Loading market data...

Coldcard Firmware Bug Exposes ~500 Wallets, $594M in Bitcoin Swept

Coldcard Firmware Bug Exposes ~500 Wallets, $594M in Bitcoin Swept

etc. Second paragraph: "How the flaw worked" - heading: "Πώς λειτούργησε το σφάλμα" Content: "The bug lived in the seed generation code. On Mk3 devices with firmware 4.0.1 through 5.0.3, and on Mk4 and Mk5 devices before version 5.6.0, as well as Q devices before 1.5.0Q, the hardware random number generator was swapped out. Instead of drawing on the chip's true random source, the firmware fell back to a software-based generator that was far less random. The result: seeds with only 72 bits of entropy instead of the intended 128. That's a difference of 2^56 possible seeds — a gap that made brute-force attacks feasible for well-resourced adversaries." Translate: "Το σφάλμα βρισκόταν στον κώδικα δημιουργίας seed. Σε συσκευές Mk3 με firmware 4.0.1 έως 5.0.3, και σε συσκευές Mk4 και Mk5 πριν από την έκδοση 5.6.0, καθώς και σε συσκευές Q πριν από την 1.5.0Q, η γεννήτρια τυχαίων αριθμών υλικού αντικαταστάθηκε. Αντί να βασίζεται στην πραγματική πηγή τυχαιότητας του τσιπ, το firmware χρησιμοποίησε μια γεννήτρια βασισμένη σε λογισμικό που ήταν πολύ λιγότερο τυχαία. Το αποτέλεσμα: seed με μόλις 72 bit εντροπίας αντί για τα προβλεπόμενα 128. Αυτή είναι μια διαφορά 2^56 πιθανών seed — ένα κενό που έκανε τις επιθέσεις ωμής βίας (brute-force) εφικτές για καλά εξοπλισμένους αντιπάλους." Third paragraph: "Who was at risk" -> "Ποιοι ήταν σε κίνδυνο" Content: "Not every Coldcard user was vulnerable. The risk depended on the device version and how the seed was generated. Seeds created with a BIP-39 passphrase or with at least 50 dice rolls were not considered compromised. The main exposure hit single-signature wallets, where one seed controls all funds. Multisignature setups require additional keys, so they were less affected. The attackers swept funds from roughly 500 wallets, suggesting they targeted seeds that were generated on the vulnerable firmware without extra entropy sources." Translate: "Δεν ήταν κάθε χρήστης Coldcard ευάλωτος. Ο κίνδυνος εξαρτιόταν από την έκδοση της συσκευής και τον τρόπο δημιουργίας του seed. Τα seed που δημιουργήθηκαν με φράση πρόσβασης BIP-39 ή με τουλάχιστον 50 ρίψεις ζαριού δεν θεωρήθηκαν παραβιασμένα. Η κύρια έκθεση αφορούσε πορτοφόλια μονού υπογραφέα, όπου ένα seed ελέγχει όλα τα κεφάλαια. Οι ρυθμίσεις πολλαπλών υπογραφών (multisignature) απαιτούν επιπλέον κλειδιά, οπότε επηρεάστηκαν λιγότερο. Οι επιτιθέμενοι απέσυραν κεφάλαια από περίπου 500 πορτοφόλια, υποδηλώνοντας ότι στόχευσαν seed που δημιουργήθηκαν στο ευάλωτο firmware χωρίς επιπλέον πηγές εντροπίας." Fourth paragraph: "Fixed firmware and lingering trust" -> "Διορθωμένο firmware και παραμένουσα εμπιστοσύνη" Content: "Coldcard released patched firmware: version 5.6.0 for Mk4 and Mk5, and 1.5.0Q for Q devices. Mk3 users were advised to upgrade to a later firmware or replace the device. The incident is a reminder that hardware wallets reduce online risks but still require trust in the firmware, the supply chain, and the user's own practices. A single firmware bug can undo the security promise of cold storage." Translate: "Η Coldcard κυκλοφόρησε διορθωμένο firmware: έκδοση 5.6.0 για Mk4 και Mk5, και 1.5.0Q για συσκευές Q. Οι χρήστες Mk3 συμβουλεύτηκαν να αναβαθμίσουν σε μεταγενέστερο firmware ή να αντικαταστήσουν τη συσκευή. Το περιστατικό υπενθυμίζει ότι τα hardware πορτοφόλια μειώνουν τους διαδικτυακούς κινδύνους, αλλά