PANews丨APP全面升级
PANews丨APP全面升级|Aug 19, 2026 03:01
"Update on the Coldcard Bitcoin theft case: First wave of attackers may have been identified by the FBI, but evidence of 'inside job' is insufficient. The Coldcard hardware wallet theft incident has seen new developments: the Block engineering team discovered that the attacker used a paid account from a certain on-chain data service provider to query source addresses. The logs and attack methods match closely, and the clues have been handed over to law enforcement. Galaxy Research analyst Alex Thorn stated, 'Law enforcement may already know the identity of the first wave of attackers.' This wave of attacks siphoned off 1,082.65 BTC (approximately $70.2 million) within 41 minutes, and the stolen funds remain untouched. As of early August, total losses have exceeded 1,800 BTC (approximately $118 million). Root cause of the vulnerability: In March 2021, Coinkite CTO Peter Gray (alias Doc-Hex) replaced a well-vetted cryptographic library with an obscure library called libngu, written by someone using the alias 'Switch.' This led to the random number generator relying on a low-entropy software pseudo-random number generator, making private keys on older devices vulnerable to brute-force attacks. Researchers discovered through GPG signatures that 'Switch' and Peter Gray used the same private key, suggesting a connection between the two identities. An article by Bitcoin Magazine pointed out that this seems more like a series of amateur mistakes rather than a deliberate 'inside job': the 'Switch' identity was poorly concealed and easily exposed, Coinkite's management is still publicly addressing the aftermath and releasing patches, which contrasts sharply with classic inside job cases where culprits vanish with the funds. Multiple independent technical reviews have also found no evidence of intentionally planted vulnerabilities. #Bitcoin #Coldcard #CryptoNews #BTC #Blockchain
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads