< Back to all clusters
[TECHNOLOGY] · Canada · 12 sources

started · updated

Coldcard firmware flaw leads to $116M+ Bitcoin theft

A significant security vulnerability in Coldcard hardware wallets has led to the theft of approximately 1,596 to 1,816 BTC, valued between $116 million and $130 million. The exploit targeted a firmware integration error introduced in March 2021, which caused devices to use a weak software-based random number generator instead of the intended hardware entropy during seed phrase generation. This flaw reduced cryptographic security from 128 bits to roughly 40 bits, making recovery phrases susceptible to brute-force attacks.

In response to the breach, on-chain data indicates a massive movement of assets, with approximately 233,000 BTC being moved from long-term holder wallets to safer locations. Some of this migration included users from other hardware wallet brands, such as Ledger and Trezor, who moved funds to multisig setups as a precautionary measure.

Coinkite has issued a security advisory, urging all users who generated seeds on firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and migrate their funds immediately to new, patched devices.

Entities

Bitcoin · Casa · Coinkite · Coldcard · Galaxy Research · Nick Neuman

Claims

What the coverage asserts, and how many sources carry each claim.