to leave a comment.

▲ iPhone, cryptocurrency hacking/AI generated image
Over 1,596 BTC were stolen due to the Coldcard hacking incident. In contrast, South Korean Bitcoin holders largely avoided direct damage thanks to their unique seed generation practices.
According to the cryptocurrency specialized media BeInCrypto on August 6 (local time), despite a considerable number of Coldcard users in the South Korean Bitcoin community, almost no clear direct damage was reported. This attack originated from faulty random number generation functions in some Coldcard devices. In three confirmed attacks and smaller incidents, approximately 7,300 addresses were affected, and over 1,596 BTC were stolen. The estimated damage, including additional suspicious cases, is approximately $130 million.
Random numbers are a key element in creating seed phrases that determine wallet access. If the randomness of the numbers is insufficient, the likelihood of an attacker guessing the seed phrase increases. Coldcard recommended discarding remaining vulnerable products and advised users to generate new seeds.
South Korean users opted for a method that did not rely on random numbers generated by the hardware wallet itself. They manually created random numbers by rolling dice or flipping coins and generated BIP39 seed phrases in an offline environment. They also utilized methods such as flipping a coin 128 times for a 12-word seed and 256 times for a 24-word seed. During the conversion process, they used hardware calculators and printed BIP39 word lists instead of smartphones.
Analyst Koji Higashi attributed the South Korean community's avoidance of damage not to individual technical skill levels, but to structural habits inherent in self-custody practices. Some users only used SeedSigner for verification value calculations and applied additional passwords or separate random numbers generated with dice. In contrast, the English-speaking community's excessive trust in influential figures with commercial ties to Coldcard manufacturer Coinkite led to greater damage, according to the analysis.
Higashi also pointed out that an information environment where only similar views are repeated exacerbated the risk. South Korean community leaders, having relatively fewer commercial and personal interests with the manufacturer, independently assessed the product's security and advised users to generate random numbers themselves. This incident left a lesson that the principle of "don't trust, verify" should be applied not only to code but also to information providers and hardware manufacturers.
[Article Key Summary]
-Over 1,596 BTC were stolen in an attack exploiting Coldcard vulnerabilities, with estimated damages, including suspicious cases, totaling approximately $130 million.
-South Korean Bitcoin holders largely avoided direct damage by generating random numbers with dice and coins and creating BIP39 seeds offline.
-The practice of not blindly trusting manufacturers and influential figures, and independently verifying all security procedures, was presented as a key defense.
*Disclaimer: This article is for investment reference only, and we are not responsible for any investment losses based on it. The content should be interpreted for informational purposes only.*
Newsletter
Get key news delivered to your email every morning
to leave a comment.