← 回總覽

超 5.8 亿资产被盗!硬件钱包爆出史诗级漏洞

📅 2026-08-03 10:25 区块链头条 媒体资讯 5 分鐘 6132 字 評分: 84
区块链安全 硬件钱包 比特币盗窃 安全漏洞 加密资产
📌 一句话摘要 本文披露 Coldcard 硬件钱包自 2021 年固件更新后存在的致命漏洞,导致 4585 个钱包被攻破、1367 枚 BTC 被盗,涉案 5.87 亿元人民币,彻底动摇了冷钱包绝对安全的行业认知。 📝 详细摘要 文章详细披露 Coldcard 硬件钱包自 2021 年 3 月固件 4.0.0 版本后存在的底层随机数生成漏洞,导致助记词熵值从 128 位降至 40 位,黑客可通过暴力破解直接盗取资产。截至 8 月 2 日,已有 4585 个钱包被攻破,1367 枚 BTC 被盗(约 5.87 亿元人民币)。事件引发行业安全认知重构,用户大规模迁移资产,头部人士呼吁钱包多样

Title: 超 5.8 亿资产被盗!硬件钱包爆出史诗级漏洞 | BestBlogs.dev

URL Source: https://www.bestblogs.dev/article/be84693380?amp%3Butm_medium=feed&%3Butm_campaign=resources&%3Bentry=rss_article_item

Published Time: 2026-08-03 10:25:00

Markdown Content: Skip to main contentAudio 2 ![Image 2: LogoBest Blogs](https://www.bestblogs.dev/ "BestBlogs.dev")

Search Ctrl+K

Change language Switch ThemeSign In

[](https://www.bestblogs.dev/en/explore/brief "Daily Brief")[](https://www.bestblogs.dev/en/explore/newsletter "Weekly Picks")[](https://www.bestblogs.dev/en/explore/topics "Topics")

[](https://www.bestblogs.dev/en/settings "Settings")[](https://www.bestblogs.dev/en/docs "Help Center")

Narrow Mode

84

超 5.8 亿资产被盗!硬件钱包爆出史诗级漏洞

This article reveals a critical vulnerability in Coldcard hardware wallets existing since the 2021 firmware update, resulting in 4,585 compromised wallets, 1,367 BTC stolen (worth approximately 58.7 million yuan), which fundamentally challenges the industry's perception of absolute cold wallet security. ![Image 3: 区块链头条区块链头条](https://www.bestblogs.dev/articles?sourceid=8f498bcc "View More From This Source")Follow·

Today·1305 words (about 6 min)

·View Source →

AI Summary & Key Points

Summary

The article details a fundamental random number generation vulnerability in Coldcard hardware wallets present since firmware version 4.0.0 released in March 2021, which reduced mnemonic entropy from 128 bits to 40 bits. As of August 2nd, 4,585 wallets have been compromised with 1,367 BTC stolen (approximately 58.7 million yuan). The incident has triggered a paradigm shift in industry security awareness, prompting mass asset migration by users and calls for diversified wallet configurations from industry leaders. The article emphasizes that simply updating firmware cannot rectify historically generated high-risk mnemonics, requiring users to proactively migrate assets.

Main Points

* 1. Coldcard hardware wallets contain a 5-year unpatched firmware vulnerability.

The vulnerability emerged in the March 2021 firmware 4.0.0 version, creating defects in the random number generation mechanism that significantly reduced mnemonic entropy, exposing wallets to hacking risks.

* 2. Hackers can directly steal assets through brute-force attacks without physical access to devices.

Attackers exploited the reduced mnemonic entropy to conduct high-efficiency offline computational attacks, enabling batch cracking of wallets and asset theft.

* 3. The incident has reshaped industry security perceptions and asset allocation patterns.

Mass asset migration by users has shifted industry security definitions from single offline storage to a new paradigm combining regulated custody, multi-dimensional distribution, and continuous risk control.

