Coldcard Firmware Flaw Exposes Thousands of Wallets to Remote Attack
A vulnerability in the March 2021 Coldcard firmware release allowed attackers to drain Bitcoin from thousands of wallets without needing physical access.
The flaw, which Coinkite estimates affects around 40 bits of entropy on the Mk3 and about 72 bits on the Mk4, Mk5, and Q models, enables remote key derivation by bypassing the hardware random number generator.
Galaxy Research identified 1,196 addresses involved in transactions tied to the July 30 sweep, tracing activity between 1:10 AM and 1:51 AM UTC across blocks 960,183 to 960,191. The attackers used a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator, allowing them to reproduce candidate output streams offline.
The losses from this attack are estimated near $89 million, with the latest wave targeting smaller balances and using more complex transaction patterns. Galaxy Research warned that future attacks may not reuse the same on-chain 'fingerprint,' meaning wallet owners should be cautious and consider migrating their funds.