[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/biz/ - Business & Finance

Name
Options
Comment
Verification
4chan Pass users can bypass this verification. [Learn More] [Login]
File
  • Please read the Rules and FAQ before posting.

08/21/20New boards added: /vrpg/, /vmg/, /vst/ and /vm/
05/04/17New trial board added: /bant/ - International/Random
10/04/16New board for 4chan Pass users: /vip/ - Very Important Posts
[Hide] [Show All]


Janitor acceptance emails will be sent out over the coming weeks. Make sure to check your spam folder!


[Advertise on 4chan]


File: 1757872449359364.png (225 KB, 600x600)
225 KB PNG
Never heard of coldcard before, but i have autism and a software engineer by trade. Here is what I found.

The Coldcard wallet hack was not a breach of the Bitcoin network as some retards claim, but rather an exploit of a severe firmware flaw that allowed a specific attacker to guess users' private keys offline. (Company should be sued for this with a class action on coinkite. This screams criminal negligence)

he vulnerability resulted in the theft of over $75 million in Bitcoin (1,158+ BTC) across thousands of addresses they used computers to "fast guess" the software addresses.

Coinkite, who makes the devices, did not do this intentionally, but is 100% liable. This "hack" is elementary in nature and I'm willing to point the finger on them to either knowingly leaving the bug in or didn't audit the incoming code. Their are tools we use in the software engineering world that will check for bug like this. This should have have been a thing. EVER.

A hardware wallet’s sole job is to generate absolute randomness (entropy) to create a private key that is impossible to guess. If the randomness is predictable, the keys can be reverse-engineered. From what I can tell, the bug was applied with firmware version 4.0.0 in March 2021.

Because the hardware RNG was bypassed, the software PRNG relied on highly predictable variables to seed its "randomness".

This also means, the attacker did not need to physically touch or hack into the Coldcard devices, because the underlying variables were limited and predictable, the hacker recreated the candidate output streams completely offline using custom software they built for the purpose.

TL;DR - They either chose to not audit the incoming code back in March 2021 with the bug in it, or they let it go through on purpose. Either way, they should be sued into the ground for this and answers gathered in court as to way no one caught it And I'm wondering if they hid it through obfuscation.
>>
Do you seriously believe that coinkite has $75 million?
>>
>>62551843
Thank you for sharing your thoughts with us.
>>
>>62551848
Re-read the text.
>>
>>62551843
How are the bitcoin influencers going to recover?

There's half a decade of receipts of them promoting coldcard and trashing better alternatives.
There's something wrong with them it's very cliquey.
>>
>>62551843
sorry for the typoes

I just wanted to add and to be more clear.

When the issue was discovered, Coinkite immediately worked to ship emergency hotfix firmware to patch the loophole across all affected models. They are responsible for the firmwares. People saying otherwise are misdirecting either on purpose or by accident.
>>
>>62551860
Imagine listening to jewtubers ever, or store coins on a cex lel.
>>
>>62551861
NVK also denied it at first then they sent marching orders for all the influencers to blame a.i.

It looks like a retard mistake being covered up.
>>
>>62551843
>Don't even need the devices
>Just guess all the seed phrases
The perfect hardware wallet scam.

Fucking clown world of finance.
>>
>>62551861
Here is the issue in code form in python

They originally had for seeds (Secure)
>seed = bytearray(32)
>rng_bytes(seed)

(March 2021, firm: 4.0.0)
but changed it to (predictable)
>seed = random.bytes(32)

This is very baffling to me as a coder, since this format should have triggered an audit alert had they ran one (Which they are supposed to)

Again, people should be suing over this. Its their fault.
>>
>>62551843
You're retarded if you think you can sue them. Their terms of service literally says they are not responsible for lost of funds due to software bugs or user error. Get real buddy boy. The big guys win again.
>>
>>62551928
Actually, this is a pretty winnable case. I'd be willing to bet the lawyers will argue gross negligence. (Which it clearly is)

They will point out that Coinkite marketed these devices as maximum security, yet left a basic coding error in the open source firmware that completely turned off the hardware random number generator for five years.

I'm pretty sure coinkite will lose the case.
>>
>>62551885
I'm willing to bet it was a purposeful backdoor by nork plants. They've been infesting IT industry since remote became popular (because it's easier to pass hiring screens); the timeline matches. And they have local intelligence industry targeting crypto specifically. Just wondering why they chose this specific point to harvest
>>
NEVER heard of this coldcard brandy. Is It new? I don't watch any crypto YouTube content anymore but I used to during the lockdown days and I don't remember anyone promoting It. Plus, 78 million losses in total is nothing. Sorry for the individuals that Lost their money though
>>
>>62551843
Since you know what you are talking about, what do you think about the truebit hack throught integer overflow in january? Was 24 million. Does it deserve a class action lawsuit too because of massive neglegience?
https://olympixai.medium.com/truebit-26-6m-exploit-integer-overflow-and-the-cost-of-abandoned-code-84ed3aa64e43
>>
>>62551843
>was not a breach of the Bitcoin network
It kinda was since the network doesn't give you straight forward on-chain custody tools like vaults with timelocks, multisig and clawbacks.
>>
>>62551938
Obvious to me it's because we're in the capitulation phase which means they're dictated by grander schemers who want to control when and how normies buy and when they're stolen from before they're cashing out. Timing alone tells me a pretty good indicator the real perpetrators aren't getting any real punishment at and best some fall guy will. As usual.
>>
>>62551843
The thing is it is also old. But this shows cold wallets aint save. This is when brokers are better because then you could sue them for not having a better cyber security.
>>
>>62552038
Turns out its not so cold
>>
>>62551843
is this brainwallet 2.0?
>>
i believe that within 5 years, this is going to happen to bank accounts, brokerages, retirement funds ect.
the vast majority of "wealth" in western countries is numbers on a screen
hacking is just going to get easier and easier
offense is easier than defense
if you don't hold it, you don't own it
>>
>>62552152
>if you don't hold it, you don't own it
you clearly haven't been paying attention to the news lately, child.
>>
>>62552152
Well but if its not decentralized a hack can just be undone with a few clicks. Unfortunate for crypto.
>>
>>62552152
Okthx, just sold 100k numbers on a screen and boat your pm bags ok?
>>
Coinkite also used to have a web wallet in the mid 2010s that was sat shaving transactions, supposedly a "bug."
>>
File: 1000001445.png (21 KB, 601x220)
21 KB PNG
>>62551860
They can always retreat to Epstein's island till the dust settles
>>
>>62551995
Not OP, but I believe Truebit was negligent, yes. I also find it hard to believe that such an elementary error was left there by mistake. However, it's a much grayer area in the legal system because they did not sell a security product like Coinkite, and the legal status of smart contracts remains patchy.
>>
How does people even cash out crypto without everyone noticing who he is?

Its so easy to track transactions in crypto



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.