Coldcard Wallet Flaw Exposed: $70M Stolen from 1,100 Wallets
A major security flaw in the Coldcard wallet has been exposed after hackers quietly drained over $70 million worth of Bitcoin from more than 1,100 wallets. The attack happened on July 30 between 01:10 and 01:51 UTC when an attacker recreated wallet private keys offline by exploiting a weakness in how some Coldcard wallets generated recovery seed phrases.
Researchers believe the hacker already possessed the private keys and simply automated the withdrawals, which were made using unusually high transaction fees. The issue began with a firmware update released in 2021 that disabled hardware randomness on affected devices, reducing the effective security of wallet seed phrases from 128 bits to around 40 bits.
Coinkite has urged users who generated recovery phrases on affected firmware to immediately move their funds to a newly created wallet using the latest firmware. The company also noted that users who protected their wallets with an additional BIP-39 passphrase face much lower risk due to the extra security layer.