According to monitoring by on-chain analysis firm Galaxy Research (@glxyresearch), the ColdCard wallet hacking incident has developed into a third wave, with an additional 207.73 BTC stolen. Currently, the three waves of attacks have cumulatively stolen 1,367.05 BTC (approximately $88.6 million), involving 4,585 addresses. On-chain data shows that the three waves of attacks exhibit highly similar characteristics: identical fund consolidation topology, identical P2WPKH target addresses, and mixed derivation paths. Each wave occurred approximately 27 hours apart, suggesting they were carried out by the same attacker, but there is currently no direct evidence to confirm this. Currently, all terminal addresses controlled by the hackers hold a total of 1,366.39 BTC (approximately $88.6 million), all of which are in an unspent state on-chain. Galaxy Research noted that the above data is based solely on Bitcoin block data and UTXO set analysis, and has not yet computationally verified whether the victim addresses have vulnerabilities due to low-entropy generation.

CZ: Software always has vulnerabilities; what matters is how the team behind it handles the issues

Odaily News: Binance founder CZ reposted on X platform about a user's encounter with a Coldcard wallet attack and stated that software will always have vulnerabilities; the key lies in how the team behind it handles the problems.CZ added that Trust Wallet faced a similar issue years ago, when a non-truly random pseudo-random number generator led to losses of approximately $12 million, but the team ultimately covered the user losses.Previous report: A third wave of attacks suspected to target addresses generated by Coldcard has emerged, with the attacker transferring approximately 207.7294 BTC again. Data shows that the scale of Coldcard-related attacks observed so far has expanded to about 1,367.05 BTC, involving approximately 4,585 addresses, valued at around $88.6 million at current prices.

Stealing $72.71 Million in Bitcoin, Coldcard RNG Vulnerability Exploit Cluster Begins Moving Funds

Odaily News: The Coldcard RNG vulnerability exploit cluster has stolen 1,159.42 BTC, approximately $72.71 million, from 870 exploited addresses. The attacker transferred 0.06 BTC to a new address, worth approximately $3,780; the remaining 1,159.35 BTC is still distributed across the original 8 attacker addresses, valued at around $72.7 million.

Dice rolls cannot protect all Coldcard features; multiple features may be affected by Yasmarang PRNG flaw

Odaily News: Bitcoin News posted on X platform, stating that even if the mnemonic remains secure because it was generated via dice rolls or imported from an existing mnemonic, multiple Coldcard features may still be vulnerable due to the Yasmarang PRNG flaw. Affected features include paper wallets, device cloning, USB sessions, Secret Teleport, co-signing keys, password generator, and HSM mode. If the mnemonic was imported or generated through a sufficient number of dice rolls, the mnemonic itself remains secure, but using these features may still expose secret information generated by the flawed random number generator.

Self-custody confidence permanently changed, Strive VP says Bitcoin custody may enter its next phase

Strive Vice President Joe Burnett posted on X, saying that recent weeks may be among the worst in Bitcoin's history. Many people purchased approved hardware wallets, generated seed phrases offline, and followed established best practices, yet still lost significant amounts of Bitcoin due to a vulnerability affecting seed phrases generated by COLDCARDwallet since March 2021. The vulnerability went undetected for over five years. Joe Burnett stated this will permanently change people's confidence in self-custody. Self-custody will still exist, but it has been permanently changed. For those who want to directly control large amounts of Bitcoin, the standard should be multi-vendor multisignature, with keys independently generated using different hardware and different software, and stored in different physical locations. If they cannot accept this approach, they should use institutional-grade custodians. Joe Burnett noted that the current wave of Bitcoin adoption is occurring through ETFs, treasury companies, and institutional custodians, primarily driven by people who never intended to become experts in private key generation, hardware security, firmware, backups, inheritance planning, and physical storage. A single key generated by one hardware wallet protecting large amounts of Bitcoin carries excessively high concentration risk. Joe Burnett also said that institutional custody may ultimately lead to too much Bitcoin being concentrated in the hands of large companies, creating risks of censorship, seizure, and confiscation. However, Bitcoin's portability and settlement properties provide a critical counterbalance — users can create a wallet and request the custodian to send Bitcoin, shifting from counterparty risk to direct ownership within minutes. Joe Burnett believes that as long as Bitcoin itself remains secure, the failure of one custody method does not negate the underlying monetary system, but rather forces the market to develop better tools, stronger standards, and more resilient custody architectures. This week may ultimately mark the end of one era of Bitcoin custody and the beginning of the next wave of Bitcoin adoption.

