Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
A firmware flaw in the Coldcard Bitcoin‑only hardware wallet enabled a 41‑minute sweep that drained over 1,000 BTC, worth roughly $70 million at the time.
A firmware flaw in the Coldcard Bitcoin‑only hardware wallet enabled a 41‑minute sweep that drained over 1,000 BTC, worth roughly $70 million at the time.
On July 30, an attacker executed a rapid sweep that drained 1,196 Bitcoin addresses in just 41 minutes, extracting 1,082.65 BTC—worth about $70.2 million at the time.
The sweep was traced by Galaxy Research, which mapped the movement of coins from the compromised wallets to a series of addresses controlled by the attacker.
The investigation pointed to a firmware flaw in Coldcard, the Bitcoin‑only hardware wallet produced by Canadian firm Coinkite.
The flaw originates from a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the secure hardware‑based random source.
As a result, the device could generate predictable seeds, allowing an attacker to reconstruct the private keys for the affected wallets.
Coldcard’s design includes a PIN protection and a recovery phrase, but the PRNG issue bypassed those safeguards by enabling the attacker to predict the seed before the PIN was entered.
Coinkite has issued an advisory urging users to update to the latest firmware version, which replaces the faulty PRNG with a true random source.
The company also recommends that users verify the firmware checksum and, if possible, generate a new seed on a trusted device.
Industry observers note that the incident underscores the importance of rigorous firmware testing, especially for devices that handle large amounts of cryptocurrency.
While the Coldcard community has expressed concern, the manufacturer remains committed to security and is working on additional patches to prevent similar vulnerabilities.
On July 30, an attacker executed a rapid sweep that drained 1,196 Bitcoin addresses in just 41 minutes, extracting 1,082.65 BTC—worth about $70.2 million at the time.
The sweep was traced by Galaxy Research, which mapped the movement of coins from the compromised wallets to a series of addresses controlled by the attacker.
The investigation pointed to a firmware flaw in Coldcard, the Bitcoin‑only hardware wallet produced by Canadian firm Coinkite.
The flaw originates from a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the secure hardware‑based random source.
As a result, the device could generate predictable seeds, allowing an attacker to reconstruct the private keys for the affected wallets.
Coldcard’s design includes a PIN protection and a recovery phrase, but the PRNG issue bypassed those safeguards by enabling the attacker to predict the seed before the PIN was entered.
Coinkite has issued an advisory urging users to update to the latest firmware version, which replaces the faulty PRNG with a true random source.
The company also recommends that users verify the firmware checksum and, if possible, generate a new seed on a trusted device.
Industry observers note that the incident underscores the importance of rigorous firmware testing, especially for devices that handle large amounts of cryptocurrency.
While the Coldcard community has expressed concern, the manufacturer remains committed to security and is working on additional patches to prevent similar vulnerabilities.