Saturday, August 1, 2026

Creating liberating content

Why 110 corporate blockchains...

Corporate blockchains are multiplying, but Coinbase CEO Brian Armstrong expects the boom to...

Coldcard Wallet Flaw Exposes...

The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is...

Coinbase spent 5 years...

Coinbase told investors on Thursday that 88% of its second-quarter net revenue came...

New Bitcoin study shows...

A new arXiv preprint studying seven major Bitcoin crashes found the warning signal...

Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider

Since over $70 million in Bitcoin was stolen yesterday by an attack that exploited a fault in the Coldcard’s system, it has been reported that the thief used a top blockchain services provider for help. 

Writing on X Friday, engineer at payments company Block, Clay Garrett, said that the provider — who he did not name at the request of the services provider — had been contacted after finding blockchain movements matched the “suspected workflow” of the attacker. 

“During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps,” Garrett said. 

Read More:  Bitcoin ETFs Take In Nearly $1B In New Money — But What Will The Price Do?

“That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps,” Garrett continued, adding that the authorities had been notified. 

Galaxy Digital’s research arm also wrote on X that the thief had an unusual pattern of moving the coins. 

“The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins,” the company said, adding that Bitcoiners should move funds out of single-signature Coldcard addresses and into secure custody.

Read More:  Clarity Act Enters Critical Two-Week Window As Senate Heads Into Recess

After over $35 million in Bitcoin was drained from wallets on Thursday, Coinkite said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator. 

Read More:  Cantor SPAC And Adam Back's Bitcoin Treasury Renegotiate Merger Terms, Vow New Structure

This allowed private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force.

Later on Friday, Coinkite admitted all of its models were vulnerable following more thefts. Over $70 million has so far been swiped and engineers have warned that more Bitcoin addresses could be at risk. 

The company makes a number of Bitcoin products, including cold storage hardware wallets.

Facebook Comments Box
spot_img

Continue reading

Coldcard Wallet Flaw Exposes Years Of Bitcoin Seeds After $70M In BTC Stolen

The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is at risk following a $70 million hack. Coinkite on Thursday admitted that its Coldcard Mk3 model was affected following the hack and advised users to move...

US Closes In Of Iran’s Bitcoin Insurance Policy

Iran has been dodging sanctions by accepting pay in Bitcoin from ships passing through the Strait of Hormuz, according to a Friday announcement from the U.S. Treasury’s Office of Foreign Assets Control. The OFAC sanctioned the...

Clarity Act Should Pass, Says Coinbase’s Policy Officer

The Clarity Act will likely get through despite some — older — Democrats holding it back, according to Coinbase’s Chief Policy Officer, Faryar Shirzad.  Speaking on The Hill’s morning Rising show Friday, Shirzad said that crypto was...