跳到主内容
@wquguru
精选75Bitcoin Magazine(RSS)加密货币

Coldcard熵漏洞暴露单签风险,多厂商多签成比特币托管新基线

Coinkite’s Coldcard Bug Exposed Single-Sig Risk. Multi-Vendor Multisig Is the New Bitcoin Custody Baseline

原文
发到 X
推荐理由

加密托管从业者与长期持有者应关注:Coldcard熵漏洞事件推动多厂商多签成为新基线,建议研究多签方案以降低单点故障风险,但需自行评估威胁模型。

Bitcoin Magazine

比特币杂志

Coinkite’s Coldcard Bug Exposed Single-Sig Risk. Multi-Vendor Multisig Is the New Bitcoin Custody Baseline

Coinkite 的 Coldcard 漏洞暴露了单签名风险。多供应商多重签名成为比特币托管的新基线

In the wake of Coldcard’s catastrophic entropy bug, self-custody advocates and experts have begun recommending a new standard, multi-vendor multisignature wallets, an approach that looks to minimize —among other threats— dependency on any single hardware wallet manufacturer.

在 Coldcard 灾难性的熵漏洞之后,自我托管倡导者和专家开始推荐一种新标准:多供应商多重签名钱包,这种方法旨在最小化——除其他威胁外——对任何单一硬件钱包制造商的依赖。

The Coldcard entropy bug that went undiscovered since at least 2021 has taught a hard lesson to the Bitcoin self-custody advocates and users. No matter how legitimate or competent a wallet provider might seem, how well recommended and reputable, a major bug may be possible. As a result, Bitcoiners are questioning old recommendations and assumptions, including many declaring the ‘death of single sig’ the popular self-custody method of trusting the private key pair generation to one wallet alone.

自至少 2021 年以来未被发现的 Coldcard 熵漏洞,给比特币自我托管倡导者和用户上了惨痛的一课。无论钱包提供商看起来多么合法、多么有能力,无论其推荐度多高、声誉多好,重大漏洞都可能存在。因此,比特币爱好者开始质疑旧的建议和假设,许多人宣称‘单签的死亡’,即那种信任单一钱包生成私钥对的流行自我托管方式。

The Threat Model

威胁模型

Self-custody by any measure is an advanced practice in Bitcoin. Advocates recommend it as a way to protect user funds from exchange malfeasance like that seen in the cases of FTX and MtGox, among many others. But recent events have driven a revaluation of custody practices, with many bitcoin owners moving coins to exchanges — at least temporarily — while others upgrading or changing their self-custody setups altogether. Nick Neuman, CEO of Casa, claimed that 233k bitcoins moved to safety in reaction to the Coldcard hack.

自我托管在任何衡量标准下都是比特币中的高级实践。倡导者推荐它作为保护用户资金免受交易所不当行为(如 FTX 和 MtGox 等案例)影响的方式。但近期事件促使人们对托管实践进行重新评估,许多比特币持有者将币转移到交易所——至少是暂时性的——而其他人则升级或完全改变他们的自我托管设置。Casa 的首席执行官 Nick Neuman 声称,为应对 Coldcard 黑客事件,有 23.3 万比特币被转移到了安全之处。

To understand when self-custody makes sense and for whom, it is essential to understand your personal threat model. A threat model is the careful analysis of threats to an individual, for the purpose of designing security practices and structures ahead of time.

要理解自我托管何时有意义以及适合谁,关键在于理解你的个人威胁模型。威胁模型是对个人所面临威胁的仔细分析,目的是提前设计安全实践和结构。

A simple threat model practice can be to take a step back and think about all the possible things that worry you about self-custody, and add them to a list. Then think about all the things that advocates caution users about, and append them to that same list. Next, sort or rate items on that list based on which are most likely to happen to you, and which are most likely to happen in general. Finally, you can rank each item in the list by how catastrophic it would be if it occurred; can your current setup and plans survive the realization of that threat?

一个简单的威胁模型实践可以是退一步思考所有关于自我托管让你担心的事情,并将它们列成一个清单。然后思考倡导者提醒用户注意的所有事项,并将它们添加到同一清单中。接下来,根据哪些最可能发生在你身上,以及哪些在一般情况下最可能发生,对清单上的项目进行排序或评级。最后,你可以根据每个项目如果发生会有多灾难性来对清单中的每一项进行排名;你当前的设置和计划能否承受该威胁的实现?

Two of the most likely causes of loss of funds in Bitcoin self-custody are user error related to backups or forgotten passwords, and of course theft. Many of the wallets believed to be lost bitcoins that have not moved come from bad backups of private keys in the early days, resulting in data loss after a computer failed. Others simply used passwords too difficult to brute force, and then forgot them, encrypting their private keys forever.

