
$38 million worth of BTC has been drained from 500 cold wallets, thanks to a hardware wallet bug exploited by hackers.
Coldcard is a hardware wallet built by Canadian company Coinkite. It is a small device that stores bitcoin keys offline, away from internet-connected computers. It is continually updated with successive generations such as Mk2, Mk3, Mk4, Q and Mk5.
However, a flaw in the coding for the Mk3 was exploited by hacker(s) who managed to access 500 affected wallets and drain them of 594 bitcoin in total ($38 million in value).
The entire hack was completed in 25 minutes
As per CoinDesk, each wallets’ seed, a 24-word phrase used to control the funds, is supposed to be randomly generated from a pool so vast that it is impossible to guess. However, the flaw in question resulted in the MK3’s randomness chip being skipped.
This meant that the seed generation was simply being done via a basic software substitute that used a chip’s serial number and clock registers, none of which are secret information, allowing the hacker(s) to use artificial intelligence to “brute force” the guessing of seed phrases.
Coinkite said seeds generated on an Mk3 running firmware version 4.0.1, which was released in March 2021, or any later Mk3 version up to version 5.0.3, may be at risk. The Mk4, Q and Mk5 are reportedly not affected.
For more on cryptocurrency, check out our coverage of the man who used AI to remember his password after he got high and forgot it, or the X user who tricked Grok into sending $200,000 in crypto using Morse code.
Nguồn bài viết: Xem bài gốc tại KnowYourMeme


