Ledger, Trezor say ‘funds are safe’ after Coldcard flaw helps hacker steal 38M Bitcoin

摘要:Bitcoin hardware wallet providers Ledger and Trezor have distanced themselves from Coinkite‘s Coldcard $38M exploit. An unfortunate code flaw within Coldcard’s firmware allowed an attacker to steal 38M worth of BTC or more from the hardware wallet. Since Coldcard shares part of the hardware design involving the True Random Number Generator (TRNG) with other providers, investors were worried that other wallets could also be at risk. However, Ledger clarified that it uses a slightly more secure design, maintaining that their Bitcoin hardware wallets were “not affected” by Coldcard‘s flaw. Source: X The firm added that it uses a 256-bit mathematical complexity system (entropy), which makes seed phrases difficult to crack. On the contrary, Coldcard’s flaw downgraded Coinkite‘s system from a 128-bit to a guessable 40-bit system, which could easily be cracked using brute force. Trezor, another Bitcoin hardware provider, also assured its users that they should not be alarmed about the Coldcar

Bitcoin hardware wallet providers Ledger and Trezor have distanced themselves from Coinkites Coldcard $38M exploit.

An unfortunate code flaw within Coldcards firmware allowed an attacker to steal 38M worth of BTC or more from the hardware wallet.

Since Coldcard shares part of the hardware design involving the True Random Number Generator (TRNG) with other providers, investors were worried that other wallets could also be at risk.

However, Ledger clarified that it uses a slightly more secure design, maintaining that their Bitcoin hardware wallets were “not affected” by Coldcards flaw.

The firm added that it uses a 256-bit mathematical complexity system (entropy), which makes seed phrases difficult to crack.

On the contrary, Coldcard‘s flaw downgraded Coinkite’s system from a 128-bit to a guessable 40-bit system, which could easily be cracked using brute force.

Trezor, another Bitcoin hardware provider, also assured its users that they should not be alarmed about the Coldcard incident.

Trezor users: your funds are safe. The recent Coldcard issue is limited to their own custom firmware and how some of their devices generated randomness. Trezor does not share that code.

BTC dumps 3% to 2-week low after Coldcard exploit

Despite the assurance, the Coldcard exploit sparked broader fear about safety on hardware wallets and self-custody.

According to TaprootWizards Udi Wertheimer, self-custody is now “worryingly unrealistic,” warning that AI models with cybersecurity attack capabilities will intensify the hacks.

For his part, Coinbase CEO Brian Armstrong said the best way to improve physical security is by “air-gapping keys,” citing his firms operational standard for crypto ETF custody.

As the community discussed Bitcoin self-custody threats, BTCs sentiment dropped to a four-month low. According to Santiment data, the soured sentiment mirrored the market caution seen as the West Asia crisis intensified in April.

As a result, Bitcoin [BTC] price dropped sharply by nearly 3%, tagging a 2-week low of $62.4K. But the crypto asset slightly recovered back above $63K as of writing.

Source: Santiment

Others projected that the overwhelming effort to handle self-custody amid the ongoing risks would force investors to opt for U.S. Spot ETFs.

However, the ETF demand was also impacted by the weak sentiment on Friday. The products recorded a daily net outflow of $265. It remains to be seen whether the spot BTC ETFs will attract new investors worried by self-custody risks and upcoming quantum attack vectors.

Final Summary

  • Ledger and Trezor said they were “not affected” by the Coldcard flaw as they operate different systems for their hardware wallets.
  • Coinbase CEO said “air-gapping keys” can help reduce some threats.

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

劍橋大學研究顯示以太坊(ETH)位居PoS能耗強度下游

下一篇

Merck與Hashgraph Group推出基於Hedera的產品護照以符合歐盟合規要求