Coldcard Flaw Exposes Millions in Stolen Bitcoin
A recent vulnerability in Coldcard devices has been linked to over $38 million in stolen Bitcoin, according to blockchain analytics firm Chainalysis. The issue stems from a firmware integration error that weakened the randomness used to generate wallet seeds.
Coinkite's security advisory warned that affected devices generated seeds with only 40 bits of effective entropy, rather than the intended 128-bit security target. Later models, including Mk4 and Q devices, increased this to around 72 bits, but still fell short.
The attacker systematically targeted higher-value wallets before expanding to smaller balances, stealing around $30 million in the first 10 minutes. Chainalysis identified 1,196 affected UTXOs, with one worth approximately $1.8 million.