A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain-monitoring firms.
No, the cold wallets were using a predictable algorithm to generate key phrases. When you set up the wallet, you use the generated key phrase to pair it with your coins. So this wallet is supposed to live offline, keeping your coins safe because the key is kept offline. No way to hack it if it’s entirely offline. But a flaw caused the generated keys to be predictable, meaning hackers were able to brute force the keys and initiate coin transfers without even messing with the cold wallet.
Imagine you lock a million dollars behind a super secure vault door. This vault is impervious to all kinds of physical and digital attacks. The only way to open it is with the key. The vault is in a public area, but (again) there is no way to open it without the key. This vault only has one key, which you keep safely stored in a separate secure facility. Additionally, this key has like a thousand pins and tumblers, so it should be nearly impossible for a hacker to guess the correct key. The hackers essentially realized that due to a flaw in the lock’s design, there were only like three dozen potential key combinations. The thousand pins didn’t actually matter, because they were predictably arranged at the factory that built the lock. So the thieves just made like two dozen fake keys (until they got the correct one,) then took the money. All without touching (or even seeing) your key.
I’m confused. Pickpockets are now hackers?
No, the cold wallets were using a predictable algorithm to generate key phrases. When you set up the wallet, you use the generated key phrase to pair it with your coins. So this wallet is supposed to live offline, keeping your coins safe because the key is kept offline. No way to hack it if it’s entirely offline. But a flaw caused the generated keys to be predictable, meaning hackers were able to brute force the keys and initiate coin transfers without even messing with the cold wallet.
Imagine you lock a million dollars behind a super secure vault door. This vault is impervious to all kinds of physical and digital attacks. The only way to open it is with the key. The vault is in a public area, but (again) there is no way to open it without the key. This vault only has one key, which you keep safely stored in a separate secure facility. Additionally, this key has like a thousand pins and tumblers, so it should be nearly impossible for a hacker to guess the correct key. The hackers essentially realized that due to a flaw in the lock’s design, there were only like three dozen potential key combinations. The thousand pins didn’t actually matter, because they were predictably arranged at the factory that built the lock. So the thieves just made like two dozen fake keys (until they got the correct one,) then took the money. All without touching (or even seeing) your key.
Why is the vault in public? First rule of a heist movie is you gotta put the vault in a secure room with guards and stuff
Because the blockchain is a ledger that is available to anyone who wants to view it.