Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users
An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on Thursday, in a theft traced to a flaw in how Coldcard, an air-gapped hardware wallet built...
Watchlist
Published in the last two hours. A tracked entity is involved.
An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on Thursday, in a theft traced to a flaw in how Coldcard, an air-gapped hardware wallet built by Toronto-based Coinkite, generated their key. About 562 BTC has been consolidated in a single address.
A wallet’s seed is supposed to be random and practically impossible to guess. But a build setting saw Coinkite’s devices build keys from a known unique identifier timer state and call history instead of a random number generator, according to a Thursday report from Block’s bitcoin engineering and security teams. The same fault also produced Coldcard’s paper wallet private keys, seed-splitting masks and device cloning keys.
Block said Exposure depends on the firmware a device was running when the wallet was created, not on when the hardware was bought, and a later upgrade does not repair a seed that was already generated. Anyone who exported an affected seed into a different wallet is still holding a weak one, the team warned.
The issue impacted Coldcard Mk3 models using v4.0.0, released in 2021, and later as well as models Mk4, Q and Mk5, according to Block. Coinkite in its advisory said “the impact on Mk4, Mk5 and Q is not as severe but is still serious.”
Coinkite told affected users that a BIP-39 passphrase leaves funds at minimal risk and recommended migrating to a seed generated on an unaffected device.
Every drained wallet was single-signature and held more than 0.15 BTC, and many had sat dormant for years, with the coins spanning 2021 to 2026, a range that tracks the bug’s age almost exactly.
The disclosure comes days after Zilliqa halted native transactions over a flaw in the Ledger signing app it created that let attackers rebuild private keys from data already public on-chain, another weakness that had gone unnoticed since 2019.
Related Listen: Why Authorities Can’t Freeze Crypto Fast Enough: DEX in the City
{"@context":"http:\/\/schema.org\/","@id":"https:\/\/unchainedcrypto.com\/coldcard-firmware-flaw-lets-attacker-drain-594-bitcoin-from-users\/#arve-youtube-qu4alw3wh4w","@type":"VideoObject","embedURL":"https:\/\/www.youtube-nocookie.com\/embed\/qu4AlW3WH4w?feature=oembed&iv_load_policy=3&modestbranding=1&rel=0&autohide=1&playsinline=1&autoplay=0"}
The post Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users appeared first on Unchained.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on UnchainedRelated market context
Coinkite warns Coldcard Mk3 users of firmware flaw that may have compromised wallet seeds
The firmware flaw highlights the critical importance of robust RNGs in hardware wallets, emphasizing the need for vigilant securit...
‘Funds may be at risk’: Coinkite issues warning for Coldcard Mk3 users amid 594 BTC theft reports
Coinkite recommends that Mk3 users create a strong, unique BIP-39 passphrase on the device and move funds to the resulting wallet.
Coinkite Warns Coldcard Mk3 Owners After Reports of $38M Bitcoin Loss
Coinkite issued a security advisory Thursday warning owners of its Coldcard Mk3 hardware wallet that funds tied to certain firmwar...
Coldcard issues Mk3 warning as experts examine $38M Bitcoin wallet drain
Coinkite urged Coldcard Mk3 users to migrate funds after identifying a potential seed-generation risk, as Bitcoin security experts...
Crypto News, July 31: July Round Up, Kospi Coming Back, Bitcoin Price Ignores Political Noise as Market Splits
The Kospi ended July with a powerful rebound, while the Bitcoin price stayed remarkably steady despite several major headlines. We...
Security Firm Blockaid Says 212 Onchain Exploits Stole $1.1B as AI and Wallet Attacks Accelerate
The first half of 2026 was the most active period for onchain security threats on record, with Blockaid verifying 212 high-thresho...