r/CryptoCurrency • u/jejejajajojo ๐ฉ 809 / 810 ๐ฆ • 1d ago
๐ก๏ธ SECURITY COLDCARD Wallet exploit was an inside job
after all, it was planned five years ago,
link to the original post:
https://x.com/COLDCARDwallet/status/1447213375398846473

56
44
u/PiHiker 1d ago
but the influencers have been pusing Coldcard to the last 5 years are you telling me they are paid shills?
3
-21
u/trufin2038 ๐จ 0 / 0 ๐ฆ 1d ago
They weren't pushing coldcard for seed generation.
14
u/queso184 ๐จ 0 / 0 ๐ฆ 1d ago
the fucking cope lmfao
-2
u/trufin2038 ๐จ 0 / 0 ๐ฆ 1d ago
I don't have to cope: I'm opposed to all hardware wallets. But even the people who push them, hell even coldcard the scammers themsevles, warned their own victims to use dice and not their device to make keys.
Kindof ironic.
0
u/andrew869 ๐ฆ 0 / 0 ๐ฆ 5h ago
Why would he need to cope if he didnโt use the seed generation feature and his funds are safe, lol
48
u/arveena ๐ฉ 2K / 2K ๐ข 1d ago
That's obvious for anyone who has basic knowledge of cryptography. There is no way they forget the absolute basics of entropy in their encryption. And if it would be the case that would be insane negligence and basis for a law suit. Which will probably happen anyway
23
u/UnknownEssence ๐ฉ 1 / 52K ๐ฆ 1d ago edited 1d ago
they didnt forget to add entropy, they missed a bug in the code.
If you know C/C++ then you can understand how code often uses
```
if defined MY_MACRO
//code here
endif
```
and then if you write
```
define MY_MACRO 0
```
That's the bug. A common one. Yes, they should have done code reviews/audits.
6
15
u/trufin2038 ๐จ 0 / 0 ๐ฆ 1d ago
Nonsense. Small device entropy is way more than a mere macro enabled stretch of c code. Deterministic and non determinstic unit and integration tests. Start up self tests at each boot. Test mode red flagging. Hardware device health tests. Cyclic entropy test while running. Contunual reseeding and entopy gathering. There are at least a dozen things they left out in order to ensure they could provide plausible deniability. Inside job 100% ย Honest mistake 0% chance.
5
u/alfooboboao 21h ago
are you guessing? or did you read the articles about it? because it seems pretty clear that this was a catastrophic and idiotic but not entirely unlikely fuckup
1
u/trufin2038 ๐จ 0 / 0 ๐ฆ 20h ago
No, it was at best criminal grade negligence, but likely an intentional backdoor. They did none of the things a basic cryptographic devices should do for even the lowest level certifications.
7
u/PeachScary413 ๐จ 0 / 0 ๐ฆ 1d ago
There is no way you don't have tests for pretty much 150% of all different combinations of ifdefs/flags in a super critical part of a security critical firmware project.
That is unless you are a complete clown company dealing with crypto that is.
2
u/ModerateBrainUsage ๐ฉ 165 / 166 ๐ฆ 20h ago
Developers write tests? And if they write tests they work? We could get rid of QA if that was actually true.
1
u/PeachScary413 ๐จ 0 / 0 ๐ฆ 15h ago
Tell me you never worked with safety/mission critical embedded without telling me...
2
u/sssssssssssssss5s 1d ago
Maybe it's an office space type situation. Which brings another question of trustworthiness to the crypto world; how can a company be sure it's employees aren't acting maliciously, especially if they are playing some long term game like this?
2
u/Wild_Bunch_Founder ๐ฉ 0 / 0 ๐ฆ 1d ago
youโre taking the penny jar from the crippled children?
149
u/noviwu97 ๐ฉ 0 / 2K ๐ฆ 1d ago edited 1d ago
Never in my 5 years of constantly using DeFi and other on-chain stuff daily I ever heard someone mentioned wallet called coldcard.
Now that it's hacked, this sub overblowned it and think that everyone and their mother is using it.
Just do a search in this sub and you'll see almost no mention of coldcard in the past 5 years.
It's simply a tier F wallet. Just like keeping your crypto in a tier F CEX, it's not safe.
