Coldcard Vulnerability Exposed: 1800+ BTC Stolen via Mnemonic Weakness
A vulnerability in Coldcard hardware wallets has led to at least 1,815.75 BTC being stolen from approximately 5,294 addresses since 2021.
The issue arose due to a code migration error in 2021, where some devices mistakenly connected the wallet seed generation path to a software pseudo-random number generator instead of the intended hardware random number generator.
This resulted in a significantly lower actual search space for mnemonics generated by some firmware compared to the design target, making it easier for attackers to exploit.
Galaxy Research identified four rounds of suspected attacks involving 1,367.05 BTC and 4,585 addresses, with a fourth round detected on August 3.
Coinkite, the manufacturer of Coldcard, initially denied any device-level vulnerability but later expanded the affected scope to include Mk2, Mk3, Mk4, Mk5, Q, and Q Edge devices using specific firmware versions.