Loading market data...

Coldcard Bug Drains 1,596 BTC as Korean Users Dodge the Blast

Coldcard Bug Drains 1,596 BTC as Korean Users Dodge the Blast

...

etc. Second paragraph:

How the bug worked

-

איך פעלה התקלה

or "איך עבדה התקלה". Then the paragraph. "The vulnerability stemmed from Coldcard's internal random number generator in certain devices. Attackers exploited the weak entropy to derive private keys, sweeping funds in at least three distinct waves. A potential fourth wave remains unconfirmed but is being watched. Coldcard responded by destroying remaining vulnerable inventory and urging all users to generate fresh seeds immediately." Translate: - "The vulnerability stemmed from Coldcard's internal random number generator in certain devices." - הפגיעות נבעה ממחולל המספרים האקראיים הפנימי של Coldcard במכשירים מסוימים. - "Attackers exploited the weak entropy to derive private keys, sweeping funds in at least three distinct waves." - תוקפים ניצלו את האנטרופיה החלשה כדי לגזור מפתחות פרטיים, וגרפו כספים בשלושה גלים נפרדים לפחות. - "A potential fourth wave remains unconfirmed but is being watched." - גל רביעי אפשרי עדיין לא אושר, אך נמצא במעקב. - "Coldcard responded by destroying remaining vulnerable inventory and urging all users to generate fresh seeds immediately." - Coldcard הגיבה בהשמדת מלאי פגיע שנותר ובקריאה לכל המשתמשים ליצור זרעים חדשים מיד. Third paragraph:

Why Korean users dodged the bug

-

מדוע משתמשים קוריאנים התחמקו מהתקלה

Then: "Korean community leaders had long advocated generating seed phrases and entropy independently — using physical dice or coin flips rather than relying on the vendor's internal randomness. Their recommended method: flip a coin 128 or 256 times for a 12- or 24-word seed, convert the binary to decimal with a hardware calculator (not a phone), cross-reference printed BIP39 word lists, and use an air-gapped tool like SeedSigner solely for checksum calculation. That practice, baked into local Bitcoin culture, made the Coldcard RNG flaw largely irrelevant for Korean users." Translate: - "Korean community leaders had long advocated generating seed phrases and entropy independently — using physical dice or coin flips rather than relying on the vendor's internal randomness." - מנהיגי קהילה קוריאנים דגלו זה מכבר ביצירת ביטויי זרע ואנטרופיה באופן עצמאי — באמצעות קוביות פיזיות או הטלות מטבע במקום להסתמך על האקראיות הפנימית של הספק. - "Their recommended method: flip a coin 128 or 256 times for a 12- or 24-word seed, convert the binary to decimal with a hardware calculator (not a phone), cross-reference printed BIP39 word lists, and use an air-gapped tool like SeedSigner solely for checksum calculation." - השיטה המומלצת שלהם: להטיל מטבע 128 או 256 פעמים עבור זרע של 12 או 24 מילים, להמיר את הבינארי לעשרוני עם מחשבון חומרה (לא טלפון), לבדוק מול רשימות מילים BIP39 מודפסות, ולהשתמש בכלי מנותק כמו SeedSigner רק לחישוב checksum. - "That practice, baked into local Bitcoin culture, made the Coldcard RNG flaw largely irrelevant for Korean users." - נוהג זה, שהוטמע בתרבות הביטקוין המקומית, הפך את פגם ה-RNG של Coldcard לבלתי רלוונטי ברובו עבור משתמשים קוריאנים. Fourth paragraph: "Analyst Koji Higashi attributed the resilience to structural strengths in community self-custody practices rather than individual skill. "It's not that Korean users are smarter," he said. "The community built systems that assume the hardware might be compromised."" Translate: - "Analyst Koji Higashi attributed the resilience to structural strengths in community self-custody practices rather than individual skill." - האנליסט Koji Higashi ייחס את החוסן לחוזקות מבניות בפרקטיקות של אחסון עצמי בקהילה, ולא למיומנות אישית. - ""It's not that Korean users are smarter," he said. "The community built systems that assume the hardware might be compromised."" - "זה לא שהמשתמשים הקוריאנים חכמים יותר," הוא אמר. "הקהילה בנתה מערכות שמניחות שהחומרה עלולה להיות פגומה." Fifth paragraph:

English-speaking communities hit harder

-

קהילות דוברות אנגלית נפגעו יותר

Then: "English-speaking users fared worse, in part because many relied on influencers for setup advice — some of whom had sponsorships or ties to Coldcard maker Coinkite. The core lesson, according to post-mortem discussions, is that Bitcoin's 'not trust, verify' principle should apply to information sources, not just code. Trusting a single influencer or vendor recommendation without independent verification proved costly." Translate: - "English-speaking users fared worse, in part because many relied on influencers for setup advice — some of whom had sponsorships or ties to Coldcard maker Coinkite." - משתמשים דוברי אנגלית נפגעו יותר, בין השאר משום שרבים הסתמכו על משפיענים לעצות התקנה — חלקם היו בעלי חסויות או קשרים ליצרנית Coldcard, Coinkite. - "The core lesson, according to post-mortem discussions, is that Bitcoin's 'not trust, verify' principle should apply to information sources, not just code." - הלקח המרכזי, לפי דיונים