Coldcard Flaw Exposes Hardware Wallet Vulnerability
A flaw in one of the industry's longest-running hardware wallets has led to a loss of over $100 million worth of Bitcoin, prompting questions about the security of all hardware wallets.
The Coldcard entropy bug was discovered on July 31 and affected multiple devices. Researchers at Galaxy Digital claim that attackers have been able to steal more than 1,596 BTC through coordinated attacks since then.
Coldcard's firmware fixes and instructions for users to migrate their funds have been released, but the incident has shaken Bitcoin holders. It raises an uncomfortable question: if Coldcard wallets can be exploited, does that mean all hardware wallets are potentially insecure?
The bug did not exploit Bitcoin itself or break modern cryptography, but it struck at something more fundamental: randomness. Every Bitcoin wallet begins by generating a seed phrase from a pool of random data.