Coldcard Breach Exposes Hardware Wallet Vulnerability Worth Over $100 Million
A recent security breach involving Coldcard has exposed a significant vulnerability in hardware wallets. The issue was identified by Anthropic's Claude Code, an AI that analyzed the wallet's source code and flagged the problem in just eight minutes.
The flaw is linked to the way affected Coldcard firmware generates cryptographic randomness, specifically random number generation. This process is crucial for crypto wallets as it produces unpredictable values for private keys and digital signatures.
As a result of this weakness, attackers stole over 1,080 BTC in under an hour, with initial estimates placing total losses above $100 million. However, more recent estimates within the community suggest that the actual loss may be even higher.
Alex Thorn, head of research at Galaxy, noted on X that another wave of attacks may be imminent. He emphasized that Coldcard users should immediately move any remaining funds off affected devices and use transaction fees to maximize their chances of beating attackers to confirmation.