BTC $62,829.85 -1.33%
ETH $1,875.05 -0.66%
BNB $607.58 -0.96%
XRP $1.00 -0.60%
SOL $75.72 -0.46%
TRX $0.3333 -0.61%
DOGE $0.0698 -0.72%
ADA $0.1822 -1.88%
BCH $205.49 -4.73%
LINK $8.80 +0.80%
HYPE $56.66 -0.70%
AAVE $87.19 -1.96%
SUI $0.6798 -1.19%
XLM $0.1586 -1.39%
ZEC $489.26 -1.44%
BTC $62,829.85 -1.33%
ETH $1,875.05 -0.66%
BNB $607.58 -0.96%
XRP $1.00 -0.60%
SOL $75.72 -0.46%
TRX $0.3333 -0.61%
DOGE $0.0698 -0.72%
ADA $0.1822 -1.88%
BCH $205.49 -4.73%
LINK $8.80 +0.80%
HYPE $56.66 -0.70%
AAVE $87.19 -1.96%
SUI $0.6798 -1.19%
XLM $0.1586 -1.39%
ZEC $489.26 -1.44%

coldcard

All
Article
Flash

153 stolen addresses contain 132.95 BTC, and researchers are still unable to reproduce the Coldcard attacker's seed

According to monitoring by Bitcoin News, new research published by @PraveenPerera shows that Coldcard attackers seem to first identify addresses with vulnerabilities, then sort them by the amount of Bitcoin held, starting to transfer in batches from the addresses with the highest holdings. The transfer software used was relatively crude.One address had 225 spendable UTXOs, and the attackers extracted exactly the latest 200, leaving the earliest 25, which included a UTXO worth 0.16 BTC. This aligns perfectly with the limitation of a blockchain API investigated by researchers, which defaults to returning 200 records, indicating that the attackers may have failed to load the next page of data. The software even spent a UTXO of 294 satoshis, reportedly increasing the transaction fee by about 2040 satoshis, with the spent amount significantly higher than the value of the UTXO itself.The authors of the study believe that the builders of this tool may have a better understanding of the account balance system than of the Bitcoin UTXO model. Although the attackers seem to have obtained the complete seed of the victims, at least 75 BTC still remain in other addresses derived from the same seed. The biggest suspicion currently is that among the 153 stolen addresses, there are still 132.95 BTC, and researchers have been unable to reproduce the seed behind these addresses, so it cannot be ruled out that the attackers obtained undisclosed private device data or candidate data.

The cryptocurrency industry is once again debating "who should hold the private keys" due to the $130 million theft case involving the Coldcard wallet

A wallet security incident involving approximately $130 million in Bitcoin losses is reigniting discussions in the crypto industry about asset custody models: should Bitcoin holders rely on personal self-custody or turn to institutional custody? Hardware wallet manufacturer Coldcard had a vulnerability in its firmware in 2021 that led to some mnemonic phrases generated by the device being predictably risky. This vulnerability was discovered years later, and approximately 5,200 addresses and about 2,000 BTC have been stolen, with losses amounting to around $130 million.After the incident, some investors began to turn to Wall Street custody products. Data shows that the U.S. spot Bitcoin ETF saw a net inflow of about $626 million within days of the incident. Bloomberg ETF analyst Eric Balchunas stated that such security incidents could further drive funds into ETFs. However, the Bitcoin core community still insists on the self-custody concept. Casa co-founder Jameson Lopp stated that recent events should not undermine users' confidence in self-custody and pointed out that third-party custody also carries risks. Bitcoin Core early developer Peter Todd also believes that self-custody has a better long-term safety record than centralized institutions.Onramp co-founder Michael Tanguma believes that both options have flaws. He stated that concentrating a large amount of assets in a single institution creates a "honey pot," while hardware wallets face risks related to supply chains, firmware, and random number generation. Tanguma proposed a "multi-institution custody" solution, where multiple regulated institutions hold keys through a multi-signature mechanism, requiring multiple institutions to jointly sign any transaction to reduce single points of failure. However, this model has also sparked controversy. Critics argue that while multi-institution custody enhances security, it also introduces permissioned management, conflicting with the decentralized ideals originally pursued by Bitcoin. As Bitcoin gradually enters the fields of pensions, trusts, and institutional asset allocation, the industry is seeking new custody solutions suitable for long-term wealth management. The Coldcard vulnerability incident once again highlights that achieving a balance between security, decentralization, and usability remains a core challenge facing the Bitcoin ecosystem.

Coldcard has suspended the automatic deletion of customer data due to a security incident and will retain relevant records in accordance with the law

The cryptocurrency hardware wallet manufacturer Coldcard has released an update on its customer data retention policy. Due to legal compliance requirements arising from the security incident disclosed on July 30, the company has temporarily suspended its original automatic customer data deletion mechanism.Previously, Coldcard's standard practice was to automatically clear customer records after 120 days, retaining only the user's email address and country information, while allowing customers to request early deletion of data at any time after product delivery. Coldcard stated that due to the security incident involving ongoing and potential legal proceedings, the company is obligated to retain records that may be relevant to litigation. Therefore, customer data that was originally scheduled for deletion will be temporarily retained until the law permits the resumption of normal processes.However, users can still request Coldcard to handle their personal information according to the original data retention policy. If users wish for their data not to be included in this legal retention scope, they can contact official customer service to make a request. Coldcard emphasizes that the retained data will be strictly protected, accessible only to authorized personnel, and will not be used for any purposes other than fulfilling legal obligations. The company will restore the previous automatic data deletion mechanism once legally permissible.
app_icon
ChainCatcher Building the Web3 world with innovations.