Block Traces COLDCARD Attack to Blockchain Services Provider
A $38 million Bitcoin theft on July 30 highlighted the vulnerability of some COLDCARD hardware wallets, with Block's engineering team tracing the attack to a blockchain services provider.
The breach occurred within a 25-minute window between 01:31 and 01:56 UTC, draining approximately 594 BTC from around 500 wallets. The affected devices were primarily Mk3 models and some Mk2 units where seeds had been generated under compromised firmware versions.
The root cause of the attack was a five-year-old firmware bug that deactivated the hardware random number generator on affected COLDCARD devices, replacing it with a predictable software fallback using non-secret seed values. The attacker, who apparently sat on this knowledge for years, targeted dormant accounts and pre-computed vulnerable seeds before scripting the draining process.
Block and Coinkite coordinated an urgent disclosure of the vulnerability, allowing users to take immediate action. Coinkite issued an advisory recommending that users generate entirely new seeds on unaffected hardware and migrate all funds immediately, as newer models were not affected by the RNG flaw.