From the Coldcard $70 million heist, see how institutional-level assets can be secured with HSM.

CN
1 hour ago

At the end of July 2026, a hacking incident erupted in the crypto industry, disrupting the public's perception of security: the well-known Bitcoin hardware wallet Coldcard, which emphasizes "physical isolation, private keys not leaving the device," was extensively hacked.

In just 41 minutes, attackers directly transferred over 1,080 bitcoins from 1,196 Coldcard wallet addresses, resulting in losses ranging from 70 million to 88.6 million dollars. Shockingly, the attackers never had physical contact with any device, and many of the stolen wallets had been offline and stored in safes for several years.

Being offline does not equal absolute safety.

This painful case once again proves that the fundamental line of defense for digital asset security does not depend on whether a device is connected to the internet, but rather on the physical randomness (entropy) of the private key at the moment of generation and whether the key is stored and approved with financial-grade hardware isolation.

I. Incident Review: "41-Minute Offline Exploit" Triggered by Firmware Configuration Negligence

Many investors blindly believe that "as long as the private key exists in an offline hardware device, the assets are absolutely safe." However, the root cause of the Coldcard heist lies in the fact that the fate of the private key was determined from the moment of its creation.

According to an in-depth review by the Block engineering team and on-chain security agencies, the vulnerability originated from a construction configuration oversight in the Coldcard firmware update in March 2021 [1]:

  1. Random Number Generator (RNG) Downgrade: The underlying logic for hardware wallets to generate private keys is to extract physical noise to produce high-entropy true random numbers (TRNG). However, the flawed Coldcard firmware accidentally skipped the hardware random number generator while generating the root random number (Seed), reverting (Fallback) to a software pseudo-random number generator (PRNG) relying on firmware code calculations.

  2. Entropy Collapse: The pseudo-random algorithm relied solely on the device's fixed serial number and initialization time register, causing what should have been a private key generation space of 2^{256} (inconceivably vast) to shrink down to only about 2^{32} (approximately 4 billion possibilities).

  3. Offline Exhaustion and Global Sweep: For hackers, the search space transformed from "finding a needle in a haystack" to "a simple enumeration of several billion." Attackers only needed to quickly offline run through these 4 billion mnemonic combinations on their computing equipment, derive the corresponding public key addresses, and compare them with the blockchain ledger. Once a match was found, they could directly broadcast the transaction on-chain, transferring all assets from the offline wallet in one go.

Similar to the Profanity vanity address vulnerability losing 160 million dollars [2], and the Lubian mining pool losing 127,000 BTC (approximately 15 billion dollars) due to weak randomness being cracked [3]—the scarcity of algorithmic entropy is the most covert and deadly poison in the crypto world.

II. The Life Start of the Private Key: From True Randomness to Source Security

In cryptography, randomness is the cornerstone of all security rules. The private key of the blockchain is derived from mnemonic phrases, and the mnemonic phrases entirely depend on the entropy value of the initially generated random number.

Common software pseudo-random algorithms (PRNG) are calculated based on deterministic mathematical formulas. As long as the initial seed or variable is known, the subsequent “random sequence” can be completely predicted. In contrast, true security must rely on true random number generators (TRNG), which extract pure "physical entropy" by capturing unpredictable quantities such as quantum micro-noise, circuit thermal noise, or atomic decay from the physical world.

Cactus Custody's Private Key Generation Paradigm

To eliminate any risks of entropy collapse caused by logical calculation flaws from the physical source, Cactus Custody refuses to use any software pseudo-random models.

In Cactus Custody's architecture, both the private key and seed are directly generated within a hardware security module (HSM) that has the highest level of security certification. The HSM is equipped with an industrial-grade physical entropy source generator (TRNG), which produces irregular, unpredictable true random numbers through thermal noise at the physical level, ensuring the private key's generation space possesses complete cryptographic strength, mathematically sealing off any possibility of offline exploitation or reverse derivation.

III. Key Custody Paradigm: Consumer-Grade Cold Wallet vs. Institutional-Level HSM Hardware Base

Besides the entropy issues in the generation phase, there exists an essential generational gap in the storage mechanism between consumer-grade hardware wallets and institutional-level custody.

Intrinsic Limitations of Consumer-Grade Hardware Wallets

Common consumer-grade hardware wallets (like Ledger, Trezor, or Coldcard) primarily function to prevent private keys from being directly stolen by Trojan viruses on connected computers. However, to facilitate ordinary users in backing up and migrating, the private keys and 12/24 mnemonic phrases can essentially be exported or backed up on paper-based media. Once the mnemonic phrases are written down, leaked, photographed, or physically accessed, hackers can replicate the private key on any device.

