跳到主内容
精选85Coin Bureau(YouTube)加密货币多源精选 ×14

冷钱包漏洞致超1亿美元比特币被盗

$100M DRAINED From Crypto's Safest Wallet!

原文
推荐理由

这是一起影响面巨大的安全事件,涉及冷钱包的严重漏洞,导致大量资金被盗。建议持有相关设备的用户立即检查是否受影响,并采取紧急措施(如迁移资金),同时关注官方后续公告。

If you hold your Bitcoin on a hardware wallet because you thought that it meant it's 100% safe, you need to watch this immediately. Over the past few days, attacker scripts have drained more than $100 million in Bitcoin from thousands of cold card wallets. The exact devices recommended by top security experts. So, today we're breaking down the 5-year-old bug that destroyed the gold standard of self-custody. How automated drainers swept 500 wallets in under 25 minutes. and the exact step-by-step emergency protocol that you must follow right now to secure your funds.

My name is Lewis and this is the Coin Bureau. Now, let's start with what happened on the night of the 30th of July 2026. Between roughly 131 and 156 UTC, 594 Bitcoin, around $38 million, left approximately 500 single signature wallets. Over just 25 minutes, everything we know about self- custody changed. Then it kept going. The wider sweep that night hit 1,196 addresses for $1,082 bitcoin, about $70 million in a 41minute window.

By the 2nd of August, Galaxy Research had it at 4,585 addresses and roughly $89 million. By the third, we're at 1,816 Bitcoin across somewhere between 5,200 and 7,300 addresses. And Galaxy's Alex Thorne was watching fresh sweeps land in the meool as he provided realtime updates. The coins that were taken had on average sat completely untouched for over 3 years. These were the people who did everything right. Bought the recommended device, wrote the words down, and never touched their wallets again.

But there's some important detail here that makes this different to every hack that we've ever covered on this channel. You see, nobody got fished here, and nobody plugged their device into a dodgy computer. Not one user proved a malicious transaction. The devices were sitting offline in safes, or hidden away in some corner of the house. One victim, a Canadian entrepreneur called Jonathan Goodman, lost 18.25 Bitcoin, roughly 1.6 million Canadian dollars from wallets stored in a safety deposit box drained in a 7-minute window while the device itself sat in a vault untouched.

So, the attack never actually touched the hardware. It went after the software that generated the seed phrase in the first place. Now, to understand how that's even possible, we have to go back to the 1st of March 2021. Coite was migrating its firmware over to a new cryptography library called Libangu. And inside that library, there was one line of code that asked the wrong question. To get a little technical, in CC code, you can check two different things about a setting.

You can check whether the setting exists or you can check whether the setting is switched on. Those may sound like the same question, but they are certainly not. Think of it like walking into a room and asking, "Is there a light switch on the wall?" Well, yes, there is. Brilliant. But that tells you nothing about whether the light is actually on. Cold Card's board configuration had a setting called Micropy HW enable RNG and Coin Kite had deliberately set it to zero to off because they were using their own separate hardware randomness wrapper instead.

But the library only checked whether the switch existed. So the code concluded that hardware randomness was handled and stopped calling the chip's dedicated hardware random number generator. Instead, it fell back to a software substitute buried inside MicroPython called the Yasmarang generator. And that software fallback created the random numbers using the chip's serial number and the exact timing of when it started up.

In simpler terms, that means values an attacker can guess, narrow down, or simply enumerate one by one. And after that initial startup, it never collected any fresh randomness again. Every single output after that was just a calculation from a starting point somebody else could reconstruct. And the reason nobody caught this for over 5 years, well, the hardware random number generator was still alive and working elsewhere in the firmware.

Internal reviews confirmed it was present and it was configured. Nobody noticed that one code path that actually creates your seed phrase was walking straight past it. So, 5 years of devices shipping a downgrade that looked identical to a device working perfectly. Scary stuff. Now, let's look at what the downgrade actually did to your keys. Because this is the part that decides whether you're affected. Your seed phrase, those 12 or 24 words written down somewhere, is really just one enormous number picked at random out of a pool.

And the whole security model rests on that pool being so absurdly large that guessing your number is next to impossible. The target is 128 bits or 256 bits for the paranoid. To give you a sense of what 256 bits means, there are not enough atoms in the observable universe to give every possibility its own atom. Not with every computer on Earth running until the sun burns out, at least. Now, here's what the bug did. On cold cards MK2 and MK3 devices, the bug reduced the seat's effective security from 128 bits to roughly 40 bits.

The newer MK4, MK5, and Q models still had around 72 bits because their secure chips added some extra randomness. 40 bits, though, is small enough to simply write down as a list. It's about a trillion possibilities. And that is something an ordinary laptop can grind through offline in hours. Same 24 words on your screen and the same little OLED display telling you everything is fine. But a completely different universe of difficulty settings behind it.

And this is exactly why the drains were automated and why they were so fast. The attacker didn't really break anything. They didn't need a vulnerability in Bitcoin and there was no need to even touch your device. They generated every candidate seed in the shrunken pool on their own machine, derived the addresses, checked which ones held coins, and then swept them. Kraken's chief security officer, Nick Peroko, noted that the secure element chips in the MK4 and MK5 were properly certified components, but that quote, "Nobody verified which code path actually ran.

Oh, and there's one more thing that's being under reportported in this story. That same broken randomness path wasn't only used for seed phrases. It also fed paper wallet private keys, seed XR split masks, device cloning keys, USB encryption keys, key teleport temporary keys, and even the web 2FA secrets and secure notes passwords. So, the blast radius is wider than your main stack. Now, as you could likely tell by now, keeping on top of a story like this is nearly impossible for a single person.

It requires a team of people doing research all day to stay ahead of the curve. So, we made things easier for you. Right here on YouTube, you can join the Coin Bureau Club light plan for just $10 a month. You get all the important daily market updates across both crypto and traditional finance. Our teams read on where things are going and none of the noise. Just tap the join button below this video to get started. And now back to the wallets because there is a group of people who came through this completely untouched and why they survived is one of the most insightful parts of this whole story.

Three groups were safe. First, anyone who rolled their own dice during setup. You see, cold cards let you roll physical dice and feed that into your seed. And Coin Kite's threshold here is at least 50 fair independent rolls. If you did that, you injected real world randomness the firmware could not ruin. Second, anyone using a strong BIP39 passphrase. That's an extra secret word or phrase that you type in on top of your 24 words and it produces a completely separate wallet.

Guessing the weak seed gets an attacker nothing without it. Third, anyone in a genuine multi-IG setup where you need multiple different keys from multiple different devices to move funds. And this is being shown in the data. As of the 3rd of August, across all four waves, not a single multi-IG wallet had been hit.

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

关联讨论

同一事件的更多信源

相似阅读

另一事件,读法相近