Live data from Hacker News

Coldcard's $38M (so far) exploit shakes faith in self-custody

coindesk.com

1–10 of 30 posts

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#4
so there was $70 million just sitting there for five years in the open that anyone could have taken. Nuts.

Enticed by riches, hackers worldwide are now going through all firmware source code , wit the help of the latest AI models, for all wallets to find misconfigurations and other problems. Expect more thefts from low entropy bugs. AI has clearly been shown to be more more adept at auditing code than humans.

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#6
Incredible hyperbole from the Amicus guy:

"This is hugely damaging to the people who believe that 8 billion people will hold their Bitcoin in cold storage in the future," Lawrence said. "That dream is over. Done."

Sky is falling stuff. Actual cryptography experts have shown the importance (and difficulty) of random number generation for ages. Yes, if your "hardware wallet" aka computer and software is implemented poorly you will have issues.

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#8

so there was $70 million just sitting there for five years in the open that anyone could have taken. Nuts. Enticed by riches, hackers worldwide are now going through all firmware source code , wit the help of the latest AI models, for all wallets to find misconfigurations and other problems. Expect more thefts from low entropy bugs. AI has clearly been shown to be more more adept at auditing code than humans.

Meanwhile nobody has ever been able to hack a bank. Probably because they employ the actual pros unlike crypto.

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#9
post #2

Coldcard Security Advisory: https://blog.coinkite.com/coldcard-mk3-seed-generation-warni...

That advisory would probably be more helpful if it described what the actual issue is. (I’m thinking maybe some content got lost when the Update at the top was added?)

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#10
From the Twitter advisory [1]:

>>> To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike.

Kinda turns the “many eyes” principle of OSS on its head, eh?

[1] https://x.com/nvk/status/2083216713693151552?s=61

Post reply on HN