$70 Million in Bitcoin Vanishes From Coldcard Wallets Due to Five-Year-Old Bug
The security of cold storage wallets took a hit this week when hackers swept over $70 million in BTC from more than 1,000 Coldcard wallets. The attack occurred without any interaction with the devices themselves, no phishing attempts, and no need for PINs or passwords.
According to Galaxy Digital's blockchain analysts, the losses were initially estimated at around $38 million but later revised upward as more addresses turned up in the sweep. Hardware wallet maker Coinkite confirmed the flaw and rushed out patched firmware, but by then, the funds had already been drained.
The root cause of the issue lies in a five-year-old bug that affected how Coldcard wallets generated their keys. The device's software started skipping its dedicated hardware random number generator and fell back to predictable values, reducing the expected 128 bits of entropy to around 40 or 72 bits on affected builds.
Users who were hit by the attack did everything right: they stored their BTC in cold storage offline, following standard self-custody advice. However, this meant that when the funds vanished, there was little they could do to recover them. In fact, users who added extra inputs during setup, such as dice rolls or passphrases, appear to have been protected.
Coinkite advises users with affected devices to treat their seeds as compromised and move their funds. This involves updating the firmware, generating a new seed, and sending everything to a fresh wallet. Unfortunately, there is no self-test to determine whether a particular seed falls within the guessable range, so it's best to err on the side of caution.