Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider

الملخص:Over $70 million in Bitcoin was stolen via an attack exploiting a Coldcard vulnerability. Block engineer Clay Garrett said the thief used a paid account at an unnamed well-known blockchain-services provider to query source addresses during the sweeps, and authorities were notified. Galaxy Digital noted the movement pattern showed a single attacker. Coinkite disclosed that a firmware bug in Coldcard Mk3 devices, starting with version 4.0.1 in March 2021, caused seed generation to fall back to a weak software pseudorandom number generator rather than hardware randomness, making many single-signature wallets predictable. Coinkite later admitted all models were vulnerable. Engineers warn more addresses may be at risk.

Since over $70 million in Bitcoin was stolen yesterday by an attack that exploited a fault in the Coldcards system, it has been reported that the thief used a top blockchain services provider for help.

Writing on X Friday, engineer at payments company Block, Clay Garrett, said that the provider — who he did not name at the request of the services provider — had been contacted after finding blockchain movements matched the “suspected workflow” of the attacker.

“During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps,” Garrett said.

“That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps,” Garrett continued, adding that the authorities had been notified.

Galaxy Digitals research arm also wrote on X that the thief had an unusual pattern of moving the coins.

“The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins,” the company said, adding that Bitcoiners should move funds out of single-signature Coldcard addresses and into secure custody.

After over $35 million in Bitcoin was drained from wallets on Thursday, Coinkite said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator.

This allowed private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force.

Later on Friday, Coinkite admitted all of its models were vulnerable following more thefts. Over $70 million has so far been swiped and engineers have warned that more Bitcoin addresses could be at risk.

The company makes a number of Bitcoin products, including cold storage hardware wallets.

عدم اعطاء رأي

الآراء الواردة في هذه المقالة تمثل فقط الآراء الشخصية للمؤلف ولا تشكل نصيحة استثمارية لهذه المنصة. لا تضمن هذه المنصة دقة معلومات المقالة واكتمالها وتوقيتها ، كما أنها ليست مسؤولة عن أي خسارة ناتجة عن استخدام معلومات المقالة أو الاعتماد عليها.
المنشور السابق

تُظهر عملة XRP إشارتين صاعدتين على السلسلة قبيل دخول شهر أغسطس

التالي

Zcash تؤكد أن البرهان الرسمي لـ Ironwood يستبعد وجود ثغرات تتيح تزوير العملات دون إمكانية اكتشافها