Canadian Users Account for 25% of Losses Related to Coldcard Vulnerability
Canadian Bitcoin users suffered the highest losses, accounting for 25% of the total, from a vulnerability affecting the Coldcard hardware wallet, a situation analysts link to the strong local presence of its parent company Coinkite headquartered in Toronto. Australia followed with 15-20% of losses, while the US and Thailand accounted for 10-15%. Though the exploit hit English-speaking and early Bitcoin-adopting regions hardest, global impact was seen across Western Europe, Latin America, and key African crypto hubs.
The total stolen assets reached $116 million. Galaxy Research identified a March 2021 firmware update—specifically the faulty implementation of a new random number generator (RNG)—as the single point of failure. A configuration error rendered the hardware RNG inactive, silently defaulting to a weaker software-based one, which generated private keys with low entropy for over five years before an attacker stole $70 million from 1,200 wallets in 41 minutes.
In response, security experts urged manufacturers to eliminate backup RNG mechanisms in production and strictly adhere to validation standards like NIST FIPS 140-3. For incident response, immediate user communication and clear mitigation steps were prioritized alongside rigorous patch testing.
For users with compromised seed phrases, a strict protocol was recommended: purchase a new reputable hardware wallet, generate a new seed offline, verify it with a test transaction, transfer all funds to the new setup, *then* attempt to update the original device's firmware. Experts also advised diversifying risk by using hardware wallets from different manufacturers to avoid a single point of failure.
The incident sparked a fundamental debate about self-custody security models. Critics argue that offline storage alone isn't foolproof, highlighting that trust is always delegated to third parties, like wallet manufacturers. The consensus is shifting towards multi-vendor setups and mandatory baseline standards like multi-signature or Multi-Party Computation (MPC) wallets. The goal is to move from "trusting one device" to ensuring no single compromised component or entity can move funds, distributing trust across independent organizational and technological failure domains.
cryptonews.ruHace 13 hora(s)