Coldcard Exploit Drains $88.6M in BTC from Over 4,500 Wallets
A firmware vulnerability in Coldcard devices has been exploited to drain over $88.6 million worth of BTC from more than 4,500 wallets.
The exploit targeted the randomness used to generate recovery seeds, making them predictable enough for an attacker to reproduce offline.
The vulnerability existed in firmware versions 4.0.0 through 5.0.3 and was present since March 2021. In roughly 25 minutes on July 30, approximately $38 million worth of BTC was drained from about 500 addresses.
Coldcard has urged all affected users to generate new recovery seeds on updated firmware, but updating firmware does not retroactively fix seeds that were already generated with weak randomness.