started · updated
Coldcard hardware wallet flaw leads to $100 million Bitcoin theft
A significant security vulnerability in Coldcard hardware wallets has resulted in the theft of over 2,000 Bitcoins, valued at more than $100 million. The exploit targeted users practicing self-custody through the Coldcard Mk3 model, which was previously considered a gold standard for security due to its offline nature.
The breach originated from a flaw in firmware version 4.0.1, released in March 2021. The bug compromised the entropy—the level of randomness required to generate secure cryptographic seeds—during the seed generation process. While a standard 128-bit seed provides a virtually unguessable number of combinations, the bug reduced the effective entropy to approximately 40 bits. This reduction allowed attackers to use sufficient computing power to navigate the significantly smaller search space and extract funds without needing physical access to the devices.
In response to the incident, specialists and industry experts have urged users to review their devices, update firmware, and move funds to newly generated, secure wallets. The event has sparked intense discussion within the cryptocurrency community regarding the risks of hardware-based self-custody and the critical importance of cryptographic randomness.