Coldcard Wallets Hit by $114 Million Hack
A major security vulnerability in Coldcard wallets led to over $114 million being stolen from more than 5,200 addresses. The issue, which started in March 2021, allowed attackers to recover offline keys by brute-forcing a limited range due to the use of a software pseudo-random number generator instead of a hardware one.
The first wave of attacks on July 30 took only 25 minutes and brought in 594 BTC. By August 2, three waves had emptied 4,585 addresses, and the next day researchers recorded a fourth. At least 15 independent attackers joined the scheme, with total losses potentially reaching $130 million.
CoinKite released an emergency firmware update for all affected models on August 4 and directly contacted owners to warn them about the risk.
The incident highlighted weaknesses in hardware wallets, particularly when it comes to seed phrase generation. Coldcard's strengths include its focus on Bitcoin, key isolation, hardware entropy generation, and additional security modes, but a high entry threshold may deter beginners from using the device properly.