Loading market data...

Coldcard Entropy Bug Lets Hackers Drain 594 BTC; Peter Todd Warns Single-Sig Wallets Unsafe

Coldcard Entropy Bug Lets Hackers Drain 594 BTC; Peter Todd Warns Single-Sig Wallets Unsafe

The vulnerability

The bug lies in how Coldcard generates random numbers for private keys. A weak entropy source made it possible for attackers to brute-force the keys, effectively guessing them. The exploit didn't require physical access to the device in every case — remote attackers could scan the blockchain for vulnerable addresses and sweep the funds.

Czech:

Zranitelnost

Chyba spočívá v tom, jak Coldcard generuje náhodná čísla pro soukromé klíče. Slabý zdroj entropie umožnil útočníkům prolomit klíče hrubou silou, tedy je efektivně uhodnout. Zneužití nevyžadovalo v každém případě fyzický přístup k zařízení — vzdálení útočníci mohli prohledávat blockchain a hledat zranitelné adresy a vybrat z nich prostředky.

"brute-force" - "hrubou silou" or "brute-force" often used. I'll use "hrubou silou" and maybe "brute-force" in parentheses? But I'll keep it simple. "sweep the funds" - "vybrat prostředky" or "odčerpat prostředky". I'll use "vybrat". Third:

594 BTC drained

On-chain data shows 594 BTC moved from multiple addresses linked to Coldcard users. At current prices that's about $38 million. The theft appears to have happened over several days, with the hackers methodically targeting wallets that used the compromised entropy. It's one of the larger hardware-wallet-related heists in recent memory.

Czech:

594 BTC odčerpáno

Data v řetězci ukazují, že 594 BTC bylo přesunuto z více adres spojených s uživateli Coldcard. Při současných cenách to je asi 38 milionů dolarů. Krádež zřejmě probíhala několik dní, přičemž hackeři metodicky cílili na peněženky, které používaly kompromitovanou entropii. Je to jedna z největších loupeží souvisejících s hardwarovými peněženkami v nedávné paměti.

"On-chain data" - "data v řetězci" or "on-chain data" often kept. I'll use "data v řetězci" but might be too literal. Actually "on-chain" is often used as is. I'll use "On-chain data" but in Czech we can say "Data v blockchainu" or "Data v řetězci". I'll use "Data v řetězci" but maybe "On-chain data" is acceptable. I'll go with "Data v řetězci" to be natural. But to be safe, I'll use "On-chain data" as it's a technical term. Actually, in Czech crypto articles, they often say "on-chain data". I'll keep "On-chain data" as it's understood. But we can translate. I'll use "Data v řetězci" but it might sound odd. I'll decide: "On-chain data" is fine, but since we are translating, maybe "Data v blockchainu" is better. Let's use "Data v blockchainu" - but "blockchain" is also used. I'll use "Data v blockchainu" to be clear. Actually, let's be consistent. I'll use "Data v blockchainu" for "On-chain data". So: "Data v blockchainu ukazují, že 594 BTC bylo přesunuto..." That works. Fourth:

Peter Todd's warning

Todd, a longtime Bitcoin core developer, didn't mince words. He said that after this bug, relying on a single signature from any hardware wallet is too risky. He didn't name Coldcard specifically in every tweet, but the context was clear. The warning lands hard because single-sig wallets are the default for most Bitcoin users — one key, one point of failure.

Czech:

Varování Petera Todda

Todd, dlouholetý vývojář jádra bitcoinu, si nebral servítky. Řekl, že po této chybě je spoléhání se na jediný podpis z jakékoli hardwarové peněženky příliš riskantní. Nezmínil Coldcard konkrétně v každém tweetu, ale kontext byl jasný. Varování dopadá tvrdě, protože jednopodpisové peněženky jsou výchozí volbou pro většinu uživatelů bitcoinu — jeden klíč, jeden bod selhání.

"didn't mince words" - "si nebral servítky" is a good idiom. "lands hard" - "dopadá tvrdě". "point of failure" - "bod selhání". Fifth:

What users should do

Anyone using a Coldcard — or any hardware wallet that relies on a single private key — should consider moving funds to a multisignature setup. Multisig requires multiple keys to authorize a transaction, so a single compromised device doesn't mean lost coins. The timing isn't great: the market is already jittery, and a $38 million theft doesn't help confidence.

Coldcard has not yet released a public statement about the bug or a firmware patch. Users are left waiting for an official fix while the stolen BTC sits in wallets controlled by the hackers. Whether those coins can ever be recovered is an open question.

Czech:

Co by měli uživatelé udělat

Každý, kdo používá Coldcard — nebo jakoukoli hardwarovou peně