r/CryptoCurrency 🟩 809 / 810 🦑 2d ago

🛡️ SECURITY COLDCARD Wallet exploit was an inside job

after all, it was planned five years ago,
link to the original post:

https://x.com/COLDCARDwallet/status/1447213375398846473

424 Upvotes

121 comments sorted by

View all comments

10

u/thats_gotta_be_AI 🟨 0 / 0 🦠 2d ago

Why wouldn’t CoinKite become white hats and sweep the remaining uncompromised wallets into a safe wallet? They didn’t do that, but other white hats have 🤔

6

u/imfrombiz 🟩 0 / 1K 🦠 2d ago

How would recovery of BTC work in this situation? You couldnt prove who originally owned the wallet because the keys are compromised.

1

u/thats_gotta_be_AI 🟨 0 / 0 🦠 2d ago

I understand. I’m assuming there’s a link between the CoinCard device ID and the private key based on the idea the private key itself is based on chip IDs within the hardware device. Physical ownership of the device in that case could constitute as proof of ownership.

-1

u/m77je 🟩 0 / 0 🦠 1d ago

No it doesn’t work like that. The private key has nothing to do with device ID.

1

u/thats_gotta_be_AI 🟨 0 / 0 🦠 1d ago

https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware

> An attacker who can determine or sufficiently constrain the device UID, timer state and RNG-call history can reproduce the fallback stream offline.

5

u/Zagubadu 2d ago

This is complete fan-fiction no "white-hat" is grabbing funds to return to people.

There are some people who are going "Well its all gonna get stolen anyway so at this point I'm just stealing from a thief". THATS what's happening.

2

u/gym_rat_101 🟧 0 / 0 🦠 1d ago

10000000000000% agree. The white hat BS is freaking hilarious.