COLDCARD Hardware Wallet Exploit Traced to Blockchain Services Provider
A $38 million Bitcoin theft has been linked to a blockchain services provider after Block's engineering team identified the entity behind the COLDCARD hardware wallet exploit. The breach, which occurred on July 30, drained approximately 594 BTC from around 500 wallets in a 25-minute window between 01:31 and 01:56 UTC.
The root cause of the vulnerability was a five-year-old firmware bug that made it possible for attackers to replicate wallet seeds derived from device-specific metadata. This flaw was introduced by a March 2021 firmware update, specifically version 4.0.0, which deactivated the hardware random number generator on affected COLDCARD devices.
The attacker appears to have sat on this knowledge for years, targeting dormant accounts before executing the draining process over a 25-minute window. Block and Coinkite coordinated an urgent disclosure of the vulnerability, allowing users to take immediate action to protect their funds.