Coldcard Bug Exposes $70M+ in Bitcoin to Brute-Force Attacks
A series of thefts targeting Coldcard Bitcoin wallets has left over $70 million in cryptocurrency stolen, with engineers at Block citing that the thief used a top blockchain services provider for help.
The attacks exploited a firmware bug in Coldcard Mk3 devices, starting with version 4.0.1 in March 2021, which caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator.
This allowed private keys for many single-signature wallets, especially those created without dice rolls or a strong BIP-39 passphrase, to be predictable enough for attackers to brute-force.
According to engineer Clay Garrett at payments company Block, the thief used a paid account at a well-known blockchain-services provider to query source addresses and perform other related activity during the sweeps.