bitcoin
Bitcoin (BTC) $62,681.00 0.30%
ethereum
Ethereum (ETH) $1,860.96 0.20%
tether
Tether (USDT) $0.999282 0.00%
bnb
BNB (BNB) $576.80 1.80%
usd-coin
USDC (USDC) $0.999698 0.00%
xrp
XRP (XRP) $1.06 0.50%
solana
Solana (SOL) $71.89 1.90%
tron
TRON (TRX) $0.328315 0.70%
figure-heloc
Figure Heloc (FIGR_HELOC) $1.02 2.20%
staked-ether
Lido Staked Ether (STETH) $2,265.05 3.46%

Following an incident in which over $70 million in Bitcoin was illicitly acquired through a vulnerability in the Coldcard system, it has been indicated that the perpetrator sought assistance from a prominent blockchain services provider.

In a post on X, Clay Garrett, an engineer at the payments company Block, noted that the provider—whose name was withheld at their request—was approached after an analysis of blockchain movements revealed a “suspected workflow” associated with the attacker.

“During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps,” Garrett stated.

“This pattern led us to a hypothesis that has since been confirmed: the operator utilized a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activities during the sweeps,” Garrett added, further mentioning that authorities had been alerted.

Additionally, the research division of Galaxy Digital reported on X that the thief exhibited an atypical pattern in the movement of the coins.

“The pattern indicates that these transactions were all executed by the same attacker—it does not reflect the attack itself, which resembles the actions of a coin owner moving their assets,” the firm stated, suggesting that Bitcoin users should relocate funds from single-signature Coldcard addresses to more secure storage options.

Following the theft of over $35 million in Bitcoin from wallets on Thursday, Coinkite acknowledged that a firmware bug within Coldcard Mk3 devices—stemming from version 4.0.1 released in March 2021—caused seed generation to revert to a less secure software Pseudorandom Number Generator, rather than utilizing the hardware-based true random number generator.

This oversight rendered the private keys for many single-signature wallets—particularly those set up without dice rolls or a robust BIP-39 passphrase—predictable enough to be susceptible to brute-force attacks.

Subsequently, Coinkite admitted that all of its models were compromised following additional thefts. To date, over $70 million has been illicitly obtained, and engineers have cautioned that further Bitcoin addresses may be at risk.

Coinkite manufactures a range of Bitcoin products, including cold storage hardware wallets.

Source link

Leave a Comment

I accept the Terms and Conditions and the Privacy Policy

bitcoin
Bitcoin (BTC) $62,681.00 0.30%
ethereum
Ethereum (ETH) $1,860.96 0.20%
tether
Tether (USDT) $0.999282 0.00%
bnb
BNB (BNB) $576.80 1.80%
usd-coin
USDC (USDC) $0.999698 0.00%
xrp
XRP (XRP) $1.06 0.50%
solana
Solana (SOL) $71.89 1.90%
tron
TRON (TRX) $0.328315 0.70%
figure-heloc
Figure Heloc (FIGR_HELOC) $1.02 2.20%
staked-ether
Lido Staked Ether (STETH) $2,265.05 3.46%