Coldcard Hack Exposes Flaw in Commercial Crypto Gadgets
A severe crisis of confidence has hit the hardware crypto wallet market after a technical flaw in Coldcard devices allowed hackers to drain more than $38 million from over 500 Bitcoin addresses.
The attack, which was carried out with a single automated transfer, saw 594.48 BTC transferred to one wallet. This is not an isolated incident, as nearly all Coldcard models are vulnerable to the flaw, including the Mk2, Mk3, Mk4, Q, and Mk5 models.
The issue lies in the firmware's seed phrase generation mechanism, which has been malfunctioning since March 2021. In older devices, this meant that keys were generated using a predictable software algorithm, while in newer models, critical portions of data were truncated, reducing the number of possible secret phrase combinations and making them vulnerable to brute-force attacks.
Peter Todd, a well-known Bitcoin developer who has been identified as Satoshi Nakamoto, has long been skeptical of commercial crypto gadgets. He believes that the incident is a result of the lack of independent scrutiny and auditing of the project's codebase. Todd advocates for end-to-end deterministic testing of real hardware to ensure the entropy comes from a reliable source.