Coldcard Wallet Security Flaw Puts Millions of Dollars of Bitcoin at Risk
A security flaw in the Coldcard hardware Bitcoin wallet has put years of user funds at risk. The vulnerability, linked to the theft of $38 million worth of BTC, affects nearly 500 single-signature wallets.
The issue lies with the random number generator (RNG), which uses 'predictable periodic down-counter,' including the device's serial number and internal clock, instead of sufficient hardware-generated randomness. This means that affected devices may have generated wallet seeds using a predictable pattern rather than true randomness.
CoinKite, the Canadian crypto firm behind Coldcard, is urging users to withdraw their funds due to this vulnerability. The company acknowledges that updating an affected wallet will not repair its existing seed and advises users to generate a new seed on a newer device and verify the new address as well as test transaction to transfer any remaining BTC.
The issue affects devices with firmware version 4.0.1 and above, dating back to March 2021. Additionally, seeds generated on Mk4 and Mk5 devices before version 5.6.0 and on Q devices before version 1.5.0Q had about 72 bits of entropy rather than the expected 128 bits.