[REVISION HISTORY]
Bitcoin ecosystem security vulnerabilities and Coldcard hack
Updated 18 times since CLSTR started tracking revisions of this situation.
What changed
2026-09-26 00:13 UTC → 2026-09-29 01:37 UTC ·
added
removed
The Bitcoin ecosystem has faced significant security challenges stemming from widespread vulnerabilities in software and hardware. Research identified nearly 5,000 high-risk or critical flaws across various applications, including wallets, node software, mining pools, and exchanges. A notable weakness was found in the CryptoJS JavaScript library, where a reliance on Math.random led to a $5.7 million loss affecting 2,114 addresses. A critical focus involves entropy failures in hardware wallets. A firmware error in Coldcard devices (specifically Mk2, Mk3, Mk4, Q, and Mk5 models) dating back to March 2021 caused devices to use a predictable software-based pseudo-random number generator instead of a true hardware random number generator. This flaw reduced cryptographic security from 128 bits to as low as 32 or 40 bits, allowing attackers to reconstruct seeds through brute-force attacks. In response, Coldcard released critical firmware updates, but warned that these will not repair existing, compromised seed phrases. Exploitation of this flaw has resulted in the theft of over 2,000 Bitcoin, valued at more than $100 million. Recent developments involve white-hat hackers moving 52.37 BTC, valued at over $4.5 million, into a recovery address associated with the Wyoming-based Crypto Recovery Trust. This action aims to secure funds from the Coldcard exploit before they can be stolen by malicious actors. Galaxy Digital researcher Alex Thorn noted that the transferred funds were consolidated from several attacker clusters, including those labeled as ‘Wave 2’ and ‘Footprints AA, AU, and AX’. The transaction included an OP_RETURN message directing affected users to the Crypto Recovery Trust website to file claims. The recovered Bitcoin represents approximately 2.8% of the total funds linked to the exploit, with total losses estimated between $100 million and $154 million. Victims of the exploit are now pursuing legal recourse.
Versions
- 2026-09-29 01:37 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-09-26 00:13 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-09-25 08:02 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-09-23 04:34 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-09-22 08:05 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-09-07 22:38 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-09-01 04:17 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-08-25 11:03 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-08-25 03:11 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-08-21 12:12 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-08-20 20:29 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-08-20 20:26 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-08-19 06:19 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-08-17 16:58 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-08-16 16:27 UTC Bitcoin ecosystem security vulnerabilities and Coldcard hack
- 2026-08-12 22:52 UTC Bitcoin ecosystem security vulnerabilities
- 2026-08-12 19:17 UTC Bitcoin ecosystem security vulnerabilities
- 2026-08-11 23:30 UTC Bitcoin ecosystem security vulnerabilities
- 2026-08-09 02:53 UTC Bitcoin ecosystem security vulnerabilities
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.