Coldcard Hack Exposes Vulnerability in Hardware Wallets
A significant security breach has affected Coldcard, a hardware wallet developed by Coinkite. The incident occurred due to a five-year-old firmware vulnerability that was exploited remotely without any physical interaction or malicious software installation required.
The attack allowed hackers to steal approximately $89 million worth of Bitcoin, making it the largest Bitcoin heist this year, according to Coldcard Sweep Watch dashboard statistics as of August 3rd. There are suspicions of a fourth wave of attacks ongoing, with losses still increasing.
Coinkite estimates that around 1359 BTC were stolen, representing a significant loss for users who had stored their assets in these wallets. The breach was possible due to a code migration issue in 2021, where the firmware failed to utilize the hardware true random number generator (TRNG) chip, instead relying on a software pseudo-random number generator that used public or predictable inputs.
Attackers could then use offline brute-force attacks to enumerate potential seed values and calculate corresponding addresses. Once matched with on-chain public addresses, this enabled hackers to obtain private keys and transfer funds directly.
The severity of the vulnerability varies by device model, with the most affected Mk3 models having an effective randomness reduced from 128 bits to approximately 40 bits. Coinkite's Q and Mk4/Mk5 devices also suffered from compromised randomness, although to a lesser extent.