Coldcard Flaw Exposes $116M in Bitcoin to Theft
A vulnerability in Coldcard hardware wallets has left around $116 million in Bitcoin exposed to theft. According to Bobby Gray, founder of TEXITcoin, users who relied solely on their devices to generate secure seed phrases were vulnerable to attacks.
The issue arose from a firmware integration error that caused affected devices to use a predictable software random-number generator instead of the intended hardware source when creating wallet seeds.
Firmware versions 4.0.1 through 4.1.9 on Coldcard Mk2 and Mk3 devices were affected, leaving the error active for more than five years before Coinkite disclosed it on July 30.
Coinkite estimated that seeds created on affected Mk2 and Mk3 devices contained about 40 bits of effective entropy, while vulnerable Mk4, Mk5, and Q devices generated about 72 bits instead of the expected 128 bits.