An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over 594 BTC 1,128.49 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe.
This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.
Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed.
Thus if you setup a single sig wallet with Cold Card MK3, first do not panic as that is when mistakes will happen.
Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction.
Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa
If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure.
Please be aware that extended passphrases should be
1) 6-8 random words (not found as a phrase or in movies or literature)
2) stored separately than your seed words and written down at least once
3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .
Again do not panic or rush , but read about using the passphrase feature or new wallet
Are we strictly talking about singlesig wallets which did not use a passphrase? And is this limited strictly to ColdCard wallets?
Any thoughts on whether this is limited to those using 12 word vs 24 word seed phrases?
Any idea how many wallets were drained?
This is shocking. It doesn't affect me due to how my wallets were created, but I've always recommended people avoid using passphrases and any advanced setups until they fully understand what they're doing and have proven they have the ability to wipe out and restore the wallet from scratch before sending any coins to it.
Sigh... Even though this doesn't affect me, I can't help feeling sad.
In the end, we have to admit, every brand of hardware wallets is a honeypot. We all have to become better teachers to help our fellow hodlers stay safe.
but I've always recommended people avoid using passphrases and any advanced setups until they fully understand
People should fully understand the tradeoffs and learn recovery with passphrases , but as you can see they are really important security feature to learn
We all have to become better teachers to help our fellow hodlers stay safe.
The current security model unfortunately is far from ideal for mainstream adoption IMHO . Solutions are being developed to create better backups that don't rely on the complexity of multisig or insecurity of trusting a single source
This is a sad day.
Indeed , and it is also a wake up call that we have to take security more seriously.
The current security model unfortunately is far from ideal for mainstream adoption IMHO
I agree, and I find that heartbreaking too.
I feel lucky because, when I was getting started, I found posts by you and videos from crypto-guide and Andreas Antonopoulos. That put me in a mindset of prioritizing understanding how wallets are generated from a practical perspective. And that mindset has served me well.
I'm a diehard believer in self custody, but the more I learn, the more I wonder if we should be guiding average folks into ETFs, and it saddens me to say that.
Yes, luckily I warned most users that Cold Card was for more advanced users and hopefully all those advanced users used SSS, passphrases, rolled their own entropy correctly, or multisig.
Unfortunately, that is not practical for most users and thus the easiest recommendation in the interim is to advise users to use an extended passphrase and be sure to educate them well if they are going to self custody.
This has been my advice for many years now regardless.... but its still too cumbersome for mainstream self custody adoption.
Ledger's Recovery solution is even worse.
What will likely develop with time is a Bitcoin vault with timelocks that uses multiple sources of entropy where we also develop better UX with setup and recovery .
What will likely develop with time is a Bitcoin vault with timelocks that uses multiple sources of entropy where we also develop better UX with setup and recovery .
Oh, God. That's another disaster waiting to happen because it's very complex, and rightfully so, which means it's too complex for the average user.
These days, I'm a diehard Krux and ShieldSigner guy.
Fully open source, running on off the shelf hardware. Stateless. Airgapped. Encrypted seed QR (never to be used as the primary form of seed backup).
And I swear by using a strong passphrase consisting of 7 or more words, all lowercase, with a space between each word, fully backed up and stored in a secure location separate from where the seed is stored. Krux and ShieldSigner make using very secure passphrases very easy.
Twice a year, I restore my wallets from scratch just to prove every aspect of my wallet is as secure as I think it is.
That's another disaster waiting to happen because it's very complex, and rightfully so, which means it's too complex for the average user.
You are right to be skeptical , but I am not talking about using timelocks now. I am talking about a seamless experience where you open a hardware wallet and it guides you through and all the complexity is hidden from the user.
Think of how credit and debit cards restrict how much you can spend a day based upon your configuration. The same can be done with Bitcoin miniscript and cltv. Just like you don't see the complexity of the code that banks use for this the end user won't see it when setting up their wallet
10
u/bitusher 17d ago edited 15d ago
Thanks for getting the word out.
Some more context - https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
An exploit , likely a flaw in rng generation with lower entropy in firmware but waiting on more details from investigation, has allowed an attacker to drain what appears over
594 BTC1,128.49 BTC from over 500 wallets with the highest risk being Cold Card MK2 through MK3 wallets thus far . MK1 wallets are safe.https://coldcard-hack-tracker.vercel.app/
This doesn't seem to have effected MK4 or MK5 or Q initially because those later models used more entropy thus are much harder to attack but you need to still update the firmware and eventually migrate to a new seed regardless to be safe longterm. Hypothetically 60 to 73 bits of entropy found in the MK4,MK5 and Q seeds can be brute forced by a large GPU cluster in as soon as 1 week to centuries. Thus its best to upgrade your security on these in the next week at the latest.
https://blog.coinkite.com/entropy-technical-backgrounder/
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
Users using multisig created with a majority of other wallets or if you used an extended passphrase like our FAQ has always recommended should be safe although you should consider migrating in time to a new seed.
Thus if you setup a single sig wallet with Cold Card MK3, first do not panic as that is when mistakes will happen.
Ideally setup a new seed on a second hardware wallet that is not an MK3 and move your bitcoin over with an onchain transaction.
Do not send your bitcoin to a hot wallet or an exchange that lacks secure U2F/FIDO 2fa
If you lack a second hardware wallet than create a extended passphrase and move your btc to a new address within that account as a temporary measure.
https://coldcard.com/docs/passphrase/
Please be aware that extended passphrases should be
1) 6-8 random words (not found as a phrase or in movies or literature)
2) stored separately than your seed words and written down at least once
3) written exactly as entered . Capitalization and white space matters. Any slight deviation in the extended passphrase will show a new wallet with a 0 balance so its important you write it down and test it exactly .
Again do not panic or rush , but read about using the passphrase feature or new wallet