DigitalMoneyBox Signal Desk
DigitalMoneyBox Crypto market intelligence
Browse sections
Bitcoin Unchained

Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users

An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on Thursday, in a theft traced to a flaw in how Coldcard, an air-gapped hardware wallet built...

72 /100
Market signal

Watchlist

Published in the last two hours. A tracked entity is involved.

Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users

An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on Thursday, in a theft traced to a flaw in how Coldcard, an air-gapped hardware wallet built by Toronto-based Coinkite, generated their key. About 562 BTC has been consolidated in a single address.

A wallet’s seed is supposed to be random and practically impossible to guess. But a build setting saw Coinkite’s devices build keys from a known unique identifier timer state and call history instead of a random number generator, according to a Thursday report from Block’s bitcoin engineering and security teams. The same fault also produced Coldcard’s paper wallet private keys, seed-splitting masks and device cloning keys.

Block said Exposure depends on the firmware a device was running when the wallet was created, not on when the hardware was bought, and a later upgrade does not repair a seed that was already generated. Anyone who exported an affected seed into a different wallet is still holding a weak one, the team warned.

The issue impacted Coldcard Mk3 models using v4.0.0, released in 2021, and later as well as models Mk4, Q and Mk5, according to Block. Coinkite in its advisory said “the impact on Mk4, Mk5 and Q is not as severe but is still serious.”

Coinkite told affected users that a BIP-39 passphrase leaves funds at minimal risk and recommended migrating to a seed generated on an unaffected device.

Every drained wallet was single-signature and held more than 0.15 BTC, and many had sat dormant for years, with the coins spanning 2021 to 2026, a range that tracks the bug’s age almost exactly.

The disclosure comes days after Zilliqa halted native transactions over a flaw in the Ledger signing app it created that let attackers rebuild private keys from data already public on-chain, another weakness that had gone unnoticed since 2019.

Related Listen: Why Authorities Can’t Freeze Crypto Fast Enough: DEX in the City

{"@context":"http:\/\/schema.org\/","@id":"https:\/\/unchainedcrypto.com\/coldcard-firmware-flaw-lets-attacker-drain-594-bitcoin-from-users\/#arve-youtube-qu4alw3wh4w","@type":"VideoObject","embedURL":"https:\/\/www.youtube-nocookie.com\/embed\/qu4AlW3WH4w?feature=oembed&iv_load_policy=3&modestbranding=1&rel=0&autohide=1&playsinline=1&autoplay=0"}

The post Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users appeared first on Unchained.

Why this matters

Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.

Original source

Read on Unchained

Related market context