比特币自我托管中资金损失的两个最可能原因是与备份或遗忘密码相关的用户错误,当然还有盗窃。许多被认为丢失且未移动的比特币钱包,源于早期私钥备份不当,导致电脑故障后数据丢失。另一些人则只是使用了过于复杂难以暴力破解的密码,然后忘记了它们,从而永久加密了他们的私钥。

On the theft dimension, bad entropy attacks likely rank among the most successful attacks on self-custody to date, with Coldcard joining a significant list of other wallets that have suffered bugs of the sort, intentional or otherwise, such as Trust Wallet, and many lesser-known and possibly malicious mobile wallets. In some cases, fake wallets like the iOS Sparrow Wallets simply stole user funds by keeping a copy of the user-generated private keys and sweeping the funds once deposited. In all of these examples, more thoughtful user behavior before trusting random software with your life savings is the solution.

在盗窃方面,不良熵攻击可能至今仍是对自我托管最成功的攻击之一,Coldcard加入了其他遭受此类漏洞(无论是有意还是无意)的钱包的重要名单,如Trust Wallet,以及许多不太知名且可能恶意的移动钱包。在某些情况下,像iOS Sparrow Wallets这样的假钱包只是通过保留用户生成的私钥副本并在存款后扫走资金来窃取用户资金。在所有这些例子中,用户在信任随机软件处理毕生积蓄之前,更周到的行为才是解决方案。

Once users have a clear threat model in place and a good enough understanding of the technology, designing security practices becomes more a science than an art. And while every individual has specific circumstances they need to take into account, some structures have emerged as the most resilient to most threats. One such practice becoming widely recommended and adopted among long-term self-custody Bitcoin holders is a carefully formed multisig setup.

一旦用户有了清晰的威胁模型和对技术的足够理解,设计安全实践就更多是一门科学而非艺术。虽然每个人都需要考虑自己的具体情况,但一些结构已被证明对大多数威胁最具韧性。其中一种被广泛推荐并在长期自我托管比特币持有者中采用的做法是精心构建的多重签名设置。

Multi-vendor Multisig

多供应商多重签名

The term “Multi-vendor Multisig” is relatively new in the self-custody niche. The term “multisig” has nevertheless gone viral in 2026, clearly triggered by the Coldcard hack that saw the loss of over 100 million dollars worth of bitcoin, mostly from single seed wallets. Most single-seed Coldcard users appear to have generated their private keys on the device without adding an extra passphrase, extra words that add custom entropy to the private keys, nor without extra dice rolls, which do the same in a different format.

“多供应商多重签名”一词在自我托管领域相对较新。然而,“多重签名”一词在2026年迅速走红,显然是由Coldcard被黑事件引发的,该事件导致超过1亿美元的比特币损失,主要来自单一种子钱包。大多数单一种子Coldcard用户似乎是在设备上生成私钥,而没有添加额外的密码短语(为私钥添加自定义熵的额外单词),也没有额外的骰子投掷(以不同格式做同样的事情)。

The weak entropy from the Coldcard firmware — which users had no reason to distrust, given the company’s strong brand — in turn made guessing the related private keys easy, with a bit of custom work, which hackers eventually figured out.

Coldcard固件中的弱熵——鉴于公司强大的品牌,用户没有理由不信任——反过来使得猜测相关私钥变得容易,只需一些定制工作,黑客最终发现了这一点。

The resulting viral interest in multisig is warranted. Multisig Bitcoin wallets protect users from such hardware manufacturer errors by letting users construct a Bitcoin address that requires signing from multiple private keys and thus multiple devices, in what is known as a Bitcoin script.

由此引发的对多重签名(multisig)的病毒式关注是合理的。多重签名比特币钱包通过让用户构建一个需要多个私钥(即多个设备)签名的比特币地址,从而保护用户免受此类硬件制造商错误的影响,这被称为比特币脚本。

Bitcoin scripts are contracts of sorts that set spending conditions for a bitcoin wallet. All Bitcoin wallets can be thought of as having some kind of script involved, with the simplest and most popular being that anyone who can sign a valid transaction can spend all or any funds therein. Multisig scripts instead require a threshold of valid signatures from different keypairs to result in a valid withdrawal. These scripts are enforced by the Bitcoin consensus rules.

