perhaps we're lucky because we're broke.. but that doesn't mean we remain ignorant. I'm sure many of us would have been a victim given the fact that most just assume "I'd rather have self custody than keep in a cex.." without understanding how these wallets work if you’re setting up your own storage, I recommend taking the time to understand how these wallet provider creates the seed phrase.. including setting up passphrase with 128 bits entropy as the baseline, plus multiple signers from different seedphrases - understand what is entropy - understand BIP39 passphrase - understand multisig - understand firmware authentication seriously, a coldcard is so strong that it usually only signs transactions via microSD or QR rather than internet connection. in this specific case, a simple line of code from 2021 told the device to skip its randomness chip and use a predictable fallback instead.. because if this bug, the randomness of generated seed phrase dropped from 128+ bits (3.4×10³⁸ possibilities) to 40 bits (1 trillion possibilities) imagine your seed phrase is only one of 1 trillion possibilities.. the attacker only had to calculate these within 25 minutes, and waited patiently for 5 years for these wallets to get funded this reveals a truth, seed phrases are generally strong themselves, but the environment that creates them can be weak important questions to ask when dealing with wallets - was this phrase generated by a suspicious tool? - did it come from a compromised service? - was the entropy source truly random? - or maybe someone else had access to the phrase during generation, etc.. if you'll ever hold significant funds, you need to stop treating treating wallets like the magic security box.. understand the tools you work with, don't wait until somebody smarter takes advantage now I can't even imagine what happens if this bug was from trezor or ledger crypto aside, I think for anything sensitive, it would also be very important to understand why any tool needs to be updated and what changed vs the current version rather than just updating because update is available
🚨 BREAKING: THE WORST HARDWARE WALLET HACK IN BITCOIN HISTORY!!! $38M drained from 500 cold wallets in 25 minutes. The attacker never touched a single device. If you are a Coldcard Mk3 owner, move your coins today. Quick version of what happened: 594 BTC drained from ~500 air-gapped wallets in 25 minutes. These wallets never touched the internet. Turns out another 488 BTC was stolen earlier the same way and nobody noticed. Over 1,000 BTC gone. And the attacker never hacked a single device. A firmware bug from 2021 made the Mk3 skip its randomness chip when creating seeds. So your "random" 24 words were basically generated from the device clock and how fast you pressed buttons. One developer literally predicted his own seed phrase by counting his button presses during setup. Think about that. Life savings protected by button timing. The attacker figured this out, precomputed the keys, then sat on them for 5 years waiting for the wallets to fill up. Then took everything in one shot. And the uncomfortable part: This code was open source the whole time. Public repo, "thousands of eyes," don't trust verify, all of it. The bug sat there for 5 years and nobody looked. If your seed came out of a black box you never checked, you don't really own your Bitcoin. You're holding it until someone smarter takes it. (If you used a passphrase or dice rolls you're fine. Mk4, Mk5, Q, Ledger, Trezor also fine. And watch out for fake "support" accounts in your DMs right now, they're circling.)
· 8 Views