Coldcard Firmware Flaw Exposes Bitcoin Investors to Brute-Force Attacks
Coldcard Firmware Flaw Exposes Bitcoin Users to Brute-Force Attacks
A vulnerability in the firmware of Coldcard devices has been linked to significant losses ranging from $38 million to $88.6 million in Bitcoin. Coinkite, the maker of Coldcard, discovered that a bug reduced seed entropy, the randomness protecting private keys, from 128 bits to as low as 40 bits on affected Mk3 units.
The flaw was caused by a single build error that swapped secure hardware randomness for predictable values, leaving private keys exposed to brute-force attacks. This means that users who generated their seeds on vulnerable firmware versions are at risk of having their funds swept in coordinated bursts.
Coinkite recommends updating to patched firmware, generating a new seed, and migrating all funds after testing with a small transaction first. Seeds created with substantial dice-roll entropy or a strong BIP-39 passphrase carry reduced risk, but only seeds generated on affected firmware versions are vulnerable.
The incident has raised concerns about the security of hardware wallets and the role of AI-powered code-auditing tools in discovering vulnerabilities. Analysts suspect that these tools may have discovered and scaled this exploit, compressing the window between a bug's introduction and its weaponization.