Binance Square
#coldcard

coldcard

40,928 рет көрілді
118 адам талқылап жатыр
Joyce加密研究
·
--
超过1000枚BTC被盗,这次被攻破的不是比特币,而是“随机数”。 这个Coldcard漏洞比普通交易所被黑更值得注意。 因为这次不是用户点了钓鱼链接,也不是私钥上传到云端。 问题出在最开始: 钱包帮你生成助记词的时候,随机得不够随机。 受影响的部分Mk3种子有效熵大约只有40 bits,本来大家以为自己拿着一把几乎不可能猜中的钥匙,结果攻击者面对的搜索空间小了几个数量级。 更麻烦的是,Mk4、Mk5和Q的旧版本也受到影响,只是攻击难度更高。 这事真正打脸的是一句币圈老话: “Not your keys, not your coins.” 现在看来还得补一句: 你的keys,也得确认到底是怎么生成的。 短期对 $BTC 只给轻度利空,3/10。 1000 BTC不足以改变BTC供需。 但对硬件钱包行业,明显利空,8/10。 以后大户买冷钱包,不会只问“有没有联网”“有没有安全芯片”,还会问: 随机数从哪来?熵够不够?代码谁审计过? 反而多签、独立熵、不同厂商组合这些方案,我觉得会因此得到更多重视。 还有个细节挺有意思:开发者已经借助前沿AI模型快速复现了攻击。 以后安全行业最大的变化可能就是—— 漏洞发现速度和漏洞利用速度,都被AI一起加速了。 如果你手里的冷钱包种子本身有问题,升级设备并不会让旧种子突然变安全。 这可能才是很多人最容易误解的地方。 $BTC #Coldcard #硬件钱包 #coldcard漏洞被盗594枚btc
超过1000枚BTC被盗,这次被攻破的不是比特币,而是“随机数”。
这个Coldcard漏洞比普通交易所被黑更值得注意。
因为这次不是用户点了钓鱼链接,也不是私钥上传到云端。
问题出在最开始:
钱包帮你生成助记词的时候,随机得不够随机。
受影响的部分Mk3种子有效熵大约只有40 bits,本来大家以为自己拿着一把几乎不可能猜中的钥匙,结果攻击者面对的搜索空间小了几个数量级。
更麻烦的是,Mk4、Mk5和Q的旧版本也受到影响,只是攻击难度更高。
这事真正打脸的是一句币圈老话:
“Not your keys, not your coins.”
现在看来还得补一句:
你的keys,也得确认到底是怎么生成的。
短期对 $BTC 只给轻度利空,3/10。
1000 BTC不足以改变BTC供需。
但对硬件钱包行业,明显利空,8/10。
以后大户买冷钱包,不会只问“有没有联网”“有没有安全芯片”,还会问:
随机数从哪来?熵够不够?代码谁审计过?
反而多签、独立熵、不同厂商组合这些方案,我觉得会因此得到更多重视。
还有个细节挺有意思:开发者已经借助前沿AI模型快速复现了攻击。
以后安全行业最大的变化可能就是——
漏洞发现速度和漏洞利用速度,都被AI一起加速了。
如果你手里的冷钱包种子本身有问题,升级设备并不会让旧种子突然变安全。
这可能才是很多人最容易误解的地方。
$BTC #Coldcard #硬件钱包 #coldcard漏洞被盗594枚btc
忽必烈烈:
多签钱包。 如果资金不超 50 万美元,放币安就很安全。
#coldcardexploitattackerscontrol1366btc أمس: تم فقد 594 BTC خلال 25 دقيقة. 😱 اليوم: المتسلّلون يتحكّمون في 1,366.38 BTC! 📉📉📉 يقول «Galaxy Research» إنها رسميًا 3 موجات من الهجمات. هل انتهت بعد؟ 🕵️‍♂️ ربما هو هاكر واحد لديه أداة أفضل، أو ربما المزيد انضمّوا إلى الحفلة! فوضى كاملة لمستخدمي Coldcard منذ مارس 2021. 💸 ماذا تفعل؟ حدّث البرنامج الثابت الآن، وانتقل إلى عبارة بذرة (Seed phrase) جديدة، أو ربما فقط خزّن BTC تحت مرتبتك؟ (مزحة!) 😂 لا تنخدع! ليس نصيحة مالية. متابعة من فضلكم #BTC #Coldcard #HackerAlert $BTC {future}(BTCUSDT)
#coldcardexploitattackerscontrol1366btc
أمس: تم فقد 594 BTC خلال 25 دقيقة. 😱
اليوم: المتسلّلون يتحكّمون في 1,366.38 BTC! 📉📉📉
يقول «Galaxy Research» إنها رسميًا 3 موجات من الهجمات. هل انتهت بعد؟ 🕵️‍♂️ ربما هو هاكر واحد لديه أداة أفضل، أو ربما المزيد انضمّوا إلى الحفلة! فوضى كاملة لمستخدمي Coldcard منذ مارس 2021. 💸
ماذا تفعل؟ حدّث البرنامج الثابت الآن، وانتقل إلى عبارة بذرة (Seed phrase) جديدة، أو ربما فقط خزّن BTC تحت مرتبتك؟ (مزحة!) 😂 لا تنخدع!
ليس نصيحة مالية.

