Coldcard Firmware Flaw Exposed: $70M Drained from 1,196 Bitcoin Wallets
On July 30, an attacker exploited a firmware flaw in Coldcard devices to drain $70 million from 1,196 Bitcoin wallets during a 41-minute sweep.
The theft occurred between 01:10 and 01:51 UTC, with the attacker broadcasting transactions in batches across six blocks. Galaxy Research found that three of these blocks contained no related transactions, indicating a deliberate attempt to minimize detection.
The affected wallets were mostly SegWit addresses, but also included seven older standard addresses and six even older ones. The seed-generation flaw reduced the possible seeds from an immense range to a searchable set, allowing attackers to recreate the seed without touching the wallet.
Coldcard's maker, Coinkite, warned Mk3 owners that their devices may be vulnerable, but newer models are unaffected. However, Block's report places the Mk2, Mk4, Q, and Mk5 within the affected scope, leaving users uncertain about which devices are safe.