Ξliézer Ndinga
Ξliézer Ndinga|8月 02, 2026 14:52
Explaining in layman terms the @COLDCARDwallet vulnerability: Recent analysis by @glxyresearch estimates that nearly $89 million worth of Bitcoin was stolen from more than 4,500 wallets due to a firmware vulnerability. It’s an incredibly sad moment for the victims who lost a significant portion of their savings. What happened? A software bug dating back to 2021 affected the random-number generation in certain Coldcard firmware versions. Hardware wallets are designed to act like digital safes: they create a highly random secret (the seed phrase) that only the owner controls to move funds. In this case, the randomness was weaker than it should have been, similar to a password that a strength meter would flag as only “medium” or “weak.” Because the possible secrets came from a much smaller set than expected, attackers could systematically generate them offline on their own computers, match them to wallets that held Bitcoin on the public blockchain, and move the funds, all without ever touching the physical devices. In the physical world, it would be closer to discovering that a particular brand of combination lock only ever used a limited range of codes, then trying those codes from afar until the locks opened.(Ξliézer Ndinga)
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads