
Guides2 min read
The Robot news gave PI a boost
Pi Network's $PI token received a short-term price boost this week after Fabric Foundation (@FabricFND) announced that @PiCoreTeam had joined RoboPay as a payment partner. The news landed on
You can also read this news on BH NEWS: Massive Security Flaw in Bitcoin Wallets Could Lead to Financial Catastrophe A critical flaw in certain Coldcard hardware wallets has left thousands at
You can also read this news on BH NEWS: Massive Security Flaw in Bitcoin Wallets Could Lead to Financial Catastrophe
A critical flaw in certain Coldcard hardware wallets has left thousands at risk, with losses soaring past $130 million as attackers exploit the vulnerability. Galaxy Research reports that more than 7,300 Bitcoin wallets are compromised, sparking compliance alerts from security experts who fear the issue remains widely unaddressed.
The root of the problem lies in specific firmware issues within Coldcard devices, designed by Coinkite for securely holding Bitcoin. Researchers pinpointed a flaw related to the generation of private keys, where compromised firmware versions defaulted to a less secure method of generating wallet seeds. This loophole exposed wallet addresses to fraudsters using Bitcoin’s public blockchain for targeting, leveraging brute-force methods to illegally access funds.
Experts identified the bug as stemming from limited entropy due to reliance on MicroPython’s software fallback rather than a robust random number generator. This lack of sufficient randomness allowed anyone with the know-how to exploit the vulnerability, putting both new and long-time Bitcoin holders at risk, with many potentially unaware of their compromised wallets.
Estimates by Coinkite reveal alarming disparities in entropy levels across Coldcard models. The older Mk2 and Mk3 devices only achieved 40 bits of entropy, drastically below the 128-bit standard. Though the Mk4 improved to 72 bits, this figure still lags behind industry expectations.
Consequently, attackers have successfully drained funds from countless wallets. Although Galaxy Research has documented numerous victim reports, the true scale of affected users likely surpasses reported figures.
Rodolfo Novak, Coinkite co-founder, issued a public apology and announced hotfixes for all affected wallet models. On July 31, he reassured users through a direct address, underscoring the necessity of the urgent updates but acknowledging the threat persists for users who remain lax in their response.
Rodolfo Novak stated that Coinkite takes full accountability for the firmware bug and has issued urgent updates, but he warned that “the threat is still active” for users who have not yet migrated their Bitcoin to new, unaffected wallets.
Without decisive action, affected users stand exposed to ongoing theft attempts. Urgent wallet upgrades and precautionary measures are highly encouraged by Coinkite and security analysts to safeguard against further losses. Those delaying the secure transfer of funds risk prolonged susceptibility to breaches.
Continue Reading: Massive Security Flaw in Bitcoin Wallets Could Lead to Financial Catastrophe