Coldcard Hardware Wallets Hit by Vulnerability Exploited for $89 Million in BTC
A vulnerability in Coldcard hardware wallets has led to the theft of approximately 1,367 BTC, worth around $89 million, from over 4,500 addresses since coordinated attacks began on July 30. The bug, quietly sitting in firmware since March 2021, weakened the randomness used to generate wallet seeds so severely that attackers were eventually able to crack them.
Coldcard's firmware version 4.0.1, released in March 2021 by Canadian manufacturer Coinkite, introduced a bug during a significant code rewrite. The issue was with the entropy generation code, which produced seeds with roughly 72 bits of randomness instead of the required 128 bits.
Coordinated attacks exploiting the weakness began on July 30, and within days, approximately 1,367 BTC had been siphoned from wallets whose seeds were generated on affected firmware versions. Coinkite released patched firmware on July 31, but updating firmware alone doesn't fix the problem - users who generated seeds on the vulnerable firmware still need to migrate to entirely new seeds.
Zach Herbert, CEO of Foundation Devices, a competing hardware wallet manufacturer, emphasized that open-source code was central to the community's ability to detect and respond quickly. He argued that proprietary firmware would have made the problem harder to find and even harder to fix.