Coldcard Releases New Firmware After $130 Million Bitcoin Exploit
Coldcard has released new firmware to address security concerns after a seed-generation flaw allowed attackers to steal more than $130 million in Bitcoin. The vulnerability, which was exploited starting in July, made it possible for hackers to guess wallet seeds with too little randomness.
The issue, dating back to 2021, reduced the security from 128 bits of entropy to roughly 40 bits, making wallet seeds easier to guess without physical access to the device. Coinkite, the maker of Coldcard, has now fixed issues involving transaction signing, USB data handling, firmware validation, Delta Mode, and wallet backups.
The updated firmware requires users to add randomness when generating a new seed using at least 65 key presses, 50 dice rolls, or 128 coin flips. Coinkite also replaced its Yasmarang backup pseudo-random number generator with SHA-256 Hash_DRBG and added checks intended to catch failures in the hardware random number generator.
Coinkite urges users of Coldcard Mk4, Mk5, and Q devices to upgrade to firmware 5.6.1 or 1.5.1Q as soon as possible. The company has also announced that it is working with law enforcement authorities to investigate the thefts and identify those responsible.