Coldcard Vulnerability Drains $70M in BTC From Over 1,000 Addresses
A vulnerability affecting several firmware versions of the popular hardware wallet Coldcard has led to significant losses for Bitcoin holders. According to Galaxy Research, more than 1,000 BTC worth approximately $70 million have been stolen from nearly 1,200 addresses since July 30. The firm's analysis revealed a consistent pattern in the transactions, indicating they were likely executed by the same attacker.
Coinkite, the manufacturer of Coldcard devices, initially identified affected units running firmware version 4.0.1 or later but expanded the advisory to include selected Mk4, Mk5, and Coldcard Q firmware releases. The company released emergency updates and urged users to generate a new seed phrase, transfer their Bitcoin to fresh addresses, and verify the migration with a small test transaction before moving larger balances.
Rodolfo Novak, Coinkite CEO, accepted responsibility for the flaw and suggested that advances in artificial intelligence could accelerate the discovery of software vulnerabilities. Galaxy Research warned that additional attacks remain possible if users continue relying on vulnerable seed generations.