This is the best technical analysis I have seen, so far. https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt It doesn't appear that Coinkite, the company behind ColdCard products, had a mature senior engineer in the loop. At least, no engineer who could immediately flag such sloppy code commit practices. This sort of thing is ongoing, as we can see in commits made this week, even. Clearly seems like a corpor…
The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
11–20 of 44 posts
Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
#12The way AI is advancing what is growing is the ability to look far and wide.
88M is minor by crypto hack standards, and the "cost basis" of the holders on these cards started at a fraction of that, perhaps that is why nobody bothered to find this bug earlier, it's a very niche product.
Also here's a good technical writeup
Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
#13Interesting topic, but I don’t like this writing style. It’s a lot of words to say very little and repeats sentence structure often. The author assumes the reader knows about this hack already, and doesn’t not provide context on what it is, or details like why the attacker is storing coins in 4,000+ wallets.
Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
#14This is the best technical analysis I have seen, so far. https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt It doesn't appear that Coinkite, the company behind ColdCard products, had a mature senior engineer in the loop. At least, no engineer who could immediately flag such sloppy code commit practices. This sort of thing is ongoing, as we can see in commits made this week, even. Clearly seems like a corpor…
Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
#15There's still some small part of me hoping that the later waves are whitehats and the reason they're keeping everything in segmented addresses is because they hope to find a way to return the funds.
Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
#16Interesting topic, but I don’t like this writing style. It’s a lot of words to say very little and repeats sentence structure often. The author assumes the reader knows about this hack already, and doesn’t not provide context on what it is, or details like why the attacker is storing coins in 4,000+ wallets.
Is there a good summary somewhere for those not already following the story?
Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
#17Interesting topic, but I don’t like this writing style. It’s a lot of words to say very little and repeats sentence structure often. The author assumes the reader knows about this hack already, and doesn’t not provide context on what it is, or details like why the attacker is storing coins in 4,000+ wallets.
Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
#18Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
#19That's a strange interpretation. If it was planned well, why weren't all affected addresses drained as quickly as possible? I would have continuously emptied all vulnerable addresses, from highest to lowest without taking a break in the middle.
> Instead of picking the lowest cost option, the attacker appears to be prioritizing speed in an apparent move to make themselves as untraceable as possible.
I don't see how higher fees would make the attacker less traceable. If anything, the unusually high fees stand out. Though in the long run defenders will enumerate all the vulnerable source addresses anyway, so the affected coins are inherently traceable (at least until laundered).
More likely they prioritized speed to beat other attackers, now that the vulnerability is public. No matter if this was the original attacker or a competitor.
Re: The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M
#20The Bitcoin communities seem to really be struggling with this hack. The people losing their coins in this case were following best practices. Typically when someone loses their coins there’s a big pile-on to victim blame them for making some mistake. I think it’s comforting to others to be able to identify a mistake someone else made and then convince yourself that you’re too smart to make the same mistake. In this…
also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence.
>My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone with good OPSEC at the time.
if that's a worry just search for things far before the exploit date; lots of unhappiness around cardkite for a while now -- but to be clear, it's nowhere near a revision.