# Vulnerability Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Vulnerability", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

Canadian Users Account for 25% of Losses Related to Coldcard Vulnerability

Canadian Bitcoin users suffered the highest losses, accounting for 25% of the total, from a vulnerability affecting the Coldcard hardware wallet, a situation analysts link to the strong local presence of its parent company Coinkite headquartered in Toronto. Australia followed with 15-20% of losses, while the US and Thailand accounted for 10-15%. Though the exploit hit English-speaking and early Bitcoin-adopting regions hardest, global impact was seen across Western Europe, Latin America, and key African crypto hubs. The total stolen assets reached $116 million. Galaxy Research identified a March 2021 firmware update—specifically the faulty implementation of a new random number generator (RNG)—as the single point of failure. A configuration error rendered the hardware RNG inactive, silently defaulting to a weaker software-based one, which generated private keys with low entropy for over five years before an attacker stole $70 million from 1,200 wallets in 41 minutes. In response, security experts urged manufacturers to eliminate backup RNG mechanisms in production and strictly adhere to validation standards like NIST FIPS 140-3. For incident response, immediate user communication and clear mitigation steps were prioritized alongside rigorous patch testing. For users with compromised seed phrases, a strict protocol was recommended: purchase a new reputable hardware wallet, generate a new seed offline, verify it with a test transaction, transfer all funds to the new setup, *then* attempt to update the original device's firmware. Experts also advised diversifying risk by using hardware wallets from different manufacturers to avoid a single point of failure. The incident sparked a fundamental debate about self-custody security models. Critics argue that offline storage alone isn't foolproof, highlighting that trust is always delegated to third parties, like wallet manufacturers. The consensus is shifting towards multi-vendor setups and mandatory baseline standards like multi-signature or Multi-Party Computation (MPC) wallets. The goal is to move from "trusting one device" to ensuring no single compromised component or entity can move funds, distributing trust across independent organizational and technological failure domains.

cryptonews.ru08/06 13:51

Canadian Users Account for 25% of Losses Related to Coldcard Vulnerability

cryptonews.ru08/06 13:51

Coldcard Urges Users to Move Bitcoin as Vulnerability Remains Exploited

Coldcard has urgently warned users to move their Bitcoin holdings, confirming on Tuesday that a vulnerability—which has already led to the theft of up to $114 million from self-custody wallets—remains actively exploited. The company stressed this is not a precautionary alert, citing a fourth wave of fraudulent transactions on Monday that drained approximately 449 BTC from 709 addresses. The flaw, dormant since 2021, involves firmware in cases where funds are controlled by a single key without a second confirmation. Users of Mk3 models (with firmware 4.0.1 or later) must transfer funds immediately. Owners of Mk4, Mk5, and Q models with firmware below 5.6.0 or 1.5.0Q should update firmware, generate a new wallet, then move coins. The vulnerability is tied to insufficient entropy during seed phrase generation, potentially allowing attackers to guess the key and drain wallets remotely. An exception is made for users who employed the device’s “dice roll” feature for key generation, as those wallets never touched the compromised code. Vincent Buzon, a cybersecurity expert at rival hardware wallet maker Ledger, noted the incident stemmed from an implementation failure, emphasizing that secure entropy generation must be hardware-based. He warned that software wallets on unprotected devices are riskier, and holding funds on centralized exchanges represents “not ownership, but an IOU.” Bitcoin traded around $63,800 in the U.S. on Tuesday, largely unaffected by the wallet warning.

cryptonews.ru08/05 18:05

Coldcard Urges Users to Move Bitcoin as Vulnerability Remains Exploited

cryptonews.ru08/05 18:05

MARA Opens 'Slipstream' to Public as 'Coldcard' Victims Race to Save Assets

MARA Holdings, a Nasdaq-listed Bitcoin mining and AI infrastructure company (formerly Marathon Digital), has opened its "Slipstream" service to the public. Slipstream allows users to send Bitcoin transactions directly to MARA's mining pool, keeping them hidden from the public mempool until mined into a block, rather than broadcasting them openly. The public launch coincides with a critical vulnerability discovered in Coldcard hardware wallets. A firmware bug dating to March 2021 significantly reduced the randomness when generating wallet seed phrases, making funds vulnerable to theft. Hackers have already stolen an estimated 1,816 BTC (approx. $116 million) from over 5,200 wallets. For users needing to move funds from vulnerable wallets, especially those with multi-signature setups, broadcasting a standard transaction publicly can reveal key details and allow attackers to intercept it. Slipstream mitigates this risk by keeping the transaction private until confirmation. MARA first launched Slipstream in February 2024 for large or non-standard transactions. It does not charge an extra fee; users only pay standard Bitcoin network fees. However, confirmation timing depends on MARA's mining luck, as it controls roughly 5.37% of the Bitcoin network's total hashrate. The Bitcoin community views Slipstream's open access as a practical crisis tool for Coldcard holders, not a permanent replacement for the public mempool for everyday transactions.

cryptonews.ru08/05 08:59

MARA Opens 'Slipstream' to Public as 'Coldcard' Victims Race to Save Assets

cryptonews.ru08/05 08:59

Reflections After the Coldcard Incident: Why Did Korean Users Escape Unscathed While the English-Speaking Community Suffered Heavily?

An incident involving a security flaw in Coldcard hardware wallets revealed a stark contrast in outcomes between the Korean and English-speaking Bitcoin communities. While many experienced users in the English-speaking world suffered significant losses, the Korean Bitcoin community reportedly avoided any direct financial impact. This divergence is attributed not to a gap in technical skill, but to deeper structural issues within the communities. Korean influencers and leaders strongly advocated for secure self-custody practices, specifically urging users to generate their seed phrases manually (e.g., by rolling physical dice) rather than relying on any wallet manufacturer's random number generator. This "don't trust, verify" approach was widely adopted, protecting users. In contrast, the English-speaking community saw its discourse and trust influenced by prominent influencers and podcasters who often had sponsorship ties or personal relationships with Coldcard's parent company, Coinkite. This created a "reverberation chamber" effect, where overconfidence in the product's security was amplified, leading followers to overlook potential risks. The incident underscores a critical need to extend Bitcoin's core principle of "Don't Trust, Verify" beyond code to the consumption of information itself. It highlights the dangers of over-reliance on influencers and the importance of maintaining neutrality by critically assessing the financial and relational biases of information sources. The Korean community's success serves as a lesson for the broader ecosystem to reflect on these dynamics to prevent future losses.

marsbit08/05 08:46

Reflections After the Coldcard Incident: Why Did Korean Users Escape Unscathed While the English-Speaking Community Suffered Heavily?

marsbit08/05 08:46

活动图片