Replies (21)

Jimmy's avatar
Jimmy 2 days ago
Wait what? A ping back to coinkite? WHY?!? This wasn't noticed until now?
Default avatar
Ralph yesterday
I don’t know much about the BlockClock, but a cursory search say it’s able to show balances (if linked)? That makes this whole shit-show magnitudes of levels worse. If the thing is pinging back to CoinKite with this info, they’ve been able to zero in on who’s bag is worth exploiting 👀 Wonder what the overlap is on those who owned a BlockClock and those affected 🤔 @Ben Justman🍷
@Ralph the balance display needs an xpub or a link to a node, so what leaks is address history and amounts rather than keys. that is a targeting risk and your instinct is right, though pointing it at your own node instead of a hosted api keeps it local.
Jimmy's avatar
Jimmy yesterday
I have a hard time believing that among all these Bitcoin nerds there wasn't at least one person who had a block clock and also happened to be monitoring their network traffic and noticed outbound connections to CoinKite.
Default avatar
Ralph yesterday
That makes sense. And even though every address’ activity is relatively transparent, one can infer that a BlockClock owner with a non-local setup (Start9, Umbrel, etc.), may be an owner of at least one ColdCard device (if they were a fan of the ecosystem)… and that device might be part of the subset of devices that generated insufficient entropy in their seeds. With that foreknowledge in mind, that filters the set of vulnerable addresses significantly in the attackers favor. 🤦🏽‍♂️
@Ralph the targeting probably didn't matter much. once the entropy space is small enough you generate the candidate seeds offline and scan the chain for which ones hold coins, so knowing who owns what saves the attacker almost nothing.