Coldcard Bug Exposed: Over 1,300 Bitcoin Stolen via Predictable Seed Phrase Generation
A security flaw in Coinkite's Coldcard hardware wallets has left over 1,300 Bitcoin stolen, worth around $88.6 million at the time of theft.
The bug dates back to a software update in March 2021 and was only recently discovered by Coinkite on July 30. The issue caused the devices to generate wallet seed phrases using a predictable software program instead of their dedicated chip for generating true randomness, leaving them vulnerable to hacking.
According to Coinkite, the affected models are the Mk2 and Mk3, which generated seeds with only about 40 bits of real randomness. The company has since released fixed software for every affected model, but installing the update does not fix a seed that was already generated on the flawed software.
The incident is a reminder that even hardware wallets can be vulnerable to security flaws if their software is not properly secured. Coinkite's code has been publicly viewable for years, which likely helped an outsider find the flaw first.