متابعة من فضلكم

#BTC #Coldcard #HackerAlert
$BTC
Muhammad muaaz0334:
Hello m.elon musk space x how are you i know you are a son off prostitute how many germs will be proceed of i don't know my money gone i will take a grave my god will himself take you from you are a very poor man my 3 times money going to eat allha will have to account you collect the money ate
Coldcard这次的固件漏洞,确实是硬件钱包领域少见的严重事件。 7月30日,攻击者利用种子生成过程中的随机数缺陷,在大约 40 分钟内扫走了大量 $BTC 。 初期确认金额约 594 BTC(当时约 3800万美元),来自约500个地址;Galaxy Research 后续链上分析将规模扩大到 1,082.65 BTC(约 7000万美元),涉及 1,196个地址。 问题根源在于2021年3月之后的部分固件版本,设备在生成种子时未能正确调用硬件真随机数生成器,导致熵值大幅下降(Mk3约40位),私钥可被离线重建。攻击全程无需接触实体设备。 官方已发布修复固件,但已生成的弱种子无法通过更新修复,受影响用户必须重新生成新种子并尽快迁移资金。 CZ也公开提醒:即使是硬件钱包也可能存在漏洞,风险一直存在,链上没有 100% 安全。 从影响范围和技术性质来看,这是目前已知规模最大的一次硬件钱包固件漏洞攻击,对自托管安全性的信任冲击不小。平时还是建议多关注官方安全公告,避免把所有资产集中在单一设备上。 #Bitcoin #Coldcard #硬件钱包 #链上安全
Coldcard这次的固件漏洞,确实是硬件钱包领域少见的严重事件。

7月30日,攻击者利用种子生成过程中的随机数缺陷,在大约 40 分钟内扫走了大量 $BTC

初期确认金额约 594 BTC(当时约 3800万美元),来自约500个地址;Galaxy Research 后续链上分析将规模扩大到 1,082.65 BTC(约 7000万美元),涉及 1,196个地址。

问题根源在于2021年3月之后的部分固件版本,设备在生成种子时未能正确调用硬件真随机数生成器,导致熵值大幅下降(Mk3约40位),私钥可被离线重建。攻击全程无需接触实体设备。

官方已发布修复固件,但已生成的弱种子无法通过更新修复,受影响用户必须重新生成新种子并尽快迁移资金。

CZ也公开提醒:即使是硬件钱包也可能存在漏洞,风险一直存在,链上没有 100% 安全。

从影响范围和技术性质来看,这是目前已知规模最大的一次硬件钱包固件漏洞攻击,对自托管安全性的信任冲击不小。平时还是建议多关注官方安全公告,避免把所有资产集中在单一设备上。

#Bitcoin #Coldcard #硬件钱包 #链上安全
Yee-H:
硬件都被盗
Main reason for market volatility 👍 🚨 JUST IN: #Bitcoin stolen in the Coldcard hardware wallet incident now exceeds $88 million. K According to the latest reports, the attack has now reached approximately: • 1,367 $BTC stolen ( $88.6M) • 4,500+ affected Bitcoin addresses • Researchers say this was carried out in multiple waves of exploitation. • The stolen BTC has reportedly not been moved yet. What happened? The issue is not a remote hack of Coldcard devices. Instead, it affects seed phrases generated on specific vulnerable firmware versions. If a wallet’s recovery seed was created using an affected version, the seed may have been predictable, allowing attackers to recover the wallet and drain funds. If you own a Coldcard: Update to the latest firmware. ✔️ Generate a brand-new seed phrase (updating alone is not enough if your current seed was created on an affected version). ✔️ Transfer your BTC to addresses derived from the new seed. ✔️ Verify whether your device and firmware version are included in the official advisory. ✔️ This incident is another reminder that hardware wallets are only as secure as the firmware and the seed generation process behind them. Self-custody remains one of the safest ways to hold #Bitcoin but it also means staying on top of security updates. Always verify information through official announcements before taking action. #BTC #Coldcard #SelfCustody $BTC
Main reason for market volatility 👍

🚨 JUST IN: #Bitcoin stolen in the Coldcard hardware wallet incident now exceeds $88 million.

K According to the latest reports, the attack has now reached approximately:

• 1,367 $BTC stolen ( $88.6M)
• 4,500+ affected Bitcoin addresses
• Researchers say this was carried out in multiple waves of exploitation.
• The stolen BTC has reportedly not been moved yet.

What happened?

The issue is not a remote hack of Coldcard devices.

Instead, it affects seed phrases generated on specific vulnerable firmware versions. If a wallet’s recovery seed was created using an affected version, the seed may have been predictable, allowing attackers to recover the wallet and drain funds.