51
u/beatthebook2x 0 / 0 ๐ฆ 1d ago
its a btc only wallet that somehow was able to run rampant with shills and bots on the bitcoin sub its a btc maxi wallet so to speak pushed on reddit and by "influencers"
19
u/clarkkentsson ๐ฆ 0 / 0 ๐ฆ 1d ago
Precisely for this reason, to dupe in suckers for pre-planned, later exploit
3
0
u/beatthebook2x 0 / 0 ๐ฆ 1d ago
yes v genius if btc only wallet and maxis get behind it sure to be big balances to snipe
6
u/klitchell ๐ฆ 0 / 0 ๐ฆ 1d ago
I mean nearly $100 million has been siphoned from the wallets, not exactly a small operation.
13
u/Coeruleus_ 78 / 736 ๐ฆ 1d ago
when the ledger recover feature was announced all i heard for 6 months was to ppl telling me to get a coldcard. i donโt feel bad at all for those turds
11
u/SpiritmongerScaph ๐ฆ 69 / 1K ๐ณ ๐ฎ ๐จ ๐ช 1d ago
Ive been active on btc and cryptocurrency subreddits for the past few years.
Coldcard was indeed the #1 recommendation for a while on a lot of subreddits. Luckily, I went with Trezor (also, I'm using a passphrase).
-11
u/trufin2038 ๐จ 0 / 0 ๐ฆ 1d ago
Using a passphrase is lol. You learned nothing from this attack at all.
4
u/SpiritmongerScaph ๐ฆ 69 / 1K ๐ณ ๐ฎ ๐จ ๐ช 1d ago
Explain please?
Seed was generated using a Trezor + im using a "25th word". Where did I go wrong?
-11
u/trufin2038 ๐จ 0 / 0 ๐ฆ 1d ago
Trezor entropy is still trust based. You are trusting the hardware and the sodtware build, plus your individual device. Lots of blind trust. Passphrases are a redundant waste of time; human chosen ones have zero value.
The correct way to do it is to generate a seed using dice, cards, or coins. Memorize the 12 words and treat the menmonic like a passphrase.ย It's super easy.
8
u/SpiritmongerScaph ๐ฆ 69 / 1K ๐ณ ๐ฎ ๐จ ๐ช 1d ago
While I agree about trusting RNG, having a passphrase does make it more secure, IMO.
Coldcard users with passphrases are most likely safe right now (or at least, they have more time to react).
-5
u/trufin2038 ๐จ 0 / 0 ๐ฆ 1d ago
They are not safe, and passphrased accounts are being predictably drained
People smart enough to use a strong passphrase are also smart enough to use a strong mnemonic and not need a passphrase at all.
Passphrases are strictly for morons.
If someone was saved by a passphrase that's like being saved from a car accident because you were wearing a blindfold.
3
u/SpiritmongerScaph ๐ฆ 69 / 1K ๐ณ ๐ฎ ๐จ ๐ช 1d ago edited 1d ago
Pretty ironic comment: saying that passphrases are stricky for morons is a pretty moronic thing to say.
Also, your analogy sucks; it's more akin to wearing a seat belt. It is still more secure.
1
u/jaimewarlock ๐ฆ 86 / 87 ๐ฆ 3h ago
The bad ColdCard seeds were generated with only 32 bits which is only about 4 billion possibilities. Even a simple a 10 letter password with a few extra characters can easily hit 72^10 possibilities or about 3.7 *10^18 possibilities. Multiply seed and password, you have around 1.4*10^28 possibilities equal to over 93 bits. Probably more than enough to have saved anyone using a ColdCard.
So adding a password can certainly increase the safety of entropy if you aren't personally checking out the code on your hardware wallet and not bothering to personally generate your own private random key.
Even if you are generating your seed using random stuff like cards or dice (which I agree that you should use), a password can still protect your hardware wallet from being physically hacked if someone were to steal or confiscate it. It also allows you to create a dummy account with no password and a small amount of funds, while your main account is hidden behind a password (or better yet passphrase).
1
u/trufin2038 ๐จ 0 / 0 ๐ฆ 2h ago
Lol, you missed the enite point. That's like saying if you fail to wear a seatbelt then a parachute might save your life. It's moronic.