Nunchuk Responds to Coldcard Vulnerability: Platform Keys Will Not Be Used Directly

Odaily News, according to Bitcoin News monitoring, Nunchuk stated that some Nunchuk platform keys are generated by Coldcard Mk4, but these keys will not be used directly. Nunchuk derives independent keys through custom logic, making them less susceptible to lookup table attacks based on compromised Coldcard seeds. Nunchuk added that, given enough time, it believes attackers may eventually incorporate these derived keys as well.

Galaxy Research: Bitcoin losses related to the Coldcard vulnerability have risen to $70 million

Galaxy Research stated on Friday that over 1,000 BTC from nearly 1,200 addresses have been moved, valued at approximately $70 million, with the transactions believed to be linked to a vulnerability affecting Coldcard hardware wallets.Earlier, Coldcard manufacturer Coinkite issued a warning on Thursday about an ongoing issue with seed phrases generated by Coldcard Mk3 devices. Out of caution, the company reminded all users who generated seed phrases using Mk3 devices with firmware version 4.0.1, released in March 2021, or later, that their funds may be at risk.Subsequently, Coinkite expanded the scope of its risk alert to include certain firmware versions of Mk4, Mk5, and Coldcard Q, and released emergency firmware updates for all affected models.Coinkite CEO Rodolfo Novak (also known as NVK) apologized on Friday and stated that the company takes "full responsibility" for the firmware vulnerability, acknowledging that internal review processes failed to identify the issue.Novak also suggested that the vulnerability may have been discovered with the help of artificial intelligence, noting that this incident reflects a "sobering reality under the new AI paradigm." He warned that AI-assisted code review could identify potential vulnerabilities faster than experienced security experts, while also making it easier for attackers to exploit weaknesses in public code.

Approximately $30 million stolen in the first 10 minutes, Coldcard vulnerability attacker prioritized highest-value wallets first

Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.

Reduced randomness: Seeds from some COLDCARD wallets since 2021 are easier to guess

: Bitcoin News posted on X platform stating that Coinkite said the issue is not with Bitcoin's cryptography itself, but with the way COLDCARD generates wallet seeds. During the libNgU migration in March 2021, the wallet unexpectedly used a weaker software random number generator when creating new seed phrases, instead of the device-specific hardware random number generator. This reduced the randomness protection for some wallets, making certain seeds easier to guess than expected. The vulnerability has affected seed generation since March 2021, with Mk3 devices being the most affected. Mk4, Q and Mk5 have incorporated additional hardware-generated randomness, providing stronger protection, but they still rely on the same software component afterward. Coinkite stated that the error occurred because two pieces of software used the same function name, causing the wrong function to be selected during the build process without triggering an error. The company has changed its build process to prevent this from happening again.

Coinkite Issues Coldcard Mk3 Security Warning, Suspected to Be Related to $38 Million Bitcoin Theft Incident

据 Cointelegraph 报道,加拿大比特币硬件钱包制造商 Coinkite 警告 Coldcard Mk3 用户立即迁移资金,受影响固件版本为 2021 年 3 月发布的 4.0.1 至最终版本 5.0.3,Mk4、Q 及 Mk5 不受影响。与此同时,比特币安全专家正在调查一起涉及 594.48 枚 BTC(约 3830 万美元)的异常清仓事件,涉及 1324 个 UTXO 在三个区块内通过 500 笔交易被转移,所有地址均为单签名地址。

