#circle推出机构比特币抵押借贷
This news is kind of strange, actually.. A batch of bitcoins was transferred out from a hardware wallet, and the person who took them wasn’t a hacker..
👉 热点新闻
When most people see that a hardware wallet has a problem, their first reaction is: “Self-custody isn’t safe either.”.. But what’s truly worth looking at may not be this breach itself, but what happens after—someone comes out to clean up the mess..
Let’s make it clear what happened.. Starting on July 30 this year, the Coldcard hardware wallet had three consecutive waves of issues. The cumulative estimated losses exceed $100 million.. The reason wasn’t that the private key was pried open. Instead, at the time the wallet used a relatively weak software random source to generate the seed. That seed can be reconstructed.. The manufacturer later patched the firmware, but the addresses generated from the old seed can’t be “rescued” by the patch..
What’s strange is this.. This week, 52.37 BTC were moved into a newly created “recovery trust” address. The person doing it has been identified as a white-hat. That means these coins weren’t stolen—they were actively rescued by someone who understands the technical details, consolidated for custody first, and then returned after confirming ownership..
That transaction was confirmed at block 967,948. On-chain, there’s also a note pointing to a claims website. According to Galaxy Digital’s research head, these 52.37 coins make up only 2.8% of the currently tracked stolen funds, and in the second batch, about 40% has already been identified as white-hat behavior..
Things start to look different here.. 2.8% suggests two things: first, that most of the stolen coins still have no clear outcome/recipient; second, that “coins that were recovered” and “coins that were taken” have begun to be accounted for separately..
Even more interesting is why recovery was possible this time.. It’s not because the industry suddenly grew the ability to track and reclaim funds. It’s because the vulnerability was too orderly—if the seed can be reconstructed, then whoever knows the pattern can reconstruct it too: white-hats can, and hackers can as well.. In other words, the very same weakness created the opportunity to recover this time..
But the problem is.. This recovery trust was set up voluntarily. There’s no legal force behind it, and no one is required to return how much or how long it will take.. What victims can do is take their own addresses to that website to check whether they’ve been registered..
The market and money side already has a parallel story.. Another trend is that institutions like Circle are starting to ask customers to store bitcoins in its national trust custody, then use them as collateral to borrow stablecoins.. Money and coins are concentrating toward places where “someone is backing it up, and if something goes wrong, someone is responsible.”
And on the self-custody side, the first time, “security” was forced to be translated into a concrete number.. How many coins were taken, how many can be recovered, and how long it will take to recover them..
What’s truly worth watching are two numbers.. One is the proportion of the recovery trust that has actually been claimed and returned, and the other is how many old-seed addresses remain exposed after the patch..
The twist stays here.. If the following waves can also be recovered in the same way, the trust discount on hardware wallets might be repaired very quickly; but as long as a batch of coins is confirmed to not be recoverable, then the claim that “keeping the private key yourself is the safest” will need to be re-calculated from scratch..
This news is kind of strange, actually.. A batch of bitcoins was transferred out from a hardware wallet, and the person who took them wasn’t a hacker..
👉 热点新闻
When most people see that a hardware wallet has a problem, their first reaction is: “Self-custody isn’t safe either.”.. But what’s truly worth looking at may not be this breach itself, but what happens after—someone comes out to clean up the mess..
Let’s make it clear what happened.. Starting on July 30 this year, the Coldcard hardware wallet had three consecutive waves of issues. The cumulative estimated losses exceed $100 million.. The reason wasn’t that the private key was pried open. Instead, at the time the wallet used a relatively weak software random source to generate the seed. That seed can be reconstructed.. The manufacturer later patched the firmware, but the addresses generated from the old seed can’t be “rescued” by the patch..
What’s strange is this.. This week, 52.37 BTC were moved into a newly created “recovery trust” address. The person doing it has been identified as a white-hat. That means these coins weren’t stolen—they were actively rescued by someone who understands the technical details, consolidated for custody first, and then returned after confirming ownership..
That transaction was confirmed at block 967,948. On-chain, there’s also a note pointing to a claims website. According to Galaxy Digital’s research head, these 52.37 coins make up only 2.8% of the currently tracked stolen funds, and in the second batch, about 40% has already been identified as white-hat behavior..
Things start to look different here.. 2.8% suggests two things: first, that most of the stolen coins still have no clear outcome/recipient; second, that “coins that were recovered” and “coins that were taken” have begun to be accounted for separately..
Even more interesting is why recovery was possible this time.. It’s not because the industry suddenly grew the ability to track and reclaim funds. It’s because the vulnerability was too orderly—if the seed can be reconstructed, then whoever knows the pattern can reconstruct it too: white-hats can, and hackers can as well.. In other words, the very same weakness created the opportunity to recover this time..
But the problem is.. This recovery trust was set up voluntarily. There’s no legal force behind it, and no one is required to return how much or how long it will take.. What victims can do is take their own addresses to that website to check whether they’ve been registered..
The market and money side already has a parallel story.. Another trend is that institutions like Circle are starting to ask customers to store bitcoins in its national trust custody, then use them as collateral to borrow stablecoins.. Money and coins are concentrating toward places where “someone is backing it up, and if something goes wrong, someone is responsible.”
And on the self-custody side, the first time, “security” was forced to be translated into a concrete number.. How many coins were taken, how many can be recovered, and how long it will take to recover them..
What’s truly worth watching are two numbers.. One is the proportion of the recovery trust that has actually been claimed and returned, and the other is how many old-seed addresses remain exposed after the patch..
The twist stays here.. If the following waves can also be recovered in the same way, the trust discount on hardware wallets might be repaired very quickly; but as long as a batch of coins is confirmed to not be recoverable, then the claim that “keeping the private key yourself is the safest” will need to be re-calculated from scratch..