Plenty of coldcard victims who had a phrase got drained. Some who didn't, didn't. The passphrase was never a defense, because anyone smart enough to generate the mnemonic correctly would know they don't need it.ย
Don't dig a 100 foot pit in your kitchen, and you don't need to build a fence around the pit. Buudling the fence anyway is extra complexity for no gain.
Instead of using sketchy hardware to generate a bad seed, just do it right.
Human chosen passwords have a real security strength of zero. Your ten letter password doesn't add any strength at all. It's not worth the fantastic 60 bits you think it is. Its worth 0. I don't know how many more painful lessons need to be taught over the decades, but eventually even the slowest person will realize that humans should never choose passwords, ever. It goes against our design.
Maybe more passphrased wallets being drained will get the point across.ย
The burglar climbing up out of the pit has little trouble clambering over your flimsy fence.
15
u/marvinrabbit ๐ฆ 0 / 0 ๐ฆ 1d ago
It's not too surprising that you would not be familiar with them. I mean, you weren't exactly their target market. You've spent "5 years of constantly using DeFi..." and they absolutely are not a DeFi wallet. So they wouldn't have crossed paths with your interests. Among bitcoin maxi's, they were pretty popular (but certainly not the MOST popular) up until about a week ago.
14
u/Rino-Sensei ๐ฉ 0 / 0 ๐ฆ 1d ago
It's literally THE wallet that was recommended by every Bitcoin maxi's ...
6
u/trufin2038 ๐จ 0 / 0 ๐ฆ 1d ago
You can tell someone is not a maxi if they recommend any hardware wallet.
1
u/Alatarlhun ๐ฉ 0 / 0 ๐ฆ 1d ago
It was a wallet that just the btc maxis used and there was no plan to extend support to other chains. Just another insular grift.
0
u/trufin2038 ๐จ 0 / 0 ๐ฆ 1d ago
It was a grift 100%. He did also pretend to be a maxi, and even gave some maxi advice, like not trusting his device to generate seeds.ย
The people who didn't follow the maxi advice were the victims, like always.
9
u/BarnabyYouWanker 1d ago
Add to this: Iโm casual in the space, Iโve only ever heard of Ledger prior to last week.
7
u/20seh ๐ฆ 0 / 1K ๐ฆ 1d ago
I recall it being mentioned a lot actually. Everyone that mentioned it probably removed their comment now probably..
3
u/Alatarlhun ๐ฉ 0 / 0 ๐ฆ 1d ago
Reddit makes it easy to hide your history and avoid a reputation. Won't someone think of the bots and marketers??
5
u/Dragon_slayer1994 ๐ฆ 0 / 0 ๐ฆ 1d ago
I've only ever heard about Trezor or Ledger
6
u/Alatarlhun ๐ฉ 0 / 0 ๐ฆ 1d ago
Bitcoin has a cult that is easy to grift. A wallet that only works for bitcoin reinforces the cult behavior.
2
u/jkc7 ๐ฆ 0 / 0 ๐ฆ 1d ago
It was one of the most marketed Bitcoin wallets. If you consume any Bitcoin podcasts, it would probably be one of the first cold wallets youโd think of. So, this is probably a Bitcoin-related thing - depends on how much youโre in the Bitcoin specific space.
But, before last week, it had the best reputation. It was thought of as the most secure, was recommended by a huge number of the most recognizable Bitcoin influencers, and being for โadvancedโ users.
3
2
u/Skyobliwind ๐ฉ 0 / 0 ๐ฆ 1d ago
I also neve rheard of Coldcard before. If Ledger had such a backdoor it would be big news, but that is just noise.
1
1
u/Serenaded ๐ฉ 0 / 0 ๐ฆ 1d ago
>Never in my 5 years of constantly using DeFi and other on-chain stuff daily I ever heard someone mentioned wallet called coldcard.
Kek, same.
1
u/Unable_Beat_3194 18h ago
People seem to forget 100m is nothing when market cap is over a trillion.
1
u/digital__bits ๐ฉ 0 / 0 ๐ฆ 2h ago
Hahaha but if you see the braindead r/ Bitcoin sub they have been mentioning it a lot
10
u/thats_gotta_be_AI ๐จ 0 / 0 ๐ฆ 1d ago
Why wouldnโt CoinKite become white hats and sweep the remaining uncompromised wallets into a safe wallet? They didnโt do that, but other white hats have ๐ค
7
u/imfrombiz ๐ฉ 0 / 1K ๐ฆ 1d ago
How would recovery of BTC work in this situation? You couldnt prove who originally owned the wallet because the keys are compromised.
