The safest way to store Bitcoin just lost $115 million...

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A critical vulnerability in ColdCard Bitcoin hardware wallets led to the theft of over 1,600 Bitcoin (~$115 million) from more than 7,000 wallets. The root cause was a subtle firmware bug: ColdCard's MicroPython-based firmware had two random number generators with the same function name. A flag intended to disable MicroPython's weak built-in RNG was set to zero rather than being undefined, causing an 'if not defined' check to pass and the weak RNG to be used instead of ColdCard's secure one. On bare metal hardware with no OS, MicroPython's RNG fell back to deterministic inputs — the chip serial number and a timer — making seed phrases brute-forceable. Attackers looped through all possible serial/timer combinations to derive private keys and drain wallets. Victims attempting to rescue funds faced a mempool race where attackers could front-run their transactions with higher fees; the only workaround was sending rescue transactions directly to mining pools to bypass the public mempool entirely.

5m watch time
113.4K Impressions9 Comments