Coldcard Hack Exposes Weakness in Hardware Wallets: $114M Stolen
A severe security failure has been unfolding at Coldcard, a device designed to make cryptocurrency storage secure. At least four sweeps have occurred, draining a total of nearly $114 million from affected wallets. Despite this, Bitcoin's price has not collapsed as many traders had expected.
The issue lies in the firmware used by Coldcard, which contained a software fallback for generating randomness. This allowed an attacker to reproduce candidate output streams offline, making it possible to guess seeds that were previously thought secure.
Coldcard's Mk3 firmware versions 4.0.1 through 4.1.9 are affected, as well as some Mk4, Mk5, and Q devices. Updating the device does not repair the issue, and users should generate a new seed and update their wallet before moving funds.
Coinkite, the company behind Coldcard, believes that AI tooling was used to find the bug, which sat undetected for over five years. The incident highlights the importance of verifying seeds at creation, rather than relying on after-the-fact checks.