594.48 BTC transferred in a consolidated move, Coinkite warns Coldcard Mk3 users to migrate funds

Odaily News: Canadian Bitcoin hardware manufacturer Coinkite has warned users of Coldcard Mk3 signing devices to migrate funds from wallets whose seed phrases were generated by affected firmware. Coinkite stated that seed phrases generated by Mk3 firmware version 4.0.1 and later, released in March 2021, may put funds at risk, with the impact extending to version 5.0.3, the final version supporting the Mk3. Coinkite said that Mk4, Q, and Mk5 models are not affected; affected users should generate new seed phrases on unaffected devices, verify backups and receiving addresses, send a small test transaction first, and then migrate the remaining funds. The company said its investigation is still ongoing and that a formal technical review will be published. Bitcoin security experts are examining a centralized transfer of unclear origin involving 594.48 BTC in single-signature addresses, valued at approximately $38.3 million. Rob Hamilton, CEO and co-founder of AnchorWatch, stated that 1,324 unspent transaction outputs were moved via 500 transactions within a three-block window, with 562 BTC subsequently consolidated into another address. Kevin Loaec, CEO of Wizardsardine, said the current hypothesis is that a low-entropy random number generator has caused insufficient randomness in some wallets' seed phrases, with the relevant flaw potentially stemming from a software library, secure element, specific device batch, or firmware version. He added that this hypothesis has not yet been confirmed, and wallets from which only partial funds were transferred may still face the risk of subsequent theft.

Bitcoin Core Developer Claims to Have Reproduced COLDCARD MK3 Vulnerability, MK2/MK3 Devices May Be Affected

: Bitcoin News posted on X platform, stating that Bitcoin Core developer instagibbs claimed to have successfully reproduced the reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device, using only the number of button presses during the setup process, and said, "Sorry, now is the time to panic." He believes the issue affects MK2/MK3 devices, but stated that it is currently unable to confirm whether the MK4 has the vulnerability. Developer Antoine Poinsot stated that the key difference is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually utilizes the microcontroller's True Random Number Generator (TRNG), while the MK3 does not. The proof of concept and mnemonic phrase verification are still under review.

594 BTC from 500 Single-Sig Addresses Moved in 25 Minutes, Worth Approximately $38 Million

According to Bitcoin News monitoring, approximately 594 BTC from 500 addresses were transferred within 25 minutes on Thursday, worth about $38 million, with the funds subsequently consolidated into another wallet. All affected holdings used single-signature addresses, with balances ranging from approximately 0.15 to 0.26 BTC, and many UTXOs had been dormant for years. Early speculation centered on Coldcard, as at least one victim used that device. Coldcard CEO NVK denied the existence of a device-wide vulnerability, stating that the user may have imported a seed that had previously been compromised or was weak, and noted that the transfers involved keys from different wallets. Jameson Lopp indicated that another victim only lost a portion of their UTXOs, not their entire wallet balance, which may suggest exposure of individual private keys rather than a full seed compromise. At present, the coordinated transfer event is confirmed, but the source remains unknown, with no evidence yet of a Coldcard RNG flaw, supply chain vulnerability, or a failure in Bitcoin cryptography.

Anthropic AI Model Weakens HAWK Minimum Key Strength in 60 Hours

: Anthropic's Claude Mythos Preview model discovered a flaw in the proposed HAWK digital signature scheme, effectively halving its minimum key strength. HAWK is one of the candidate schemes to replace current network and bank signatures in a post-quantum environment. This AI-driven attack took approximately 60 hours, with a computational cost of around $100,000, reducing the effort required to break HAWK's minimum parameter set from roughly 2^64 operations to 2^38 operations, and diminishing the attractiveness of larger compensating key sizes. Current Bitcoin and Ethereum signatures remain unaffected. The results indicate that the capabilities of classical cryptanalysis attacks are improving, while Bitcoin and other networks continue to discuss when and how to migrate to quantum-resistant cryptography.

Lazarus Group hackers transfer 121.5 BTC, worth $7.74 million

according to Lookonchain monitoring, Lazarus Group hackers transferred 121.5 BTC, worth $7.74 million, an hour ago.

Ostium Attack Post-mortem: Off-chain Oracle Permissions Stolen, Forged BTC Price to Arbitrage 23.75 Million USDC

According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.

AmericanFortress 推量子安全钱包方案无需迁移资金

区块链安全公司 AmericanFortress 提出新加密方案,可保护现有 BTC、ETH、SOL 钱包免受未来量子攻击,用户无需转移资金或更改地址。