Loading market data...

Coldcard Entropy Bug Lets Hackers Drain 594 BTC; Peter Todd Warns Single-Sig Wallets Unsafe

Coldcard Entropy Bug Lets Hackers Drain 594 BTC; Peter Todd Warns Single-Sig Wallets Unsafe
,

,

. Let's translate paragraph by paragraph: Original: "A critical entropy bug in Coldcard hardware wallets enabled hackers to drain 594 Bitcoin — worth roughly $38 million — from users' wallets. Bitcoin developer Peter Todd responded with a stark warning: no Bitcoin is safe on single-signature wallets anymore." Translation: "Coldcard硬件钱包中的一个严重熵漏洞使黑客能够从用户钱包中盗走594枚比特币(价值约3800万美元)。比特币开发者Peter Todd对此发出严厉警告:任何比特币在单签名钱包中都不再安全。" Second paragraph: "The bug lies in how Coldcard generates random numbers for private keys. A weak entropy source made it possible for attackers to brute-force the keys, effectively guessing them. The exploit didn't require physical access to the device in every case — remote attackers could scan the blockchain for vulnerable addresses and sweep the funds." Translation: "该漏洞源于Coldcard生成私钥随机数的方式。熵源薄弱使得攻击者能够暴力破解私钥,实际上就是猜测密钥。该漏洞并非每次都需要物理接触设备——远程攻击者可以扫描区块链上易受攻击的地址并盗取资金。" Third: "594 BTC drained" heading: "594 BTC被窃取" or "594枚比特币被盗" Paragraph: "On-chain data shows 594 BTC moved from multiple addresses linked to Coldcard users. At current prices that's about $38 million. The theft appears to have happened over several days, with the hackers methodically targeting wallets that used the compromised entropy. It's one of the larger hardware-wallet-related heists in recent memory." Translation: "链上数据显示,594枚BTC从多个与Coldcard用户相关的地址被转出。按当前价格计算,这约合3800万美元。盗窃似乎持续了数天,黑客有条不紊地瞄准使用受影响熵的钱包。这是近期记忆中与硬件钱包相关的大型盗窃案之一。" Fourth: "Peter Todd's warning" heading: "Peter Todd的警告" Paragraph: "Todd, a longtime Bitcoin core developer, didn't mince words. He said that after this bug, relying on a single signature from any hardware wallet is too risky. He didn't name Coldcard specifically in every tweet, but the context was clear. The warning lands hard because single-sig wallets are the default for most Bitcoin users — one key, one point of failure." Translation: "长期担任比特币核心开发者的Todd直言不讳。他表示,在此漏洞之后,依赖任何硬件钱包的单签名都过于冒险。他并非每条推文都点名Coldcard,但语境明确。这一警告之所以沉重,是因为单签名钱包是大多数比特币用户的默认选择——一把钥匙,一个故障点。" Fifth: "What users should do" heading: "用户应该做什么" Paragraph: "Anyone using a Coldcard — or any hardware wallet that relies on a single private key — should consider moving funds to a multisignature setup. Multisig requires multiple keys to authorize a transaction, so a single compromised device doesn't mean lost coins. The timing isn't great: the market is already jittery, and a $38 million theft doesn't help confidence." Translation: "任何使用Coldcard——或任何依赖单个私钥的硬件钱包——的用户都应考虑将资金转移到多重签名设置。多重签名需要多个密钥才能授权交易,因此单个设备受损并不意味着币丢失。时机不佳:市场本就紧张,3800万美元的盗窃案无助于提振信心。" Sixth: "Coldcard has not yet released a public statement about the bug or a firmware patch. Users are left waiting for an official fix while the stolen BTC sits in wallets controlled by the hackers. Whether those coins can ever be recovered is an open question." Translation: "Coldcard尚未就该漏洞或固件补丁发布公开声明。用户只能等待官方修复,而被盗的BTC则留在黑客控制的钱包中。这些币能否被追回仍是未知数。" Now meta description: "A Coldcard entropy bug allowed hackers to steal 594 BTC ($38M). Bitcoin developer Peter Todd warns single-signature wallets are no longer safe. Learn about the vulnerability and what users should do." Translate: "Coldcard熵漏洞导致黑客盗取594枚比特币(3800万美元)。比特币开发者Peter Todd警告称单签名钱包不再安全。了解该漏洞及用户应采取的应对措施。" Now we need to output JSON. Ensure we use double quotes, escape any inner double quotes. Also content should be a string with the HTML. We'll format the content as the original article but with translated text inside the tags. Let's construct the content string:

Coldcard硬件钱包中的一个严重熵漏洞使黑客能够从用户钱包中盗走594枚比特币(价值约3800万美元)。比特币开发者Peter Todd对此发出严厉警告:任何比特币在单签名钱包中都不再安全。

漏洞详情

该漏洞源于Coldcard生成私钥随机数的方式。熵源薄弱使得攻击者能够暴力破解私钥,实际上就是猜测密钥。该漏洞并非每次都需要物理接触设备——远程攻击者可以扫描区块链上易受攻击的地址并盗取资金。

594枚比特币被盗

链上数据显示,594枚BTC从多个与Coldcard用户相关的地址被转出。按当前价格计算,这约合3800万美元。盗窃似乎持续了数天,黑客有条不紊地瞄准使用受影响熵的钱包。这是近期记忆中与硬件钱包相关的大型盗窃案之一。

Peter Todd的警告

长期担任比特币核心开发者的Todd直言不讳。他表示,在此漏洞之后,依赖任何硬件钱包的单签名都过于冒险。他并非每条推文都点名Coldcard,但语境明确。这一警告之所以沉重,是因为单签名钱包是大多数比特币用户的默认选择——一把钥匙,一个故障点。

用户应该怎么做

任何使用Coldcard——或任何依赖单个私钥的硬件钱包——的用户都应考虑将资金转移到多重签名设置。多重签名需要多个密钥才能授权交易,因此单个设备受损并不意味着币丢失。时机不佳:市场本就紧张,3800万美元的盗窃案无助于提振信心。

Coldcard尚未就该漏洞或固件补丁发布公开声明。用户只能等待官方修复,而被盗的BTC则留在黑客控制的钱包中。这些币能否被追回仍是未知数。