Coldcard Firmware Flaw Leads to Estimated $100m Loss
A five-year-old firmware flaw in Coldcard, a Canadian firm's bitcoin-only hardware wallet, has led to an estimated $100m+ loss. An attacker began sweeping BTC from addresses generated by Coldcard on July 30th, resulting in around 594 BTC taken from approximately 500 wallets in about 25 minutes. As of August 4th, Galaxy Research estimates that at least 1,596 BTC had been taken from about 7,300 addresses across three confirmed waves and 14 smaller incidents.
The issue lies with the firmware change made by Coinkite in March 2021, which switched key generation to a predictable software randomizer instead of the chip's hardware one. This allowed an attacker to reconstruct keys offline without seeing the device. Only single-signature wallets are affected.
Coinkite has published the affected models and firmware versions. Owners must create a new key and move their coins, as a patch cannot repair already generated keys. Some setups built with independent private entropy are exempt.