COLDCARD Wallet Vulnerability Exposes Users to $102M in Bitcoin Losses
A vulnerability in COLDCARD hardware wallets has led to the theft of at least $102 million worth of Bitcoin, according to an investigation by Galaxy Research. The researchers have linked the stolen funds to a flaw in the wallet seed generation process, which allows attackers to recreate private keys and access corresponding Bitcoin addresses.
The investigation has identified at least 15 distinct attacker patterns, with a larger suspected set approaching $131 million worth of BTC. The three largest known theft waves moved approximately 1,367 BTC, with the first wave detected on July 30, where an attacker swept 1,196 Bitcoin addresses in around 41 minutes.
The affected COLDCARD firmware used a deterministic MicroPython pseudorandom-number-generator fallback rather than the expected hardware randomness, allowing attackers to generate possible seeds offline and compare them with publicly visible addresses holding funds. Galaxy Research has shared suspected attacker addresses with federal investigators, exchanges, compliance companies, cyber investigators, and the Security Alliance.
No public seizure or recovery of funds has been announced, as the attackers still control the private keys. The incident highlights the complexity of recovering stolen cryptocurrency, particularly when it involves cross-chain conversion and fragmentation of funds.