If you own a Coldcard:

Update to the latest firmware. ✔️

Generate a brand-new seed phrase (updating alone is not enough if your current seed was created on an affected version). ✔️

Transfer your BTC to addresses derived from the new seed. ✔️

Verify whether your device and firmware version are included in the official advisory. ✔️

This incident is another reminder that hardware wallets are only as secure as the firmware and the seed generation process behind them.
Self-custody remains one of the safest ways to hold #Bitcoin but it also means staying on top of security updates.

Always verify information through official announcements before taking action.
#BTC #Coldcard #SelfCustody $BTC
🚨$70M GONE IN 41 MINUTES - no hack, no phishing, no physical access. Nearly 1,200 COLDCARDS wallets drained. The attacker never touched a device or stole a seed phrase. The reverse-engineered predictable randomness in flawed firmware (Mk2-Mk5, Q) to recreate private keys offline. Pure math, zero contact. This is your reminder: NEVER hold 100% of your stack in one wallet or one brand. Hardware wallets aren't infallible, diversify across devices, use multi-sig, split your cold storage. One flaw = total loss. If you're on affected Coldcard firmware, migrate NOW. Not your keys, not your coins. But also: not your diversification, not your safety.🔐 #bitcoin #BTC #Coldcard
🚨$70M GONE IN 41 MINUTES - no hack, no phishing, no physical access.

Nearly 1,200 COLDCARDS wallets drained. The attacker never touched a device or stole a seed phrase. The reverse-engineered predictable randomness in flawed firmware (Mk2-Mk5, Q) to recreate private keys offline. Pure math, zero contact.

This is your reminder: NEVER hold 100% of your stack in one wallet or one brand. Hardware wallets aren't infallible, diversify across devices, use multi-sig, split your cold storage. One flaw = total loss.

If you're on affected Coldcard firmware, migrate NOW.
Not your keys, not your coins. But also: not your diversification, not your safety.🔐

#bitcoin #BTC #Coldcard
8900万美元,Coldcard 被黑。 更没想到的是——这次投资者的反应,居然和 FTX 崩盘时正好相反。 2022年FTX暴雷,大家吓得赶紧提币,疯狂涌向冷钱包,觉得“只有自己拿住私钥才安全”。 现在 Coldcard 一出事,反而有人开始把 BTC 往交易所转了。 有意思。 逻辑其实也简单:既然自托管硬件钱包也能被攻破,那“绝对安全”的信仰就动摇了。与其放在自己手里提心吊胆地管技术风险,还不如直接丢给交易所的保险和风控。 一次攻击,直接改写了市场对“安全”的定义。 不过话说回来,到底是因为害怕继续持有这种钱包,还是准备转移仓位搞别的?链上数据可能藏着答案。 安全这东西,永远是相对的不是绝对的。你怎么看? #Coldcard #BTC #加密安全
8900万美元,Coldcard 被黑。

更没想到的是——这次投资者的反应,居然和 FTX 崩盘时正好相反。

2022年FTX暴雷,大家吓得赶紧提币,疯狂涌向冷钱包,觉得“只有自己拿住私钥才安全”。

现在 Coldcard 一出事,反而有人开始把 BTC 往交易所转了。

有意思。

逻辑其实也简单:既然自托管硬件钱包也能被攻破,那“绝对安全”的信仰就动摇了。与其放在自己手里提心吊胆地管技术风险,还不如直接丢给交易所的保险和风控。

一次攻击,直接改写了市场对“安全”的定义。

不过话说回来,到底是因为害怕继续持有这种钱包,还是准备转移仓位搞别的?链上数据可能藏着答案。

安全这东西,永远是相对的不是绝对的。你怎么看?

#Coldcard #BTC #加密安全
⚡ 洞察:彭博社的 Eric Balchunas 质疑 Coldcard 的安全性。 他表示,Coldcard 仅有 5 人团队,这正是 Coinbase、Ledger,尤其是现货比特币 ETF 值得支付额外费用的原因。 #比特币 #Coldcard #安全
⚡ 洞察:彭博社的 Eric Balchunas 质疑 Coldcard 的安全性。

