Loading market data...

Coldcard Hack Drains Nearly $90M After Firmware Flaw Goes Unnoticed for Five Years

Coldcard Hack Drains Nearly $90M After Firmware Flaw Goes Unnoticed for Five Years

and

tags. Let's translate: First paragraph: "A vulnerability in Coldcard hardware wallets has been exploited to steal nearly $90 million in cryptocurrency, according to Galaxy Research. The flaw, which shipped in March 2021, reduced the entropy of seed generation to about 40 bits on some models, letting attackers guess private keys. The attack is still ongoing, and the tally of drained addresses keeps climbing." Translation: "Një dobësi në portofolat harduerikë Coldcard është shfrytëzuar për të vjedhur gati 90 milionë dollarë në kriptomonedhë, sipas Galaxy Research. Defekti, i cili u lëshua në mars 2021, reduktoi entropinë e gjenerimit të farës në rreth 40 bit në disa modele, duke i lejuar sulmuesit të hamendësojnë çelësat privatë. Sulmi është ende në vazhdim, dhe numri i adresave të zbrazura vazhdon të rritet." Second paragraph: "The five-year-old bug" -> "Defekti pesëvjeçar" (as h2). Then paragraph: "Coldcard wallets are designed to generate seeds using a hardware entropy source. But a preprocessor guard routed seed generation to a weak software PRNG called Yasmarang instead, collapsing the effective entropy to roughly 40 bits. That's a far cry from the 256 bits you'd expect. With only 40 bits, a determined attacker can brute-force the keys." Translation: "Portofolat Coldcard janë projektuar për të gjeneruar fara duke përdorur një burim entropie harduerik. Por një mbrojtës paraprocesori e drejtoi gjenerimin e farës në një PRNG të dobët softuerik të quajtur Yasmarang, duke e shembur entropinë efektive në rreth 40 bit. Kjo është shumë larg nga 256 bit që do të prisnit. Me vetëm 40 bit, një sulmues i vendosur mund të thyejë me forcë brutale çelësat." Third paragraph: "The flawed code shipped in March 2021 and stayed in publicly readable firmware for more than five years. Nobody noticed until someone started sweeping addresses. Attackers initially hit 500 addresses. Galaxy Research's count now stands at 4,585 addresses and nearly $90 million, with no sign of stopping." Translation: "Kodi me defekt u lëshua në mars 2021 dhe mbeti në firmware të lexueshëm publikisht për më shumë se pesë vjet. Askush nuk e vuri re derisa dikush filloi të fshinte adresat. Sulmuesit fillimisht goditën 500 adresa. Numri i Galaxy Research tani është 4,585 adresa dhe gati 90 milionë dollarë, pa shenja ndalimi." Fourth paragraph: "Why the license change didn't help" -> "Pse ndryshimi i licencës nuk ndihmoi" (h2). Then: "Coinkite, the company behind Coldcard, had moved its firmware from a free-software license to source-available terms (MIT with a Commons Clause) after Foundation Devices used the code in a competing product. The idea was to keep others from copying it. But that move didn't increase protection at all." Translation: "Coinkite, kompania pas Coldcard, e kishte zhvendosur firmware-in e saj nga një licencë softueri i lirë në kushte të disponueshme burimi (MIT me një Klauzolë Commons) pasi Foundation Devices përdori kodin në një produkt konkurrues. Ideja ishte të pengonte të tjerët ta kopjonin. Por kjo lëvizje nuk rriti aspak mbrojtjen." Fifth paragraph: "The bug lived in code that a machine could read regardless of the license. The license change only changed the economics of finding the bug. It didn't remove the information. In the age of highly skilled AI, everything distributed is readable. Binaries can be decompiled, and obfuscation doesn't remove information. Trade secrecy in shipped software is just obscurity, and reverse engineering a product you lawfully possess is fair play." Translation: "Defekti ishte në kodin që një makinë mund ta lexonte pavarësisht licencës. Ndryshimi i licencës vetëm ndryshoi ekonominë e gjetjes së defektit. Nuk e hoqi informacionin. Në epokën e AI-së shumë të aftë, gjithçka që shpërndahet është e lexueshme. Binaret mund të dekompilohen, dhe obfuskimi nuk heq informacion. Sekreti tregtar në softuerin e shpërndarë është vetëm errësirë, dhe inxhinieria e kundërt e një produkti që e zotëroni ligjërisht është lojë e ndershme." Sixth paragraph: "AI found what auditors missed" -> "AI gjeti atë që auditorët humbën" (h2). Then: "Coinkite's working assumption is that someone used AI to comb the publicly available firmware and find the bug. That's plausible. An AI-assisted audit run weeks before the theft found nothing. But since the attack started, researchers have shown several frontier models locating the same flaw in minutes from a single prompt." Translation: "Supozimi i punës i Coinkite është se dikush përdori AI për të kontrolluar firmware-in e disponueshëm publikisht dhe për të gjetur defektin. Kjo është e besueshme. Një auditim i ndihmuar nga AI i kryer javë para vjedhjes nuk gjeti asgjë. Por që nga fillimi i sulmit, studiuesit kanë treguar disa modele kufitare që lokalizojnë të njëjtin defekt në minuta nga një prompt i vetëm." Seventh paragraph: "This isn't an isolated case. On July 20, mathematician Levent Alpöge posted a counterexample to Keller's Jacobian conjecture, open since 1939, using Anthropic's Claude Fable 5. The result was verified by Lean within hours. In May, an OpenAI model toppled the Erdős unit-distance conjecture, open since 1946. In late July, a 30-year-old graph-theory conjecture fell to four prompts. AI isn't just reading code; it's solving problems that have stumped humans for decades." Translation: "Ky nuk është një rast i izoluar. Më 20 korrik, matematikani Levent Alpöge postoi një kundërshembull për konjekturën Jacobian të Keller, e hapur që nga 1939, duke përdorur Claude Fable 5 të Anthropic. Rezultati u verifikua nga Lean brenda orësh. Në maj, një model OpenAI rrëzoi konjekturën e distancës njësi të Erdős, e hapur që nga 1946. Në fund të korrikut, një konjekturë e teorisë së grafeve 30-vjeçare ra pas katër promptesh. AI nuk po lexon vetëm kod; po zgjidh probleme që kanë hutuar njerëzit për dekada." Eighth paragraph: "The new security reality" -> "Realiteti real