Coldcard Firmware Hack Exposes Millions in Wallets
A devastating hack has left millions of dollars exposed after an attacker exploited a long-buried flaw in Coldcard firmware. The Coinkite seed vulnerability, which was introduced over five years ago, was used to drain around $38 million from approximately 500 single-signature wallets between July 31st and August 1st.
The attack, which took place within a three-block window, saw 562 BTC consolidated into a single address that has not moved since. The hack's success is attributed to the compromised seed generator, which reduced entropy from 128 bits to around 72 bits.
Coinkite has warned users who generated a seed on an affected device running firmware version 4.0.1 or later (from March 2021 onward) that their funds may be at risk. The company has published detailed step-by-step mitigation guidance for affected users, including those with Mk3 devices.
Users who added at least 50 independent dice rolls during seed creation are considered protected, but all others should migrate immediately to a new seed on fixed firmware. Coinkite has also provided an interim path for users whose only option is the Mk3, allowing them to create a passphrase-protected wallet and move funds from the original wallet into it.