Cactus Custody: Thales Financial-Grade HSM Physical Protection

As a professional institutional-level digital asset custody provider, Cactus Custody employs the Thales hardware security module (HSM), which is commonly used by top financial institutions and central banks, as the underlying defense.

【Consumer-Grade Cold Wallet】

Private key generation ──► Exist in consumer-grade chip ──► Mnemonic phrases are exportable/backed up ──► Facing risks of physical access leaks/exhaustion

【Cactus Custody Institutional-Level HSM Architecture】

TRNG physical true random generation ──► Locked inside Thales HSM ──► Strongly marked as "non-exportable" ──► Physical disassembly self-destruction

  1. Non-exportable: In Cactus Custody's Thales HSM, once the private key is generated internally within the chip, it is forcibly marked as non-exportable. The private key physically can never leave the secure boundaries of the HSM from its birth to use.

  2. Closed Signing Within Chip: All transaction signatures are completed within the secure area of the HSM, and only valid signature results are broadcast outward, meaning that no matter how attackers attempt to access via remote networks or firmware extraction, they cannot touch the private key itself.

  3. Physical Tamper Resistance and Self-Destruction Mechanism: The Thales HSM has a military-grade physical protection casing. Any attempt to attack the HSM through physical disassembly, micro-probe scanning, or environmental anomalies will instantly trigger a physical protection circuit, automatically clearing and physically self-destructing all keys stored within the chip.

  4. Multi-signature Architecture: Utilizing a multi-signature governance structure, a single private key cannot unilaterally deploy cold storage funds, eliminating single points of decision-making, significantly reducing risks of single points of failure and internal malice.

  5. Random Private Key Generation: Each address's private key is independently generated by the hardware true random number generator (TRNG) embedded in the HSM chip, conforming to FIPS 140-2/3 and NIST SP 800-90 standards, not employing master seed derivation (e.g., BIP32/44 HD Wallet) architecture. Keys are mathematically unlinked, eliminating the mass risk of "if one point is compromised, all are lost," fundamentally removing single points of failure.

IV. Beyond Technical Defense: Trust Licenses and Top Compliance Audit Systems

For institutional investors and Web3 enterprises, a top-tier technical architecture (HSM + TRNG) is the foundation of security, while compliant governance structures and external independent audits form the complete armor for safeguarding funds.

To provide legally protected bankruptcy isolation and trust protection, Cactus Custody has set industry benchmarks in compliance and risk control:

  • Hong Kong TCSP Trust License: Cactus Custody holds a compliant trust or company service provider license in Hong Kong. This legally establishes its identity as a qualified trust custodian, ensuring strict legal separation between client-held digital assets and the custodian's own assets, meaning client assets are unaffected by the custodian's financial condition.

  • SOC 1 & SOC 2 Type II Dual Third-Party Audit: Cactus Custody has fully passed the rigorous audits of the renowned international accounting firm Deloitte for SOC 1 Type II and SOC 2 Type II. This signifies that our asset management internal controls, risk control processes, system security, availability, and data privacy protection systems have completely reached the highest review standards of traditional finance.

  • Integrated ISO International Standard Dual Certification: The operations team has earned the integrated certifications of ISO 27001 (Information Security Management System) and ISO 27701 (Privacy Information Management System), issued by the internationally recognized certification body SGS, to ensure that information security and user privacy management align with global top standards.

Conclusion

As renowned cryptography expert Bruce Schneier said, “Security is a process, not a product.” For digital asset custody, a single wallet or technology is not omnipotent; layered defense, multi-signature, and risk diversification are the true ultimate in security.

From blind signing attacks (such as the Bybit 1.5 billion dollar incident) to the Coldcard entropy collapse event, facts have repeatedly demonstrated that as attackers' methods evolve towards offline computing exploitation, supply chain poisoning, and high-dimensional social engineering, relying on consumer-grade cold wallets for large asset management has become difficult in facing current security challenges.

Digital asset governance is accelerating towards institutionalization. Cactus Custody will continue to use physical HSM hardware as the foundation combined with compliant trust frameworks and SOC/ISO dual audit systems to provide unshakeable top-tier asset protection barriers for global Web3 institutions, funds, and high-net-worth clients.

References:

【1】Block: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware

【2】1inch: https://1inch.com/blog/post/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool

【3】Arkham: https://info.arkm.com/research/us-government-btc-seizure-lubian-chen-zhi-pig-butchering

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink