Coldcard Exploit Unleashes Massive $111M Bitcoin Heist
The Coldcard exploit has led to significant losses for Bitcoin holders, with investigators uncovering over $111 million in stolen funds. The attack occurred due to a flaw in some Coldcard wallets using firmware released after March 17, 2021, which may have affected wallet-seed security or generation.
The seed served as the master key for Bitcoin wallets, and attackers who managed to recreate it could access the money without physically compromising the Coldcard. The investigators found that no stolen coins came from wallets created before the mentioned firmware release date.
Over 25 attack patterns across three waves were identified, suggesting multiple threat actors exploited the vulnerability. Not every Coldcard wallet was affected, but those using Mk3, Mk4, Mk5, and Q models, which ran firmware released after March 17, 2021, appeared vulnerable.