他表示,Coldcard 仅有 5 人团队,这正是 Coinbase、Ledger,尤其是现货比特币 ETF 值得支付额外费用的原因。

#比特币 #Coldcard #安全
🚨 Security Update: Coldcard Vulnerability Exploited — August 2, 2026 $BTC {future}(BTCUSDT) Following up on the Coldcard hardware wallet vulnerability we flagged last week: it's now been actively exploited, draining approximately $70M in BTC from affected users. 🤔 What happened: Coldcard CEO Rodolfo Novak issued a public apology, confirming the company's review process failed to catch the firmware bug before it could be exploited. Emergency firmware has now been released: version 4.2.0+ for Mk3, 5.6.0+ for Mk4/Mk5, and 1.5.0Q+ for Coldcard Q. ⚠️ Critical detail for anyone affected: Simply updating firmware does NOT secure existing funds — private keys derived from a compromised seed remain unchanged even after the update. Affected users must generate an entirely new recovery phrase on the corrected firmware and migrate their BTC to it. Security firm Galaxy has also warned that future attacks remain possible against any Coldcard-generated address from the vulnerable period. 📊 Why this matters beyond Coldcard users: This reinforces something we discussed last week — even "cold storage" (designed to be the safer option) isn't automatically immune to every risk category. Firmware-level vulnerabilities are a different threat than remote hacking, but they're still a real risk that hardware wallet users need to stay aware of. 📌 My take: This is a sobering real-world example of the theoretical risk we covered days ago. If you use a Coldcard device, checking official channels for the exact remediation steps (new seed generation, not just firmware update) should be an immediate priority, not something to delay. ⚠️ Disclaimer: This is commentary based on public reporting, not financial or security advice. Verify directly with official Coldcard channels if affected. #Crypto #CryptoSecurity #Coldcard #BinanceSquare
🚨 Security Update: Coldcard Vulnerability Exploited — August 2, 2026
$BTC


Following up on the Coldcard hardware wallet vulnerability we flagged last week: it's now been actively exploited, draining approximately $70M in BTC from affected users.

🤔 What happened:

Coldcard CEO Rodolfo Novak issued a public apology, confirming the company's review process failed to catch the firmware bug before it could be exploited. Emergency firmware has now been released: version 4.2.0+ for Mk3, 5.6.0+ for Mk4/Mk5, and 1.5.0Q+ for Coldcard Q.

⚠️ Critical detail for anyone affected:

Simply updating firmware does NOT secure existing funds — private keys derived from a compromised seed remain unchanged even after the update. Affected users must generate an entirely new recovery phrase on the corrected firmware and migrate their BTC to it. Security firm Galaxy has also warned that future attacks remain possible against any Coldcard-generated address from the vulnerable period.

📊 Why this matters beyond Coldcard users:

This reinforces something we discussed last week — even "cold storage" (designed to be the safer option) isn't automatically immune to every risk category. Firmware-level vulnerabilities are a different threat than remote hacking, but they're still a real risk that hardware wallet users need to stay aware of.

📌 My take: This is a sobering real-world example of the theoretical risk we covered days ago. If you use a Coldcard device, checking official channels for the exact remediation steps (new seed generation, not just firmware update) should be an immediate priority, not something to delay.

⚠️ Disclaimer: This is commentary based on public reporting, not financial or security advice. Verify directly with official Coldcard channels if affected.

#Crypto #CryptoSecurity #Coldcard #BinanceSquare
⚠️ Security alert The Coldcard hack has triggered massive on-chain activity, with 39,600 BTC moved via small transactions. CryptoQuant notes this is the largest sub-1 BTC movement since the FTX collapse, with the attack still active. #Coldcard #Security ‎
⚠️ Security alert

The Coldcard hack has triggered massive on-chain activity, with 39,600 BTC moved via small transactions. CryptoQuant notes this is the largest sub-1 BTC movement since the FTX collapse, with the attack still active.

#Coldcard #Security
·
--
Төмен (кемімелі)
#coldcardflawdrains594btc капитализацией на уровне $2,1 трлн. Фокус инвесторов сместился с макроэкономики на масштабный кризис доверия к методам холодного хранения активов и законодательные тупики в США Один из самых надежных #BTC -кошельков #Coldcard (производитель Coinkite) столкнулся с критической уязвимостью прошивки Ущерб: Скомпрометировано около 1200 сингл-сигнатюрных адресов, с которых злоумышленники за считанные минуты вывели 594 $BTC (порядка $38 млн).Суть проблемы: Ошибка в коде (внедренная еще в 2021 году) отключала генератор аппаратной случайности. Кошелек генерировал приватные ключи на основе предсказуемых данных — серийного номера чипа и времени. Хакеры смогли легко вычислить сид-фразы. Предполагается использование ИИ-инструментов для анализа уязвимости Кто в зоне риска: Пользователи устройств Coldcard Mk3, создавшие кошельки на прошивке версии 4.0.1 и выше. Обновление ПО не исправляет уже созданные слабые ключи — Coinkite призывает срочно переводить средства на новые адресаПаника вокруг уязвимости Coldcard и сезонный фактор (исторически август закрывался в «красной зоне» четыре года подряд) создают риск просадки к уровням $58 000 – $62 000 #BinanceSquareFamily {spot}(BTCUSDT)
#coldcardflawdrains594btc капитализацией на уровне $2,1 трлн. Фокус инвесторов сместился с макроэкономики на масштабный кризис доверия к методам холодного хранения активов и законодательные тупики в США Один из самых надежных #BTC -кошельков #Coldcard (производитель Coinkite) столкнулся с критической уязвимостью прошивки Ущерб: Скомпрометировано около 1200 сингл-сигнатюрных адресов, с которых злоумышленники за считанные минуты вывели 594 $BTC (порядка $38 млн).Суть проблемы: Ошибка в коде (внедренная еще в 2021 году) отключала генератор аппаратной случайности. Кошелек генерировал приватные ключи на основе предсказуемых данных — серийного номера чипа и времени. Хакеры смогли легко вычислить сид-фразы. Предполагается использование ИИ-инструментов для анализа уязвимости Кто в зоне риска: Пользователи устройств Coldcard Mk3, создавшие кошельки на прошивке версии 4.0.1 и выше. Обновление ПО не исправляет уже созданные слабые ключи — Coinkite призывает срочно переводить средства на новые адресаПаника вокруг уязвимости Coldcard и сезонный фактор (исторически август закрывался в «красной зоне» четыре года подряд) создают риск просадки к уровням $58 000 – $62 000 #BinanceSquareFamily
Y A S I R -:
❤️👍
#ColdcardFlawDrains594BTC 💀 Coldcard уязвимость слила 594 $BTC за 25 минут Ошибка в генерации сид-фразы на Coldcard Mk3 (прошивки 4.0.0 – 5.0.3) позволила хакеру вывести ~594.5 BTC ($38 млн) с 500 кошельков за 25 минут. Проблема: устройство использовало предсказуемый программный генератор вместо аппаратного, создавая сид на основе серийного номера чипа. Модели Mk4, Q и Mk5 не затронуты. Срочный совет: переместите средства с Mk3 на новый кошелек, созданный через dice-rolls или на незатронутой модели. 🔥 Как думаете, это подорвет доверие к аппаратным кошелькам? Пишите в комментариях! 👉 Подпишись на новости безопасности! #Coldcard #SecurityAlert #trade 👇 {spot}(BTCUSDT) {spot}(ETHUSDT) {spot}(BNBUSDT)
#ColdcardFlawDrains594BTC
💀 Coldcard уязвимость слила 594 $BTC за 25 минут

