Some Multisignature Wallets May Be At Risk

Neo ⚡️

npub1lyqkzmcq5cl5l8rcs82gwxsrmu75emnjj84067kuhm48e9w93cns2hhj2g

hex

da3ae7fb34b90d9d992689587d2bf446b37c4c590a7acf9d188f286480525a7e

nevent

nevent1qqsd5wh8lv6tjrvanyngjkra906ydvmuf3vs57k0n5vg72ryspf95lsprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgs0jqtpduq2v060n3ugr4y8rgpa702vaeefr6ha0twta6nujhzcufcp5t9rs

Kind-1 (TextNote)

2026-08-01T10:47:29Z

Some Multisignature Wallets May Be At Risk

Peter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds. “Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds.”

The transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee. Fortunately, such cases have a solution: the MARA mining pool can help in this case with their private mempool mining service, Slipstream; “because they promise to keep your transaction – and thus pubkeys – secret until they’re already in a block. Dramatically reducing the ability of the attacker to steal the funds,” said Todd. He added that “If you’ve already reused addresses, this isn’t relevant, and you should just try to move your funds ASAP. But if you haven’t, MARA may be able to help.”

https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack

原始 JSON

{
  "kind": 1,
  "id": "da3ae7fb34b90d9d992689587d2bf446b37c4c590a7acf9d188f286480525a7e",
  "pubkey": "f901616f00a63f4f9c7881d4871a03df3d4cee7291eafd7adcbeea7c95c58e27",
  "created_at": 1785581249,
  "tags": [
    [
      "client",
      "Primal iOS"
    ]
  ],
  "content": "Some Multisignature Wallets May Be At Risk\n\nPeter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds. “Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds.”\n\nThe transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee. Fortunately, such cases have a solution: the MARA mining pool can help in this case with their private mempool mining service, Slipstream; “because they promise to keep your transaction – and thus pubkeys – secret until they’re already in a block. Dramatically reducing the ability of the attacker to steal the funds,” said Todd. He added that “If you’ve already reused addresses, this isn’t relevant, and you should just try to move your funds ASAP. But if you haven’t, MARA may be able to help.”\n\nhttps://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack",
  "sig": "c93720c593d2ff18447e15d6af69edb7609bb4da246d29a529b7f206ac2c6b1c2429053435820227f62145bd1f6bc15a9a444ca9c86f97ac63f614b17a74a824"
}