Crypto Prices

Peter Todd Raises Alarm: Bitcoin Assets at Risk After $38 Million Coldcard Exploit

49 minutes ago
1 min read
1 views

Significant Vulnerability in Coldcard Devices

The hardware cryptocurrency wallet sector is grappling with a significant blow to its credibility following a serious vulnerability identified in Coldcard devices. This issue enabled hackers to exploit over 500 Bitcoin wallets, culminating in a single attack that resulted in the theft of 594.48 BTC, approximately valued at $38.3 million, which was sent to a single wallet address.

Expert Insights from Peter Todd

Peter Todd, a noted Bitcoin developer previously cited in an HBO documentary as a potential originator of Bitcoin under the pseudonym Satoshi Nakamoto, chimed in on the matter. His response was colored by a longstanding mistrust of commercial hardware wallets, which he regards as a risky investment. Todd explained that the security of such wallets hinges on the randomness of their seed phrase generation. Unfortunately, a flaw in Coldcard’s firmware, present since March 2021, has compromised this essential randomness.

Research Findings on Vulnerabilities

Research from Block Security has revealed that nearly all models, including Mk2, Mk3, Mk4, Q, and Mk5, are vulnerable. Older models suffered from a critical coding error that disabled the built-in hardware random number generator, forcing key generation through a predictable software process. Meanwhile, newer devices faced issues that reduced the operational data size, severely limiting the number of possible secret phrase combinations and making them susceptible to brute-force attacks, achievable in just minutes.

Concerns Over Hardware Wallets

In his comments on social media platform X, Todd expressed deep concern about the lack of comprehensive independent reviews of the code, remarking, “I’ve always been skeptical of hardware wallets. You pay a lot of money for a device running code that few people will ever vet, on hardware potentially susceptible to supply chain attacks.”

He urged for a better approach—one that incorporates end-to-end deterministic testing of hardware to ensure clarity about the source of entropy.

Alternative Key Generation Methods

Todd also proposed alternative methods for generating secure keys, such as physical random number generation techniques using everyday items like a deck of cards, and reiterated a previous suggestion for using a button-based random number generator.

Recommendations for Bitcoin Users

In light of the current vulnerabilities, while utilizing a hardware wallet within a multisig configuration may still have its merits, Todd argues that relying on well-audited software on standard hardware is likely a safer option for singlesig setups. Moreover, fears have arisen that even multisig setups could be compromised if all keys were created using the flawed Coldcard devices, as the underlying issue arises at the seed phrase generation phase—mere exportation of the seed phrase to a secure device is insufficient to mitigate the risk.

To safeguard their Bitcoin assets, experts are strongly advising users to immediately switch to new seed phrases generated on third-party hardware and promptly transfer their funds to fresh addresses. The only users currently shielded from these vulnerabilities are those who employed an additional BIP-39 passphrase during the initial setup, as this provides an extra safeguard against brute-force attempts.

Popular