比特币脚本是一种合约,为比特币钱包设定花费条件。所有比特币钱包都可以被认为涉及某种脚本,最简单且最流行的是,任何能签署有效交易的人都可以花费其中的全部或任何资金。多重签名脚本则要求来自不同密钥对的一定数量的有效签名,才能进行有效提款。这些脚本由比特币共识规则强制执行。

Multi-vendor multisig theory posits that users should make sure every keypair used to construct a Bitcoin multisig is generated from a different wallet vendor.

多供应商多重签名理论认为,用户应确保用于构建比特币多重签名的每个密钥对都来自不同的钱包供应商。

One example that is likely popular today might be the use of a Trezor Safe 7 hardware wallet with one key, a second key generated by a Ledger Nano, and a third key generated by a multisig wallet provider, considered a recovery key. A script of this sort would require any 2 valid signatures out of the three possible signatures in the setup.

如今可能流行的一个例子是,使用Trezor Safe 7硬件钱包生成一个密钥,第二个密钥由Ledger Nano生成,第三个密钥由多重签名钱包提供商生成,作为恢复密钥。这种脚本要求在此设置中的三个可能签名中,任意两个有效签名即可。

By using two different hardware wallet providers, the user minimizes trust in any single wallet vendor, protecting them from an entropy failure like the one seen in Coldcard.

通过使用两个不同的硬件钱包供应商,用户最小化了对任何单一钱包供应商的信任,从而保护他们免受像Coldcard中出现的熵故障的影响。

Other Multisig setups can add more keys, with a 3-of-5 threshold also being common and a standard offering of a multisig-specialized wallet like Casa. It is at this point that the terminology commonly used and understood to describe Bitcoin spending software starts to break down, and as a result merits clarification.

其他多重签名设置可以添加更多密钥,3-of-5阈值也很常见,并且是像Casa这样的多重签名专业钱包的标准提供。正是在这一点上,通常用来描述比特币花费软件的术语开始变得模糊,因此需要澄清。

Wallets like Casa are software interfaces that let users combine partially signed transactions from different private key pairs. In this scenario, it becomes more useful to describe ‘hardware wallets’ like Trezor or Ledger as ‘key signers’ since no single keypair in the set holds enough of the key material to spend all the Bitcoin held in the Multisig script address.

像Casa这样的钱包是软件界面,允许用户组合来自不同私钥对的部分签名交易。在这种情况下,将Trezor或Ledger等“硬件钱包”描述为“密钥签名者”更为有用,因为集合中的任何单个密钥对都不足以持有足够的关键材料来花费多重签名脚本地址中持有的所有比特币。

So Casa is a Multisig wallet that lets you use a threshold of hardware signers to secure and send bitcoin funds. Fundamentally, they help users interact with Bitcoin script and create consensus-valid transactions easily. Other examples of such multisig wallet providers include Nunchuck, Sparrow desktop wallet and Unchained Capital.

因此,Casa是一个多重签名钱包,允许你使用一定数量的硬件签名者来保护和发送比特币资金。从根本上说,它们帮助用户与比特币脚本交互,并轻松创建符合共识的交易。其他此类多重签名钱包提供商的例子包括Nunchuck、Sparrow桌面钱包和Unchained Capital。

In cases like Casa and Unchained, the wallet provider offers users a recovery key controlled by the company, which some users find useful. Nunchuck and Sparrow, on the other hand, are designed for full user autonomy in this regard, though Nunchuck does offer a premium recovery key-related plan as well.

在Casa和Unchained这类案例中,钱包提供商为用户提供一把由公司控制的恢复密钥,一些用户觉得这很实用。另一方面,Nunchuck和Sparrow则旨在实现用户在此方面的完全自主,尽管Nunchuck也提供与恢复密钥相关的高级计划。

The Upsides of Multivendor Multisig

多供应商多重签名钱包的优势

Another benefit of a multisig wallet is its potential resistance to the infamous wrench attacks. Countries like France, which make Bitcoin and crypto ownership a matter of public record as a consequence of tax filings, have become focal points for crypto theft-related kidnapping. Self-custody or not, targets of this kind of crime are vulnerable to theft, particularly when the funds can be moved in full quickly, be it from a custodial exchange the user can access from their phone, or some self-custody setup.

多重签名钱包的另一个好处是它可能抵御臭名昭著的“扳手攻击”。像法国这样的国家,由于税务申报,比特币和加密货币的所有权成为公开记录,已成为与加密货币盗窃相关的绑架事件的高发地。无论是否自我托管,这类犯罪的受害者都容易遭受盗窃,尤其是当资金可以迅速全额转移时,无论是从用户手机上可访问的托管交易所,还是某种自我托管设置。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

关联讨论

同一事件的更多信源

相似阅读

另一事件,读法相近