Coldcard Users Lose Tens of Millions in Vulnerability-Driven Heist
A recent attack on Coldcard users has resulted in the loss of tens of millions of dollars' worth of Bitcoin. The exploit, which occurred on July 30, targeted wallets that generated their recovery seeds using vulnerable firmware released from March 2021 onward.
Coldcard is a hardware wallet made by Canadian manufacturer Coinkite, designed to keep Bitcoin keys isolated from internet-connected devices. However, the company's Random Number Generator (RNG) failed to produce truly random seeds, instead relying on predictable device information such as chip identifiers and internal clock values.
The affected wallets belonged largely to long-term holders who had generated their recovery seeds using Coldcard devices running vulnerable firmware. The attacker moved rapidly, paying elevated fixed transaction fees and leaving no change outputs, suggesting an automated operation using a prepared list of private keys.
Coldcard's CEO, Rodolfo Novak, apologized for the failure and acknowledged that the company accepted full responsibility for the firmware issue. He warned developers that artificial intelligence tools can now scan old public code for hidden weaknesses faster than traditional review processes may detect them.