Coldcard Wallets Hit by Multi-Million Dollar Attack Series
A series of attacks on Coldcard-generated Bitcoin wallets has compromised over $89 million in assets. The attacks, which have unfolded in three waves, have targeted a total of 4,585 addresses and drained 1,367 BTC.
The vulnerability exploited by the attackers was a flaw in the firmware used to generate seed phrases for these wallets. Specifically, the issue arose from a version of the firmware released in March 2021, which relied on a predictable random number generator instead of the hardware source of randomness.
This allowed an attacker with sufficient computational resources to offline reproduce the compromised keys and drain funds from affected addresses without ever accessing the physical devices themselves. The attackers' tactics have evolved over time, with each wave targeting more addresses and draining fewer funds per address.
The first wave on July 30th targeted 1,196 addresses in just 41 minutes, moving around 1,083 BTC. In the third wave, an additional 208 BTC were drained from 1,912 addresses. Coinkite has released corrected firmware for affected Coldcard models, but users who created seeds with vulnerable software must create a new seed phrase and transfer their Bitcoin to a new address.