A devastating attack is currently tearing through the cryptocurrency ecosystem, siphoning millions of dollars’ worth of bitcoin out of user wallets and into the hands of different hacking collectives. The hack is targeting users of the Coldcard hardware wallet, a wallet designed exclusively for storing bitcoin, meaning other cryptocurrencies have not been affected. The losses already amount to well over $100 million, but this figure continues to grow with each passing day. Thousands of users have been affected.
Hardware wallets are designed to provide a secure way for people to store and access their cryptographic assets, but in this case, things have gone horribly wrong. After the vulnerability emerged, Coinkite, the Toronto-based company behind the wallet, even instructed users to move their funds as soon as possible.
As usual when a large-scale hack occurs in the crypto industry, the debate between self- and third-party custody has started raging once again, with no clear winner emerging.
The entire point of self-custody in crypto is that a person’s digital assets cannot be touched by anyone else unless the required cryptographic authorisation is provided. This typically means signing a transaction with a private key, something that is only known by the individual who generated it in the first place. The private key provides ultimate control over these assets, but consequently, this makes it a single point of failure if stolen. This is why exposing private keys in day-to-day operations on an internet-connected device is considered bad practice. Malware or key loggers could potentially steal the key, granting the bad actor immediate and unrestricted access to the affected wallet.
This is why many people elect to use a hardware wallet instead. A hardware wallet allows people to sign transactions while keeping the private key contained within a secure element placed inside the device. The private key is therefore never exposed to the local machine, nor to the internet at large. The hardware wallet keeps all the critical information away from prying eyes, while allowing funds to be moved around by means of a PIN or passphrase, input directly into the device. Under normal circumstances, a potential attacker would need physical access to the device, along with the PIN necessary to unlock it.
This is all well and good, but then why are thousands of wallets being drained of their funds? The answer, as far as cybersecurity experts (and Claude) are able to ascertain, is due to a coding error in the Coldcard firmware. The details become a little more troublesome here but are worth taking the time to properly understand.
A private key is just a number. It is one number sampled among an unimaginably huge array of other numbers. Finding a simple number may seem trivial, but the sheer number of possibilities in question makes the task statistically impossible. It would be like trying to find one grain of sand, not just on Earth, but in the entire universe.
The trick is to generate the number with a degree of randomness that cannot possibly be replicated. This is where regular random number generators fail. Regular RNG as used in most software starts with a seed number, which is then put through a bunch of known mathematical functions. The process is deterministic, meaning that the same input always leads to the same output.
This will not do. Crypto software relies instead on cryptographic random number generators, which are not deterministic. Numbers produced in such a manner cannot be predicted, under any circumstance, meaning the resulting private key is truly unknowable. This process has been the foundation of cryptocurrencies since their inception.
The apparent vulnerability found in the Coldcard firmware is that the private key generation mechanism used a regular RNG as opposed to a cryptographic one. The private keys were predictable because they were generated using deterministic RNG, which vastly reduced the total array of numbers from which they were sampled. Once someone figured this out, it was a simple matter of replicating the seed generation process on external hardware and reproducing the same private keys independently. Once this was done, draining the wallets in question was trivial.
If this is indeed how some of the keys were generated, then the wallets in question were about as cryptographically secure as the average toaster. This would also explain why the attack does not appear to be a singular event but rather an ongoing process as attackers continue to find new keys.
Coldcard users did everything right. They were careful. They spent money on what they thought was a secure hardware wallet in order to protect their bitcoin. They were robbed anyway. “Unfair” doesn’t even begin to cover it. And yet, in an extremely cruel way, the bitcoin mantra of “don’t trust, verify”, emerged from this stronger than ever. The fact is that thousands of people did not verify the source code of the hardware wallet they were using; they paid the price.
On the other side of the equation, there are people out there who recognise their technological limits and entrust their funds with the likes of Coinbase or Binance. Fair enough, but the immediate counterargument to that lies with Mt. GOX, QuadrigaCX, Cryptopia and a long list of other exchanges that suddenly went dark, leaving their customers with nothing.
The crypto industry does not currently have an answer. When people fall victim to credit card theft, their bank will often block the transaction, freeze the card and ship a new one within a couple of days. There is absolutely no equivalent in crypto. The recent hack has in fact prompted calls for more regulated crypto exposure; something currently being held up by the failure of the US Congress to pass the Clarity Act.
About the Author
Lawrence J. came from a strong technical and engineering background before pivoting into a more financial role later on in his career. Always interested in international finance, Lawrence is experienced in both traditional markets as well as the emerging crypto markets. He now serves as the financial writer for RADEX MARKETS.
Reviewed by RADEX MARKETS
Risk Warning: Trading derivatives and leveraged products carries a high level of risk, including the risk of losing substantially more than your initial investment.