Coldcard Firmware Vulnerability Exposed: $90M Lost in Coordinated Attacks
A vulnerability in Coldcard firmware has led to a series of coordinated attacks on Bitcoin hardware wallets.
The first wave, which emerged on July 30, saw nearly 500 wallets drained of about $40 million. A second wave hours later targeted over 1,196 wallets, pushing losses past $70 million.
The latest sweep brings the total stolen to 1,367 BTC, up from roughly 1,083 BTC ($70 million) reported a day earlier.
The attacks exploit a firmware build configuration that causes affected devices to generate wallet seeds using predictable hardware values instead of dedicated random-number generators. This allows attackers to recreate the seed and sweep funds without touching the physical device.
The incident has highlighted a unique supply-chain risk: users who securely stored offline wallets for years remained vulnerable if the wallet was originally created with the affected firmware, regardless of whether the device was later updated.