COLDCARD Wallet Flaw Exposed to $88.6M Bitcoin Heist
A security vulnerability in COLDCARD hardware wallet firmware has been linked to an estimated $88.6 million Bitcoin theft from thousands of wallets whose seeds were generated using a flawed random number generator.
Digital asset research firm Galaxy Research says it identified an initial wave of transactions on July 30 that likely exploited the vulnerability, draining approximately 1,083 BTC, worth $70.2 million, from 1,196 addresses in just 41 minutes.
The attackers used an automated tool to sweep funds from the affected wallets, leaving no change output and using a hardcoded fee rate of 30 satoshis per virtual byte, which is significantly higher than the median fee rate that week.
Chainalysis found that the attacker prioritized high-value wallets, stealing approximately $30 million during the first ten minutes and taking $1.8 million from one victim.