Skip to main content

Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken

3 weeks 3 days ago
"A hardware wallet is supposed to be the safest place to keep Bitcoin," writes The Street, since it never connects to the internet, its keys never leave the device, and "the whole point is that an attacker would need to physically hold it to steal anything." The problem is that anyone who can reproduce the recovery seed doesn't need to possess the COLDCARD, Nerds.xyz points out. More from The Street: [The recovery seed] is supposed to come from a hardware random number generator producing 128 bits of entropy, a number so large that guessing it is computationally impossible. It wasn't. According to Block's engineering team a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure and called it preliminary. The gap between 128 bits and 40 bits is not a matter of degree. It is the difference between a lock that cannot be picked and one that can be brute-forced by anyone with rented cloud computing.... Chainalysis found the attacker went after the largest balances first, pulling more than $30 million in the opening ten minutes. Within about 25 minutes, roughly 594 BTC had moved out of some 500 single-signature wallets. One victim lost around $1.8 million... Coinkite has shipped fixed firmware, but with a warning that matters more than the patch itself. Updating does not repair an existing seed. A seed created with weak entropy stays weak forever. Affected users have to generate an entirely new wallet on updated hardware and move their coins to it. By Saturday morning Galaxy research was tracking 1,158.66 BTC, worth roughly $75.1 million, taken from 2,673 addresses, according to the article. And "The Coldcard exploit is ONGOING," Galaxy Research posted an hour ago on X.com. "Move Coldcard single-sig funds to safe locations immediately!" We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators. Thanks to Slashdot reader BrianFagioli for sharing the news.

Read more of this story at Slashdot.

EditorDavid

Is Big Tech's AI Gamble Starting to Look Riskier?

3 weeks 3 days ago
The Washington Post looks at giant tech companies "feeding every available dollar into the cash-incinerating maw of AI machines." They warn "Tech superstars that once had oodles of cash left over at the end of each year are now flipping into the red..." [While optimists expect] huge corporate profits and a society-wide boost to wealth and well-being... questions about that AI vision are now growing more urgent: When, if ever, will this payoff arrive? And what will the fallout be for Americans if the titanic investment doesn't quickly deliver? "This AI thing better work out because if it doesn't ... we're going to have a problem," said Torsten Slok, chief economist at investment firm Apollo Global Management. AI costs and doubts are spreading. The U.S. stock market has swooned this summer over fear of the AI bubble going bust... The AI gamble sweeping up American fortunes is led by tech companies splurging on hulking data centers packed with computer chips and equipment needed to develop sophisticated AI models and deliver them to customers. In investor calls in the past week, Google, Microsoft, Meta and Amazon pointed to soaring AI-related sales and business deals. Advertisers are using the technology to tailor marketing pitches and corporations and start-ups are buying access to chatbots and other AI software to boost productivity... But this spending can only continue if AI generates an even larger avalanche of new revenue to pay for it all. Financial results released over the past week show that the AI titans' mammoth costs are largely swamping the sales boost from the technology. At Google, for every dollar of cash its business generated in the past three months, $1.15 went out the door to pay for AI computer chips and equipment, land for AI data centers and other big-ticket purchases. The company is covering the difference partly by borrowing money and selling more of its stock. Next year, five leading AI companies — Google, Amazon, Microsoft, Meta and Oracle — are projected to have negative free cash flow, which measures the cash left over after paying expenses and AI infrastructure costs. The figures, based on investment analyst projections compiled by S&P Global Market Intelligence, show a stunning reversal for what have been some of the world's most cash-generating corporations... The companies remain profitable by standard financial accounting measures that spread out the costs of their AI infrastructure spending over many years... Pessimists see a bet so gargantuan that it cannot possibly pay off. The pessimists are growing louder. The Bank for International Settlements, a typically measured institution in Switzerland that advises government bankers around the world, recently warned there was risk of "economy-wide recessions" if the AI boom falters. That could mean pain for workers and communities across the United States. "I'm not saying AI is going to go away, it's just not clear to me these guys are going to make money on it," said Christopher Wood, global head of equity strategy at investment bank Jefferies who has correctly predictedpast financial bubbles.

Read more of this story at Slashdot.

EditorDavid