Loading market data...

Coldcard Bug Drains 1,596 BTC as Korean Users Dodge the Blast

Coldcard Bug Drains 1,596 BTC as Korean Users Dodge the Blast

How the bug worked

->

Как работала ошибка

Paragraph:

The vulnerability stemmed from Coldcard's internal random number generator in certain devices. Attackers exploited the weak entropy to derive private keys, sweeping funds in at least three distinct waves. A potential fourth wave remains unconfirmed but is being watched. Coldcard responded by destroying remaining vulnerable inventory and urging all users to generate fresh seeds immediately.

Translation:

Уязвимость возникла из-за внутреннего генератора случайных чисел Coldcard в некоторых устройствах. Злоумышленники использовали слабую энтропию для получения приватных ключей, вычищая средства как минимум тремя отдельными волнами. Потенциальная четвёртая волна остаётся неподтверждённой, но за ней следят. Coldcard ответил уничтожением оставшихся уязвимых запасов и призвал всех пользователей немедленно сгенерировать новые сид-фразы.

Next h2:

Why Korean users dodged the bug

->

Почему корейские пользователи избежали ошибки

Paragraph:

Korean community leaders had long advocated generating seed phrases and entropy independently — using physical dice or coin flips rather than relying on the vendor's internal randomness. Their recommended method: flip a coin 128 or 256 times for a 12- or 24-word seed, convert the binary to decimal with a hardware calculator (not a phone), cross-reference printed BIP39 word lists, and use an air-gapped tool like SeedSigner solely for checksum calculation. That practice, baked into local Bitcoin culture, made the Coldcard RNG flaw largely irrelevant for Korean users.

Translation:

Лидеры корейского сообщества давно выступали за самостоятельную генерацию сид-фраз и энтропии — с помощью физических игральных костей или подбрасывания монеты, а не полагаясь на внутреннюю случайность производителя. Их рекомендуемый метод: подбросить монету 128 или 256 раз для сид-фразы из 12 или 24 слов, преобразовать двоичный код в десятичный с помощью аппаратного калькулятора (не телефона), сверить с напечатанными списками слов BIP39 и использовать изолированный от сети инструмент, такой как SeedSigner, только для расчёта контрольной суммы. Эта практика, укоренившаяся в местной биткоин-культуре, сделала дефект генератора случайных чисел Coldcard в значительной степени неактуальным для корейских пользователей.

Next paragraph:

Analyst Koji Higashi attributed the resilience to structural strengths in community self-custody practices rather than individual skill. "It's not that Korean users are smarter," he said. "The community built systems that assume the hardware might be compromised."

Translation:

Аналитик Кодзи Хигаси объяснил устойчивость структурными преимуществами практик самостоятельного хранения в сообществе, а не индивидуальными навыками. «Дело не в том, что корейские пользователи умнее, — сказал он. — Сообщество создало системы, которые предполагают, что оборудование может быть скомпрометировано».

Note: Koji Higashi is a Japanese name, but we keep as is. In Russian, we might transliterate: Кодзи Хигаси. But the instruction says keep proper nouns in original form. So we can keep "Koji Higashi" as is. But in Russian text, it's common to transliterate. However, the instruction says "Keep proper nouns (names, company names) in original form" - so we should keep "Koji Higashi" in Latin script. But that might look odd. Actually, the instruction says "Keep proper nouns (names, company names) in original form" - meaning we don't translate them, but we can transliterate? Usually in translation, we keep names as is, but in Russian text, we might write them in Cyrillic. But the instruction says "original form" - so we should keep them as they are in English. So we'll write "Koji Higashi" as is. Similarly, "Coldcard", "Coinkite", "SeedSigner", "BIP39" - keep as is. So we'll keep "Koji Higashi" in Latin. Next h2:

English-speaking communities hit harder

->

Англоязычные сообщества пострадали сильнее

Paragraph:

English-speaking users fared worse, in part because many relied on influencers for setup advice — some of whom had sponsorships or ties to Coldcard maker Coinkite. The core lesson, according to post-mortem discussions, is that Bitcoin's 'not trust, verify' principle should apply to information sources, not just code. Trusting a single influencer or vendor recommendation without independent verification proved costly.

Translation:

Англоязычные пользователи пострадали сильнее, отчасти потому, что многие полагались на советы инфлюенсеров по настройке — некоторые из них имели спонсорские или иные связи с производителем Coldcard, компанией Coinkite. Основной урок, согласно обсуждениям после инцидента, заключается в том, что принцип биткоина «не довер