After carefully analysing and testing the
@COLDCARD
rng bug, I am quite sure the attacker(s) knew about the bug already and spent weeks if not months to enumerate some vulnerable wallets. The whole enumeration did not take 3 days (the delta between Kimi K3 release and the attack)
Login to reply
Replies (2)
if I could guess words on electrum and open existing wallets imagine what someone who made a hardware wallet with a bug could do. they've probably been curating a list each time a coldcard was purchased ๐
But if the wallets only had an entropy of 30 to 40 bits, which you can easily enumerate in hours on a regular PC, i wonder why it took 3 days to hit all unprotected wallets (e.g. my wallet without passphrase, where I left some dust behind, got swept only on Monday morning, 3 days after the initial attack)