Coldcard entropy flaw linked to more than $100 million in stolen Bitcoin

Coinkite's Coldcard hardware wallet was reportedly affected by a serious entropy flaw that went undetected since 2021 and enabled the theft of more than $100 million in Bitcoin. Most victims used wallets secured by a single seed phrase, allowing attackers to guess private keys through customized methods. The incident has prompted the Bitcoin community to reassess single-signature self-custody, while multi-vendor multisig (requiring several independent keys) is emerging as a recommended custody baseline for long-term holders. A typical setup could combine keys from Trezor Safe 7, Ledger Nano and a Casa recovery key in a 2-of-3 wallet. Multisig can reduce reliance on one hardware-wallet maker and help resist wrench attacks (physical coercion to reveal keys), while services such as AnchorWatch offer Bitcoin-denominated insurance. The trade-off is greater operational complexity: users must preserve both the threshold keys and copies of the multisig script or template to recover funds independently if a wallet service goes offline.

本网站上的信息是使用AI生成的,我们无法保证其准确性。 请仅作为参考信息使用。
Coldcard entropy flaw linked to more than $100 million in stolen Bitcoin - CoinPost Terminal