Coldcard hardware wallet reveals a serious security vulnerability. Galaxy Research’s latest report shows that approximately 1,719 of the $BTC tokens have been stolen, worth about $111 million. Galaxy has received reports from more than 250 victims.
What’s even more alarming is that on-chain tracking indicates the creation records of these stolen tokens can be traced back to affected Coldcard firmware versions first published on March 17, 2021. In other words, the vulnerability may have been lurking for more than four years. The scope of affected devices appears to be currently focused on Coldcard Mk3, Mk4, Mk5, and Q-series units running that firmware, with no evidence so far that it has impacted other hardware wallets or signing devices outside Coldcard.
Galaxy further notes that more suspicious funds are still under verification, and it is expected that total losses may exceed $130 million. For users who hold Coldcard devices, the top priority is to quickly check the firmware version and migrate assets to a brand-new seed (mnemonic) wallet, while also keeping an eye on the official follow-up disclosures detailing the affected firmware.
Cold wallets are not absolutely secure. Even small vulnerabilities in the firmware supply chain or random number generation process may only surface years later through on-chain anomalies.
#硬件钱包 #Coldcard #BTC
What’s even more alarming is that on-chain tracking indicates the creation records of these stolen tokens can be traced back to affected Coldcard firmware versions first published on March 17, 2021. In other words, the vulnerability may have been lurking for more than four years. The scope of affected devices appears to be currently focused on Coldcard Mk3, Mk4, Mk5, and Q-series units running that firmware, with no evidence so far that it has impacted other hardware wallets or signing devices outside Coldcard.
Galaxy further notes that more suspicious funds are still under verification, and it is expected that total losses may exceed $130 million. For users who hold Coldcard devices, the top priority is to quickly check the firmware version and migrate assets to a brand-new seed (mnemonic) wallet, while also keeping an eye on the official follow-up disclosures detailing the affected firmware.
Cold wallets are not absolutely secure. Even small vulnerabilities in the firmware supply chain or random number generation process may only surface years later through on-chain anomalies.
#硬件钱包 #Coldcard #BTC