Ошибка в генерации сид-фразы на Coldcard Mk3 (прошивки 4.0.0 – 5.0.3) позволила хакеру вывести ~594.5 BTC ($38 млн) с 500 кошельков за 25 минут. Проблема: устройство использовало предсказуемый программный генератор вместо аппаратного, создавая сид на основе серийного номера чипа. Модели Mk4, Q и Mk5 не затронуты.
Срочный совет: переместите средства с Mk3 на новый кошелек, созданный через dice-rolls или на незатронутой модели.

🔥 Как думаете, это подорвет доверие к аппаратным кошелькам? Пишите в комментариях!
👉 Подпишись на новости безопасности!

#Coldcard #SecurityAlert #trade 👇
#coldcardexploitattackerscontrol1366btc ​🚨 CRITICAL SECURITY ALERT: EXPANDING EXPLOIT ON COLCARD USERS 🚨 ​The bleeding hasn't stopped. What began with an alarming 594 BTC drained in under 30 minutes yesterday has now escalated—exploiters currently hold over 1,366.38 BTC under their control! ​Analysis from Galaxy Research confirms three distinct waves of attacks so far. The burning question every holder is asking: Is the assault over, or are more breaches incoming? Whether this is a solitary hacker deploying upgraded exploit vectors or multiple attackers capitalizing on legacy vulnerabilities dating back to March 2021, the danger is real. ​🛡️ IMMEDIATE ACTION PLAN (PROTECT YOUR ASSETS): ​Patch Right Away: Update your device firmware to the latest official release without delay. ​Generate a New Seed: Transfer your funds to a completely fresh, uncompromised seed phrase. ​Stay Proactive: Cold storage is only as safe as your security hygiene—don't wait until your wallet is drained to take action! ​Stay paranoid, stay secure, and protect your holdings! 🔒⚡ ​Disclaimer: Not financial advice. Always Do Your Own Research (DYOR). ​#BTC #Coldcard #HackerAlert $VELVET {future}(VELVETUSDT) $BEAT {future}(BEATUSDT) $BTC {future}(BTCUSDT)
#coldcardexploitattackerscontrol1366btc

​🚨 CRITICAL SECURITY ALERT: EXPANDING EXPLOIT ON COLCARD USERS 🚨

​The bleeding hasn't stopped. What began with an alarming 594 BTC drained in under 30 minutes yesterday has now escalated—exploiters currently hold over 1,366.38 BTC under their control!

​Analysis from Galaxy Research confirms three distinct waves of attacks so far. The burning question every holder is asking: Is the assault over, or are more breaches incoming? Whether this is a solitary hacker deploying upgraded exploit vectors or multiple attackers capitalizing on legacy vulnerabilities dating back to March 2021, the danger is real.

​🛡️ IMMEDIATE ACTION PLAN (PROTECT YOUR ASSETS):

​Patch Right Away: Update your device firmware to the latest official release without delay.

​Generate a New Seed: Transfer your funds to a completely fresh, uncompromised seed phrase.

​Stay Proactive: Cold storage is only as safe as your security hygiene—don't wait until your wallet is drained to take action!

