header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

In the Coldcard Theft Incident, I Learned Why the Impact Was Much Greater Than Meets the Eye

Read this article in 13 Minutes
What is truly impacted is Bitcoin's most core group of believers

Unexpectedly, a vulnerability from 5 years ago led to this year's largest Bitcoin theft.


On July 30, an anomaly was discovered when hundreds of bitcoins were rapidly drained from hundreds of addresses. The attack quickly expanded as the perpetrator scanned thousands of Bitcoin addresses, making off with nearly 2,000 bitcoins worth hundreds of millions of dollars.


The root cause was swiftly identified as a bug in a hardware wallet called Coldcard during the mnemonic seed generation process. It was a weak random number generation issue, meaning the randomness was not so random and could be guessed.


Initially, there was not much attention from domestic users due to Coldcard's low market share in the country. However, overseas reactions were explosive as Coldcard is highly regarded internationally. After fermenting for several days, a single-day transfer volume of less than 1 BTC on July 31 reached 39,600 BTC, marking the highest level since the 2022 FTX flash crash.


This incident was likely another vulnerability discovered and exploited by an AI model, similar to the impact of Zcash's halving attack. This time, the consequences seem to be more severe, not evident in the data, affecting mostly trust, which is immeasurable.


To understand the frontline perspective on the Coldcard incident and its impact, BlockBeats reached out to SlowMist founder Cosmos. Some victims have engaged SlowMist for assistance, and the team has been monitoring the Coldcard incident closely. According to Cosmos, the theft's repercussions are profound as it targets Bitcoin's most core group of believers.


BlockBeats Interview: Has Coldcard engaged a security firm to assist in recovering the assets? With the stolen bitcoins now valued at hundreds of millions, is the likelihood of recovery high?


Cosmos: It is currently unclear which hacking group is behind this. We need to analyze their subsequent transfer methods to make a judgment. If it turns out to be a state-sponsored hacking group (e.g., North Korean hackers), recovery will be challenging.


Thus far, aside from issuing some security notices, we have not seen any efforts by Coldcard to involve a security team. Some individual victims of Coldcard theft have approached us to help them recover their assets.


BlockBeats Interview: Looking at the cause of this theft, it boils down to a lack of randomness in the random number generation. Randomness issues seem to surface almost every year in the crypto industry's history. Why does this incident appear to be exceptionally severe?


Cosine: Solely in terms of quantity and amount, a transaction of over a thousand bitcoins is not the largest in history. In the past, events such as Mt. Gox, Bitfinex, and the Luhod mining pool were hacked, resulting in the loss of tens of thousands to hundreds of thousands of bitcoins. Even a random bridge hack could exceed the amount involved in this incident.


However, the issue lies in Coldcard's excellent reputation. They are open-source, transparent, and cater to geeks with a minimalist approach, making them a favorite among Bitcoin OGs and believers. The fact that something that seemed so perfect encountered a problem dealt a significant blow to this steadfast user base.


At the core of this incident was a severe lack of entropy during the generation of the mnemonic, leading to a seed with much weaker randomness than expected. Hackers could use brute force to derive a user's mnemonic. This is the most fundamental and also the most lethal security issue concerning crypto assets.


What I find most absurd is that with the emergence of powerful AI models, neither Coldcard nor Bitcoin believers bothered to review the code using AI, but the hackers did. Because if the focus is solely on vulnerabilities related to the mnemonic's randomness, AI today can easily identify and discover such issues.


Therefore, this incident has garnered significant attention because it shook the core belief system of the community.


Rhythm BlockBeats: So, from your perspective just now, would you say that this hack will have a profound impact on the crypto industry?


Cosine: When a historically reputable, open-source geek hardware wallet encounters issues despite being considered "perfect," it severely undermines the community's confidence in similar products. Users will start to question: Does the wallet I currently use have issues? Are the mnemonics generated in the future secure?


