Bitcoin Wallet Flaw Drains 594 BTC From Coldcard Wallets in 25 Minutes

Blockonomics


Set as Google Preferred SourceFollow on Google News

TLDR

  • An attacker drained about 594 BTC from roughly 500 Coldcard-linked wallets in 25 minutes.
  • Around 562 BTC was consolidated into one address after the wallet sweep.
  • The flaw affected seeds generated on Coldcard Mk3 firmware versions 4.0.1 to 5.0.3.
  • Coinkite said Mk4, Mk5, and Q devices are not affected based on early analysis.
  • Block traced the issue to weak randomness tied to serial numbers and clock registers.

A major Bitcoin wallet flaw has drained about 594 BTC, worth nearly $38 million, from roughly 500 older single-signature wallets linked to Coldcard key-generation weakness.

Bitcoin Wallet Flaw Hits Older Coldcard Seeds

The attack unfolded between 01:31 and 01:56 UTC on Friday. During that 25-minute window, an attacker moved 1,324 chunks of Bitcoin across about 500 transactions.

The funds were taken within a three-block window, showing a fast and coordinated sweep. Around 562 BTC was later consolidated into one address that had not moved at the time of reporting.

Every affected wallet was single-signature and held more than 0.15 BTC. Many wallets had been inactive for years, while the coins involved dated from 2021 to 2026.

The issue was traced to how some Coldcard hardware wallets generated wallet seeds. Coldcard is a Bitcoin-only hardware wallet made by Canadian firm Coinkite.

Coldcard devices are designed to keep Bitcoin private keys offline. However, exposure in this case depends on the firmware used when the wallet seed was created, not when the hardware was purchased.


Zuna


Randomness Bug Made Some Seeds Guessable

A wallet seed should come from a large random pool, making private keys practically impossible to guess. The affected Coldcard firmware failed to use that protection correctly.

Block’s Bitcoin engineering and security teams said a build setting caused the device to skip its hardware randomness generator. A supporting library checked only whether the setting existed, not whether it was switched on.

That error pushed key generation toward a weaker software substitute. The substitute used details such as the chip serial number and clock registers.

Those details are not secrets. A serial number is fixed factory information, while clock values can be narrowed or measured by an attacker using similar hardware.

Block traced the change to a March 1, 2021 commit that shipped in firmware 4.0.0. Coinkite later warned users who generated seeds on a Coldcard Mk3 running firmware 4.0.1 through 5.0.3.

Coinkite said, “Mk4, Q and Mk5 are not affected based on our early analysis.” The company also said it is still investigating and plans to publish a more detailed technical review.

The weakness may reach beyond regular wallet seeds. The same generator was also used for paper wallet private keys, seed-splitting masks, device cloning keys, and Key Teleport transfers.

Coinkite Urges Users to Move Funds Carefully

Coinkite advised affected users to create a new wallet using unaffected hardware. The company also urged users to verify backups and receiving addresses before moving larger balances.

Users with BIP-39 passphrases on affected wallets may face lower risk. Coinkite still advised caution, especially for anyone who generated a seed on the affected Mk3 firmware versions.

Experienced users were also given a dice-roll seed generation method. That method avoids the Mk3 random-number generator and relies on manual randomness instead.

Block said it disclosed its findings to Coinkite, and Coinkite acknowledged the issue. Both teams described their work as preliminary, while Block said publication became urgent because exploitation was already underway.





Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*