Canadian Users Account for 25% of Losses Related to Coldcard Vulnerability

cryptonews.ru发布于2026-08-06更新于2026-08-06

文章摘要

Canadian Bitcoin users suffered the highest losses, accounting for 25% of the total, from a vulnerability affecting the Coldcard hardware wallet, a situation analysts link to the strong local presence of its parent company Coinkite headquartered in Toronto. Australia followed with 15-20% of losses, while the US and Thailand accounted for 10-15%. Though the exploit hit English-speaking and early Bitcoin-adopting regions hardest, global impact was seen across Western Europe, Latin America, and key African crypto hubs. The total stolen assets reached $116 million. Galaxy Research identified a March 2021 firmware update—specifically the faulty implementation of a new random number generator (RNG)—as the single point of failure. A configuration error rendered the hardware RNG inactive, silently defaulting to a weaker software-based one, which generated private keys with low entropy for over five years before an attacker stole $70 million from 1,200 wallets in 41 minutes. In response, security experts urged manufacturers to eliminate backup RNG mechanisms in production and strictly adhere to validation standards like NIST FIPS 140-3. For incident response, immediate user communication and clear mitigation steps were prioritized alongside rigorous patch testing. For users with compromised seed phrases, a strict protocol was recommended: purchase a new reputable hardware wallet, generate a new seed offline, verify it with a test transaction, transfer all funds to the new setup, *t...

Canadian Bitcoin holders have emerged as the largest group affected by the ongoing attack on the Coldcard hardware wallet, accounting for 25% of all associated losses. Analysts note that such a high regional concentration of losses aligns with the strong local presence of Coldcard's parent company, Coinkite, whose headquarters are located in Toronto.

According to a Chainalysis visual analysis, Australia ranks as the second most severely impacted country in the attack, accounting for 15% to 20% of the total damage. Meanwhile, the United States and Thailand follow closely with losses in the range of 10% to 15%. While the exploit has primarily hit English-speaking countries and early Bitcoin-adopting jurisdictions, the data indicates broad global consequences across Western Europe, Latin America, and key African crypto hubs such as Nigeria and South Africa.

The total value of assets stolen in the incident has reached $116 million. In its analysis of the incident, Galaxy Research identified a firmware update released in March 2021—specifically the implementation of a new random number generator—as the single point of failure that made the attack possible.

"The issue was that it was wired incorrectly and defaulted to using a weaker generator. The failure occurred silently, without any warnings. No one knew their private keys were being generated with low entropy," stated Galaxy Research. "Five years later, an attacker drained $70 million from 1,200 wallets in 41 minutes."

Explaining why standard checks failed to detect this error for over five years, Natalie Newson, Senior Blockchain Investigator at CertiK, reported that the root cause was a specific configuration error: the MICROPY_HW_ENABLE_RNG variable was set to zero.

"For a static #ifndef check, a macro set to 0 is still considered defined," Newson explained. "The security check returned true, suppressing the #error protection and allowing the build system to proceed as if everything was configured correctly."

Incident Response and Emergency Remediation Protocols

To prevent such silent fallbacks to software pseudo-randomness, Newson urged manufacturers to review their architectural standards. "The most robust control is to remove the fallback mechanism from the production environment and have exactly one approved RNG provider," she emphasized, noting that the entire path from entropy sourcing to seed generation must strictly fall within validation boundaries defined by the NIST FIPS 140-3 standard.

Addressing the operational risk management related to rushing out emergency patches during active automated exploitation, Newson stressed that incident response must prioritize user notification alongside technical testing.

"The priority should be immediate notification about the scope of the vulnerability, identifying affected users, and providing clear mitigation guidance, while thoroughly vetting any patch before release," stated Newson, adding that transparency is no less important than the fix itself.

For non-technical users holding compromised seed phrases and fearing bricking their devices during emergency firmware updates, Newson recommended a strict remediation protocol: first, users should acquire a reliable hardware wallet, generate a new seed phrase offline, and verify the setup with a small test transaction. They should then move all remaining funds to the newly verified configuration before attempting a firmware update on the original device.

