Coldcard Hack Exposes Hardware Wallet Vulnerability
A five-year-old firmware bug in Coldcard hardware wallets has led to four waves of automated sweeps draining an estimated $114 million from over 5,200 addresses since July 30. The root cause of this issue dates back to a March 2021 firmware update for Coldcard Mk3 devices, which introduced a coding error in how the wallet generated seed phrases.
The seed phrase security approach used by these wallets is compromised because instead of pulling randomness from the device's hardware random number generator (RNG), the firmware fell back to a software-based alternative that produced far more predictable results. This reduced entropy from 128 bits to roughly 40 bits, making it easier for attackers to reconstruct possible seed phrases and check them against public blockchain data.
The attack is attributed to an attacker likely using AI to comb through Coinkite's open-source code and identify the flaw. The company admitted its own AI-assisted code review missed the same bug weeks earlier.
Coldcard users are advised to treat their wallets as compromised if they created a seed on a Mk3 device running firmware 4.0.1 or later. Installing patched firmware, generating a new seed phrase, and transferring funds to a new address is recommended.