Coldcard Firmware Flaw Drains $89M From 4,500 Bitcoin Wallets
A coding error in the March 2021 firmware release of the Coldcard Mk3 has enabled attackers to steal approximately $89 million worth of Bitcoin from 4,585 addresses. Galaxy Research tracked three separate waves of attacks between July 30 and August 2, with each wave draining funds from vulnerable wallets.
The flaw exists in version 4.0.1 of the firmware, which mistakenly routed seed phrase generation to a software-based random number generator instead of the dedicated hardware chip inside the device. This allowed attackers to reconstruct possible private keys offline and check them against funded addresses without handling physical wallets.
The first wave hit on July 30, draining 1,082.65 BTC from 1,196 addresses in a 41-minute window. The second wave targeted mid-sized wallet balances, while the third wave routed each victim's coins to a unique destination address instead of funneling them into shared collector addresses.
Coinkite CEO Rodolfo Novak apologized for the firmware bug and acknowledged that the company's internal review process failed to catch the error. He suggested the vulnerability may have been uncovered through AI-assisted code analysis, calling it 'a sober reality of the new AI paradigm.'