Coldcard Hack Exposes Self-Custody Risks as Thousands Lose Millions
A devastating cyberattack on Coinkite's Coldcard hardware wallets has left thousands of Bitcoin owners scrambling to secure their funds. On July 30th, attackers began draining Bitcoin from addresses linked to seeds generated by compromised devices, netting around $130 million in just a few hours.
The hack, which involved at least 15 different attackers, was a disaster for the Bitcoin community. With over 4,385 addresses affected, it's one of the worst incidents in Bitcoin's history.
The attack targeted Coldcard devices manufactured by Coinkite, which were considered among the most secure options available to users. However, an investigation revealed that the firmware used in these devices had a critical flaw, it bypassed the use of a hardware chip called a true random-number generator (TRNG), instead relying on a less random software function.
The TRNG issue allowed attackers to generate candidate seeds and compare them with public blockchain data, making it an offline search problem. This vulnerability remained undetected for over five years, despite the fact that Coinkite's firmware was open-source and available for review.