​Stay paranoid, stay secure, and protect your holdings! 🔒⚡

​Disclaimer: Not financial advice. Always Do Your Own Research (DYOR).

#BTC #Coldcard #HackerAlert

$VELVET
$BEAT
$BTC
ZoyaQueen16:
How does BABY help improve Bitcoin's long-term utility?
⚡ LATEST UPDATE ⚡ **Coldcard Wallet Vulnerability Losses Approach $89 Million** Galaxy Research has identified a third wave of unauthorized fund transfers linked to a suspected Coldcard hardware wallet vulnerability, with an additional 207.73 $BTC recently moved from compromised addresses. The total scope observed by Galaxy has grown to approximately 1,367 $BTC (valued at roughly $88.6M) across 4,585 Bitcoin addresses. The operational method has shifted: while the initial two exploit waves consolidated funds into a few central wallets, the latest activity distributed assets across hundreds of separate addresses, complicating tracking efforts for analysts. Galaxy emphasized that these estimates are derived from on-chain transaction analysis and victim reports rather than direct wallet audits confirming flawed seed generation. As a result, the data remains preliminary. However, risks remain elevated as public disclosure of the vulnerability may prompt other malicious actors to target wallets created with weak seed phrases. #Bitcoin #Coldcard #CryptoNews $NEAR $XRP Source: Compiled
⚡ LATEST UPDATE ⚡

**Coldcard Wallet Vulnerability Losses Approach $89 Million**

Galaxy Research has identified a third wave of unauthorized fund transfers linked to a suspected Coldcard hardware wallet vulnerability, with an additional 207.73 $BTC recently moved from compromised addresses.

The total scope observed by Galaxy has grown to approximately 1,367 $BTC (valued at roughly $88.6M) across 4,585 Bitcoin addresses.

The operational method has shifted: while the initial two exploit waves consolidated funds into a few central wallets, the latest activity distributed assets across hundreds of separate addresses, complicating tracking efforts for analysts.

Galaxy emphasized that these estimates are derived from on-chain transaction analysis and victim reports rather than direct wallet audits confirming flawed seed generation. As a result, the data remains preliminary. However, risks remain elevated as public disclosure of the vulnerability may prompt other malicious actors to target wallets created with weak seed phrases.

#Bitcoin #Coldcard #CryptoNews

$NEAR $XRP

Source: Compiled
Crypto Security Update A software vulnerability in the popular Coldcard hardware wallet has reportedly led to the theft of nearly 600 BTC, worth around $70 million. According to Chainalysis, the attack primarily targeted high-value wallets, sending another reminder that even self-custody solutions are not immune to security risks. $NVDAB {spot}(NVDABUSDT) $AAPLB {spot}(AAPLBUSDT) The incident highlights the importance of keeping wallet firmware updated, verifying every transaction, and following strong security practices to protect digital assets. Security remains one of the biggest priorities in crypto. Stay cautious, stay informed, and always protect your private keys. #Bitcoin #BTC #Coldcard #ColdcardFlawDrains594BTC
Crypto Security Update

A software vulnerability in the popular Coldcard hardware wallet has reportedly led to the theft of nearly 600 BTC, worth around $70 million. According to Chainalysis, the attack primarily targeted high-value wallets, sending another reminder that even self-custody solutions are not immune to security risks.
$NVDAB
$AAPLB

The incident highlights the importance of keeping wallet firmware updated, verifying every transaction, and following strong security practices to protect digital assets.

Security remains one of the biggest priorities in crypto. Stay cautious, stay informed, and always protect your private keys.

#Bitcoin #BTC #Coldcard #ColdcardFlawDrains594BTC
🚨 Coldcard Flaw Drains 594 BTC A newly reported security flaw linked to Coldcard wallets has resulted in the loss of approximately 594 BTC, raising fresh concerns about hardware wallet security and operational risks. ⚡ THOR Edge 594 BTC reportedly drained through the exploit. Hardware wallets remain highly secure, but improper setup, compromised firmware, or user errors can still create attack vectors. The incident is a reminder that cold storage isn't immune to operational vulnerabilities. 🎯 THOR Verdict This event is likely to increase scrutiny on wallet security practices rather than weaken confidence in self-custody itself. Expect the crypto community to closely monitor the investigation and any vendor response. #bitcoin #Coldcard #IDOL #ColdcardFlawDrains594BTC #HedgeFundsAddBullishOilBets $AKE {future}(AKEUSDT) $EPIC {future}(EPICUSDT) $IDOL {future}(IDOLUSDT)
🚨 Coldcard Flaw Drains 594 BTC

A newly reported security flaw linked to Coldcard wallets has resulted in the loss of approximately 594 BTC, raising fresh concerns about hardware wallet security and operational risks.

⚡ THOR Edge
594 BTC reportedly drained through the exploit.
Hardware wallets remain highly secure, but improper setup, compromised firmware, or user errors can still create attack vectors.
The incident is a reminder that cold storage isn't immune to operational vulnerabilities.

