$70M Worth of Bitcoin Stolen Through Coldcard Firmware Flaw
A significant vulnerability in Coldcard's firmware allowed an attacker to steal over $70 million worth of Bitcoin on July 30. The exploit targeted wallet addresses, draining 1,196 accounts in just 41 minutes, with the attacker taking 1,082.65 BTC.
The issue dates back to a firmware integration mistake introduced in March 2021, when affected devices relied on a deterministic software pseudorandom number generator instead of using the STM32 chip's hardware random number generator to create wallet seeds. This made it possible for attackers to recreate possible seed phrases offline by estimating key device information.
Researchers at Block explained that if an attacker can estimate key device information, including the chip's unique ID, timer state, and previous RNG activity, they may be able to recreate possible seed phrases offline. Those candidate seeds can then be tested against public Bitcoin addresses until a match is found.
CoinKite released emergency firmware updates for all affected Coldcard models on July 31, but simply updating the device does not fix wallets that were originally created with the vulnerable firmware. Users whose seeds may have been exposed are being advised to generate a brand new seed using the patched firmware and transfer their Bitcoin to the new wallet.