Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users
An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on Thursday, in a theft traced to a flaw in how Coldcard, an air-gapped hardware wallet built...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on Thursday, in a theft traced to a flaw in how Coldcard, an air-gapped hardware wallet built by Toronto-based Coinkite, generated their key. About 562 BTC has been consolidated in a single address.
A wallet’s seed is supposed to be random and practically impossible to guess. But a build setting saw Coinkite’s devices build keys from a known unique identifier timer state and call history instead of a random number generator, according to a Thursday report from Block’s bitcoin engineering and security teams. The same fault also produced Coldcard’s paper wallet private keys, seed-splitting masks and device cloning keys.
Block said Exposure depends on the firmware a device was running when the wallet was created, not on when the hardware was bought, and a later upgrade does not repair a seed that was already generated. Anyone who exported an affected seed into a different wallet is still holding a weak one, the team warned.
The issue impacted Coldcard Mk3 models using v4.0.0, released in 2021, and later as well as models Mk4, Q and Mk5, according to Block. Coinkite in its advisory said “the impact on Mk4, Mk5 and Q is not as severe but is still serious.”
Coinkite told affected users that a BIP-39 passphrase leaves funds at minimal risk and recommended migrating to a seed generated on an unaffected device.
Every drained wallet was single-signature and held more than 0.15 BTC, and many had sat dormant for years, with the coins spanning 2021 to 2026, a range that tracks the bug’s age almost exactly.
The disclosure comes days after Zilliqa halted native transactions over a flaw in the Ledger signing app it created that let attackers rebuild private keys from data already public on-chain, another weakness that had gone unnoticed since 2019.
Related Listen: Why Authorities Can’t Freeze Crypto Fast Enough: DEX in the City
{"@context":"http:\/\/schema.org\/","@id":"https:\/\/unchainedcrypto.com\/coldcard-firmware-flaw-lets-attacker-drain-594-bitcoin-from-users\/#arve-youtube-qu4alw3wh4w","@type":"VideoObject","embedURL":"https:\/\/www.youtube-nocookie.com\/embed\/qu4AlW3WH4w?feature=oembed&iv_load_policy=3&modestbranding=1&rel=0&autohide=1&playsinline=1&autoplay=0"}
The post Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users appeared first on Unchained.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on UnchainedRelated market context
Your crypto hardware wallet can stay secure while everything around it fails
Two wallet incidents this week exposed a growing weakness in crypto self-custody: the systems surrounding hardware devices. D’CENT...
3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt
A routine Radix code refactor created a vault flaw that enabled a roughly $1.3 million theft and later forced validators to halt t...
WaterPlum infects 30,000 devices, steals data from 7,000 crypto wallets
The WaterPlum incident underscores the growing sophistication of state-sponsored cyber threats, highlighting vulnerabilities in gl...
18 Polymarket Users Face Korean Prosecutors After Police Traced Their Wallets
South Korean police have referred 18 Polymarket users to prosecutors on suspicion of illegal gambling, in an investigation that be...
Robinhood warns users it doesn’t endorse tokens, and $WALLET crashes 90%
Robinhood's disclaimer highlights the risks of speculative trading on its chain, emphasizing user responsibility and potential mar...
Fake AI crypto software is secretly replacing browser wallet extensions
HP Wolf Security, the company's threat-research team, said a fake AI crypto-trading assistant distributed malware that could repla...