Coldcard Wallets Vulnerable to $38M Bitcoin Heist Due to Firmware Flaw
A critical flaw in the firmware of Coinkite's Coldcard hardware wallet allowed an attacker to drain approximately $38 million worth of Bitcoin from nearly 500 wallets.
The vulnerability, which was discovered using AI-assisted analysis of the open-source firmware, traces back to a software change made in March 2021 with firmware version 4.0.0.
During the integration of Bitcoin Core's libsecp256k1 library, a build configuration error inadvertently replaced the device's secure hardware random number generator with a predictable software-based fallback.
This weakened the randomness of the seeds generated on affected devices, leaving them vulnerable to brute-force attacks.
Coldcard devices running firmware versions between 4.0.0 and the patched releases are affected, but Coinkite has released emergency updates to fix the issue.