🎯 THOR Verdict
This event is likely to increase scrutiny on wallet security practices rather than weaken confidence in self-custody itself. Expect the crypto community to closely monitor the investigation and any vendor response.

#bitcoin #Coldcard #IDOL #ColdcardFlawDrains594BTC #HedgeFundsAddBullishOilBets

$AKE
$EPIC
$IDOL
🚨 تقرير: 70 مليون دولار مسروقة من محافظ Coldcard بسبب ثغرة كشفت تقارير من Galaxy Digital عن استنزاف حوالي 70 مليون دولار من حاملي البيتكوين، متأثرين بثغرة في محافظ Coldcard. تتعلق الثغرة بخلل في توليد المفاتيح، مما أثر على عدة نماذج وإصدارات للبرامج الثابتة. أدى هذا الخلل إلى سرقة 594 بيتكوين من حوالي 500 عنوان. ━━━━━━━━━━━━━━ 📊 التأثير: 🔥 مرتفع جداً 🏷️ OTHER #Coldcard #Bitcoin #Security #Exploit #Cryptocurrency 📰 المصدر: dailyhodl.com
🚨 تقرير: 70 مليون دولار مسروقة من محافظ Coldcard بسبب ثغرة

كشفت تقارير من Galaxy Digital عن استنزاف حوالي 70 مليون دولار من حاملي البيتكوين، متأثرين بثغرة في محافظ Coldcard. تتعلق الثغرة بخلل في توليد المفاتيح، مما أثر على عدة نماذج وإصدارات للبرامج الثابتة. أدى هذا الخلل إلى سرقة 594 بيتكوين من حوالي 500 عنوان.

━━━━━━━━━━━━━━
📊 التأثير: 🔥 مرتفع جداً
🏷️ OTHER

#Coldcard #Bitcoin #Security #Exploit #Cryptocurrency

📰 المصدر: dailyhodl.com
📉 Coldcard Wallet Vulnerability Linked to $70 Million Bitcoin Theft   A security flaw in the widely used Coldcard hardware wallet has reportedly led to the theft of nearly 600 $BTC BTC, worth around $70 million. According to Chainalysis, the attack appears to have targeted high-value wallets, raising fresh concerns about the reliability and security of self-custody solutions for crypto holders.   For context, $BTC BTC is currently trading around $62,717.24 on Binance, slightly down over the last 24 hours. Today’s range is $62,275.00 to $63,150.00, which helps show the market backdrop around a 600 $BTC BTC event of this size. #ColdcardFlawDrains594BTC #BTC #Coldcard
📉 Coldcard Wallet Vulnerability Linked to $70 Million Bitcoin Theft

A security flaw in the widely used Coldcard hardware wallet has reportedly led to the theft of nearly 600 $BTC BTC, worth around $70 million. According to Chainalysis, the attack appears to have targeted high-value wallets, raising fresh concerns about the reliability and security of self-custody solutions for crypto holders.

For context, $BTC BTC is currently trading around $62,717.24 on Binance, slightly down over the last 24 hours. Today’s range is $62,275.00 to $63,150.00, which helps show the market backdrop around a 600 $BTC BTC event of this size.
#ColdcardFlawDrains594BTC #BTC #Coldcard
🚨 ¡ALERTA BTC! Galaxy Detecta Nueva Oleada de Ataques a COLDCARD ⚠️ 💥 Galaxy Digital reportó una tercera oleada de ataques dirigidos a billeteras frías COLDCARD. Las pérdidas totales superan ya los 88 millones de dólares 📉. 🔒 Medida urgente: Se recomienda a quienes tengan fondos en cualquier modelo fabricado después de 2020 mover sus BTC de inmediato a una dirección segura 🛡️. 📉 Mientras tanto, Bitcoin cotiza cerca de los $62,620 con leve caída. 👉 ¿Usas billeteras frías? ¡Protege tus activos y comparte esta información! 🚀 #bitcoin #Coldcard #BinanceSquare #GalaxyDigital $BTC {spot}(BTCUSDT) $ETH {spot}(ETHUSDT) $BNB {spot}(BNBUSDT)
🚨 ¡ALERTA BTC! Galaxy Detecta Nueva Oleada de Ataques a COLDCARD ⚠️

💥 Galaxy Digital reportó una tercera oleada de ataques dirigidos a billeteras frías COLDCARD. Las pérdidas totales superan ya los 88 millones de dólares 📉.

🔒 Medida urgente: Se recomienda a quienes tengan fondos en cualquier modelo fabricado después de 2020 mover sus BTC de inmediato a una dirección segura 🛡️.

📉 Mientras tanto, Bitcoin cotiza cerca de los $62,620 con leve caída.

