比特币橙子Trader
比特币橙子Trader|Aug 02, 2026 00:06
Whoa, the Coldcard incident is escalating further. Galaxy Research has uncovered a third wave of suspected crypto theft, with another 207.7294 BTC being transferred out. As of now, the total scale observed on-chain has risen to: 1,367.05 BTC Approximately $88.6 million Involving 4,585 addresses This has become one of the most costly security breaches in the hardware wallet industry. The real issue occurred at the moment the mnemonic phrase was generated: Some Coldcard firmware versions failed to properly invoke the hardware true random number generator as designed, accidentally using a more predictable software pseudo-random method instead, resulting in severely insufficient entropy for seed generation. Coinkite's preliminary estimates: - Mk2/Mk3 effective search space: ~40 bits - Mk4/Q/Mk5: ~72 bits Attackers can enumerate weak seeds offline and then scan corresponding addresses. Once a match is found, air gaps, offline setups, and secure chips become meaningless. What’s even more alarming is that the third wave of attacks is noticeably different from the first two. The first two waves used a few common aggregation addresses, transferring funds to P2WPKH addresses with highly similar behavioral patterns. The third wave, however: - Each victim has a unique destination address - Funds are sent to P2WSH addresses - On average, 6.37 victims are emptied per batch - Only default derivation paths are scanned This could mean the same attacker has upgraded their anti-tracking tools, or it could indicate a second attacker independently scanning the same weak key space. On-chain data cannot confirm whether the three waves of attacks are from the same individual. Of the 1,367.05 BTC observed by Galaxy, approximately 1,366.3865 BTC currently remains at the attacker-controlled final addresses and has not been moved further. The affected addresses are primarily small wallets holding less than 1 BTC, but the stolen value mainly comes from addresses with larger balances. The third wave of funds is dispersed across 293 unspent P2WSH addresses. Only when these addresses make their first transaction will the hidden script structure be revealed, allowing researchers to gather more clues about the attacker. Coldcard has now released an emergency update. For affected users, the most important steps are not to continue using the old wallet after upgrading, but to: 1. Upgrade the firmware first 2. Generate a completely new mnemonic phrase 3. Migrate all assets The main affected versions include: - Mk2/Mk3: 4.0.1 to 4.1.9 - Mk4/Mk5: Below 5.6.0 - Q: Below 1.5.0Q - Edge versions must also be updated to the corresponding fixed versions Upgrading the firmware can only prevent the generation of new weak seeds; it cannot fix old mnemonic phrases. When migrating, users should first verify the wallet fingerprint and receiving address, send a small test transaction, and only transfer the remaining funds after confirming everything is correct.
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads