Skip to content

In the Coldcard Theft Case, I Learned on the Front Lines Why This Incident Had a Far Greater Impact Than Meets the Eye

Aug 4, 14:31
In the Coldcard Theft Case, I Learned on the Front Lines Why This Incident Had a Far Greater Impact Than Meets the Eye

Unexpectedly, a vulnerability from 5 years ago has led to this year's largest Bitcoin theft.


On July 30, someone noticed unusual activity. Initially, hundreds of bitcoins were rapidly consolidated from hundreds of addresses. The attack quickly escalated as the attacker scanned over a thousand Bitcoin addresses, making off with over 1,300 bitcoins worth hundreds of millions of dollars.


The root cause was promptly identified: a bug in a hardware wallet called Coldcard during the seed phrase generation process. It was a weak random number generation issue where the randomness was not so random and could be guessed.


Since Coldcard has few users in China, initially, there was not much attention paid to it. However, the situation exploded internationally as Coldcard is well-known overseas. After a few days of brewing, panic reached its peak. On July 31, the total amount of transfers under 1 BTC reached 39,600 BTC in a single transaction, setting a new high since the 2022 FTX crash.


This incident was most likely also an AI-model-discovered vulnerability and attack, similar to the Zcash incident that halved its value in a day. This time seems to be even more severe, not visibly in the data, but affecting confidence, which is immeasurable.


To understand the frontline perspective on the Coldcard incident and its impact, Odaily BlockBeats spoke with SlowMist founder Cosmos. Some victims have entrusted SlowMist to help them, and SlowMist has been tracking the Coldcard incident throughout. In Cosmos's view, the repercussions of this theft are profound as it has shaken the faith of Bitcoin's core believer community.


Odaily BlockBeats: Has Coldcard engaged a security company to assist in asset recovery? The stolen bitcoins are now valued at over a hundred million dollars. Is the likelihood of recovery high?


Cosmos: It is still uncertain which hacker group is behind this. It will depend on their subsequent transfer methods to determine. If it is eventually confirmed to be a state-sponsored hacker group (such as North Korea's hackers), recovery will be difficult.


Officially, apart from releasing some security advisories, we have not seen them involve a security team. Currently, some individual victims of Coldcard theft have approached us to help them recover their assets.


Odaily BlockBeats: Looking at the reason for this theft, in simple terms, the random number is no longer random. I recall that random number issues occur almost every year in the encryption industry's history. Why does this incident appear to be so severe?


Cosine: Solely in terms of quantity and amount, a transaction involving thousands of bitcoins is not the largest in history. In the past, there have been events such as Mt. Gox, Bitfinex, and the Lubián mining pool being hacked, resulting in the loss of tens of thousands or even hundreds of thousands of bitcoins. Even a casual bridge hack could surpass the amount involved in this incident.


However, the issue lies in the fact that Coldcard has a very good reputation. They are open-source, transparent, geeky, and minimalist, and have been used by many Bitcoin OGs and believers for a long time. When something that seemed so perfect encounters a problem, it deals a heavy blow to that group of most steadfast users.


At the core of this issue is the severely inadequate entropy during the mnemonic generation process, leading to a seed with much weaker randomness than expected. A hacker could use brute force to derive a user's mnemonic phrase. This is the most fundamental and also the most fatal security issue concerning crypto assets.


I find it most absurd that with the emergence of powerful AI models, neither Coldcard nor Bitcoin believers bothered to review the code using AI, but the hackers did. Because if the focus is solely on vulnerabilities related to the mnemonic seed randomness, AI nowadays can easily identify and discover such issues.


Therefore, this incident has had a significant impact because it has shaken the most core group of believers.


Rhythm BlockBeats: So, from your perspective just now, the impact of hacks like Mt. Gox, Bitfinex, and the Lubián mining pool being stolen this time is quite profound on the crypto industry?


Cosine: When a long-standing, open-source, geeky hardware wallet encounters issues under the perceived "perfect" scenario, it will severely undermine the community's confidence in similar products. Users will start to question: Does the wallet I'm currently using have issues too? Are the mnemonic phrases generated in the future secure?


Rhythm BlockBeats: Would you recommend that crypto projects now run their code through AI to find vulnerabilities? Or how is SlowMist currently handling this?


Cosine: I would recommend doing so.


The impact of AI on the entire security industry is much greater than what the public currently perceives. Hackers are almost unrestricted; they can construct targeted powerful models, while the defense side faces various limitations such as model access, computing power, scrutiny, and more.