👉 ¿Usas billeteras frías? ¡Protege tus activos y comparte esta información! 🚀

#bitcoin #Coldcard #BinanceSquare #GalaxyDigital
$BTC
$ETH
$BNB
⚠️ اختراق Coldcard يثير تساؤلات حول أمان المحافظ الباردة أدى اكتشاف ثغرة برمجية في محفظة Coldcard، وهي محفظة أجهزة شائعة لتخزين العملات المشفرة، إلى سرقة ما يقرب من 600 بيتكوين. يثير هذا الحادث تساؤلات حول مدى أمان الحلول الذاتية لحفظ العملات المشفرة وتحديات إدارة المفاتيح الخاصة للمستثمرين. ━━━━━━━━━━━━━━ 📊 التأثير: 🔥 مرتفع جداً 🏷️ OTHER #Coldcard #Security #HardwareWallet #CryptoNews #SelfCustody 📰 المصدر: coindesk.com
⚠️ اختراق Coldcard يثير تساؤلات حول أمان المحافظ الباردة

أدى اكتشاف ثغرة برمجية في محفظة Coldcard، وهي محفظة أجهزة شائعة لتخزين العملات المشفرة، إلى سرقة ما يقرب من 600 بيتكوين. يثير هذا الحادث تساؤلات حول مدى أمان الحلول الذاتية لحفظ العملات المشفرة وتحديات إدارة المفاتيح الخاصة للمستثمرين.

━━━━━━━━━━━━━━
📊 التأثير: 🔥 مرتفع جداً
🏷️ OTHER

#Coldcard #Security #HardwareWallet #CryptoNews #SelfCustody

📰 المصدر: coindesk.com
🚨 Cold storage was supposed to mean untouchable. ⚠️ It didn't. $71,000,000+ in BTC — gone. Not phished. Not hacked at the device. Drained from wallets that never left a safe. 💀 Cold. Offline. Untouched. And still emptied. The old belief: hardware wallets are immune because attackers need physical access. The new reality: entropy failed silently, and math did the rest. Coldcard's 2021 firmware bug collapsed seed randomness down to a guessable range. No phishing link. No malware. No device compromise required. The attacker never touched a single wallet. ⏱️ 1,196 addresses. 41 minutes. Over 1,082 BTC swept. Predictability killed more wallets than any hacker ever could. 🔓 The uncomfortable truth: a wallet is only as cold as its randomness. Offline storage protects against network attacks — it does nothing against a flawed random number generator baked in at manufacture. The question isn't whether hardware wallets are safe. The question is whether the entropy generating the seed was ever truly random in the first place. 📌 Recommended action: 1️⃣ Update firmware immediately (Mk3: 4.2.0+, Mk4/Mk5: 5.6.0+, Q: 1.5.0Q+) 2️⃣ Generate a brand-new seed — firmware updates do NOT fix old seeds 3️⃣ Migrate all funds off the old address before touching it again 4️⃣ Where possible, add a dice-rolled passphrase for extra entropy 🔥 Rolling your own dice at setup? Those wallets survived untouched. What does "cold storage" actually protect against, if the randomness behind it was never secure? $BTC #Bitching #Coldcard #CryptoSecurity #DeFi Not financial advice. DYOR.
🚨 Cold storage was supposed to mean untouchable.

⚠️ It didn't.

$71,000,000+ in BTC — gone. Not phished. Not hacked at the device. Drained from wallets that never left a safe.

💀 Cold. Offline. Untouched. And still emptied.

The old belief: hardware wallets are immune because attackers need physical access.

The new reality: entropy failed silently, and math did the rest.

Coldcard's 2021 firmware bug collapsed seed randomness down to a guessable range. No phishing link. No malware. No device compromise required.

The attacker never touched a single wallet.

⏱️ 1,196 addresses.
41 minutes.
Over 1,082 BTC swept.

Predictability killed more wallets than any hacker ever could.

🔓 The uncomfortable truth: a wallet is only as cold as its randomness. Offline storage protects against network attacks — it does nothing against a flawed random number generator baked in at manufacture.

The question isn't whether hardware wallets are safe. The question is whether the entropy generating the seed was ever truly random in the first place.

📌 Recommended action:
1️⃣ Update firmware immediately (Mk3: 4.2.0+, Mk4/Mk5: 5.6.0+, Q: 1.5.0Q+)
2️⃣ Generate a brand-new seed — firmware updates do NOT fix old seeds
3️⃣ Migrate all funds off the old address before touching it again
4️⃣ Where possible, add a dice-rolled passphrase for extra entropy

🔥 Rolling your own dice at setup? Those wallets survived untouched.

What does "cold storage" actually protect against, if the randomness behind it was never secure?

$BTC #Bitching #Coldcard #CryptoSecurity #DeFi
Not financial advice. DYOR.
Көбірек контент көру үшін кіріңіз
Binance Square платформасында әлемдік криптоқоғамдастыққа қосылыңыз
⚡️ Криптовалюта туралы ең соңғы және пайдалы ақпаратты алыңыз.
💬 Әлемдегі ең ірі криптобиржаның сеніміне ие.
👍 Расталған авторлардың нақты пікірлерін табыңыз.
Электрондық пошта/телефон нөмірі