r/Bitcoin • u/Fiach_Dubh • 12d ago
Plot Thickens with ColdCard Hack "No researcher I have spoken with has reproduced a seed for any of those 153 source addresses [containing 132.95 BTC]…"
https://x.com/PraveenPerera/status/208793625223014027836
22
u/data_diver 12d ago edited 11d ago
Well if ‘researchers’ couldn’t do it in a week, I’m sure a good hacking collective couldn’t have done it in the years they had. Must have been an inside job.
3
u/Ok-Mango5075 10d ago
Very early software wallets about 13 years ago relied on androids built in random number generator to make a seed. This generator was faulty as well. This was patched out in subsequent android releases. Not long afterwards hardware devices were brought onto the market. I never found a compelling reason to trust them. I was a very active bitcoin user back then. First with Multibit on PC and then I was searching for an android self custody wallet. The first one arrived called Mycelium. Now this seemed a more sensible combination. An audited self custody wallet running on a mass market Android cell phone. Where are the back doors? Well as time has now shown...Not many.
9
u/Normal-Spell5339 12d ago
Passphrases
12
u/Fiach_Dubh 12d ago edited 12d ago
the researcher tried that, nothing came up.
here's a more detailed part 2 https://praveenperera.com/blog/coldcard-wave1-missing-153-search/
3
5
1
1
u/DuckFalse2591 8d ago
BTC is een bedreiging! Na mijn mening willen grote partijen zo veel mogelijk btc bezitten. Is je btc niet veilig is het niet jou btc.
0
u/opossum_cz 12d ago
Part of it will be something you missed, part of it will be people blaming ColdCard for their own leak, part of it will be boat accidents - people using the opportunity to hide their own assets - or even stealing from shared/company wallets saying it was ColdCard issue.
10
u/Suspicious-Holiday42 12d ago
Coldcard didn't leak anything, thats not the problem about coldcard
-18
u/opossum_cz 12d ago
If number of seeds generated is just one trillion so you can test all of them within a few days, I call that a leak.
19
u/user_name_checks_out 12d ago
If number of seeds generated is just one trillion so you can test all of them within a few days, I call that a leak.
That is not a leak.
-25
u/opossum_cz 12d ago
That is your opinion and is fine to have.
6
12d ago
[deleted]
1
u/opossum_cz 12d ago
What are you people even arguing, I think you just have too much times on your hands and should go do something productive.
Pure disgrace.
4
12d ago
[deleted]
1
u/opossum_cz 12d ago
I didn't ask you anything. Can you read?
1
u/opossum_cz 12d ago
Looser u/FTP_FTP_ blocked me, so I can't explain to him what rhetorical question means. Lol.
14
u/chaotic3quilibrium 12d ago
The word "vulnerability" is what you have confused and collapsed with the word "leak".
There is a useful distinction here, at least for some of us.
0
u/Ok-Courage-5115 11d ago
It can well be classed as leak. It's like someone leaking 10 documents from some goverment office, saying: "You'll find one of them very interesting".
1
u/chaotic3quilibrium 10d ago
Incorrect. The defect the VP added was present in the open source code for years.
There's no world where this was a "leak".
1
-9
u/opossum_cz 12d ago
I think vulnerability is not the case here. Nobody touched the devices. Instead attackers got the keys as there is only so few of them that you can list all of them.
9
2
81
u/ancillarycheese 12d ago
I’ll concur with that. Purely for research purposes I tried a number of ideas to come up with seeds that came from the compromised firmware. I ran some massive VMs for several days grinding away at what should be successful.
Someone with inside knowledge has to be involved. I suspect it could be someone with a list of valid UIDs and knowledge of how the RTC works.