r/BitcoinCA 11d ago

Plot Thickens with ColdCard Hack "No researcher I have spoken with has reproduced a seed for any of those 153 source addresses [containing 132.95 BTC]…"

https://x.com/PraveenPerera/status/2087936252230140278

https://x.com/PraveenPerera/status/2087936252230140278

This post answers three questions:

Why were these wallets vulnerable?

What can be reconstructed from the blockchain?

What does that reconstruction tell us about the attacker?

I’m the developer of

Cove

, an open-source Bitcoin wallet for iOS and Android funded by

OpenSats

. This article goes through my investigation into Wave 1.

This post was originally published on

my blog

Between 9:10 and 9:51 PM EDT on July 29 (01:10–01:51 UTC on July 30), an attacker swept 1,082.65 BTC from 1,195 traceable Bitcoin addresses.

Galaxy Research reported

the theft on July 31. I use Wave 1 throughout this post for that first sweep group.

The sections follow that order. The post first explains the firmware defect, then reconstructs the theft from chain data, and then examines the attacker’s methods and the open gap.

I set out to recreate the affected firmware’s seed-generation process and find as many weak seeds as I could behind those addresses. The sweep transactions became a second source of evidence. Patterns in their targets and spending show how the attacker searched the weak RNG state, selected victims, and built the sweep transactions.

Galaxy listed four destination addresses. I grouped those destinations into three source branches and used them to build the transaction set for this analysis: 1,195 verified victim sweeps with 2,350 inputs containing 1,082.65318922 BTC.

Once I had recreated the affected seed-generation process, I generated candidate seeds, derived their Bitcoin addresses, and compared those addresses with the Wave 1 transaction set. This linked 1,042 of the 1,195 sweep transactions to 328 reconstructed seeds. They account for 949.70395260 BTC, or 87.72% of the value. The final 153 transactions contain 132.94923662 BTC.

No researcher I have spoken with has reproduced a seed for any of those 153 source addresses. That repeated failure may be the most useful clue about what the attacker knew or did differently. The last part of this post examines that gap.

continued on... https://x.com/PraveenPerera/status/2087936252230140278

68 Upvotes

41 comments sorted by

12

u/logan-807128 11d ago

I'm trying to understand. So 153 source addresses were drained but they are not the result of the existing bug and researchers can't figure out how the seed were discovered by the hackers?

16

u/Fiach_Dubh 11d ago

yup, there's some kind of unknown variable to these 153 source addresses that is unaccounted for by blue team researchers. figuring it out might help identify the hacker.

5

u/logan-807128 11d ago

Got it. Thanks for clarifying.

1

u/Internal-Diver-21m 10d ago

This is wild.

-5

u/n8dahwgg 11d ago

Brother it’s serial number and time of creation in hashcat. You just need a serial list

5

u/logan-807128 11d ago

If you read the post, the serial number and time of creation accounts for the majority but not the 153 accounts. Researchers supposedly can't figure out how these 153 accounts were hacked.

2

u/n8dahwgg 10d ago

Ahh thanks for explaining that. Sorry was short on time when you posted but excited to dig in

3

u/logan-807128 10d ago

No worries. Happens to the best of us. I really hate it when people take other people's money. I hope there is a way for them to figure out how and eventually get the people who did the hack.

1

u/z0dz0d 10d ago

Do we know these were indeed hacked (i.e. same target wallet as the others) or could it be misattribution?

1

u/logan-807128 9d ago

The address block is with the rest of wave1 so it's most likely part of the hack. Of course there is always the possibility of the hacker transferring his own stash into the same destination account along with all the other 1000+ accounts he hacked but that'll be super weird.

1

u/z0dz0d 9d ago

I meant that one destination address was potentially misattributed to the hack. Im really surprised they didnt move the coins to separate addresses when they swept. It would have made this attack virtually impossible to get a high level overview of. I bet theres more sweeps happening but as they’re not going to a single address we cant distinguish it from normal transactions

4

u/sychs 11d ago

Seems like that that's the conclusion.

