AI News AI资讯 16h ago Updated 10h ago 更新于 10小时前 46

Coldcard Bitcoin Hardware Wallet Exposed with Random Number Vulnerability, ~$110 Million Bitcoin Stolen 比特币硬件钱包Coldcard被曝存在随机数漏洞,约1.1亿美元比特币被盗

Coldcard Bitcoin hardware wallet has a critical random number generation (RNG) vulnerability that allows systematic reconstruction of mnemonic seeds from affected devices Attackers have drained over 1,755 BTC (approximately $110 million) from roughly 5,000 compromised wallets as of August 3, 2026 Manufacturer Coinkite has confirmed the flaw and released a firmware patch, urging immediate user updates Coldcard was long regarded as one of the most secure cryptocurrency storage solutions, making th Coldcard硬件钱包存在随机数生成缺陷漏洞,导致约5000个钱包的助记词可被系统性推算 攻击者已盗走超过1755枚比特币,按当时市值计算约合1.1亿美元 制造商Coinkite已确认漏洞并发布修复固件,呼吁用户及时更新 Coldcard长期被视为最安全的加密货币存储方式之一,此次漏洞影响重大 今年上半年全球加密货币被盗总额达9.72亿美元,黑客攻击事件207起,创历年半年度新高

72
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • Coldcard Bitcoin hardware wallet has a critical random number generation (RNG) vulnerability that allows systematic reconstruction of mnemonic seeds from affected devices
  • Attackers have drained over 1,755 BTC (approximately $110 million) from roughly 5,000 compromised wallets as of August 3, 2026
  • Manufacturer Coinkite has confirmed the flaw and released a firmware patch, urging immediate user updates
  • Coldcard was long regarded as one of the most secure cryptocurrency storage solutions, making this breach particularly damaging to trust in hardware wallets
  • The incident contributes to a record-breaking H1 2026 where global crypto thefts reached $972 million across 207 attacks

Why It Matters

This vulnerability strikes at the core assumption of hardware wallets: that offline, air-gapped devices produce cryptographically secure random numbers immune to remote exploitation. For AI practitioners and security researchers, it highlights the critical importance of entropy sources in any system generating secrets, and serves as a cautionary case study in how seemingly isolated hardware can harbor exploitable flaws. The breach also underscores the growing sophistication of crypto attacks, which now target foundational infrastructure rather than just software layers.

Technical Details

  • The vulnerability is in Coldcard's random number generator, which is responsible for deriving mnemonic seeds; a flaw in the RNG allows attackers to systematically narrow or reconstruct the possible seed space
  • Approximately 5,000 wallets were affected, with over 1,755 BTC siphoned by the time of reporting
  • Coinkite acknowledged the defect and issued a firmware fix, indicating the vulnerability was addressable at the software/firmware level rather than a permanent hardware limitation
  • The attack exploits the deterministic nature of broken RNG: if the output space is reduced or predictable, brute-force or statistical reconstruction of private keys becomes feasible

Industry Insight

  • Hardware wallet manufacturers must treat entropy generation as a first-class security concern, investing in certified RNG hardware and regular third-party audits rather than relying on reputation alone
  • Users of affected Coldcard devices should update firmware immediately and consider migrating funds to newly generated wallets on patched hardware, as old seeds may already be compromised
  • The broader crypto security landscape is seeing escalating attack volumes and losses; organizations and individuals should adopt multi-layered custody strategies and assume that any single device or protocol may harbor undiscovered vulnerabilities

TL;DR

  • Coldcard硬件钱包存在随机数生成缺陷漏洞,导致约5000个钱包的助记词可被系统性推算
  • 攻击者已盗走超过1755枚比特币,按当时市值计算约合1.1亿美元
  • 制造商Coinkite已确认漏洞并发布修复固件,呼吁用户及时更新
  • Coldcard长期被视为最安全的加密货币存储方式之一,此次漏洞影响重大
  • 今年上半年全球加密货币被盗总额达9.72亿美元,黑客攻击事件207起,创历年半年度新高

为什么值得看

这篇文章揭示了即使是业界公认最安全的硬件钱包也存在严重安全漏洞,对加密货币用户和硬件钱包制造商具有重要警示意义。

技术解析

  • 漏洞类型:随机数生成缺陷,导致离线冷钱包生成的助记词可被系统性推算
  • 影响范围:约5000个受影响钱包,被盗超过1755枚比特币
  • 损失金额:按当时市值计算约合1.1亿美元
  • 修复措施:制造商Coinkite已确认漏洞并发布修复固件
  • 行业背景:今年上半年全球加密货币被盗总额达9.72亿美元,黑客攻击事件207起,创历年半年度新高

行业启示

  • 硬件钱包的安全性和可靠性需要持续验证,即使是业界公认最安全的设备也可能存在未知漏洞
  • 加密货币安全行业需要加强漏洞披露和响应机制,用户应及时更新固件
  • 此次事件凸显了随机数生成在加密货币安全中的关键作用,硬件钱包制造商需要更加重视密码学实现的安全性

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全