Coldcard Wallet Vulnerability Allows Attackers to Drain Nearly $89 Million

An ongoing cryptocurrency exploit tied to a firmware vulnerability in Coldcard hardware wallets has resulted in the theft of nearly $89 million in Bitcoin across thousands of digital addresses. According to The Hacker News, the attacks began on July 30 when an initial wave drained more than 1,000 bitcoin from 1,196 digital wallets in just 41 minutes.

Exploitation of Coldcard Firmware Flaw Drains Millions

Security researchers and industry executives have urged users of the handheld storage devices to immediately migrate their funds. According to a security advisory from Block’s Bitcoin Engineering and Security team, a coding mistake in certain versions of Coldcard weakened a key security feature, making recovery phrases predictable enough for sophisticated attackers to deduce without physically touching the wallets.

Origins of the Software Bug and Affected Devices

The vulnerability traces back to a March 2021 firmware integration error by Canadian company The Hacker News, the manufacturer of Coldcard. Instead of utilizing the STM32 hardware random number generator, the firmware routed seed generation to a deterministic software pseudorandom number generator due to a production configuration issue.

From Instagram — related to coldcard wallet vulnerability allows, Coldcard Bitcoin attack

Coinkite estimated that the effective entropy was reduced to roughly 40 bits on the Mk3 model and about 72 bits on the Mk4, Mk5, and Q models, far below the standard 128 bits for a 12-word BIP-39 seed. While initial warnings focused on older devices, Coinkite subsequently expanded the list of affected products to include additional models and software versions. The company noted that customers who created their recovery phrases using at least 50 private dice rolls are not affected by this specific flaw alone.

Waves of Attacks and Expanding Losses

Following the initial July 30 incident, Galaxy Research identified two additional suspicious waves of activity. By early Sunday, a third wave of sweeps drained roughly 208 bitcoin from 1,912 addresses between Friday midday and Saturday morning UTC. In total, observed losses across all three waves reached 1,367 bitcoin, amounting to nearly $89 million across 4,585 addresses, according to Decrypt.

Coldcard Wallet Vulnerability Allows Attackers to Drain Nearly $89 Million
Photo: Foxbusiness

Galaxy Research stated that it has flagged roughly 600 suspected attacker-controlled addresses and reported them to federal investigators, compliance firms, and cybersecurity researchers. Alex Thorn, head of research at Galaxy, described the sweeps as deliberate and likely orchestrated with a large language model, warning that every single-signature Coldcard address created after the flawed 2021 firmware update will eventually be drained.

Mitigation Steps and User Response

Coinkite released a software update to prevent the problem from affecting newly created wallets, but experts emphasize that updating the firmware does not secure a compromised seed phrase. Coinkite and Block clarified that moving an existing recovery phrase into an updated device or another wallet does not resolve the issue, as the weakness follows the recovery phrase itself.

Bitcoin Cold Wallet Attack Steals $89M – What You Need to Know!

Affected holders have been advised to generate a completely new seed and migrate their funds immediately. The crisis has prompted an unusual shift among some users, who have temporarily moved Bitcoin off self-custody and back onto centralized cryptocurrency exchanges or freshly generated addresses as a precaution against ongoing sweeps.

Keep reading


Discover more from Archyworldys

Subscribe to get the latest posts sent to your email.