COLDCARD Hardware Wallets Hit in $38M BTC Heist Exploiting Five-Year-Old Firmware Bug
A significant breach of COLDCARD hardware wallets has been identified and disclosed. The attack drained approximately $38M worth of BTC from around 500 wallets in a 25-minute window between July 30, 01:31 and 01:56 UTC.
The root cause of the breach was a five-year-old firmware bug in COLDCARD's version 4.0.0, released in March 2021. The update deactivated the hardware random number generator on affected devices, replacing it with a predictable software fallback that used non-secret seed values.
The attacker exploited this flaw to replicate wallet seeds derived from device-specific metadata, targeting dormant accounts and pre-computing vulnerable seeds before scripting the draining process. Block's engineering team worked alongside Coinkite to identify the entity behind the attack and traced it to a blockchain services provider used during the theft.