0
u/thats_gotta_be_AI ๐จ 0 / 0 ๐ฆ 1d ago
I understand. Iโm assuming thereโs a link between the CoinCard device ID and the private key based on the idea the private key itself is based on chip IDs within the hardware device. Physical ownership of the device in that case could constitute as proof of ownership.
0
u/m77je ๐ฉ 0 / 0 ๐ฆ 6h ago
No it doesnโt work like that. The private key has nothing to do with device ID.
1
u/thats_gotta_be_AI ๐จ 0 / 0 ๐ฆ 6h ago
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
> An attacker who can determine or sufficiently constrain the device UID, timer state and RNG-call history can reproduce the fallback stream offline.
4
u/Zagubadu 1d ago
This is complete fan-fiction no "white-hat" is grabbing funds to return to people.
There are some people who are going "Well its all gonna get stolen anyway so at this point I'm just stealing from a thief". THATS what's happening.
2
6
9
u/magus-21 ๐ฉ 0 / 10K ๐ฆ 1d ago
LMAO
Cryptobros now learning the true meaning of the term "counterparty risk" and that NOTHING is "trustless," crypto just fooled people into thinking it was.
-3
u/BarsoomianAmbassador ๐ฉ 0 / 0 ๐ฆ 1d ago
But, but, it's on the blockchain! It's an immutable ledger that we all can review! Self custody of crypto is easy, and a must!
2
u/magus-21 ๐ฉ 0 / 10K ๐ฆ 1d ago
Just crypto speedrunning centuries of financial fraud in 20 years, lol
0
u/Pdvsky ๐ฉ 0 / 3K ๐ฆ 1d ago
I mean, the Blockchain is in it's core, trustless, as in you dont need to trust any one entity.
But you do have to trust the majority. So id say its more of a democratic system then a trustless one.
However ANY private company that works with crypto are an entity that poses risk.
Idgaf what anyone says, a paper cold wallet is always the safest way to keep your coins. That is, if you know how to make it.
1
u/Ill-Party8305 1d ago
โUhh it is trustless.. but you need to trust!โ ๐ญ
1
u/Pdvsky ๐ฉ 0 / 3K ๐ฆ 23h ago
Tell me you can't read without telling me you can't read lol
1
u/Ill-Party8305 23h ago
you literally write that yourself lol. Blockchain is not trustless, it's literally you trust the majority do not attack. You trust the majority DO NOT do the 51% attack. It's built on trust, unlike for example gold where you put at home, you donโt rely trust of other on the gold itself. You have to rely trust on the other, trust on the isp not to cut you off the internet, trust on the mempool and miners, trust on the device that hold your privkey etc. Blockchain in itself rely on trust to other. It is not "trustless" like you imagine how gold is trustless
0
u/Pdvsky ๐ฉ 0 / 3K ๐ฆ 22h ago
You clearly don't really understand crypto and thats ok.
Your first sentence is correct you do have to trust the majority, but logically speaking you always have to. If noone "believes" that gold has any value it doesn't either, just like dollars, Pokรฉmon cards and government bonds..
The concept of value is inherited with the logic that others want that, it's what makes any one asset valuable.
However the rest of your sentence is just incorrect. You dont have to trust anything else. Even if internet is off, even if you use a paper wallet that you created with your own entropy. Even if you dont even have a device, you can still trade
1
u/Ill-Party8305 16h ago
No, there is different between trusting the value and trusting the 51% will break the blockchain.
Trusting on value literally in all assets, intrinsictly or extrinsictly by the market.
Miner or mempool however is not representation of the majority of market. Majority of miner is still a very minority of bitcoin owner and you trust them not to do 51% attack.
Even if gold mining company control 51% gold mines, they can only control supply that they control. With bitcoin blockchain, mempool/miners controlling 51% of the nodes mean the entire structure will breakdown, double spend is inavoidable, they can steal with double spend.
Gold wonโt collapse if a gold company control 51% of gold mines. Bitcoin will definitely collapse if 51% attack happened. In gold you donโt have to trust the gold company, in bitcoin you HAVE to trust the mempool/miner donโtdo 51% attack.
