Bitcoin Hardware Wallets Exposed: Coldcard Compromise Rocks Crypto Community
Researchers have uncovered a significant hardware wallet compromise involving over 1,000 Bitcoin (BTC) Coldcard wallets. The exploit allowed attackers to remotely drain funds from the wallets without ever needing physical access or users' recovery phrases.
The attack targeted the wallet creation process itself and relied on a firmware bug introduced in March 2021. Affected devices generated recovery seed phrases using predictable software-based randomness instead of their secure hardware random number generator.
Attackers could mathematically reconstruct victims' private keys remotely, making it one of the rare cases where a flaw in the wallet's entropy generation led directly to large-scale theft.
The incident highlights how even trusted hardware security can be undermined if cryptographic randomness fails at the point a wallet is created. The flaw affects only Coldcard Mk3 wallets created using firmware version 4.0.1 or later during the affected period.