We do not conduct audits on the source code of public chains such as Bitcoin and Ethereum because of limited resources. We prioritize important clients to ensure that the likelihood of them facing risks in the AI era is reduced. We retrospectively examine past projects using AI and have indeed discovered many issues that were previously overlooked, with very effective results.


Rhythm BlockBeats: This raises another rather pessimistic question. As models become stronger, will the distrust of early cryptocurrency technology intensify? For example, Zcash had a similar impact in the past?


Cosine: It definitely will. Security can never reach 100%. The arms race between attacks and defenses is always ongoing. Hackers' motivation and ability to act using AI far exceed that of the defense side because once they break through, they can directly cash out, making it very cost-effective. Meanwhile, the defense side is constrained by various processes and resources.


In this unequal scenario, security incidents far exceeding previous levels will definitely occur, with the possibility of reaching the tens of billions of dollars. Even Bitcoin's own code could potentially have issues discovered in the future.


However, overall, I am not pessimistic about the industry's response to these threats. The arms race between attacks and defenses will always exist, and cryptographic events will undoubtedly become more robust.


Rhythm BlockBeats: Some opinions are starting to turn towards highlighting the advantages of centralized exchanges, believing that centralized exchanges are safer. What is your view?


Cosine: Indeed, several top centralized exchanges have made significant investments in basic security. Even if issues arise, they have a certain level of backstop capability unless it is an extremely catastrophic event.


For most users, it's actually difficult to independently handle hardcore operations like mnemonic phrases and multi-signatures. In the past, wallets were more often chosen based on reputation and recommendations from people around them. However, this incident has made everyone realize that even wallets widely considered good may have hidden dangers. As a result, some users feel it's more reassuring to place their assets back in a reputable centralized exchange. This kind of thinking is understandable.


Rhythm BlockBeats: For ordinary users who don't understand the technology and don't look at wallet code, how should they guard against events like Coldcard?


Cosine: First of all, I recommend that all users use a passphrase for their mnemonic phrase. Think of it as adding a password layer to the mnemonic phrase, which is much better than not having one. Adding a slightly complex passphrase of at least 8 characters—just don't forget it yourself. Nowadays, most mainstream hardware wallets support this.


Even if a similar event occurs again, hackers will prioritize moving funds that do not have a passphrase. This provides a significant buffer for your main assets. For example, you can place a tiny portion of your funds in a non-passphrase-protected regular address and the majority in an address with a passphrase. If the small amount is transferred, it indicates a mnemonic phrase leak. As cracking the passphrase is very costly for hackers, this buys you time.


For the average user who has no understanding of the industry at all, it's fine to use the services of centralized institutions and rely on them to handle any issues.


Additionally, here are three general pieces of advice for all players:


· Organize Your Assets: Take the time to check if your wallet recovery phrase is clear and if there has been any possibility of leaking the mnemonic. If there is any uncertainty, consider changing your storage method.

· Stay Calm: Do not rush into a fake wallet or fall victim to phishing attacks out of haste.

· Practice Segregated Thinking: Place uncertain assets in a separate device (even air-gapped), do not mix them together. This is much safer than assuming everything is fine.


By following these steps, more than 90% of common risks can be effectively mitigated.


Recommended

"The 'AI Stock God' Margin Call and the 'Korean Stock Market Crash' may just be a prelude to a bigger storm."

Aug 4, 16:00
"The 'AI Stock God' Margin Call and the 'Korean Stock Market Crash' may just be a prelude to a bigger storm."

For the first time since 1955, S&P 500 earnings are 14% above the long-term trend.

Aug 4, 15:03
For the first time since 1955, S&P 500 earnings are 14% above the long-term trend.

On the eve of Circle's earnings report, Wall Street is sharply divided on CRCL valuation

Aug 4, 13:25
On the eve of Circle's earnings report, Wall Street is sharply divided on CRCL valuation

Dalio Latest Interview: Already in an AI Bubble, 1% of Portfolio Is Bitcoin

Aug 4, 12:23
Dalio Latest Interview: Already in an AI Bubble, 1% of Portfolio Is Bitcoin

The Silicon Valley That Copies China's Homework, Next Question: AI Applications

Aug 4, 11:36
The Silicon Valley That Copies China's Homework, Next Question: AI Applications

Palantir’s AI Story Starts to Show Up in Earnings and Contract Tables

Aug 4, 10:31
Palantir’s AI Story Starts to Show Up in Earnings and Contract Tables