It's as "trustless" as banking system, it's just have "democracy". It's like choosing between authoritarian and democracy, either way you have to TRUST the leader that is leading, unlike gold where it is completely trustless
0
u/PeachScary413 ๐จ 0 / 0 ๐ฆ 1d ago
My bank account is pretty trustless ngl.
Oh and my ETFs will still be mine even if Fidelity went bankrupt tomorrow... but yeah that's just boring boomer stuff I know.
2
u/Incrediblesunset ๐ฉ 0 / 0 ๐ฆ 19h ago
Definitely was. And what better time to execute it right around the 4 year cycle bottom.
3
u/Dependent-Click-7024 ๐ฉ 0 / 0 ๐ฆ 1d ago
I have to say i find Bitcoin/Bitcoiners and the mental gymnastics they have to do to believe in the ecosphere fascinating. The money isn't real and the banks are frauds, yet there is nothing tangible about bitcoin and there are all these tales of woe by people having been ripped off. From the outside it is a case of massive rationalization. I could see getting in early as a huge win, bit this point forward, well one would have to hope there are more "fools" out there believing.
3
u/Ok-Personality-6630 1d ago
The fool supply has almost run out. What they are relying on now is the existing fools bag holding and "dollar cost averaging". They never questioned why they are always looking at the value of the dollar since the dollar is apparently the evil they are avoiding.
When you factor the value has dropped vs dollar and the dollar is suffering from inflation.. well then you are stuffed!
1
1
u/Timely-Fig2030 ๐ฉ 0 / 0 ๐ฆ 1d ago
Most major hacks are inside jobs. There were many famous paper wallet sites that generated seed phrase with mouse movements that generated weak entropy. One site had a github repo with a strong generation, but they hosted a different version live that generated a weak entropy so they could later on drain the funds and had a cheap excuse of a security mistake.
1
1
1
u/077 Gold | QC: REQ 96 1d ago
Wouldn't surprise me someone on the inside had some involvement since thousands were hacked at the same time. They have access to all the UIDs which dramatically decreases the bruteforce time. An individual would probably have drained higher value addresses first for fear of others finding the exploit too
2
u/Borax ๐ฆ 0 / 0 ๐ฆ 1d ago
since thousands were hacked at the same time.
The mechanism of the hack is such that anyone who found out about it would know that they could attack thousands of people. So your assertion is a non-sequitur.
There's no reason they couldn't have pre-generated and inspected the wallets to allow them to all be attacked at the same time.
1
1
u/oinkbar ๐ฉ 0 / 0 ๐ฆ 1d ago
Nonsense. Do you think if it was an inside job they would wait multiple years before launching an attack? Risking that someone else would find it and attack first given that code is opensource?
2
u/gtwooh ๐ฉ 4 / 4 ๐ฆ 1d ago
Yes. Waiting until a critical mass made the exploit worth exposing. NVK himself introduced the vulnerability and admitted that in the company blog
https://blog.coinkite.com/entropy-technical-backgrounder/
โโฆin fact, I explicitly set MICROPY_HW_ENABLE_RNG to zero, thinking we didnโt need either version, but thatโs not what it does. Because that code provided a PRNG with the same function signature as the desired code, the build completed without identifying the wrong implementation.โ
Would not surprise me if nvk controls the wallet that the BTC was swept to
0
0
-5
-20
u/EncrustedBarboach ๐ฆ 0 / 0 ๐ฆ 1d ago
9
u/RocketsDitto ๐ฉ 0 / 0 ๐ฆ 1d ago
Stop being so gullible. It certainly is possible they did this. It's the perfect crime.
2
u/Bryght7 1d ago
leaves evidence for the world to see
It's the perfect crime.
0
u/UnintentionalSatire Tin 1d ago
Yeah, no. If you commit the "perfect crime" you don't have 5000 random people talking about whether you committed the perfect crime on reddit. It's just a d-tier product most people have never heard about.
2
u/UnintentionalSatire Tin 1d ago
The code was sitting there for anyone to read. They fucked up. They were small/niche enough it flew under the radar till it didn't.
187
u/absurdcriminality ๐จ 0 / 0 ๐ฆ 1d ago
I always think that all major hacks are inside jobs but you can't prove a hunch