Coldcard Security Flaw Exposes Over $70 Million in BTC
A five-year-old security flaw in Coldcard software may have allowed an attacker to reconstruct private keys and sweep over $71 million worth of BTC. The incident became public after roughly 594 BTC moved from about 500 single-signature bitcoin addresses on July 30.
When the news first broke, Bitcoin.com News noted that the transfers occurred within approximately 25 minutes and appeared to target wallets with a shared technical weakness. Later blockchain reviews expanded the possible scale of the theft, estimating that between 1,082 and 1,196 addresses may have been affected during a period of about 41 minutes.
A custom dashboard called Coldcard Sweep Watch placed the total at 1,128.4717 BTC, worth about $71.1 million when bitcoin traded near $63,044. Most of the funds were consolidated into an address holding hundreds of bitcoin, where a large portion remained largely stationary.
The affected addresses were linked by one important detail: Their recovery seeds had been created on Coldcard hardware wallets manufactured by Canadian company Coinkite. A recovery seed is a list of words that controls access to a cryptocurrency wallet. Anyone who can reconstruct or obtain that seed can usually move the wallet’s funds without possessing the physical device.
Coldcard Finds a Broken Randomness System
Coinkite issued an urgent advisory warning that certain seeds generated on Coldcard devices could be weak. Mk3 devices running firmware version 4.0.1, released around March 2021, and later versions were among those facing the greatest risk.
The flaw involved the process used to generate random data. Secure wallets depend on high-quality randomness so that their recovery seeds cannot be guessed. On the most seriously affected Mk3 devices, researchers estimated that the seed may have contained only about 40 bits of effective randomness instead of the intended 128 bits.