Coldcard Exploit Swells to $88 Million as Attackers Drain Wallets
A vulnerability in Coinkite's Coldcard firmware has led to an ongoing exploit that has seen around $88.6 million stolen from affected users' wallets, with Galaxy Research tracking losses across 4,585 addresses.
The flaw, which was introduced in a March 2021 firmware build error, causes seed phrases to be generated with too little randomness, making private keys guessable. According to Alex Thorn of Galaxy Research, the sweeps are likely deliberate and programmatic, potentially orchestrated by a large language model.
Evidence suggests that every single-sig Coldcard address created after the 2021 update will eventually be drained, as seen in the three documented waves tracked by Galaxy Research.
The affected users have been moving their Bitcoin back to centralized exchanges or freshly generated addresses, an inversion of the industry's usual 'not your keys, not your coins' ethos. The warnings from security experts came too late for some, with Canadian coach Jonathan Goodman reporting that 18.25 BTC was swept from his wallets in a seven-minute span on July 29.