Coldcard Hack Exposes Vulnerability in Self-Custody Security
The recent Coldcard hack has left the Bitcoin community reeling, raising questions about the security of self-custody wallets.
On July 30th, attackers began draining Bitcoin from addresses linked to seeds generated by compromised Coldcards, a type of cold storage wallet manufactured by Coinkite. The attack was unprecedented in scale and speed, with at least 15 different attackers stealing around 2,000 Bitcoins worth approximately $130 million from 4,385 addresses within just a few hours.
The hack highlights the risks associated with self-custody, which is often touted as a way to avoid institutional corruption and counterparty risk. However, it also underscores the importance of technical skill in securing one's own Bitcoin holdings. The incident shows that even with self-custody, there is no guarantee of safety if the underlying hardware or software is compromised.
The vulnerability in Coinkite's firmware was discovered by AI-assisted security review, which found a link-time error causing seed generation to use a deterministic pseudorandom-number generator instead of the intended true random-number generator. This allowed attackers to generate seeds with ease, making it possible for them to drain the affected addresses.
The incident has sparked debate about the merits of self-custody versus professional custody. While some argue that self-custody carries greater concentration risk, others point out that custodians can also pose significant risks, as seen in cases like Mt. Gox and FTX.