• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 19, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

‘Bypass’ Attack in Coldcard Bitcoin Wallet Could Trick Users Into Sending Incorrect Funds

25 November 2020
in Blockchain
Reading Time: 2 mins read
A A
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT


Cryptohopper
ADVERTISEMENT

The bitcoin-only hardware wallet Coldcard has released a beta firmware patch for a vulnerability that also affected a competitor hardware wallet earlier this year.

Ben Ma, a security researcher who works for hardware wallet manufacturer Shift Crypto, discovered that the Coldcard hardware wallet has a flaw: An attacker could trick a Coldcard user into sending a real bitcoin transaction when they think they are sending a “testnet” transaction – or a payment on Bitcoin’s testing network, which is not the same as the mainnet.

Both testnet and mainnet bitcoin transactions, though, “have the exact same transaction representation under the hood,” Ma writes in his post disclosing the vulnerability. An attacker, then, could generate a bitcoin mainnet transaction for the hardware wallet but make it look like a testnet transaction. The mainnet transaction is presented like a testnet transaction on the user’s wallet, making it difficult for users to recognize the error.

Ma learned of the vulnerability after a pseudonymous researcher discovered the so-called “isolation bypass” attack in the French-manufactured Ledger hardware wallet. 

Unlike Coldcard, Ledger supports many coins, so the bypass attack could work by tricking wallet users into sending bitcoin when they mean to send litecoin and bitcoin cash, in addition to testnet BTC.

When the initial vulnerability in the Ledger wallet was disclosed, Coinkite founder and Coldcard creator Rodolfo Novak said, “Coldcard doesn’t support any shitcoins, we find that to be the best path,” implying that his bitcoin-only wallet would be safe since the flaw (in part) resulted from the fact that Ledger devices previously managed different coins using the same private key. 

Since Coldcard doesn’t support multiple coins, it theoretically shouldn’t have this problem. And it wouldn’t, if it weren’t for the fact that it can be exploited with bitcoin testnet addresses, as well.

If a user’s computer is compromised – and their Coldcard device is unlocked and connected to that computer – then an adversary could trick them into sending real bitcoin when they think they are sending testnet bitcoin.

“The attacker merely has to convince the user to e.g. ‘try a testnet transaction’ or to buy an ICO with testnet coins (I’ve heard there was a ICO like this recently) or any number of social engineering attacks to make the user perform a testnet transaction. After the user confirms a testnet transaction, the attacker receives mainnet bitcoin in the same amount,” Ma writes in the post. 

Seeing as an attacker could execute this attack remotely, it met Shift Crypto’s criteria as a critical issue, triggering the responsible disclosure process. 

According to the post, Ma disclosed the vulnerability to Coinkite on Aug. 4 and Novak acknowledged it the next day. On Nov. 23, Coldcard released a beta firmware to patch the vulnerability.



Source link

Related articles

Blockchain Enters The City: London Stock Exchange Launches Private Funds Platform

Blockchain Enters The City: London Stock Exchange Launches Private Funds Platform

16 September 2025
Blockchain Powers Jack Ma’s -B Ant Group Energy Asset Strategy

Blockchain Powers Jack Ma’s $8-B Ant Group Energy Asset Strategy

9 September 2025
[crypto-donation-box]
Tags: AttackBitcoinBypassColdcardFundsIncorrectSendingTrickUsersWallet
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

XRP and Stellar Altcoins Surge to All-Time High

Next Post

Price analysis 11/25: BTC, ETH, XRP, LINK, BCH, LTC, BNB, DOT, ADA, BSV

Related Posts

Blockchain Enters The City: London Stock Exchange Launches Private Funds Platform

Blockchain Enters The City: London Stock Exchange Launches Private Funds Platform

16 September 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure London Stock Exchange Group (LSEG) has launched...

Blockchain Powers Jack Ma’s -B Ant Group Energy Asset Strategy

Blockchain Powers Jack Ma’s $8-B Ant Group Energy Asset Strategy

9 September 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure According to Bloomberg, Ant Digital Technologies has...

