šŸ”„The Coldcard vulnerability and how it affects cryptocurrency self-custody šŸ‘€

More new incidents continue to come out about the Coldcard wallet vulnerability, which has already led to the theft of more than 1,300 #BTC worth approximately $83 million to date. These funds were taken from thousands of addresses since last week (when the vulnerability was detected), making this one of the biggest self-custody failures in history of #bitcoin .

According to Jameson Loop, a Bitcoin security researcher, this incident shouldn’t affect self-custody overall, but it does send a clear message to those who decide to practice self-custody: ā€œDon’t trust—verify.ā€

This refers to the fact that self-custody users end up trusting the hardware provider, software developers, and security researchers (audits). The user who chooses self-custody has to verify.

How did the #Coldcard vulnerability happen?
The vulnerability detected in Coldcard is in the seed generation process from 2021. By Coldcard’s design, the entropy used to randomize wallet seeds was reduced, which allowed attackers to carry out brute-force attacks (it’s even said with the help of AI) against the affected wallets without needing to physically touch the devices.

That’s why Coldcard’s manufacturer, Coinkite, had to release an emergency patch (firmware) for all affected models. It also advised users who had generated a seed with the faulty software (March 2021 version) to move funds to a wallet address created with a new seed.

And you—do you trust cold wallets to store your cryptocurrencies, or do you prefer to keep them on a centralized exchange like Binance?

šŸ‘‰More crypto updates...
Share and follow me for more šŸ‘ˆšŸ˜Ž
$BTC