The way AI is advancing what is growing is the ability to look far and wide.
88M is minor by crypto hack standards, and the "cost basis" of the holders on these cards started at a fraction of that, perhaps that is why nobody bothered to find this bug earlier, it's a very niche product.
Also here's a good technical writeup
In this case, there isn’t much of a mistake to point out. I’ve seen a couple attempts from people trying the told-you-so routine using some arguments about multisig wallets as the only option, but mostly it looks like people are panicking and wondering if their choice of wallet has some undiscovered vulnerability waiting to be exploited. I mostly try to stay away from Bitcoin communities but in events like this it spills over everywhere. I feel sorry for anyone who lost coins, of course, but it’s also interesting to watch the communities grapple with reconciling their appreciation for irreversible key-based transactions with the realities of how this works when their money is on the line. The old ideas about having perfect OPSEC and being smarter than the other coiners are starting to get weakened with examples like this.
My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone with good OPSEC at the time.
also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence.
>My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone with good OPSEC at the time.
if that's a worry just search for things far before the exploit date; lots of unhappiness around cardkite for a while now -- but to be clear, it's nowhere near a revision.
Seems like part of the issue here is that it was open source in a way that from the discussion here (https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt) may have made vulnerabilities easier to spot for an attacker...?
That’s how the retroactive victim blaming always works: It is retroactively determined that there were signs, which turns into victim blaming anyone who didn’t predict that those signs would lead to loss of their coins.
You are doing it.
> also as far as I care the btc community members who chose to go with one of the few hardware wallets that wasn't open source were not doing due their diligence.
I can’t tell if you’re confused about the details of this story or if you’re trying to make a point that isn’t landing. You may want to read up on the open source status of the wallet before doing the whole victim blaming song and dance.
I don’t buy this. There is no $249 device that I would trust with even 1 BTC. These folks looked at the options to preserve $100,000 and picked a $249 device over an exchange. Or a bank. Or the DOW.
It is heartbreaking the loss that some have suffered. But it doesn’t benefit anyone to say “Who could have known?” Everyone knew: because not one person said “I have verified this product and it cannot possibly be vulnerable”. So “it’s open source and you can verify it yourself!” Ok. Nobody did! “Well maybe they did, they just didn’t find the exploit” - that’s the point!
> My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone with good OPSEC at the time.
Yeah. I didn’t use it. I would never use it. The problem is that “everyone with good OPSEC” are “obviously just plants of Big Bank and the IRS”. The criminals that benefit from “normal” people “legitimizing” bitcoins have really good PR department.
Bitcoin communities have been advocating for hardware wallets over exchanges for a long time. The phrase goes “not your wallet, not your coins”
Like if I woke up one morning and found money in my bank account that wasn't supposed to be there, I could just tell the bank to send it back where it came from.
https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt
It doesn't appear that Coinkite, the company behind ColdCard products, had a mature senior engineer in the loop. At least, no engineer who could immediately flag such sloppy code commit practices. This sort of thing is ongoing, as we can see in commits made this week, even.
Clearly seems like a corporate culture issue. A very low bar seems standard practice.
2. For each seed, generate a few addresses using BIP-32.
3. Use a blockchain explorer API to check if those addresses have been used.
4. For each address that contains unspent coins, generate the corresponding private key (again using BIP-32) then create a transaction sending the coins to the attacker.
That's a strange interpretation. If it was planned well, why weren't all affected addresses drained as quickly as possible? I would have continuously emptied all vulnerable addresses, from highest to lowest without taking a break in the middle.
> Instead of picking the lowest cost option, the attacker appears to be prioritizing speed in an apparent move to make themselves as untraceable as possible.
I don't see how higher fees would make the attacker less traceable. If anything, the unusually high fees stand out. Though in the long run defenders will enumerate all the vulnerable source addresses anyway, so the affected coins are inherently traceable (at least until laundered).
More likely they prioritized speed to beat other attackers, now that the vulnerability is public. No matter if this was the original attacker or a competitor.
Or, given that previous hacks and losses didn't affect the price from shooting up to new highs, is this the perfect time to buy?
That said, there’s a lot of speculation and money laundering which provides a floor on prices. If you look at the historical numbers it looks like the whales will somewhat reliably step in around $60k to reverse a decline, which suggests there’s a benefit for some of them around that price. If you’re canny, you can probably make a decent return but I wouldn’t spend any money you can’t afford to lose.
this is an inexcusable slop-y error that made me press close on the tab.
While no one knows if there might have have been earlier exploitation, the new exploitation just started and did not extend back to the vulnerable firmware release.