Sign in to highlight text and take notes as you read. Sign in now

原创 Black 2026-08-03 10:25 福建

!Image 4

所有持币用户紧急自查 !Image 5 硬件钱包安全危机持续发酵,打破 “冷钱包绝对安全” 认知

本轮席卷整个币圈的Coldcard硬件钱包致命漏洞事件,成为8月加密市场最大黑天鹅,彻底击碎了行业长期以来“冷钱包绝对安全”的固有认知,给所有自托管资产用户敲响终极安全警钟。作为圈内公认的高安全性硬件钱包,Coldcard一直是大额持币大户、资深投资者的首选存储工具,凭借离线存储、离线签名的特性,被视作规避平台跑路、线上盗币风险的“资产安全底线”,但本次爆发的固件漏洞,直接颠覆了这一行业共识。

据海外安全机构最新披露,该致命漏洞并非临时突发,而是自2021年3月固件4.0.0版本更新后就已潜伏,长达5年的时间里未被发现与修复。漏洞核心问题出在钱包底层的随机数生成机制缺陷,设备会跳过安全硬件随机数生成器,大幅压缩助记词熵值,原本128位的高强度加密随机熵被削弱至仅40位左右,极大降低了助记词的破解难度。黑客无需接触用户硬件设备、无需获取用户私钥与助记词,仅通过离线算力推演、暴力枚举的方式,就能批量破解有效助记词,直接盗取钱包内全部资产,属于顶级高危的底层固件漏洞。

目前本次安全事件的被盗规模仍在持续攀升,数据触目惊心。截至8月2日统计,黑客已发起多轮集中攻击,累计攻破4585个Coldcard钱包地址,盗取1367枚比特币,涉案总价值高达8670万美元(折合人民币约5.87亿元),其中最快一轮攻击仅25分钟就清空500个钱包、盗走594枚BTC,攻击效率与危害程度创下近年硬件钱包盗币事件新高。更值得警惕的是,受影响设备覆盖多款Coldcard主流型号,大量2021年后使用对应固件版本的用户,均处于风险暴露状态。

此次事件暴露了行业长期存在的隐蔽隐患:硬件钱包并非无懈可击,厂商底层代码审计、固件迭代风控、长期安全巡检存在严重短板。多数普通投资者陷入认知误区,认为冷钱包离线存储就可以高枕无忧,忽略了固件漏洞、代码缺陷、算法漏洞等底层安全风险,相比于交易所盗币、线上钱包泄露,硬件固件漏洞具备隐蔽性强、潜伏期久、批量破防、无法溯源预警的特点,普通用户几乎无法自行排查风险。

随着事件持续发酵,全网恐慌情绪快速蔓延,行业安全认知迎来全面重构。社区内掀起大规模资产迁移热潮,大量Coldcard用户紧急转移钱包内资产,同时行业彻底改写资产存储逻辑,单一硬件钱包托管的模式被彻底质疑。币安创始人CZ等行业头部人物纷纷发声,呼吁用户践行钱包多样化配置,分散资产存储风险。

与此同时,市场资金流向也发生明显结构性变化,大量忌惮自托管风险的资金,开始从个人硬件钱包转向合规机构托管、现货ETF等规范化渠道,行业对于“资产安全”的定义,从单纯的“离线避险”,升级为“合规托管+多元分散+持续风控”的全新体系。在此提醒所有用户:单纯升级固件无法修复历史生成的高危助记词风险,持有Coldcard设备的投资者需尽快对照官方风险清单排查,及时迁移资产、规避被盗风险。

_注:文中素材来源于网络公开资料,如有侵权请联系删除,以上内容仅代表作者个人观点。_

!Image 6: 图片

来源于网络

编 | Black 审 | 林蛋壳

!Image 7: 图片 声明:投资有风险,入市须谨慎。本资讯不作为投资理财建议。

!Image 8: 图片 阅读原文

Key Quotes

> Hardware wallets are not invincible - vendors' underlying code audits, firmware iteration controls, and long-term security monitoring have serious shortcomings.

> Simply updating firmware cannot eliminate risks from historically generated high-risk mnemonics - investors using Coldcard devices must immediately check for vulnerabilities.

Tags

Blockchain Security

Hardware Wallets

Bitcoin Theft

Security Vulnerability

Cryptocurrency Assets

Make your daily reading actually fit you.A daily brief built from the sources you follow. Get started free HomeDiscoverSettings

查看原文 → 發佈: 2026-08-03 10:25:00 收錄: 2026-08-03 20:00:08

🤖 問 AI

針對這篇文章提問,AI 會根據文章內容回答。按 Ctrl+Enter 送出。