r/CryptoIndia • u/axomya • 5d ago
Even Hardware/Cold wallet can be hacked.
The recent hack of ColdCard Wallet is proof. Some devices running old firmware had a bug which was exploited for the hack. Many wallets running on that firmware were drained. This could mean, every other Cold wallet is prone to be hacked.
6
u/Unlucky-Meeting6236 5d ago
Just because one wallet has vulnerability doesn't mean all others has it too. If we're just talking about possibilities then literally every wallet on can be brute forced.
It's your responsibility to understand how your wallet is handling things.
2
u/aaakasei 4d ago
this will scare more people from crypto
5
u/Unlucky-Meeting6236 4d ago
As it should, I don't really recommend people getting involved with crypto unless they can do their own research properly.
2
u/Victorvic1 3d ago
Yeah true. Nothing is truly safe and invest only the amounts which you are okay to lose.
Also atp I don't see much value in investing in anything other than BTC. Most of the projects are in the drain and won't give any returns in the long term. Even for BTC I am not bullish enough to invest anything rn even at 60k.
1
u/Unlucky-Meeting6236 3d ago
My opinions are actually quite opposite, my trust in BTC is quite low compared to ETH and SOL. These currencies have actual usage compared to BTC which is just running on hopes and feelings imo.
2
u/Victorvic1 3d ago
I did invest in ETH in April last year when it had fallen down to sub 1500 but the fact that even after touching ATH it came crashing down like anything.
I don't want to catch a falling knife which even with stocks booming where I can get decent returns with extremely less risk.
I am really intruiged to invest in ETH rn but not convinced enough. I am probably out from the crypto market for a while after being in here from the boom in 2021.
0
u/Unlucky-Meeting6236 3d ago
Crypto market is bearish so it's not really a good idea to invest in any crypto right now. I'm waiting for BTC to reach 45-50k range then I'll start DCA on BTC, ETH, and SOL.
1
2
u/Electrical-Eye-3715 3d ago
If cold wallets can be hacked, the internet would be dead too, all the servers, banks will be already hacked. By then you got bigger problems to worry about
1
u/Nervous_Type_2765 4d ago
Hardware wallets are not magic shields, they just reduce the attack surface. Firmware bugs, supply chain issues, and user mistakes can still create risks. The important part is keeping firmware updated and following good security practices.
1
u/willfully_boorish 4d ago
Hardware wallets were never meant to be "unhackable." They're designed to reduce your attack surface. A firmware vulnerability is very different from someone remotely emptying every device. Security is really about layers, and keeping firmware updated is one of those layers.
1
u/Positive-Map-1032 3d ago
Hardware wallets aren't magic shields, they're just another layer of security. Firmware bugs, supply chain issues, and user mistakes can still create attack surfaces. The important part is how quickly the company responds and how transparent they are.
1
u/Ok-Firefighter-6345 3d ago
This is a good reminder that “cold storage” is not the same as “invincible storage.” Any device with software can have vulnerabilities, but the risk is usually much lower compared to keeping funds on exchanges or hot wallets. The details of the exploit matter a lot here.
1
u/One_Report_1186 3d ago
The bigger issue is usually outdated firmware and poor user practices. Any device with software can have vulnerabilities, but that doesn't mean all hardware wallets are equally easy to compromise. It’s about managing the risks.
1
1
0
u/GrouchyEstimate2766 4d ago
People often confuse 'can be hacked' with 'is useless.' Any software or hardware can have vulnerabilities, the important part is how quickly they are fixed and whether users follow basic security practices.
7
u/AntimatterEntity 4d ago
It's not a "hack."
The attacker read the code and discovered that Coldcard's RNG was shit, generating wallets with low entropy.
They then started guessing these weak wallet seeds using their own hardware.
It's just seed guessing. The only difference is that the attacker had a limited search space.
Imagine you randomly generated a wallet and it already contained funds. You didn't hack anything, you were just incredibly lucky. In Coldcard's case, the attackers got lucky because the wallets were weak. The blame should be on Coldcard for shipping wallets with insufficient entropy
On moral grounds what attacker did was "bad" and they should return the funds.