started · updated
Coldcard vulnerability leads to over $100 million Bitcoin theft
A significant security vulnerability in Coldcard hardware wallets has resulted in the theft of approximately 1,596 Bitcoin, valued at over $100 million. The flaw originated from a configuration error in firmware version 4.0.0, released in March 2021, which caused a failure in the randomness (entropy) used to generate seed phrases. Instead of using a secure hardware random number generator, the devices relied on a weaker software-based method, drastically reducing the complexity required for attackers to brute-force seed phrases.
Galaxy Research estimates that at least 15 different groups of attackers exploited this vulnerability across roughly 7,300 addresses. The theft occurred without the need for physical access to the devices. While Coinkite has released firmware updates to fix the issue for future seed generation, existing vulnerable seeds remain unsafe. Users are advised to install the updates and migrate their funds to newly generated wallets.
Investigators from Block have reportedly identified an unusual pattern in the attackers' on-chain activity, noting the use of a paid blockchain data provider account to query source addresses. This information has been passed to authorities, and there are indications that law enforcement, including the FBI, may have information capable of identifying at least one attacker involved in the initial wave of thefts.
Entities
Block · Coinkite · Coldcard · FBI · Galaxy Research