Coldcard Firmware Flaw Exposed: Hackers Drain Millions of Dollars' Worth of Bitcoin
A critical flaw in Coldcard's firmware has been exposed, allowing hackers to drain millions of dollars' worth of Bitcoin from unsuspecting users. The vulnerability, which affects devices since 2021, allows attackers to guess supposedly random seed phrases, giving them access to private keys and funds.
The issue came to light on July 30 when an attacker drained 1,196 Bitcoin addresses in just 41 minutes, taking $70.2 million worth of BTC at the time. Since then, two more waves have been identified, with a total loss now exceeding $88.6 million across 4,585 addresses.
The problem lies in Coldcard's production code, which defines a hardware RNG setting but fails to check whether it is enabled. This causes devices to fall back to a weaker software pseudorandom number generator, allowing attackers to reproduce candidate output streams and test them against public blockchain data.
CoinKite has released emergency firmware updates for affected models, but these do not fix seeds that were already created. Users are advised to generate new seeds on patched firmware and move their coins, as restoring old seeds does not remove the vulnerability.