Japan Post Bank To Give Digital Yen Access To .3T Deposits

Japan Post Bank To Give Digital Yen Access To $1.3T Deposits

3 September 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Japan Post Bank is moving toward a...

The Blockchain Group Pushes Institutional Crypto Wave in Europe

The Blockchain Group Pushes Institutional Crypto Wave in Europe

10 June 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure A Bitcoin-focused company based in Paris wants...

Ripple And Japan’s Web3 Salon Spark Asia Innovation

Ripple And Japan’s Web3 Salon Spark Asia Innovation

10 June 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ripple has teamed up with Japan’s Web3...

Load More
Next Post

Price analysis 11/25: BTC, ETH, XRP, LINK, BCH, LTC, BNB, DOT, ADA, BSV

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
New solana treasury entrant, Solmate, soars on rebrand – Sherwood News

New solana treasury entrant, Solmate, soars on rebrand – Sherwood News

19 September 2025
IMX Price Eyes 300% Breakout Rally as Immutable Aims Mobile Gaming

IMX Price Eyes 300% Breakout Rally as Immutable Aims Mobile Gaming

19 September 2025
BlockchainFX Presale Takes Center Stage Today

BlockchainFX Presale Takes Center Stage Today

19 September 2025
BNB Price Prediction: ,200 Forecast As DigiTap’s Live App Lifts Presale Beyond 0K – BlockchainReporter

BNB Price Prediction: $1,200 Forecast As DigiTap’s Live App Lifts Presale Beyond $100K – BlockchainReporter

19 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • New solana treasury entrant, Solmate, soars on rebrand – Sherwood News
  • IMX Price Eyes 300% Breakout Rally as Immutable Aims Mobile Gaming
  • BlockchainFX Presale Takes Center Stage Today
  • BNB Price Prediction: $1,200 Forecast As DigiTap’s Live App Lifts Presale Beyond $100K – BlockchainReporter
  • Crypto News Shows XRP and Solana Price Gains Fail to Scare Off Meme Coin Investors – Crypto Economy

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,985.00
  • ethereumEthereum (ETH) $ 4,483.91
  • xrpXRP (XRP) $ 3.01
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 984.42
  • solanaSolana (SOL) $ 238.63
  • usd-coinUSDC (USDC) $ 0.999708
  • dogecoinDogecoin (DOGE) $ 0.267684
  • staked-etherLido Staked Ether (STETH) $ 4,480.62
  • cardanoCardano (ADA) $ 0.901574
  • tronTRON (TRX) $ 0.345501
  • wrapped-stethWrapped stETH (WSTETH) $ 5,439.19
  • chainlinkChainlink (LINK) $ 23.68
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,836.07
  • hyperliquidHyperliquid (HYPE) $ 56.19
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,961.00
  • avalanche-2Avalanche (AVAX) $ 34.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.67
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.389542
  • bitcoin-cashBitcoin Cash (BCH) $ 604.68
  • wrapped-eethWrapped eETH (WEETH) $ 4,817.06
  • wethWETH (WETH) $ 4,484.51
  • hedera-hashgraphHedera (HBAR) $ 0.239201
  • litecoinLitecoin (LTC) $ 115.66
  • leo-tokenLEO Token (LEO) $ 9.53
  • crypto-com-chainCronos (CRO) $ 0.231320
  • usdsUSDS (USDS) $ 0.999195
  • the-open-networkToncoin (TON) $ 3.12
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 116,028.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • polkadotPolkadot (DOT) $ 4.44
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.229943
  • whitebitWhiteBIT Coin (WBT) $ 43.38
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • uniswapUniswap (UNI) $ 9.21
  • moneroMonero (XMR) $ 296.25
  • mantleMantle (MNT) $ 1.67
  • ethenaEthena (ENA) $ 0.675575
  • daiDai (DAI) $ 0.999675
  • aaveAave (AAVE) $ 302.28
  • pepePepe (PEPE) $ 0.000011
  • okbOKB (OKB) $ 192.19
  • memecoreMemeCore (M) $ 2.38
  • nearNEAR Protocol (NEAR) $ 3.14
  • bitget-tokenBitget Token (BGB) $ 5.15
  • jito-staked-solJito Staked SOL (JITOSOL) $ 293.94
  • bittensorBittensor (TAO) $ 350.19