BTC $79,976.02 +0.50%
ETH $2,478.06 +1.20%
BNB $776.04 +8.15%
XRP $1.42 +1.84%
SOL $104.01 +2.53%
TRX $0.3342 +0.82%
DOGE $0.0927 +10.01%
ADA $0.2210 +4.46%
BCH $258.64 +2.71%
LINK $12.07 +3.79%
HYPE $85.66 +0.58%
AAVE $133.79 +2.61%
SUI $0.8064 +7.17%
XLM $0.1850 +3.77%
ZEC $1,031.78 +1.69%
BTC $79,976.02 +0.50%
ETH $2,478.06 +1.20%
BNB $776.04 +8.15%
XRP $1.42 +1.84%
SOL $104.01 +2.53%
TRX $0.3342 +0.82%
DOGE $0.0927 +10.01%
ADA $0.2210 +4.46%
BCH $258.64 +2.71%
LINK $12.07 +3.79%
HYPE $85.66 +0.58%
AAVE $133.79 +2.61%
SUI $0.8064 +7.17%
XLM $0.1850 +3.77%
ZEC $1,031.78 +1.69%

coldcard

All
Article
Flash

Coldcard releases new firmware to enhance security; affected users need to regenerate their mnemonic phrases and migrate their assets

Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following an emergency fix, focusing on addressing the security risks posed by previous mnemonic phrase generation attacks. Each newly generated mnemonic phrase must include at least one user entropy source, such as irregular key presses at least 65 times, physical dice rolls 50 times, or physical coin tosses 128 times, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2.The new firmware also adds pre-signing phased PSBT verification, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard states that this update aims to further reduce the risk of the device being attacked.The official reminder is that updating the firmware cannot fix existing mnemonic phrases generated by previously affected firmware. If a user's mnemonic phrase falls within the scope of this security announcement, they should first update the device, then generate and verify a brand new mnemonic phrase, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signatures of the downloaded firmware.

153 stolen addresses contain 132.95 BTC, and researchers are still unable to reproduce the Coldcard attacker's seed

According to monitoring by Bitcoin News, new research published by @PraveenPerera shows that Coldcard attackers seem to first identify addresses with vulnerabilities, then sort them by the amount of Bitcoin held, starting to transfer in batches from the addresses with the highest holdings. The transfer software used was relatively crude.One address had 225 spendable UTXOs, and the attackers extracted exactly the latest 200, leaving the earliest 25, which included a UTXO worth 0.16 BTC. This aligns perfectly with the limitation of a blockchain API investigated by researchers, which defaults to returning 200 records, indicating that the attackers may have failed to load the next page of data. The software even spent a UTXO of 294 satoshis, reportedly increasing the transaction fee by about 2040 satoshis, with the spent amount significantly higher than the value of the UTXO itself.The authors of the study believe that the builders of this tool may have a better understanding of the account balance system than of the Bitcoin UTXO model. Although the attackers seem to have obtained the complete seed of the victims, at least 75 BTC still remain in other addresses derived from the same seed. The biggest suspicion currently is that among the 153 stolen addresses, there are still 132.95 BTC, and researchers have been unable to reproduce the seed behind these addresses, so it cannot be ruled out that the attackers obtained undisclosed private device data or candidate data.
app_icon
ChainCatcher Building the Web3 world with innovations.