Coldcard Hack Exposes Weakness in Hardware Wallets
A vulnerability in Coldcard hardware wallets has led to the theft of approximately 1,367 BTC worth around $89 million from over 4,500 addresses since coordinated attacks began on July 30. The bug weakened the randomness used to generate wallet seeds so severely that attackers were eventually able to crack them.
The issue was caused by a firmware update in March 2021 that reduced the entropy generation code to 72 bits instead of the industry standard 128 bits. This made it possible for hackers to pre-compute vulnerable seeds and execute thefts in rapid succession.
Coinkite, the Canadian manufacturer of Coldcard devices, released patched firmware on July 31, but users who generated seeds on the vulnerable firmware still need to migrate to entirely new seeds because the old ones remain compromised.
Zach Herbert, CEO of Foundation Devices, a competing hardware wallet manufacturer, emphasized that open-source code was central to the community's ability to respond quickly and find the issue. He argued that proprietary firmware would have made it harder to detect and fix the problem.