Coinkite believes an attacker used AI to find a flaw that has cost owners of its Coldcard hardware wallets tens of millions of dollars in Bitcoin, and says its own AI review of the same code weeks earlier turned up nothing.
The hardware wallet manufacturer published an advisory for its Mk3 and a technical breakdown on Thursday, after learning that seeds generated by its devices were far more guessable than intended.
The losses to the flaw, which was exploited early Friday, are estimated at 594 BTC, around $38 million. Funds were drained from roughly 500 wallets inside 25 minutes, with 562 BTC since consolidated into a single address.
Coinkite said it has to assume "someone used AI to review previous versions of our firmware" in order to uncover the flaw. The firm said it had run one of the best available models over its own code a few weeks earlier, and the model "did not find this bug or anything serious." Attackers and defenders have the same tools, it wrote, but this time "it did not help us, and only helped the bad guys."
What went wrong
Coldcard's firmware calls a function to fetch randomness, and two implementations of it sat in the codebase with identical signatures: the hardware generator Coinkite wrote, and a software fallback inherited from MicroPython. A preprocessor guard checked only whether a setting was defined, without testing its value, so the build completed against the fallback without complaint. Seed generation had been drawing on it since a March 2021 migration.
Every current model is affected to some degree. Coinkite estimates the effective search space for an Mk3 seed at about 40 bits, against the 128 a seed is meant to have. Extra entropy from the secure elements on the Mk4, Q and Mk5 lifts theirs to roughly 72 bits, which the company says materially improves the position without reaching the target. Tapsigner, Opendime and Satscard use different code and are unaffected.
What owners must do
Coinkite has shipped an emergency hotfix, version 5.6.0 for the Mk4 and Mk5 and 1.5.0Q for the Q. Updating does not repair a seed already created on affected firmware. Owners need a new seed generated on patched hardware, and the company recommends a strong BIP-39 passphrase, at least 99 dice rolls, or both. Mk3 owners, whose model is out of support, are pointed to a separate migration path.
A seed created on an affected Coldcard stays weak after being restored to another brand's device, a point rival hardware wallet manufacturer Trezor made while telling its own users their funds are safe. Block, which published an independent analysis on Friday, said none of its products are affected, and its hardware lead Max Guise urged anyone exposed to move funds as soon as they safely can.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。