Coldcard Firmware Flaw Exposed: $88M in Bitcoin Stolen Using Predictable Values
A firmware flaw in Coldcard devices has been linked to Bitcoin thefts ranging from $38 million to $88.6 million, according to Coinkite, the maker of Coldcard. The bug, which affected Mk3 units running firmware versions 4.0.1 through 4.1.9, reduced seed entropy from 128 bits to as low as 40 bits.
The flaw was caused by a single build error that swapped secure hardware randomness for predictable values, leaving private keys exposed to brute-force attacks. Users who generated seeds on affected firmware versions are vulnerable, but those with seeds created using substantial dice-roll entropy or strong BIP-39 passphrases carry significantly reduced risk.
Coinkite recommends updating to patched firmware and generating a new seed on patched firmware for affected users. Security commentators describe the flaw as 'catastrophic,' destroying the entire security model that users paid for.