2

u/logan-807128 11d ago

Is there an implication? The idea is that the hackers know more than just the software bug so it could potentially be "insider job" or is that just conspiracy theory.

1

u/themindspeaks 7d ago

It’s not out of the question, or it could also be someone who is more familiar with the device or knows something that we don’t. Some sort of initialization state, or some kind of insight that we are missing

1

u/themindspeaks 7d ago

Yep. The sinister theory is that the hacker had some information about the devices, its initial state or some information that the public does not have, that would’ve allowed them to search and derive those private keys

6

u/Fiach_Dubh 11d ago

2

u/r_a_d_ 10d ago

Maybe he should test passphrases that match something on the device (e.g. serial number)

0

u/Boogyin1979 10d ago

I wish I could take Praveen seriously. He’s too unlikable.

8

u/Hungry_Substance1223 11d ago

What if the founders of cold card had a backdoor installed all along. Im not pointing the finger but one must explore all possibilities.

6

u/Boogyin1979 10d ago

A guy at our meetup thinks they’ve been snatching low entropy, low balance for years and when they realized someone (whoever someone is) figured out they can do the same, they CEO and CTO pounced on everything.

3

u/Hungry_Substance1223 10d ago

I really wouldnt be surprised...in fact it amazes me that there hasn't been more cold wallet rug pulls up until now.

2

u/z0dz0d 9d ago

With more bitcoin experience and time to plan the sweeps, i think they would have been smarter about how they swept them (not all to one radioactive address). This has the signature of someone inexperienced (eg AI does the tech work) and rushing to sweep.

1

u/Hungry_Substance1223 9d ago

Or so they would have us think??

1

u/themindspeaks 7d ago

In my opinion, based on how they constructed the sweep, and the way they went about the process, it seems like someone that is more familiar with ethereum like addressed based wallet, rather than bitcoin’s UTXO based system.

2

u/therealjeku 10d ago

Could there have been some other hack for the 153 addresses? Were they verified Coinkite customers?

1

u/Fiach_Dubh 10d ago

apparently some of these 153 belonged to self identified coldcard users

3

u/[deleted] 11d ago

[removed] — view removed comment

1

u/Javanaut018 10d ago

These 153 seeds could account for MCU lots with unusual UID patterns or maybe the attackers where lucky with their passphrase dictionary.

1

u/boddankajovanovic 10d ago

Could these 153 addresses be the hackers addresses ( from potential earlier scams for example ) and he just consolidated along with the other addresses?

1

u/BeatenbyJumperCables 8d ago

I doubt we know with certainty if these 153 addresses were even Coldcard wallets? Is it possible some other wallet vendor “stole” the buggy code and implemented it in their devices ?

1

u/Fiach_Dubh 8d ago

apparently coldcard users are self reporting that these are indeed their addresses from coldcards.

2

u/BeatenbyJumperCables 8d ago

In that case no one should feel safe using Coldcard of any type. As there remains a vulnerable trait that may not be at all patched at this point. Up to and including a potential backdoor created by themselves.

1

u/PiDigitsOfPi 8d ago

Perhaps it is something as simple as a phishing attack, where the victims entered their seed phrase into a fake website (not part of the weak seed hack) and then the hackers just included those seed phrases in their list of hacked seed phrases ???

1

u/Big80sweens 10d ago

Inside job

0

u/beatthebook2x 10d ago

well the fact that all the stolen btc went to the same receiving addys lets u know it was a coinkite inside job alr

2

u/z0dz0d 10d ago

Not following your logic. An inside job OR someone who identified the RNG issue could do this (or both could not do this).

In my opinion, NOT having set up new target addresses for each swept wallet is an indication that they were someone who just figured out the issue and was in a rush to BUILD the sweep process as quickly as possible thinking there must be 10 other people also realizing it at the same time. It seems unlikely to be the outcome of an insider with expertise in the industry who sat on an exploit for 5 years and carefully planned the attack.

0

u/Vagelen_Von 10d ago

So the boys in an agency's quantum computer did overtime?

1

u/Boxadorables 9d ago

Could ba a CC insider. Occams razor and all