Аюулгүй гэгддэг офлайн криптовалют хэтэвчнүүдээс их хэмжээний хөрөнгө хулгайлагдаж байна

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

Блокчэйн аюулгүй байдлын компаниудын хяналтаар офлайн төхөөрөмж ашигладаг Bitcoin эзэмшигчид хакерын томоохон халдлагад өртөж байгааг мэдээллээ.

Coinkite компанийн үйлдвэрлэдэг Coldcard хэтэвчийг ашигладаг Bitcoin эзэмшигчдийг дор хаяж арав гаруй өөр хакеруудын бүлэглэл бай болгож байна. Мягмар гараг гэхэд хакерууд ойролцоогоор 130 сая ам доллар хулгайлсныг судалгааны компаниуд тогтоожээ. TRM Labs компанийн мэдээлснээр энэ он гарсаар крипто компаниудад чиглэсэн 200 гаруй халдлага гарч, нийт 950 сая гаруй ам долларын алдагдал хүлээгээд байна.

Coldcard нь интернэтэд холбогддоггүй буюу хэрэглэгчийн нууц түлхүүр эсвэл үрийн хэллэгийг офлайнаар хадгалдаг тул хамгийн аюулгүй хэрэгслүүдийн нэг тооцогддог байв. Гэвч Block компанийн аюулгүй байдлын судлаачдын тогтоосноор, хакерууд Coldcard хэтэвч хэрэглэгчдийн нууц үгийг үүсгэх явцад гарсан сул талыг олж илрүүлжээ. Уг сул талын улмаас түлхүүрүүд нь урьдчилан таамаглахуйц байдлаар үүсдэг байсан бөгөөд хакерууд үүнийг ашиглан хохирогчдын нууц үгийг шууд гаргаж авсан байна.

Халдлагад өртөж 1.6 сая ам долларын алдагдал хүлээсэн Жонатан Гудман төхөөрөмжөө хэзээ ч интернэтэд холбож байгаагүй бөгөөд бүх зүйлээ найдвартай хадгалсан ч 2021 оны кодын нэг сул талоос болж хохирлоо гэж X хуудсандаа бичжээ. Coinkite пүрэв гарагт мэдэгдэл гаргаж, хэрэглэгчдэд уг сул талын талаар анхааруулга өгөн төхөөрөмжөө шинэчилж, шинэ нууц хэллэг рүү шилжихийг уриалсан байна. Компани энэ асуудлаар мэдээлэл өгөхөөс татгалзжээ.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

Hackers are in the midst of a massive theft of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the heists.

At least a dozen different hackers are said to be targeting Bitcoin owners who use the hardware crypto wallet Coldcard, made by Coinkite. At this point, it’s unclear who is behind the digital robberies, and it appears like there’s more than one group of hackers, according to Galaxy Research.

As of Tuesday, the research firm said the hackers have stolen around $130 million. Tom Robinson, the co-founder and chief scientist of crypto monitoring firm Elliptic, told TechCrunch that the estimate is roughly correct.

This is the latest effort to steal large amounts of people’s cryptocurrency. So far this year, according to blockchain monitoring firm TRM Labs, there have been more than 200 hacks targeting cryptocurrency companies, with a total loss of more than $950 million.

What makes the ongoing hacks against Coldcard wallet owners particularly interesting is that the point of using a product like Coldcard is that it’s supposed to be, at least in theory, one of the safer ways to store their cryptocurrency.

Bitcoin owners can store the secret key or seed phrase — essentially a password — to their cryptocurrency in a Coldcard wallet, a device that is not connected to the internet. With this system, Bitcoins are still on the blockchain, like all Bitcoins, but are protected by a password that lives exclusively offline. This is considered a “cold” wallet, as opposed to “hot” wallets that are online, such as those in apps, browser extensions, and accounts on commercial crypto exchanges like Binance or Coinbase.

As it turns out, hackers figured out that there was a flaw in how Coldcard wallets generated users’ seed phrases, which were predictable, according to security researchers at Block. Once they figured out the flaw, hackers simply needed to brute-force and generate the victims’ seedphrases.

By knowing how to make the keys, the hackers did not need to break into the safe that holds them. The hackers essentially figured out how to cut keys at scale.

“Perhaps the hardest part about this is that I did everything right,” Jonathan Goodman, who claimed to have had $1.6 million stolen from their Coldcard wallet, wrote on X. “I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes,” he said.

“None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability,” wrote Goodman.

In an advisory published on Thursday and updated on Saturday, Coinkite alerted users of the flaw, urged them to update their devices, and then “migrate” to a new seed phrase.

Coinkite did not immediately respond to TechCrunch’s request for comment.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

- Зар сурталчилгаа -

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img