Live data from Hacker News

Coldcard's $38M (so far) exploit shakes faith in self-custody

coindesk.com

21–30 of 31 posts

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#21

Incredible hyperbole from the Amicus guy: "This is hugely damaging to the people who believe that 8 billion people will hold their Bitcoin in cold storage in the future," Lawrence said. "That dream is over. Done." Sky is falling stuff. Actual cryptography experts have shown the importance (and difficulty) of random number generation for ages. Yes, if your "hardware wallet" aka computer and software is implemented poo…

Yes this has been a known problem of crypto/self custody since its inception. The 1 private key -> public key -> address is elegant but an horrible single point of failure.

When people create a wallet, the quality of the entropy and seed is always: I guess good, for now...

So far the only mitigation for that have been multi-signature but it has its own potential vulnerabilities.

My understanding is the next big Ethereum upgrade might include "Frame Transaction" [0] which will bring a "native multisig" capability to accounts so you can easily always have 2 addresses with different seeds origin to mitigate the risk.

- [0] https://forkcast.org/eips/8141/

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#23
post #7

This is really bad. This is going to set bitcoin back years.. if it ever comes back. There really is no point and no real use case for it outside of crime. Unless the whole world order collapses in which case we'll have bigger problems..

The AI attacks are the scary piece so now you have something that you could spend $1m on tokens and brute force compute and it is worth it, for a prize of $10m+ and one million is a lot of AI

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#24
post #2

Coldcard Security Advisory: https://blog.coinkite.com/coldcard-mk3-seed-generation-warni...

That advisory would probably be more helpful if it described what the actual issue is. (I’m thinking maybe some content got lost when the Update at the top was added?)

Yes and it is very unclear to me what are actually the risks...

I am unfamiliar with "coldcard" but can hackers find out which wallet is used for which account? or maybe it can be inferred by analysing the transaction (if any)?

If the hackers do not know which accounts to attack first there is probably no need to panic right now.

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#25
post #23
post #7

This is really bad. This is going to set bitcoin back years.. if it ever comes back. There really is no point and no real use case for it outside of crime. Unless the whole world order collapses in which case we'll have bigger problems..

The AI attacks are the scary piece so now you have something that you could spend $1m on tokens and brute force compute and it is worth it, for a prize of $10m+ and one million is a lot of AI

Is $1m a lot of AI? I’m finding that there’s significant diminishing returns in terms of what can be accomplished. The first dollar always seems to be the most impressive. By $10 I’m already underwhelmed, though.

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#26
post #23

Earlier quoted context omitted.

The AI attacks are the scary piece so now you have something that you could spend $1m on tokens and brute force compute and it is worth it, for a prize of $10m+ and one million is a lot of AI

Is $1m a lot of AI? I’m finding that there’s significant diminishing returns in terms of what can be accomplished. The first dollar always seems to be the most impressive. By $10 I’m already underwhelmed, though.

Definitely alot for vulnerability finding. It may not scale up as well for building systems.

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#27
post #26

Earlier quoted context omitted.

Is $1m a lot of AI? I’m finding that there’s significant diminishing returns in terms of what can be accomplished. The first dollar always seems to be the most impressive. By $10 I’m already underwhelmed, though.

Definitely alot for vulnerability finding. It may not scale up as well for building systems.

I’ll buy that, good take.

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#28

so there was $70 million just sitting there for five years in the open that anyone could have taken. Nuts. Enticed by riches, hackers worldwide are now going through all firmware source code , wit the help of the latest AI models, for all wallets to find misconfigurations and other problems. Expect more thefts from low entropy bugs. AI has clearly been shown to be more more adept at auditing code than humans.

Meanwhile nobody has ever been able to hack a bank. Probably because they employ the actual pros unlike crypto.

[dead]

Re: Coldcard's $38M (so far) exploit shakes faith in self-custody

#30

Earlier quoted context omitted.

Meanwhile nobody has ever been able to hack a bank. Probably because they employ the actual pros unlike crypto.

> Nobody has been able to hack a bank Bro, people lose hundreds of millions of dollars to bank scams on a yearly basis.

Bank scams mostly trick the user into making a transfer or having their credentials stolen somehow and very rarely directly hack the bank which is more like what this attack is doing.
Post reply on HN