Newson also urged users to avoid creating a "single point of failure" by using hardware wallets from different manufacturers to distribute risk across multiple accounts.

An Inflection Point for Self-Custody Philosophy

This incident has forced the self-custody industry and its advocates to confront fundamental questions about prevailing security models. Critics point to the sudden disappearance of dormant, long-held assets as proof that offline execution alone does not guarantee absolute protection.

Nanak Nihal Khalsa, co-founder of Human.tech, stated that this incident underscores the immutable reality of third-party risks within hardware wallet ecosystems.

"The slogan 'Not your keys, not your coins' misses a crucial fact: you are always delegating trust to third parties, even with self-custody. This just adds another piece of evidence that self-custody doesn't change that fact," remarked Khalsa, warning that emerging threat vectors, such as AI-based exploits, are likely to exacerbate these risks.

CertiK's Newson echoed concerns about single-signature setups, noting that mass adoption requires systems built with graceful degradation in mind, where a single mistake—be it from the user or the vendor—does not result in the loss of a user's lifetime savings.

"Single-signature self-custody leaves no room for error," said Newson. "Users relying on a single device are trusting the physical hardware, the code and all its dependencies, and the QC checks meant to catch any issues."

Consequently, industry consensus is shifting towards multi-vendor configurations, utilizing multi-signature or threshold signature schemes (MPC) as a mandatory baseline standard.

"Yes, this should be the default baseline standard," concluded Newson. "The goal is to move from 'trust in one device' to ensuring no single compromised component or party can move funds. In practice, signing keys or threshold signature shares should span independent domains of organizational and technological failure so that no single provider can recover the key or authorize a transaction on its own."

热门币种推荐

相关问答

QAccording to the article, what percentage of total losses related to the Coldcard vulnerability were suffered by Canadian users?

ACanadian users accounted for 25% of all losses related to the Coldcard vulnerability.

QWhat was identified as the single point of failure that enabled the attack on Coldcard wallets?

AThe single point of failure was a firmware update released in March 2021, specifically the implementation of a new random number generator which was incorrectly connected and defaulted to a weaker generator.

QWhat specific configuration error was the root cause that allowed the vulnerability to go undetected for over five years?

AThe root cause was a specific configuration error where the variable MICROPY_HW_ENABLE_RNG was set to zero. In static checking, a macro set to 0 is still considered defined, causing the security check to return true and suppress the #error protection.

QWhat protocol does Natalie Newsom recommend for non-technical users who own compromised seed phrases and fear bricking their devices during emergency firmware updates?

AShe recommends a strict remediation protocol: first, purchase a reliable hardware wallet and generate a new seed phrase offline, verifying the setup with a small test transaction. Then, move all remaining funds to the newly verified configuration before attempting to update the firmware on the original device.

QAccording to the industry consensus mentioned in the article, what is shifting towards becoming a mandatory baseline standard for security?

AThe industry consensus is shifting towards multi-vendor configurations, using multi-signature or threshold signature schemes (MPC) as a mandatory baseline standard to move from 'trusting a single device' to ensuring no single compromised component or actor can move funds.

你可能也喜欢

交易

现货

热门文章

加密市场宏观研报:《GENIUS Act》法案取得重大进展,BTC突破历史新高,后市全新展望

2025年5月22日,比特币价格正式突破11万美元大关,创下历史新高。在政策面、宏观经济、资金面与投资者结构共同作用下,一场结构性牛市浪潮正在展开。而此轮上涨背后的核心驱动,是美国《GENIUS稳定币法案》的实质性进展以及多项利好的叠加。本文将从政策端突破、宏观环境转向、链上与ETF资金结构、交易行为演化,以及重点受益赛道五大维度,全面解析此轮BTC再创新高的深层逻辑,并前瞻下半年市场的潜在趋势。

1.9k人学过发布于 2025.05.22更新于 2025.05.22

加密市场宏观研报:《GENIUS Act》法案取得重大进展,BTC突破历史新高,后市全新展望

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对BTC(BTC)币价的意见。

活动图片