# Пов'язані статті щодо Coldcard

Центр новин HTX надає останні статті та поглиблений аналіз на тему "Coldcard", що охоплює ринкові тренди, оновлення проєктів, технологічні розробки та регуляторну політику в криптоіндустрії.

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

The article discusses using dice rolls to generate secure Bitcoin wallet seeds, providing entropy independent of potentially flawed hardware random number generators. It explains that each fair dice roll offers about 2.585 bits of entropy, with around 50 rolls needed for a standard 12-word seed phrase and 99+ recommended for higher security. This method gained attention after a vulnerability was revealed in some Coldcard hardware wallets, where a faulty firmware RNG (dating back to 2021) compromised generated keys. The analysis notes that while a dice-generated main seed was safe from this specific flaw, other Coldcard functions (like creating paper wallets, backup keys, or passwords) could still be vulnerable if they used the defective RNG. The piece argues that while dice-based entropy is technically robust, the manual process is error-prone, tedious, and unrealistic for most new users, who might make mistakes in recording or inputting rolls. It concludes that while manual entropy generation should remain an option for advanced users, the long-term goal is to develop reliable, user-friendly hardware and software that securely generates randomness without requiring specialized knowledge. Coldcard users are advised to check their firmware version and replace any secondary secrets (like paper wallet keys) created with vulnerable devices, while also considering multi-signature setups with devices from different manufacturers for added security.

cryptonews.ruВчора 21:37

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

cryptonews.ruВчора 21:37

Attention, Bitcoin Users! Today's Hack May Be Larger Than You Think. Here's What to Do

Bitcoin users are urged to take immediate action following the disclosure of a critical security vulnerability. Hardware wallet manufacturer Coinkite has revealed a flaw in the seed phrase generation process for certain Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3. All bitcoin addresses created from seed phrases generated on these potentially affected devices are now considered at risk. This warning coincides with an ongoing investigation into a major hack that drained approximately 1,082.65 BTC (worth roughly $70.2 million at the time) from 1,196 single-signature wallets in just 41 minutes on July 30. Security analysts believe the coordinated thefts, which used identical transaction fees and left no change, were executed by an automated tool scanning for compromised private keys. Notably, this attack occurred about 30 hours before Coinkite's public disclosure of the Coldcard vulnerability, raising concerns of a possible connection. Experts strongly recommend that impacted Coldcard Mk3 users do not consider their old seed phrase safe. The advised course of action is to generate a completely new, secure seed phrase on a trusted, modern hardware wallet and then transfer all funds to addresses derived from this new seed. Simply moving the old, potentially compromised seed to a new device is not sufficient.

cryptonews.ru2 дні тому 22:01

Attention, Bitcoin Users! Today's Hack May Be Larger Than You Think. Here's What to Do

cryptonews.ru2 дні тому 22:01

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

The Coldcard hardware wallet has been compromised, with hackers stealing approximately 594.5 Bitcoin (~$40 million) from 500 addresses in just 25 minutes. The root cause was a critical software bug, undetected for five years, which disabled the device's secure chip for generating true random numbers. This led to the creation of private keys based on predictable data like the processor's serial number, drastically reducing cryptographic security. The attackers exploited this offline by brute-forcing possible seed phrases, finding active addresses on the public ledger, and signing transactions. Initially, Coinkite (Coldcard's maker) claimed only older models were at risk but later admitted all devices running the compromised firmware were vulnerable. CEO Rodolphe Novak (NVK) apologized but ruled out financial compensation for affected users. To secure funds, owners must urgently update their firmware to specific safe versions, generate a completely new seed phrase on the updated device, and transfer all assets to new addresses created with that new seed. While a BIP-39 passphrase can help, it does not replace this migration process. Other Coinkite products like TAPSIGNER were not affected. This incident underscores that even specialized hardware requires rigorous, independent code audits, especially for cryptographic functions. It parallels past failures, like a 2006 OpenSSL bug in Debian, and raises questions about whether automated code analysis can ever fully replace human scrutiny in critical security areas.

cryptonews.ru2 дні тому 21:41

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

cryptonews.ru2 дні тому 21:41

活动图片