nile1.com
AI Agents Flag 5,000 Security Issues Across 390 Bitcoin Projects in 30-Hour Sweep
A volunteer collective known as the Bitcoin Red Team has uncovered nearly 5,000 security findings across 390 Bitcoin-related software projects in a 30-hour
#coinkite is an active hashtag on Bluesky. In the last 30 days, 9 people shared 30 posts with it — around 1 a day. Activity is up 229% versus the previous week, peaking on Aug 3 with 9 posts.
Tags most often used together with #coinkite.
nile1.com
AI Agents Flag 5,000 Security Issues Across 390 Bitcoin Projects in 30-Hour Sweep
A volunteer collective known as the Bitcoin Red Team has uncovered nearly 5,000 security findings across 390 Bitcoin-related software projects in a 30-hour
nile1.com
Coldcard Flaw Triggers $116M Bitcoin Loss Across 5,200 Addresses
A fatal security flaw in Coldcard hardware wallets has enabled attackers to steal 1,816 Bitcoins worth approximately $116 million, forcing Canadian
nile1.com
Apple's Anti-Spam Caps Block Critical $200,000 macOS Security Exploit
Apple’s decision to restrict security bug submissions in an effort to combat AI-generated spam has backfired, locking out legitimate cybersecurity researchers
www.hendryadrian.com
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
A firmware flaw in Coldcard hardware wallets enabled an attacker to drain 1,196 Bitcoin addresses in 41 minutes on July 30, stealing 1,082.65 BTC worth about $70.2 million. Galaxy Research and Block linked the incident to a deterministic PRNG bug in Coinkite’s Coldcard firmware, which could allow offline seed reconstruction from...
nile1.com
Coinkite Coldcard Flaw Triggers $114 Million Bitcoin Stolen in Hardware Exploit
A critical firmware vulnerability in Coinkite’s Coldcard hardware wallets has allowed attackers to siphon more than $114 million in Bitcoin, exposing
nile1.com
Flaw in Coldcard Firmware Build Pipeline Leads to $38 Million Bitcoin Heist
A silent error in the software compilation pipeline of Coinkite’s Coldcard hardware wallets allowed an attacker to drain approximately 594 Bitcoin—worth
nile1.com
Coldcard Hardware Flaw Triggers $89M Bitcoin Theft as Tether Posts $1.5B Q2 Profit
A severe cryptographic flaw in Coldcard hardware wallets has led to the theft of more than $89 million in Bitcoin, exposing critical vulnerabilities in
nile1.com
Coldcard Wallet Flaw Triggers Massive Bitcoin On-Chain Flight as Small Holders Move $2.5 Billion
A security vulnerability inside Coldcard hardware wallets sent retail Bitcoin holders scrambling to relocate their funds on July 31, driving small-value
nile1.com
Coldcard Hardware Wallet Exploit Drains $88.6M as Entropy Flaw Forces Mass Exit from Self-Custody
Galaxy Research’s Head of Research Alex Thorn reported that a third wave of fund sweeps recently siphoned 207.73 BTC from vulnerable wallets. Thorn cautioned
nile1.com
Coinbase Posts Unexpected $359 Million Q2 Loss as Spot Trading Activity Drops
Cryptocurrency exchange operator Coinbase posted a surprise second-quarter net loss of $359 million as depressed trading activity across digital asset markets
nile1.com
AI Agents Flag 5,000 Security Issues Across 390 Bitcoin Projects in 30-Hour Sweep
A volunteer collective known as the Bitcoin Red Team has uncovered nearly 5,000 security findings across 390 Bitcoin-related software projects in a 30-hour
mstdn.moimeme.ca
Original post on mstdn.moimeme.ca
nile1.com
$130 Million Coldcard Breach Triggers Security Alarm Over Hardware Wallet Randomness
A $130 million exploit targeting air-gapped Coldcard Bitcoin hardware wallets has exposed structural vulnerabilities in cryptographic entropy generation,
nile1.com
Coinkite Coldcard Firmware Bug Triggers $130 Million Bitcoin Theft
Attackers have stolen an estimated 2,055 Bitcoin—valued at roughly $130 million—from Coinkite Coldcard hardware wallets after a long-standing coding error
nile1.com
Apple's Anti-Spam Caps Block Critical $200,000 macOS Security Exploit
Apple’s decision to restrict security bug submissions in an effort to combat AI-generated spam has backfired, locking out legitimate cybersecurity researchers
nile1.com
Coinkite Coldcard Flaw Triggers $114 Million Bitcoin Stolen in Hardware Exploit
A critical firmware vulnerability in Coinkite’s Coldcard hardware wallets has allowed attackers to siphon more than $114 million in Bitcoin, exposing
nile1.com
Coldcard Flaw Triggers $116M Bitcoin Loss Across 5,200 Addresses
A fatal security flaw in Coldcard hardware wallets has enabled attackers to steal 1,816 Bitcoins worth approximately $116 million, forcing Canadian
dlvr.it
Coldcard Wallet Security Incident Linked to Multi-Million Dollar Bitcoin Theft
There has been a connection between a critical firmware flaw in the Coldcard hardware wallet and one of the largest cryptocurrency thefts of the year, after hackers allegedly drained nearly $70.2 million in Bitcoins (BTC) from 1,196 wallets on July 30 by exploiting a critical firmware flaw, according to Galaxy Research. A firmware integration error introduced in March 2021 is responsible for the vulnerability, which affects Coldcard, a Bitcoin-only hardware wallet developed by Canadian company Coinkite. According to security researchers, affected firmware versions generated wallet recovery seeds using deterministic software-based pseudorandom number generators (PRNGs) rather than the hardware random number generators (RNGs) of the devices. In this way, the amount of randomness necessary to create cryptographic seeds has been significantly reduced. Block researchers explained that, under certain circumstances, an attacker could reproduce seed values offline under sufficient knowledge of the device's unique identification number