Coldcard Hack Exposes Five-Year-Old Bug, Thieves Drain ₹820 Crore
A recent hack of Coldcard hardware wallets has exposed a nearly five-year-old bug that allowed thieves to drain over ₹820 crore in Bitcoin from more than 4,585 wallets.
The vulnerability, which was introduced in March 2021, affected devices running firmware versions 4.0.1 through 4.1.9 and caused the device to use a predictable software-based random number generator instead of its dedicated hardware randomness chip.
Attackers likely used AI-assisted brute-force techniques to rebuild thousands of weakened seed phrases entirely offline, with no need to ever touch a victim's physical device.
CoinKite, the company behind Coldcard, has confirmed the vulnerability and released emergency firmware fixes. However, affected users must generate an entirely new wallet on patched firmware and move funds across, as installing the new firmware does not protect funds already sitting in a seed generated on vulnerable firmware.