# Self-Custody İlgili Makaleler

HTX Haber Merkezi, kripto endüstrisindeki piyasa trendleri, proje güncellemeleri, teknoloji gelişmeleri ve düzenleyici politikaları kapsayan "Self-Custody" hakkında en son makaleleri ve derinlemesine analizleri sunmaktadır.

Coldcard Urges Users to Move Bitcoin as Vulnerability Remains Exploited

Coldcard has urgently warned users to move their Bitcoin holdings, confirming on Tuesday that a vulnerability—which has already led to the theft of up to $114 million from self-custody wallets—remains actively exploited. The company stressed this is not a precautionary alert, citing a fourth wave of fraudulent transactions on Monday that drained approximately 449 BTC from 709 addresses. The flaw, dormant since 2021, involves firmware in cases where funds are controlled by a single key without a second confirmation. Users of Mk3 models (with firmware 4.0.1 or later) must transfer funds immediately. Owners of Mk4, Mk5, and Q models with firmware below 5.6.0 or 1.5.0Q should update firmware, generate a new wallet, then move coins. The vulnerability is tied to insufficient entropy during seed phrase generation, potentially allowing attackers to guess the key and drain wallets remotely. An exception is made for users who employed the device’s “dice roll” feature for key generation, as those wallets never touched the compromised code. Vincent Buzon, a cybersecurity expert at rival hardware wallet maker Ledger, noted the incident stemmed from an implementation failure, emphasizing that secure entropy generation must be hardware-based. He warned that software wallets on unprotected devices are riskier, and holding funds on centralized exchanges represents “not ownership, but an IOU.” Bitcoin traded around $63,800 in the U.S. on Tuesday, largely unaffected by the wallet warning.

cryptonews.ru6 saat önce

Coldcard Urges Users to Move Bitcoin as Vulnerability Remains Exploited

cryptonews.ru6 saat önce

Reflections After the Coldcard Incident: Why Did Korean Users Escape Unscathed While the English-Speaking Community Suffered Heavily?

An incident involving a security flaw in Coldcard hardware wallets revealed a stark contrast in outcomes between the Korean and English-speaking Bitcoin communities. While many experienced users in the English-speaking world suffered significant losses, the Korean Bitcoin community reportedly avoided any direct financial impact. This divergence is attributed not to a gap in technical skill, but to deeper structural issues within the communities. Korean influencers and leaders strongly advocated for secure self-custody practices, specifically urging users to generate their seed phrases manually (e.g., by rolling physical dice) rather than relying on any wallet manufacturer's random number generator. This "don't trust, verify" approach was widely adopted, protecting users. In contrast, the English-speaking community saw its discourse and trust influenced by prominent influencers and podcasters who often had sponsorship ties or personal relationships with Coldcard's parent company, Coinkite. This created a "reverberation chamber" effect, where overconfidence in the product's security was amplified, leading followers to overlook potential risks. The incident underscores a critical need to extend Bitcoin's core principle of "Don't Trust, Verify" beyond code to the consumption of information itself. It highlights the dangers of over-reliance on influencers and the importance of maintaining neutrality by critically assessing the financial and relational biases of information sources. The Korean community's success serves as a lesson for the broader ecosystem to reflect on these dynamics to prevent future losses.

marsbit16 saat önce

Reflections After the Coldcard Incident: Why Did Korean Users Escape Unscathed While the English-Speaking Community Suffered Heavily?

marsbit16 saat önce

Samson Mow Shares 5 Urgent Recommendations for Coldcard Users Facing Losses

Samson Mow, CEO of JAN3, shares five urgent recommendations for Coldcard users affected by losses due to a Random Number Generator (RNG) vulnerability. He emphasizes documenting all details (wallet addresses, dates, firmware versions, transaction info) for a proper incident report. Users are advised to file a police report with cybercrime units or agencies like the FBI's IC3 and to monitor coordinated efforts to track stolen funds. Mow strongly warns against destroying the affected Coldcard device or seed phrase, as they may be needed to prove ownership if stolen bitcoin is frozen on an exchange. He also cautions victims to ignore fraudulent recovery service offers that request upfront payments or sensitive wallet information. The incident highlights broader self-custody security lessons. Mow stresses minimizing single points of failure by using multi-vendor, multi-signature setups instead of relying on a single hardware provider. He acknowledges self-custody is complex and urges the community to be less critical of those using custodians or ETFs, as each storage method involves trade-offs. Coinkite, the maker of Coldcard, has issued a security advisory urging users of affected devices to update firmware, generate new seeds, and move funds if their seed was created on vulnerable versions. The aftermath includes potential legal action against Coinkite by affected users and an unsolicited blockchain message to the attacker offering money-laundering services.

cryptonews.ru2 gün önce 09:32

Samson Mow Shares 5 Urgent Recommendations for Coldcard Users Facing Losses

cryptonews.ru2 gün önce 09:32

活动图片