Coldcard Wallet Flaw Exposes $70 Million in Bitcoin Losses
A major security flaw in the Coldcard Wallet software has been linked to one of the largest Bitcoin thefts in recent history. The bug allowed hackers to generate private keys offline, exposing over 1,100 wallets and resulting in the loss of nearly $70 million in BTC.
The hack occurred on July 30, when an attacker exploited a vulnerability in firmware versions 4.0.1 to 5.0.3, released in March 2021. The hacker drained 1,196 Bitcoin wallets within 41 minutes, stealing approximately 1,082.65 BTC.
Researchers from Galaxy Research found that each transaction was made using the same rate of 30 sat/vB and without any change outputs, suggesting the attacker already had access to the private keys. The security flaw arose from a hardware random number generator not being implemented correctly, leading to predictable factors such as serial numbers and internal clocks being used for generating recovery phrases.
CoinKite has updated its warning to include firmware vulnerabilities in Mk4, Mk5, and Coldcard Q models but notes that new hardware models significantly mitigate the risk. Users are advised to move their funds immediately, with those who created recovery phrases using the compromised firmware urged to switch to a new wallet operating under the latest firmware.