TGStat
TGStat
Qidiruv uchun matnni kiriting
Ilg‘or kanal qidiruvi
  • flag Uzbek
    Sayt tili
    flag Russian flag English flag Uzbek
  • Saytga kirish
  • Katalog
    Kanal va guruhlar katalogi Kanallar qidiruvi
    Kanal/guruh qo‘shish
  • Reytinglar
    Kanallar reytingi Guruhlar reytingi Postlar reytingi
    Brendlar va shaxslar reytingi
  • Analitika
  • Postlarda qidiruv
  • Telegram'ni kuzatish
Crouton Digital | Official

4 Aug, 15:29

Telegram'da ochish Ulashish Shikoyat qilish

#Bitcoin #BTC #Coldcard #Hardware #SelfCustody ☠️

Coldcard: 5 years of silence - $114M drained across 4 sweeps

Starting July 30, an attacker allegedly swept ~1,816 BTC (~$114M) from over 5,290 addresses. Four waves in four days. Not a single device was physically opened. The cryptography held - the silence broke.


🟢 The silent bug: 5 years of invisible failure

Firmware 4.0.0 (March 2021): a preprocessor error quietly rerouted seed generation from the hardware TRNG to a software PRNG seeded with public chip data.

Entropy collapsed: Mk2/Mk3 down to ~40 bits instead of 128 (Mk4/Mk5/Q ~72). 40 bits is brute-forceable on ordinary hardware - the only people still protected are the ones who added their own entropy. The whole attack is offline: generate candidate seeds, derive the addresses, match them against the blockchain.

🟢 Four waves: the timeline

⏺️ July 30: 1,083 BTC from 1,196 addresses
⏺️ July 31: +76 → 1,158 BTC (2,673 addresses)
⏺️ Aug 1-2: +208 → 1,367 BTC (4,585 addresses)
⏺️ Aug 3: +449 → ~1,816 BTC (700+ addresses, Galaxy on-chain data, no victim confirmation)

Coinkite's first warning came ~30 hours after the first sweep.

🟢 What about Ledger and Trezor - can it happen to them?

Ledger and Trezor say they're unaffected. But it's not about whose chip is better.

Self-custody rests on one thing: the seed being unguessable. When entropy drops from 128 bits to 40, that doesn't weaken - a guessable key isn't stolen, it's re-derived.


🟢 What to do

Coinkite shipped patched firmware. But it won't fix a seed that already exists - if yours came off that firmware, you have to create a new one on an updated device, test it with a small amount, then move everything.

ZachXBT won't be tracking these coins - there's almost no getting them back on-chain. So if your seed could've been born on the broken firmware and the money's still there, move what's left anywhere, even to an exchange: counterparty risk is survivable, a re-derived key isn't. Once things settle, close the gap itself: your own entropy at generation, a passphrase on top, multisig for larger amounts.

Self-custody isn't dead. You just find out about a silent bug last - and that's what makes it vicious.

➡️Crouton.digital | About us⬅️

1k 6 2
Katalog
Kanal va guruhlar katalogi Kanallar to‘plamlari Kanallar qidiruvi Kanal/guruh qo‘shish
Reytinglar
Telegram-kanallar reytingi Telegram-guruhlar reytingi Postlar reytingi Brendlar va shaxslar reytingi
API
Statistika API'si Postlar qidiruvi API'si API Callback
Kanallarimiz
@TGStat @TGStat_Chat @telepulse @TGStatAPI
O‘qish
Академия TGStat Telegram tadqiqoti 2019 Telegram tadqiqoti 2021 Telegram tadqiqoti 2023
Kontaktlar
Справочный центр Qo‘llab-quvvatlash Email Vakansiyalar
Har xil narsalar
Foydalanuvchi shartnomasi Maxfiylik siyosati Ommaviy oferta
Botlarimiz
@TGStat_Bot @SearcheeBot @TGAlertsBot @tg_analytics_bot @TGStatChatBot