Bei der Untersuchung der gestrigen Coldcard-Diebstähle wurde ein auffälliges Muster bei den Sweeps festgestellt. Daraus entstand eine Hypothese, die inzwischen bestätigt werden konnte: Der Angreifer nutzte während der Transaktionen einen kostenpflichtigen Account bei einem bekannten Blockchain-Dienstleister, um unter anderem die betroffenen Quelladressen abzufragen.
1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
Unsere Single-Sig-Policen decken physische Risiken wie Feuer, Raub und räuberische Erpressung ab leider keine Cyberangriffe.
Wir arbeiten bereits seit einiger Zeit daran, den Versicherungsschutz auch auf diese Risiken auszuweiten. Geeignete Versicherungskapazitäten für Cyber im Zusammenhang mit Bitcoin-Selbstverwahrung zu finden, hat sich bislang als unmöglich herausgestellt.
Get the word out to everyone you know who might be affected. Help them migrate safely if you have the expertise; if you don’t, connect them with someone who does.
Stay vigilant. Scammers will inevitably exploit the confusion and fear around this incident, targeting the people who are already most vulnerable.
And push back against the narratives that will follow: Bitcoin wasn't hacked, and this does not mean self-custody is impossible. A specific implementation failed. We should learn from it, help those affected, and make self-custody safer as a result.
RE: This #Coldcard situation...
An entropy bug in seed generation of a popular hardware wallet is a nightmare scenario for self-custody. A tragedy.
Watching bitcoiners lose their life-savings because of a software bug hurts. Hearing I-told-you-sos from centralized custodians and nocoiners hurts. It's scary, too.
But I think Mr Rogers said it best, don't you?
"When I was a boy and I would see scary things in the news, my mother would say to me, ‘Look for the helpers. You will always find people who are helping.'"
They say bitcoin is money for enemies but right now I am seeing bitcoiners from all over the planet...helping. We are investigating, debugging, and documenting. We are consoling each other. We are protecting each other.
I think we can use STM32 UIDs to identify legitimate coin owners, in the event of a white-hat temporarily moving funds. Only the owner can provide a physical device with the right UID matching the mnemonic
Richtig Spannende weitere Informationen zur Coldcard Zufallsalgorithmus Datenlücke gab es heute bei @_einundzwanzig_ Live mit @coinjoined, @DerPraxmatiker und mir.
Für jeden der eine Coldcard hat oder der jemanden kennt ist das echt sehenswert:
https://t.co/5LLYie8VlA
1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
Fixing the bug and privately notifying affected users would obviously be the best outcome, but if Coinkite doesn't retain customer records, targeted disclosure becomes impossible.
White-hat recovery securing vulnerable funds and returning them to their owners through UIDs or other verifiable means might sound noble in theory, but the legal implications are murky.
Realistically, there may be little you can do beyond fixing the vulnerability, urging users to migrate before full public disclosure, and hoping nobody independently discovers and exploits it in the meantime.
And with the Mk4 and Q affected by the entropy regression as well, this is about as bad a disclosure scenario as you could design.
1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.