Coldcard Hack Exposes Vulnerable Wallet Firmware
Coldcard's firmware flaw has led to over $100 million in Bitcoin losses. The company plans a technical post-mortem after the exploit, which affected wallet seed generation and not the underlying network or cryptography.
The vulnerability was introduced during a 2021 code migration and used a predictable software random number generator instead of the intended hardware-based source when creating wallet seeds. This reduced the possible seed search space to about 40 bits on certain Coldcard models and around 72 bits on later ones.
Galaxy Research has verified the theft of 1,596 BTC from about 7,300 addresses across three coordinated attack waves. A broader analysis identified four suspected attack waves involving about 5,294 addresses and 1,815.75 BTC.
A wallet linked to the exploit moved 30 BTC worth about $1.94 million to a new address, according to blockchain monitoring platform Lookonchain.