Coldcard Wallets Hit with $70 Million Bitcoin Heist Through Firmware Flaw
A recent attack on Coldcard hardware wallets has resulted in the loss of over $70 million worth of Bitcoin. The attack, which occurred on July 30, targeted 1,196 wallets and drained nearly $70 million in a 41-minute window.
The researchers say that a firmware flaw in certain Coldcard devices made supposedly unguessable seed phrases computationally enumerable, allowing attackers to reconstruct private keys without ever touching the devices. The range of keys the device could produce collapsed from unimaginably vast to countable, making it possible for an attacker to generate candidate seeds and derive addresses on their own hardware.
The attack was carried out in batches, with three intervening blocks containing nothing, suggesting that the transactions were broadcast in batches rather than continuously. The proceeds sit in four addresses and have not moved.
Coldcard's maker, Coinkite, has warned Mk3 owners and says its newer devices are unaffected, while Block's report places the Mk2, Mk4, Q, and Mk5 in scope as well. Until that is resolved, anyone who generated a seed on the affected firmware has to assume the worst rather than verify it.