Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
Bitcoin Magazine Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is at risk following a $70 million hack. Coinkite on T...
Watchlist
Published in the last two hours. A tracked entity is involved.
Bitcoin Magazine
Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is at risk following a $70 million hack.
Coinkite on Thursday admitted that its Coldcard Mk3 model was affected following the hack and advised users to move their funds. Then, on Friday, the company said that users of the later hardware devices Mk4, Mk5, and Q should also take precautions.
Hackers on Thursday were first able to drain funds from 1,196 Bitcoin addresses because their private keys were not generated using sufficient entropy — or randomness.
Since then, a total of 1,082.65 Bitcoins have disappeared from wallets, according to data from Galaxy Research and engineers at payments company Block.
While Coinkite has not admitted that the hack is linked to their wallets, the company has said that a wallet seed generation bug in Coldcard products meant the hardware’s true random number generator wasn’t actually being used on certain firmware versions.
Coinkite and other engineers in the Bitcoin space are still investigating reportedly ongoing drains still happening at the time of writing.
What actually happenedA firmware bug in Coldcard Mk3 devices (starting with version 4.0.1 in March 2021) caused seed generation to fall back to a weak software PRNG instead of the hardware true random number generator, producing seeds with only ~40 bits of entropy rather than the intended 128. This made private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force.
A total of 594.5 Bitcoins worth over $35.7 million at today’s prices were moved to a new address from single-signature addresses on Thursday.
NEW: Over 594 BTC worth $38 million was stolen from Bitcoin hardware wallet Coldcard users.
The attacker then moved around the BTC and consolidated 562 BTC into this address below.
Users are urged to review the company's official security guidance as soon as possible. pic.twitter.com/exD2Wax7CY
More wallets were later drained, according to blockchain analysts, with the total now over $70 million.
Various affected users shared their experiences on social media, with one saying that their Bitcoin had not been moved since 2021, and all of a sudden was swiped.
Bitcoin engineers have since said that Coldcard products — specifically the Mk3 models — had “faulty entropy in wallet generation,” meaning they did not use real randomness to create a seedphrase.
What to doDevelopers in the Bitcoin space have since urged users to move their funds if they used a Coldcard. Coldcard has issued guidance for users to take, which can be found here.
The first post was the advisory and what users should do.
This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed.https://t.co/HshUxevCl3
( current evaluating Mk3 firmware release ) https://t.co/Yfdx4XcztA
Coinkite first said that their Mk3 models were affected but then on Friday said that those who did not use sufficient entropy to create a seed — in this case, 50 dice rolls — should generate a brand-new seed on the updated device. Others have warned to ditch Coldcard completely to be sure their funds are safe.
“Everything is fucked,” wrote Kevin Loaec, CEO of Bitcoin security company, Wizardsardine.
“Every single mnemonic generated [via a Coldcard] since 2021 will be public in the next few days,” Loaec warns.
This post Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on Bitcoin MagazineRelated market context
Coinkite warns Coldcard Mk3 users of firmware flaw that may have compromised wallet seeds
The firmware flaw highlights the critical importance of robust RNGs in hardware wallets, emphasizing the need for vigilant securit...
Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus
A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affe...
Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone
Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed ph...
Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users
An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on...
Coinkite Warns Coldcard Mk3 Owners After Reports of $38M Bitcoin Loss
Coinkite issued a security advisory Thursday warning owners of its Coldcard Mk3 hardware wallet that funds tied to certain firmwar...
‘Funds may be at risk’: Coinkite issues warning for Coldcard Mk3 users amid 594 BTC theft reports
Coinkite recommends that Mk3 users create a strong, unique BIP-39 passphrase on the device and move funds to the resulting wallet.