Joining us now via Zoom, Jeff Borst, the CPO at Blockstream, all to talk about a story we have been bringing our viewers the latest on the last week.
Jeff, the cold card hack.
What a story.
More than 1800 Bitcoins stolen.
The wallets keep Bitcoin offline.
How did the hackers still manage to steal what they stole?
Uh, thanks for having me, JD.
I appreciate it.
Um, you're right, it's been a, it's been a somber week in the, in the Bitcoin community.
Um, you know, basically, uh, a vulnerability in how some of the cryptographic material that gets calculated on behalf of a user to secure their keys was compromised, and it was compromised in a way that allowed remote attackers to unlock Bitcoin on the chain and, and basically, uh, take money from.
Users who were just trying to, to use Bitcoin uh with enthusiasm.
So it was a, it was a very sad day for the industry.
Jeff, was Bitcoin itself hacked or was the wallet the problem?
Oh, Bitcoin itself is, uh, is safe and secure and, uh, and, uh, no, no funds are at risk.
The, the vulnerability here was in a particular element of the, the hardware wallet that was being used by many users.
Uh, and I will say that, you know, after a moment like this, it's inspiring to see.
The way the Bitcoin community responds, um, you know, essentially, uh, all across the community, developers have been rallying to review and look for additional vulnerabilities in open source code.
And so now, despite the, the sadness of that incident, you know, we feel that the, the technical fundamental, fundamentals of Bitcoin are stronger than they've ever been.
The issue involved what are known as secret recovery phrases.
What is that and what exactly went wrong?
Uh, a recovery phrase is just a, a device that lets somebody reinput the random number that is at the sort of heart of the, the private key that lets you lock your Bitcoin on the chain.
So, um, the recovery phase itself was essentially guessable because the randomness.
That was supposed to be provided by the underlying product was not random enough, and that was due to essentially an oversight in the configuration.
As I understand it, the hardware had the capability to generate strong, secure random numbers, but unfortunately, it was not utilized correctly, and that created an opportunity for people to guess the keys of users on chain.
If you own a cold card wallet, how do you know if you're actually at risk?
Um, If you own a cold card wallet, the recommendations across the industry are it's time to move your funds to a safe and secure device.
So I think the safest thing to do is assume that you're at risk and to identify a product that you trust to move your funds into.
We're always happy to offer solutions at Blockstream such as the Blockstream Jade or the Blockstream app, but there are many reputable providers on the market, and I would recommend moving your funds in an abundance of safety.
All right, we're going to leave things there.
Jeff Borst, please come back and see us here in person at the New York Stock Exchange next time.
Great to get your take on a really important story we'll continue to follow.
Jeff Borst, CPO of Blackstream.
Jeff, thank you.