Cold storage just got a reality check.
A firmware flaw in Coldcard, one of the most trusted Bitcoin hardware wallets, let an attacker drain 594 BTC (about $38 million) from roughly 500 wallets in just 25 minutes. (Crypto News) This was not phishing. It was not malware. A bug in seed generation had weakened randomness since 2021, (CryptoTicker) making private keys guessable instead of truly random.
Here is the part that should worry every self-custody holder: updating your firmware today does not fix a seed that was already generated under the flawed code. If your seed was created during the vulnerable window, you need a brand new seed, not a patch.
My take: single-sig cold storage is not automatically safe storage. This is a strong argument for multisig across wallets from different manufacturers, so one firmware bug cannot expose your entire balance.
Would this change how you store BTC, or are you sticking with single-sig either way?
$BTC #Bitcoin #SelfCustody
A firmware flaw in Coldcard, one of the most trusted Bitcoin hardware wallets, let an attacker drain 594 BTC (about $38 million) from roughly 500 wallets in just 25 minutes. (Crypto News) This was not phishing. It was not malware. A bug in seed generation had weakened randomness since 2021, (CryptoTicker) making private keys guessable instead of truly random.
Here is the part that should worry every self-custody holder: updating your firmware today does not fix a seed that was already generated under the flawed code. If your seed was created during the vulnerable window, you need a brand new seed, not a patch.
My take: single-sig cold storage is not automatically safe storage. This is a strong argument for multisig across wallets from different manufacturers, so one firmware bug cannot expose your entire balance.
Would this change how you store BTC, or are you sticking with single-sig either way?
$BTC #Bitcoin #SelfCustody