• The Beluga Brief
  • Posts
  • 🐳 Weekly Edition: Hundreds of Crypto Wallets Drained in Coldcard Exploit

🐳 Weekly Edition: Hundreds of Crypto Wallets Drained in Coldcard Exploit

A hacker discovered a Coldcard hardware wallet bug which made seed phrases guessable due to poor randomization.

Over 1,000 Bitcoin was drained from 1,200 Coldcard hardware wallets today after a hacker exploited a bug introduced in a March 2021 firmware update. Many of these wallets had been sitting dormant for years and were targeted because of their high balances (minimum 0.15 BTC). None of the wallets were physically accessed, there was no wrench attack and phishing wasn't involved. So how did the hackers do it?

In order to understand the exploit, you first have to understand entropy. Entropy is a measure of randomness. The higher the entropy, the harder something is to guess. Guessing a random number between 1 and a billion is much more difficult than guessing a number between 1 and 10. Bitcoin seed phrases are randomly generated. The higher the entropy during the generation process, the harder the seed phrase is to crack.

Coldcard wallets have a True Random Number Generator (TRNG) that samples from the environment around it to generate high-entropy seed phrases. In 2021, Coldcard shipped a software update that accidentally caused wallets to generate keys using a Pseudorandom Number Generator (PRNG) instead of the onboard TRNG chip. PRNGs have much lower entropy and are vulnerable to brute-force attacks.

A hacker discovered the issue and was able to drain affected Coldcard wallets because the seed phrases weren't truly random and were therefore guessable. The stolen funds have been consolidated into a handful of wallets, but at the time of writing, they haven't been moved into a mixer or privacy coin.

Should you be worried? If you have a Coldcard Mk3 that generated its seed phrase on firmware versions 4.0.1 through 4.1.9, you should move your funds to a new wallet immediately. Updating the firmware alone doesn't solve the problem. You also need to generate a new seed phrase.

X via @sanket1729

I'd imagine almost none of you are affected. If you're using a different hardware wallet, you likely have nothing to worry about. This exploit was caused by a specific bug in Coldcard's software. The major hardware wallet providers generate seed phrases with high entropy and have a good track record of keeping funds safe.

The most common way people lose crypto is by giving someone their seed phrase. As long as you can avoid that, you've won 90% of the battle.

The Beluga intern has been hard at work gathering all the most important crypto news stories so you have them in one place!

The Majors

Alt Coins and Stocks

Crime

AI

Interesting Reads

It’s not that hard mom.

X via @cbspears

Check out our latest content below!

Disclaimer

The content on this site is for informational purposes only and should not be construed as investment advice. While Beluga strives to ensure the accuracy and timeliness of information, there may be discrepancies when comparing our data to that of financial institutions, service providers, or specific product websites. Always consult with a professional before making any financial decisions. Will McKinnon is the Head of Content for Beluga and has spent every day for many years trading coins. For that reason there are too many to name, however his largest holdings by a significant margin are Ethereum and Bitcoin. NFA DYOR