Article may be outdated

This article is 59 days old. Some details may have changed since publication.

Hacker News·4 min read·hard

Lines of code. 1,596 BTC gone

A
Archie627
Lines of code. 1,596 BTC gone
✦AI Summary

A critical security vulnerability in COLDCARD hardware wallets allowed attackers to drain 1,596 BTC due to a firmware change that weakened random number generation. The flaw, which went unnoticed for five years, highlights the risks of software-based entropy in hardware security.

Why it matters

This incident underscores the importance of rigorous security audits for hardware wallets, which are often considered the gold standard for cryptocurrency storage.

✦Dive DeeperCreate a free account to unlock

Two files, four lines, five years unnoticed. This is the COLDCARD entropy failure taken apart step by step — what the defect was, how attackers found the wallets, what affected owners should do — and the four checks OneKey runs so the same thing cannot happen here quietly.

Six steps, no jargon. The note beside each one is the precise technical version, for anyone who wants to check the work.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycrypto
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in