Coldcard Firmware Flaw Exposes Bitcoin to $86M Hack
A significant Bitcoin hack has been uncovered, resulting in the loss of $86 million in cryptocurrency. The incident occurred due to a silent flaw in Coldcard's firmware that compromised seed entropy for five years. According to Galaxy Research, 1,367 BTC was stolen across 4,585 addresses.
The weakness was caused by a misconfigured macro in Coldcard's firmware, which allowed the use of a software pseudo-random number generator (PRNG) instead of the hardware true random number generator (TRNG). This reduced the effective entropy from 128 bits to 40 bits, making it easier for attackers to target weak seeds.
The hack is considered one of the worst in Bitcoin history, with no phishing, physical device access, or user error required. The incident also highlights a broader issue with self-custody arrangements, where the security guarantee relies on the entropy quality of seed generation.