$38M Stolen from Coldcard Wallets Amid Predictable Key Generation Flaw
A major security breach has affected around 500 Coldcard hardware wallets, resulting in the theft of approximately $38 million worth of Bitcoin. The vulnerability was introduced in firmware version 4.0.0 in March 2021 and allowed attackers to exploit a flaw in the key generation process.
The issue caused affected wallets to use predictable software-based keys instead of secure hardware randomness, making seeds guessable. Only Coldcard Mk3 devices with firmware 4.0.1 or later are affected, while newer models appear safe.
Coinkite has warned users to check their devices and firmware versions, but the theft has had little impact on Bitcoin's market price so far.