Coldcard firmware flaw leads to massive Bitcoin seed thefts
A significant security vulnerability in Coldcard hardware wallet firmware has led to the theft of approximately 1,596 to 2,055 BTC, with total losses estimated between $70 million and $130 million. The breach stems from a March 2021 firmware error that caused the device to substitute a predictable software pseudo-random number generator for the hardware's true random number generator during seed creation. This resulted in seeds with as few as 40 bits of effective entropy, allowing attackers to reconstruct seeds without physical access to the devices.
Coinkite, the manufacturer, has released emergency firmware updates and advised users to migrate to new wallets. The vulnerability specifically impacts seeds generated on Mk3 devices using version 4.0.1 or later, as well as certain Mk4, Mk5, and Coldcard-Q firmware versions.
In a parallel development, AI-assisted security audits of broader Bitcoin wallet codebases have identified dozens of additional entropy-handling failures that had previously gone undetected by standard review processes. This has prompted calls from industry leaders, including Kraken's chief security officer, for mandatory independent entropy testing for all hardware wallet manufacturers.
Entities: Bitcoin · Coinkite · Coldcard · Galaxy Research · Kraken