B
今週中
ビットコイン用ハードウェアウォレット「Coldcard」の古いファームウェアに存在する乱数生成の欠陥が悪用され、約1,082BTC(約7,020万ドル)が盗まれ…
📌 一言でいうと
ビットコイン用ハードウェアウォレット「Coldcard」の古いファームウェアに存在する乱数生成の欠陥が悪用され、約1,082BTC(約7,020万ドル)が盗まれたことが判明しました。攻撃者はハードウェア乱数生成器ではなく予測可能なソフトウェア擬似乱数生成器が動作していた設計ミスを利用し、オフラインでシード(復旧キー)を計算して資産を奪取しました。メーカーは緊急パッチを配布しましたが、過去の脆弱な環境で生成されたシードは保護されないため、新しいシードへの移行が推奨されています。
🔍該当判定
- ビットコイン専用ハードウェアウォレット「Coldcard(コールドカード)」を社内で利用している
- Coldcardを2021年3月以前の古いファームウェアのまま利用している
- Coldcardで作成した既存のリカバリーフレーズ(シード)をそのまま使い続けている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
最新のファームウェアを適用し、脆弱な環境で生成された既存のシードを破棄して、新しいシードを再生成し資産を移行すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Coldcard ハードウェアウォレットの乱数生成欠陥による資産盗難について
お疲れさまです。Coldcardの脆弱性を悪用した大規模な資産盗難事件に関する情報共有です。
■ 概要
Coldcardの旧ファームウェアにおいて、シード生成時にハードウェア乱数生成器ではなく予測可能なソフトウェア擬似乱数生成器が使用される設計上の欠陥が判明しました。これにより、攻撃者がオフラインでシード候補を計算し、秘密鍵を特定して資産を奪取することが可能です。実際に約1,082BTCが盗まれた事例が報告されています。
■ 影響範囲
- 対象製品: CoinKit Coldcard (2021年3月頃のファームウェア統合エラーを含む旧バージョン)
■ 対応手順
1. 最新の緊急ファームウェアを適用する。
2. 【重要】既存のシードはパッチ適用後も脆弱なままであるため、最新ファームウェア環境下で新しいシードを生成し、資産を移行させる。
■ 参考情報
- CoinKit 公式アドバイザリ
対応優先度: 高
対応期限: 直ちに実施
お疲れさまです。Coldcardの脆弱性を悪用した大規模な資産盗難事件に関する情報共有です。
■ 概要
Coldcardの旧ファームウェアにおいて、シード生成時にハードウェア乱数生成器ではなく予測可能なソフトウェア擬似乱数生成器が使用される設計上の欠陥が判明しました。これにより、攻撃者がオフラインでシード候補を計算し、秘密鍵を特定して資産を奪取することが可能です。実際に約1,082BTCが盗まれた事例が報告されています。
■ 影響範囲
- 対象製品: CoinKit Coldcard (2021年3月頃のファームウェア統合エラーを含む旧バージョン)
■ 対応手順
1. 最新の緊急ファームウェアを適用する。
2. 【重要】既存のシードはパッチ適用後も脆弱なままであるため、最新ファームウェア環境下で新しいシードを生成し、資産を移行させる。
■ 参考情報
- CoinKit 公式アドバイザリ
対応優先度: 高
対応期限: 直ちに実施
Subject: [Security Alert] Asset Theft via Random Number Generation Flaw in Coldcard Wallets
Dear Team,
We are sharing information regarding a critical vulnerability in Coldcard hardware wallets that has led to significant asset theft.
■ Overview
A design flaw in older Coldcard firmware caused the device to use a predictable software pseudo-random number generator (PRNG) instead of the intended hardware RNG during seed generation. This allows attackers to computationally derive seed phrases offline and compromise associated Bitcoin addresses. Approximately 1,082 BTC have been stolen using this method.
■ Scope
- Affected Product: CoinKit Coldcard (versions affected by the March 2021 firmware integration error).
■ Mitigation Steps
1. Update to the latest emergency firmware immediately.
2. IMPORTANT: Since the patch does not protect seeds generated under the flawed firmware, users must generate a new seed using the updated firmware and migrate their assets.
■ Reference
- CoinKit Official Advisory
Priority: High
Deadline: Immediate
Dear Team,
We are sharing information regarding a critical vulnerability in Coldcard hardware wallets that has led to significant asset theft.
■ Overview
A design flaw in older Coldcard firmware caused the device to use a predictable software pseudo-random number generator (PRNG) instead of the intended hardware RNG during seed generation. This allows attackers to computationally derive seed phrases offline and compromise associated Bitcoin addresses. Approximately 1,082 BTC have been stolen using this method.
■ Scope
- Affected Product: CoinKit Coldcard (versions affected by the March 2021 firmware integration error).
■ Mitigation Steps
1. Update to the latest emergency firmware immediately.
2. IMPORTANT: Since the patch does not protect seeds generated under the flawed firmware, users must generate a new seed using the updated firmware and migrate their assets.
■ Reference
- CoinKit Official Advisory
Priority: High
Deadline: Immediate