Coldcard Hack: Coordinated Attacks Drain $86M from Over 4,500 Wallets
A recent crypto hack has compromised over 4,500 Coldcard-generated Bitcoin addresses, resulting in the theft of at least $86 million worth of BTC. The attacks targeted a firmware flaw in the wallet's pseudo-random number generator (PRNG), allowing attackers to rebuild private keys and drain funds without physical access to the devices.
The first wave of attacks on July 30 saw 1,082.65 BTC stolen from 1,196 addresses in just 41 minutes, followed by a second wave that added around 208 BTC from 1,912 addresses using more sophisticated techniques. The third and largest attack occurred later, draining 95.45 BTC from over 2,000 addresses.
Coinkite, the maker of the Coldcard wallet, confirmed that a March 2021 firmware error caused the vulnerability in its PRNG during seed phrase creation. The company released emergency firmware updates, but users who generated seeds on vulnerable builds must create new seeds and migrate funds to avoid further losses.