Galaxy Research Coldcard hack update: 1,158.81 BTC stolen from 2,673 addresses

17 pointsposted 9 hours ago
by paulpauper

7 Comments

ifwinterco

6 hours ago

This is a bad one: bug in the RNG logic during seed generation, so you can lose funds easily without any action from the user and the device never connected to the internet.

I still think crypto is unfairly maligned and will be more significant in the coming decades than most people think, but the fact it's almost impossible to do self custody safely and statistically you're less likely to lose funds just having them on Coinbase or Kraken (aka in a bank) is pretty damning

84adam

5 hours ago

> it's almost impossible to do self custody safely

The main problem here, I think, is that Coldcard (Coinkite) was one of the largest and most heavily promoted hardware wallets in the space. Many of the top influencers promoted them. And the bug in RNG was actually introduced inadvertently in an effort by Coinkite to move the firmware away from an open source license to a 'source viewable' license.

None of the other hardware wallet manufacturers introduced this class of bug into their firmware.

In-depth review of other solutions being done by many in the community now, of course. E.g.: https://xcancel.com/bitcoinsbanker/status/208361209471318024...

ifwinterco

5 hours ago

Yep and red flags were there in hindsight, but everyone ignored them.

I think the brutal truth for maxis is that coldcard was promoted by them because of coinkite’s bitcoin-only stance and there was no actual assessment of whether the team or the product was made with the care needed.

Anyone who hates “shitcoins” must be a thoughtful, conscientious person right?

Well no, as it turns out

user

4 hours ago

[deleted]