Coldcard Flaw Exposes 1,367 BTC to Predictable Attack
A critical vulnerability in Coldcard Mk3 devices has led to the theft of 1,367.05 BTC, worth around $88.6 million, in a coordinated attack on 4,585 affected addresses.
The attacks occurred across three waves, with the largest single wave hitting on July 30, 2022, and sweeping 1,082.65 BTC, roughly $70.2 million, in just 41 minutes.
Galaxy Research's analysis revealed that the attackers used a hardcoded fee of 30 sat/vB and identical batching patterns in the first two waves, suggesting a single operator or toolkit was involved.
The root cause of the issue is a predictable randomness flaw in the device's random number generator, which was introduced in March 2021 with firmware version 4.0.1.