Mk4, Q, and Mk5 seem to be OK according to this tweet
This disagrees with my analysis. I believe the attack is ~32-bits harder on Mk4+ but they're still vulnerable.
I agree. Absolutely.
It's very likely the hackers spent months pulling off this attack. Maybe even longer. I can't even imagine how many billions of seed phrases they searched, but it isn't nearly as hard as people think to do so if - and this is the point - if an exploit limits the number of wallets to search, which is surely the case in this instance.
They probably searched for months and built up a pool of wallets to hit. Then, they wiped them all out at once in order to prevent anyone from figuring out where the vulnerability was until it's too late.
I have to assume this isn't the last attack like this we'll see.
Four things I assume. Two good, two bad:
1. I assume wallets that use a passphrase are safe from these attacks because seed-phrase-hunters have no way of knowing a seed phrase generating an empty wallet has coins in a wallet using that seed with a passphrase.
2. I assume multisig wallets are safe for the same reason. Seed-phrase-hunters have no way of knowing a seed phrase generating an empty wallet has coins in a wallet generated using multiple seeds.
3. I assume it's only a matter of time before Ledger's key extraction scheme gets hacked, presumably at the firmware level. That'll be a much more difficult hack to pull off, but it'll be much worse than this ColdCard hack because Ledger is a huge honeypot.
4. I assume it's only a matter of time before exploits are found for smaller commercial wallets, leading to similar thefts.
Now, more than ever, I think it's time for people to start thinking about how to do self custody right. Generate your own random seed phrases. It's not hard, but do it right. Use a passphrase or do multisig. Learn how to document your wallet setup and store that documentation securely.
Too many people in Bitcoin are chasing brand-name cool-factor. "Yo, bro! You seen the new [insert brand-name hardware wallet here]? They're the sh!t bro!" Those people are idiots who should be buying an ETF instead because they're not ready to take self custody seriously.
I hate saying it like that... but even on a forum like this, it's shocking how many people don't take self custody seriously. They get caught up in fanboyism for brands and gadgets. And they set themselves up for disaster.