Coldcard Hack Exposes Vulnerability in Bitcoin Cold Storage Security
The security of Bitcoin cold wallets has been compromised after an attacker drained $70 million from 1,200 Coldcard wallets in just 40 minutes on July 30. The hack occurred without any physical device being accessed, as the attacker was able to reproduce predictable seeds using public data such as serial numbers and clock readings.
The vulnerability originated from a firmware bug introduced in March 2021, which limited possible seed values to 4 billion, making them reproducible by anyone with access to public data. This allowed the attacker to generate candidate seeds on their own machine, check addresses against the blockchain, and steal funds without touching any devices.
However, owners who rolled their own dice during setup or used a strong passphrase were able to protect their wallets from being compromised. Coinkite has released fixed firmware for affected models, but updating will not repair existing weak seeds, and owners must generate new seeds on the updated firmware to secure their funds.