Coldcard Hack Exposes Weakness in Hardware Wallet Security
The Coldcard Bitcoin wallet hack is one of the most significant hardware wallet security incidents in recent years, resulting in the theft of 1,367 Bitcoin (BTC) worth nearly $89 million.
Hackers exploited a flaw in how some Coldcard wallets created recovery seeds by using weak random numbers, which made it possible to recreate seed phrases instead of guessing billions of combinations.
The affected wallets were different, with the Mk2 and Mk3 models facing the highest risk. Installing the latest firmware does not make an old seed phrase safe, and users should generate a new seed phrase if their wallet created its seed with an affected firmware version.
Coldcard's software is open source, but this incident shows that even open-source code can be vulnerable to security issues. The weak seed generation exposed users, and researchers say the vulnerable code stayed public for years before anyone found the problem.