Coldcard Vulnerability Turns “Impossible to Guess” Seeds Into Guessable Ones, Draining 594 BTC

Coinmama
fiverr


TL;DR

  • An attacker drained roughly 594 BTC worth about $38 million from around 500 Coldcard wallets during a coordinated 25-minute sweep early Friday.
  • The flaw bypassed hardware randomness and generated seeds from predictable chip data, shrinking the secret space meant to make private keys effectively unguessable.
  • Coinkite issued emergency firmware updates, but existing weak seeds remain vulnerable and must be replaced; the company suspects AI helped uncover the bug at scale.

A vulnerability in Coldcard hardware wallets allowed an attacker to drain roughly 594 BTC, worth about $38 million, from around 500 single-signature wallets in only 25 minutes. The sweep occurred between 01:31 and 01:56 UTC on Friday, moving funds through 500 transactions inside a three-block window with remarkable speed and precision. A device designed to keep keys offline instead produced seeds that could be narrowed down and guessed. Investigators traced 562 BTC into one address that had not moved, while evidence showed many affected wallets had remained dormant for years before the coordinated theft began.

Predictable device data undermined Coldcard’s randomness

The failure originated in Coldcard firmware introduced during March 2021. A build setting caused devices to bypass their hardware randomness generator, while a supporting-library check tested only whether that setting existed, not whether it was enabled. Key creation then fell back to software seeded with a chip serial number and clock registers, neither of which is secret or genuinely unpredictable to attackers. The supposedly enormous search space protecting each wallet was reduced by predictable device information. Exposure depends on the firmware running when the wallet was created, rather than when the hardware itself was purchased.

okex

An attacker drained roughly 594 BTC worth about $38 million from around 500 Coldcard walletsAn attacker drained roughly 594 BTC worth about $38 million from around 500 Coldcard wallets

Coinkite warned users who generated seeds on Mk3 devices running firmware 4.0.1 or later, while describing its conclusions about newer models as preliminary. The company released emergency updates for Mk4, Mk5 and Q devices, but installing patched firmware cannot strengthen a seed already produced under vulnerable conditions. Owners must create a fresh seed and transfer funds, because software updates cannot rewrite compromised randomness. Recommended safeguards include a strong BIP-39 passphrase, at least 99 dice rolls, or both, while unsupported Mk3 users face a separate and potentially complicated migration process for protecting any remaining balances safely.

The manufacturer believes an attacker may have used artificial intelligence to inspect older versions of its open-source firmware and discover the flaw. That conclusion remains an assumption, not confirmed attribution, and carries an uncomfortable irony: Coinkite said its own AI-assisted review weeks earlier found nothing serious. The incident shows how the same analytical tools can strengthen defenders or accelerate exploitation. Beyond wallet seeds, the flawed generator may also have affected paper-wallet keys, seed-splitting masks, cloning keys and Key Teleport transfers, widening the ongoing security review beyond the 594 BTC already stolen from hundreds of victims.



Source link

Blockonomics

Be the first to comment

Leave a Reply

Your email address will not be published.


*