$70M Coldcard Hack Highlights Vulnerability of Hardware Wallets
A recent hack of Coldcard wallets has left $70 million in Bitcoin missing. On July 30, an attacker drained approximately $30 million from wallets within ten minutes, targeting the highest-value coins first.
The security breach occurred when a flaw was discovered in the firmware update of March 2021. The update caused key generation to fall back to a basic software substitute built from the chip's serial number and its internal clock readings. This reduced each device's possible seeds to around four billion, making them vulnerable to guessing.
The attacker generated candidate seeds on their own machine, working out which addresses they would produce, then checking those against the public blockchain. This process didn't touch the victim's device, effectively making it as secure as a vault.
CoinKite has released fixed firmware for affected models, but owners need to generate a new seed on the updated device and move their coins across. Importing an existing seed into a different wallet won't repair the weakness, as it lives in the number chosen by the broken firmware.