$38M in Bitcoin Stolen Through Exploited Coldcard Hardware Wallet Flaw
Coldcard, a hardware wallet manufacturer, has published an advisory after a flaw in its firmware was exploited, resulting in losses estimated at $38 million in Bitcoin. The attack occurred on Friday and affected around 500 wallets within 25 minutes.
The attackers consolidated the stolen funds into a single address containing approximately 562 BTC. Coinkite, the maker of Coldcard, believes an attacker used AI to find the flaw that was exploited, despite its own AI review of the code earlier turning up nothing.
Coldcard's firmware calls a function to fetch randomness, but it uses two implementations with identical signatures, one written by Coinkite and another inherited from MicroPython. A preprocessor guard only checks whether a setting is defined, not its value, allowing the build to complete against the fallback without complaint.
The effective search space for an Mk3 seed was reduced to about 40 bits, instead of the intended 128 bits. The company estimates that extra entropy from the secure elements on the Mk4, Q and Mk5 models lifts theirs to roughly 72 bits, which it says materially improves their position.