Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
Bitcoin Magazine Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is at risk following a $70 million hack. Coinkite on T...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Bitcoin Magazine
Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is at risk following a $70 million hack.
Coinkite on Thursday admitted that its Coldcard Mk3 model was affected following the hack and advised users to move their funds. Then, on Friday, the company said that users of the later hardware devices Mk4, Mk5, and Q should also take precautions.
Hackers on Thursday were first able to drain funds from 1,196 Bitcoin addresses because their private keys were not generated using sufficient entropy — or randomness.
Since then, a total of 1,082.65 Bitcoins have disappeared from wallets, according to data from Galaxy Research and engineers at payments company Block.
While Coinkite has not admitted that the hack is linked to their wallets, the company has said that a wallet seed generation bug in Coldcard products meant the hardware’s true random number generator wasn’t actually being used on certain firmware versions.
Coinkite and other engineers in the Bitcoin space are still investigating reportedly ongoing drains still happening at the time of writing.
What actually happenedA firmware bug in Coldcard Mk3 devices (starting with version 4.0.1 in March 2021) caused seed generation to fall back to a weak software PRNG instead of the hardware true random number generator, producing seeds with only ~40 bits of entropy rather than the intended 128. This made private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force.
A total of 594.5 Bitcoins worth over $35.7 million at today’s prices were moved to a new address from single-signature addresses on Thursday.
NEW: Over 594 BTC worth $38 million was stolen from Bitcoin hardware wallet Coldcard users.
The attacker then moved around the BTC and consolidated 562 BTC into this address below.
Users are urged to review the company's official security guidance as soon as possible. pic.twitter.com/exD2Wax7CY
More wallets were later drained, according to blockchain analysts, with the total now over $70 million.
Various affected users shared their experiences on social media, with one saying that their Bitcoin had not been moved since 2021, and all of a sudden was swiped.
Bitcoin engineers have since said that Coldcard products — specifically the Mk3 models — had “faulty entropy in wallet generation,” meaning they did not use real randomness to create a seedphrase.
What to doDevelopers in the Bitcoin space have since urged users to move their funds if they used a Coldcard. Coldcard has issued guidance for users to take, which can be found here.
The first post was the advisory and what users should do.
This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed.https://t.co/HshUxevCl3
( current evaluating Mk3 firmware release ) https://t.co/Yfdx4XcztA
Coinkite first said that their Mk3 models were affected but then on Friday said that those who did not use sufficient entropy to create a seed — in this case, 50 dice rolls — should generate a brand-new seed on the updated device. Others have warned to ditch Coldcard completely to be sure their funds are safe.
“Everything is fucked,” wrote Kevin Loaec, CEO of Bitcoin security company, Wizardsardine.
“Every single mnemonic generated [via a Coldcard] since 2021 will be public in the next few days,” Loaec warns.
This post Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on Bitcoin MagazineRelated market context
Your crypto hardware wallet can stay secure while everything around it fails
Two wallet incidents this week exposed a growing weakness in crypto self-custody: the systems surrounding hardware devices. D’CENT...
18 Polymarket Users Face Korean Prosecutors After Police Traced Their Wallets
South Korean police have referred 18 Polymarket users to prosecutors on suspicion of illegal gambling, in an investigation that be...
Wall Street gains direct oversight of Web3 security as S&P Global buys OpenZeppelin
S&P Global has agreed to acquire smart contract security company OpenZeppelin in a transaction that would put the crypto company i...
Wallets Can Offer Regulated Perps Without a Broker License, CFTC Staff Says
Software developers can build regulated derivatives trading into self-custodial crypto wallets without registering as brokers, CFT...
Robinhood warns users it doesn’t endorse tokens, and $WALLET crashes 90%
Robinhood's disclaimer highlights the risks of speculative trading on its chain, emphasizing user responsibility and potential mar...
Fake AI crypto software is secretly replacing browser wallet extensions
HP Wolf Security, the company's threat-research team, said a fake AI crypto-trading assistant distributed malware that could repla...