Coldcard Wallets Compromised: $38 Million in BTC Stolen
A security flaw in the random number generator of Coldcard hardware Bitcoin wallets has led to the theft of around $38 million worth of BTC. The vulnerability, which affects users who created their wallet seeds using firmware versions 4.0.1 and above since March 2021, was exploited by an unknown hacker who stole nearly 594 BTC from over 500 single-signature wallets in just 25 minutes.
The affected devices generated seeds using a 'predictable periodic down-counter' that included the device's serial number and internal clock, instead of sufficient hardware-generated randomness. This issue is not limited to the Coldcard Mk3, as Coinkite also noted that seeds generated on Mk4 and Mk5 devices before version 5.6.0 and on Q devices before version 1.5.0Q had about 72 bits of entropy rather than the expected 128 bits.
CoinKite is advising users to generate a new seed on a newer device and verify the new address, as updating an affected wallet will not repair its existing seed. This issue highlights the importance of security in cryptocurrency storage solutions.