Loading market data...

Coldcard Firmware Bug Drained $38M in Bitcoin, Users Urged to Move Funds

Coldcard Firmware Bug Drained $38M in Bitcoin, Users Urged to Move Funds

and

tags. Need to preserve structure. Also note that the original has

How the bug works

etc. We'll translate headings. Also meta description: "A firmware bug in Coldcard hardware wallets allowed attackers to predict private keys and steal 594.48 BTC. Coinkite urges users to move funds immediately." -> Russian: "Ошибка прошивки аппаратных кошельков Coldcard позволила злоумышленникам предсказывать закрытые ключи и похитить 594,48 BTC. Coinkite призывает пользователей немедленно перевести средства." We need to ensure numbers are correct: 594.48 Bitcoin -> in Russian we use comma as decimal separator? Typically in Russian, decimal is comma, but in financial contexts they might use period? Actually in Russian, decimal comma is standard, but for crypto amounts, often they use period. However, to be safe, we can keep as 594.48 or convert to 594,48? The original uses period, we can keep as is. But for Russian, it's common to use comma, but since it's a specific number, we can keep the original format. I'll keep as 594.48. Also "Mk3" etc. Keep as is. We need to translate "Coldcard" as is, "Coinkite" as is. Let's translate paragraph by paragraph: First paragraph: "A critical firmware bug in Coldcard hardware wallets has enabled attackers to drain 594.48 Bitcoin — worth roughly $38.3 million — by predicting private keys using only the device's serial number and internal clock. The vulnerability stems from a broken random number generator introduced in a 2021 firmware update, and a subsequent fix in 2022 failed to fully resolve the issue. Coinkite, the company behind Coldcard, is now urging all affected users to generate a new seed on updated hardware and move their funds immediately." Translation: "Критическая ошибка прошивки аппаратных кошельков Coldcard позволила злоумышленникам похитить 594,48 биткоина (примерно $38,3 млн), предсказывая закрытые ключи, используя только серийный номер устройства и внутренние часы. Уязвимость связана с неисправным генератором случайных чисел, который был введён в обновлении прошивки 2021 года, а последующее исправление в 2022 году не полностью решило проблему. Coinkite, компания, стоящая за Coldcard, призывает всех затронутых пользователей создать новую seed-фразу на обновлённом оборудовании и немедленно перевести свои средства." But we need to be careful with "seed" - we can say "сид-фраза" or "seed-фраза". Usually in Russian crypto community, "seed" is often used as is. I'll use "seed-фраза". Also "hardware wallets" - "аппаратные кошельки" is fine. Second paragraph: "The flaw disables secure random number generation on certain Coldcard models. Attackers don't need physical access to the device. If they can see a wallet address or an exported public key, they can test guesses against the predictable private key — derived from the serial number and clock — and steal the funds. The exploit is similar to the Ill Bloom attack that drained wallets via weak seed phrases earlier this year." Translation: "Ошибка отключает безопасную генерацию случайных чисел на некоторых моделях Coldcard. Злоумышленникам не нужен физический доступ к устройству. Если они могут увидеть адрес кошелька или экспортированный открытый ключ, они могут проверить догадки относительно предсказуемого закрытого ключа — полученного из серийного номера и часов — и похитить средства. Эта эксплуатация похожа на атаку Ill Bloom, которая ранее в этом году опустошила кошельки из-за слабых seed-фраз." We need to keep "Ill Bloom" as is. Third paragraph: "Only the Coldcard Mk3 is vulnerable, and only if it's running firmware version 4.0.1 or later. The Mk4, Q, and Mk5 models are not affected. Coinkite and Block are still assessing the full extent of the flaw across older firmware versions. The vulnerability also extends to paper wallets and seed backups that relied on the same broken random number generator." Translation: "Уязвим только Coldcard Mk3, и только при прошивке версии 4.0.1 или новее. Модели Mk4, Q и Mk5 не затронуты. Coinkite и Block всё ещё оценивают масштаб проблемы в более старых версиях прошивки. Уязвимость также распространяется на бумажные кошельки и резервные копии seed-фраз, которые полагались на тот же неисправный генератор случайных чисел." Fourth paragraph: "Coinkite recommends generating a new seed on a device with the latest firmware and transferring all funds to the new wallet. A firmware update alone won't undo the damage — the old seed is already compromised. Users who added an extra passphrase to their seed face substantially lower risk, but Coinkite still advises moving funds as a precaution." Translation: "Coinkite рекомендует создать новую seed-фразу на устройстве с последней прошивкой и перевести все средства на новый кошелёк. Обновление прошивки само по себе не исправит ущерб — старая seed-фраза уже скомпрометирована. Пользователи, добавившие дополнительную парольную фразу к своей seed-фразе, подвергаются значительно меньшему риску, но Coinkite всё же советует перевести средства в качестве меры предосторожности." Fifth paragraph: "The company is still working to determine how many devices and wallets were affected by the bug, which went undetected for years. For now, anyone with a Coldcard Mk3 that was updated after 2021 should treat their seed as exposed. The clock is ticking —