Coldcard Firmware Flaw Exposes $116M in Weak Seeds
A critical flaw in the Coldcard firmware has led to the largest hardware wallet exploit in crypto history, draining $116 million from over 5,200 addresses across four attack waves. The vulnerability, which persisted for five years, allowed an attacker to brute-force weak seeds and empty wallets at a pace that left no time to react.
The build configuration error shipped in March 2021, routing seed generation to a deterministic software pseudorandom number generator instead of the device's hardware random number generator. This reduced effective entropy from 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4, Mk5, and Q models.
Coinkite released emergency firmware on July 31, but updating does not repair seeds already generated on vulnerable firmware, meaning every affected user must generate a new seed and manually migrate funds to survive. The incident has sparked calls for independent audits of hardware wallet manufacturers' seed generation code.