Some Multisignature Wallets May Be At Risk

npub1lyqkzmcq5cl5l8rcs82gwxsrmu75emnjj84067kuhm48e9w93cns2hhj2g
hex
da3ae7fb34b90d9d992689587d2bf446b37c4c590a7acf9d188f286480525a7enevent
nevent1qqsd5wh8lv6tjrvanyngjkra906ydvmuf3vs57k0n5vg72ryspf95lsprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgs0jqtpduq2v060n3ugr4y8rgpa702vaeefr6ha0twta6nujhzcufcp5t9rsKind-1 (TextNote)
Some Multisignature Wallets May Be At Risk
Peter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds. “Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds.”
The transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee. Fortunately, such cases have a solution: the MARA mining pool can help in this case with their private mempool mining service, Slipstream; “because they promise to keep your transaction – and thus pubkeys – secret until they’re already in a block. Dramatically reducing the ability of the attacker to steal the funds,” said Todd. He added that “If you’ve already reused addresses, this isn’t relevant, and you should just try to move your funds ASAP. But if you haven’t, MARA may be able to help.”
https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack
Raw JSON
{
"kind": 1,
"id": "da3ae7fb34b90d9d992689587d2bf446b37c4c590a7acf9d188f286480525a7e",
"pubkey": "f901616f00a63f4f9c7881d4871a03df3d4cee7291eafd7adcbeea7c95c58e27",
"created_at": 1785581249,
"tags": [
[
"client",
"Primal iOS"
]
],
"content": "Some Multisignature Wallets May Be At Risk\n\nPeter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds. “Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds.”\n\nThe transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee. Fortunately, such cases have a solution: the MARA mining pool can help in this case with their private mempool mining service, Slipstream; “because they promise to keep your transaction – and thus pubkeys – secret until they’re already in a block. Dramatically reducing the ability of the attacker to steal the funds,” said Todd. He added that “If you’ve already reused addresses, this isn’t relevant, and you should just try to move your funds ASAP. But if you haven’t, MARA may be able to help.”\n\nhttps://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack",
"sig": "c93720c593d2ff18447e15d6af69edb7609bb4da246d29a529b7f206ac2c6b1c2429053435820227f62145bd1f6bc15a9a444ca9c86f97ac63f614b17a74a824"
}