and internal state. Attackers can then identify and steal funds from vulnerable wallets by matching those candidate seeds against publicly available blockchain addresses. It was found that the flaw occurred as a result of a production configuration error resulting in affected Coldcard devices relying on MicroPython's Yasmarang pseudorandom number generator instead of the hardware random number generator intended for them. During initialization of the fallback algorithm, unique identifiers and timer values of the device were used without the collection of fresh entropy, leading to significantly more predictable recovery seeds. Contrary to conventional cryptocurrency attacks directed towards exchanges, smart contracts, and online wallets, this incident involved hardware wallets designed to remain offline. According to security experts, the compromise did not require the device to be connected directly to the internet. As an alternative, attackers are alleged to have generated a large number of possible recovery seeds offline, derived the addresses of the corresponding wallets, and compared them with blockchain records available on the Internet until they found matching wallets containing Bitcoins. As determined by investigators, the attacker generated candidate recovery seeds using hardware configured under similar conditions, then deduced the Bitcoin address corresponding to each seed. The address of a blockchain is publicly visible, and matching the address of a recreated seed to the address of an active wallet would allow the attacker to retrieve the private keys and transfer funds without physically accessing the victim's device. A firmware update was released by Coinkite on July 31 for all Coldcard models that were affected. However, the company has stressed that installing the update alone will not secure wallets that have been created with vulnerable firmware. Users whose recovery seeds were generated on affected versions have been advised to generate new seeds utilizing the patched firmware and transfer their Bitcoin to new wallets as soon as possible. It is important to note that even when an old seed is restored on an updated firmware or another wallet, the underlying weakness remains. Galaxy Research has reported that the stolen funds were transferred in batches over a period of six Bitcoin blocks rather than through a single continuous transaction. Observations by researchers indicated that three interconnected blocks did not show any related activity, indicating that the transactions were deliberately grouped before being broadcast. Coldcard versions 4.0.1 to 4.1.9, Mk4 and Mk5 versions before 5.6.0, Q versions before 1.5.0Q, and Edge builds released prior to the latest patches are affected by this firmware. The vulnerability has been estimated by Coinkite to reduce the effective entropy of wallet recovery seeds by approximately 40 bits for Mk3 devices and around 72 bits for Mk4, Mk5 and Q devices. This results in significantly lower levels of security than a standard 12-word BIP-39 seed's 128-bit encryption. Researchers noted that practical challenges in recovering a seed are still influenced by factors such as device characteristics, boot timing and computational resources. It was noted by Coinkite that wallets generated with at least 50 fair and private dice rolls do not suffer from this vulnerability. Despite the fact that a strong passphrase provided additional security, users should nonetheless replace vulnerable seeds with stronger BIP-39 passphrases. Multisignature wallets will not be compromised if all signing devices are not affected by the same issue. There has been no public identification of the attacker. According to Galaxy Research, the observed on-chain transaction patterns indicate a coordinated wallet sweep, but do not conclusively indicate theft. Researchers also observed that blockchain activity followed a distinctive transaction pattern, though they cautioned that on-chain analysis alone cannot conclusively prove theft. The pattern instead pointing to coordinated wallet sweeps consistent with a single operator or related group of operators, which has raised concerns over the importance of secure random number generation in cryptocurrency wallets. In order to store cryptocurrency offline securely, hardware devices that remain disconnected from the internet must maintain strong cryptographic entropy during wallet creation, and any weakness in that process can compromise its security. After Coinspect released the "Ill Bloom" vulnerability in just weeks past, another weak random number generation vulnerability has led to more than $5 million worth of cryptocurrency theft across Bitcoin, Ethereum, Tron, Rootstock and Polygon, with the "Ill Bloom" vulnerability being linked to more than $5 million in cryptocurrency thefts. Even wallets designed with strong offline security can be compromised by vulnerabilities in cryptographic randomness. A subsequent update from Galaxy Research identified two more suspected Coldcard-related wallet sweeps, which increased the estimated losses to 1,367.05 Bitcoins, worth approximately $88.6 million across 4,585 addresses, for a total of 1,367.05 Bitcoins. In addition to sharing details with federal investigators, compliance organizations and cybersecurity teams about nearly 600 suspected attacker-controlled addresses, the firm said the activity is ongoing.
nile1.com
Coldcard Hardware Flaw Triggers $89M Bitcoin Theft as Tether Posts $1.5B Q2 Profit
A severe cryptographic flaw in Coldcard hardware wallets has led to the theft of more than $89 million in Bitcoin, exposing critical vulnerabilities in
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.