Rhythm BlockBeats: Would you recommend that crypto projects now run their code through AI to find vulnerabilities? Or how is SlowMist currently handling this?


Cosine: I would recommend doing so.


The impact of AI on the entire security industry is much greater than the current public perception. Hackers operate almost without any restrictions; they can construct powerful models tailored to their needs, while the defense side is constrained by model access, computing power, audits, and various other limitations.


We do not conduct audits on the source code of public blockchains such as Bitcoin and Ethereum because of limited resources. Instead, we prioritize important clients, ensuring that their risk of exposure in the AI era is minimized. By using AI to retrospectively analyze past projects, we have indeed uncovered many issues that had previously gone unnoticed, yielding excellent results.


Rhythm BlockBeats: This raises another rather pessimistic question. As models become stronger, will the general distrust of early-stage encryption technologies intensify? For example, Zcash previously experienced a similar impact?


Cosine: It definitely will. Security can never reach 100%. The battle between offense and defense is always escalating, and hackers, driven by AI, have far greater capabilities than the defense side. They can directly cash out once they break through, making it a highly cost-effective endeavor. Meanwhile, the defense side is constrained by various processes and resources.


In this unequal scenario, security incidents of a much larger scale than before are bound to occur, with the possibility of reaching the tens of billions of dollars. Even Bitcoin's own code may have issues discovered in the future.


However, overall, I am not pessimistic about the industry's response to these threats. The battle between offense and defense will always exist, and cryptographic events will undoubtedly become more robust.


Rhythm BlockBeats: Some views are beginning to turn towards the advantages of centralized exchanges, believing that centralized exchanges are more secure. What is your opinion?


Cosine: Indeed, several top centralized exchanges have made significant investments in basic security. Even if issues arise, they have a certain level of fallback ability, unless it is a super catastrophic event.


For most users, it is actually very difficult to independently handle hardcore operations such as mnemonic phrases and multi-signatures. In the past, wallets were mostly chosen based on reputation and recommendations from acquaintances. However, this incident has made everyone realize that even wallets widely recognized as good may have hidden dangers. Therefore, some users feel more at ease returning their assets to centralized exchanges with a certain level of strength. This mindset is understandable.


Rhythm BlockBeats: For ordinary users who do not understand the technology and do not review wallet code, how should they guard against incidents like Coldcard?


Cosine: First of all, I recommend that all users use a passphrase for their mnemonic phrase. This can be understood as adding a password layer to the mnemonic phrase, which is much better than not having one. Add an 8-digit, slightly complex passphrase as a starting point, provided you don't forget it. This is now supported by mainstream hardware wallets.


Even if similar incidents occur again, hackers will first transfer funds from those addresses without a passphrase. This provides significant protection for your primary assets. For example, you can place a very small amount of funds in an address without a passphrase, and keep large funds in an address with a passphrase. Once the small amount is moved, it indicates a leak of the mnemonic phrase. However, cracking the passphrase is very costly for hackers, buying you valuable time.


For the average user who has no understanding of the industry at all, it's fine to use services provided by centralized institutions and rely on them to handle any issues.


Additionally, here are three general suggestions for all players:


· Organize Your Assets: Take the time to review whether your wallet recovery phrase is clear and whether it may have been leaked. If there is any uncertainty, consider changing your storage method.

· Stay Calm: Don't rush into using a fake wallet or fall victim to phishing scams.

· Practice Segregated Thinking: Keep uncertain assets on a separate device (even air-gapped), don't mix them together. This is much safer than assuming everything is fine.


By following these steps, you can effectively mitigate over 90% of common risks.


Welcome to join the official BlockBeats community:

Telegram Subscription Group: https://t.me/theblockbeats

Telegram Discussion Group: https://t.me/BlockBeats_App

Official Twitter Account: https://twitter.com/BlockBeatsAsia

举报 Correction/Report
Choose Library
Add Library
Cancel
Finish
Add Library
Visible to myself only
Public
Save
Correction/Report
Submit