Coldcard Wallet Flaw Exposed? Hacker Quietly Drains 1,082 BTC

Blockonomics
Bybit


A firmware flaw that remained unnoticed for years has resulted in one of the largest Bitcoin hardware wallet thefts in recent months. More than 1,082 BTC, worth around $70 million, was quietly stolen from over 1,100 wallets before the wallet maker publicly warned users about the security issue.

Old Firmware Bug Allowed Hacker to Recreate Bitcoin Wallet Keys

According to research from Galaxy Research, the attacker drained 1,196 Bitcoin addresses between 01:10 and 01:51 UTC on July 30, emptying around 1,082.65 BTC within just 41 minutes. The attack happened almost 30 hours before wallet manufacturer Coinkite publicly warned users that certain Coldcard devices could be vulnerable.

Rather than hacking the devices directly, researchers believe the attacker recreated wallet private keys offline by exploiting a weakness in how some Coldcard wallets generated recovery seed phrases.

The attack targeted wallets created on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3, originally released in March 2021.

Tokenmetrics
Add Coinpedia as a trusted source in Google NewsAdd Coinpedia as a trusted source in Google News

Galaxy Research noted that every transaction used the same unusually high 30 sat/vB transaction fee and left no change output, suggesting the attacker already possessed the private keys and simply automated the withdrawals.

How the Coldcard Bug Weakened Wallet Security

Security researchers explained that the issue began with a firmware update released in 2021.

Hardware wallets normally generate recovery phrases using a dedicated hardware random number generator, making wallet keys practically impossible to guess. However, engineers at Block found that a coding mistake accidentally disabled this hardware randomness on affected devices.

Instead, wallets relied on a software-based random number generator using predictable information such as the device serial number and internal clock.

This reduced the effective security of wallet seed phrases from the expected 128 bits of entropy to around 40 bits on affected Mk3 devices, making large-scale brute-force attacks possible with modern computing power.

Coinkite later expanded the warning to include certain Mk4, Mk5 and Coldcard Q firmware versions, where entropy was reduced to around 72 bits, although the company said newer hardware architecture significantly reduced the overall risk.

Millions in Bitcoin Remain Frozen

The stolen Bitcoin was quickly consolidated into several wallets, with researchers identifying one address that still holds more than 562 BTC. Other wallets contain 398 BTC, 89 BTC, and 32 BTC, with none of the funds moving after consolidation.

Coinkite has urged anyone who generated a recovery phrase on affected firmware to immediately move funds to a newly created wallet using the latest firmware.

The company also noted that users who protected their wallets with an additional BIP-39 passphrase face much lower risk because the extra passphrase adds another security layer beyond the compromised seed.

Security experts believe the attacker likely generated millions of possible wallet keys in advance and simply waited for matching wallets to appear on the Bitcoin network, warning that additional vulnerable wallets could still be at risk if owners do not migrate their funds.

Was this writing helpful?

Story Ends Here

Trust with CoinPedia:

CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.

Investment Disclaimer:

All opinions and insights shared represent the author’s own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.

Read the Next News





Source link

Coinmama

Be the first to comment

Leave a Reply

Your email address will not be published.


*