pull down to refresh

If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.

What we're doing today:
  • We've shipped a firmware hotfix that removes the software fallback path entirely. This protects new seeds going forward. It does not fix seeds that were already generated on vulnerable firmware. If your seed was generated before the fix, it needs to be individually migrated to a new seed. A firmware update alone cannot do that for you.
  • We will publish a full technical writeup of how the bug entered the codebase and why our own review process didn't catch it once we've verified every detail. We would rather be accurate than fast on the technical postmortem, even though we know people want answers now.
  • We will publish updates at https://blog.coinkite.com/ as we learn more. We do not have full attribution or scope of the issue yet, and we won't speculate until our full technical evaluation is complete.
  • We are committed to working with affected users who want to pursue a police report, insurance claim, or their own investigation. We will provide a written incident summary specific to your loss and any transaction data we can share. We are cooperating fully with the on-chain investigators and any law enforcement agency that opens a case.
We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust. That starts with being open and telling the truth about how this happened.
To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike.

Fuck NVK - Fuck Coinkite - Fuck Cold Card

Coinkite had their chance, had their ride and they let the horse out of the gate....

They lost site of what is important - they fell back into FIAT traps - FIAT incentives

Bitcoin is the way - Don't fall into the FIAT traps

reply
508 sats \ 0 replies \ @aljaz 1 Aug

Past examples of how well nvk handles reports and feedback on lack of security in his products https://thecharlatan.ch/COLDCARD-Supply-Chain/ for anyone wondering why ppl didnt catch this before - because he was always hostile towards anyone not praising him for his godlike superiority and intellect

reply
1888 sats \ 9 replies \ @Aeneas 31 Jul

His AI shit is a red herring, I think. From what I understand, the intended random number generator was simply not called? Because of a developer mistake that linked to the wrong RNG library entirely, one that was intended for... testing and not real-world usage?

Nvk shifting the blame to AI here is cute and certainly in line with the times, but it sounds like yet another mistake best attributed to boring everyday "Human Stupidity," and that should've and could've been caught with a modicum of due diligence.

Piling this into the AI narrative seems to distract from the negligence.

reply

I also don't understand how they didn't have within their testing a process for ensuring the seed was really being hardware generated, and not relying on the software fallback (which should've been disabled in production in the first place)

reply

I've seen something similar-ish once, spotted in a cycle test, where a component didn't have any wear at all, but that turned out to be a test scope error, not a firmware bug.

which should've been disabled in production

That snippet describes exactly what last night's hotfix does.

reply
reply

Oh wow, my favorite pastime, reading slop. Thank you for your generous contribution to my hobby, anon, you're awesome.

reply
340 sats \ 0 replies \ @Aeneas 31 Jul

Exactly.
Oh but I'm sure if they would've been able say "Fucking AI did this!" about the failed O-ring seals on the Space Shuttle Challenger, they would have.

reply

Blame shifting.

reply

A new AI use case: scape goat.

reply

isn’t that why everyone prefaces everything with “Claude said…”?

reply

Actually all vulnerabilities are a human error. That doesn't prevent them from existing. And theoretically if a system is built without any error, no hacker can attack it.

reply
We are cooperating fully with the on-chain investigators and any law enforcement agency that opens a case

This is a dog whistle for Chain analysis. What a crazy timeline.

Big fat piece of humble pie for NVK

reply

EXACTLY! Reduced to sucking up to chainalysis.

reply

They are the only ones victims can turn to when crimes like theft happen in bitcoin. The whole Sorry For Your Loss (SFYL) always rubbed me the wrong way. Which I’m sure the cocky NVK often championed.

People who steal should be punished plain and simple! What’s the point of having extreme property rights when someone can steal your life savings and you have zero recourse to get it back and to punish those who stole!

And just imagine the looks people get when they go to law enforcement “didn’t he know bitcoin is a scam why would he hold his life savings on something that looks like an elementary school calculator”.

reply

Well... it's now time for pitchforks & shiz and everyone is going to be busy with that.

But what may be interesting is to find out which explorer was used for the initial theft itself, which can be open source investigation. May help in access log retention.

reply
reply
228 sats \ 2 replies \ @Diego 31 Jul

so what does this actually mean? someone used a block explorer to find out which addresses keys were vulnerable!

reply

Yes, instead of runner ng their own instance of core and querying the block data, they relied on a third party block explorer to figure out which addresses to attack.

This means the block explorer company likely has logs of the queries, possibly IP addresses or browser finger printing data.

reply
301 sats \ 0 replies \ @Diego 31 Jul

thanks for clarifying. oh please be true 🙏

Thanks!!! That is the best news in 24h.

All the shit done after the irresponsible disclosures is going to be on the (same, lol) security researchers. But at least there is a slim path to recovery here.

reply

From auditing wallets professionally, the RNG is always one of the first thing you go to hunt for. It's a classical vulnerability in cryptographic engineering (even in this space e.g libbitcoin milk.sad).

Sadly, with information available, there is no "AI chamanism" to have. It's kind of vulnerability that senior security researchers have already found with good eyes and hands in the past.

That AI might help to the weaponization at scale, this is another discussion.

reply

Day late and a sat short.

reply

That "sober reality" is that hidden defects aren't hidden anymore. No matter how deep they are sitting in your code. It's just a matter of time. Also for AI generated code. The bar for quality is extremely high now.

This vuln was low hanging fruit.

reply

Yeah. I don't use coldcard. I figured using the software with the most eyes on it is better, but at the end of the day it's not like I have that much better certainty.

I rhink the paradigm has always been: Be paranoid -- no one is responsible for your sats except you

reply
the paradigm .. no one is responsible for your sats except you

Exactly!

the software with the most eyes on it is better

Most eyes makes sense, but it is not a catch-all, also not in Core - and not everything goes into release notes.

In coding life, I'm really unsure what to do with legacy "known minor defects". Not making any new ones is very important, that I know. Fixing old ones with priority, especially when they need refactor, would, on some of the code bases I am deeply familiar with, be risky and expensive. It's just something that is a bit unprecedented.

reply

From experience professionally auditing wallets in the space, the RNG is always one of the first component you go to hunt for. It's just a classic of cryptographic vulnerability (not latter in the space that libbitcoin's milk.sad).

Sadly, from the information available, there is no "AI mysticism" to have here. Security researchers have found vulnerabilities of the same complexity, with no AI before (e.g XZ utils).

That AI might help on the weaponization at scale, that's another discussion.

151 sats \ 9 replies \ @justin_shocknet 31 Jul -420 sats

Oof

https://m.stacker.news/150381