Coldcard Wallet Bug Exposes $70 Million Bitcoin Theft Across 1,100 Wallets

Bybit
Paxful


What to know:

  • Coldcard Wallet bug linked to theft of 1,082 BTC worth nearly $70 million from over 1,100 wallets.
  • Firmware flaw reduced recovery seed security, allowing attackers to recover private keys through brute-force methods.
  • Researchers traced the attack to vulnerable Coldcard Mk3 firmware, with later warnings extended to some Mk4, Mk5, and Q devices.

Coldcard Wallet bug has been connected to one of the biggest Bitcoin hardware wallet theft cases that have occurred recently. Over 1,082 Bitcoins worth almost $70 million were stolen from 1,100+ Bitcoin wallets before Coinkite announced this security problem.

As per the research, the hacker did not hack into these devices directly. It is claimed that the bug in the Coldcard Wallet software allowed generating private keys offline, hence allowing access to the wallets.

Galaxy Research revealed that the attacker drained 1,196 Bitcoin wallets from 01:10 UTC to 01:51 UTC on July 30. The attacker stole around 1,082.65 BTC in 41 minutes during the attack period.

okex

The hack took place almost 30 hours before the security alert was posted by Coinkite, warning people about their Coldcard Wallet being compromised due to vulnerabilities in some of its firmware versions. Experts think that the hacker attacked wallets generated from Coldcard Mk3 wallets through firmware versions 4.0.1 to 5.0.3, which were introduced in March 2021.

This report highlighted the fact that each transaction was done using the same rate of 30 sat/vB and without any change outputs. Such similarity in these transactions implies that the attacker already knew the private keys and was just automating his withdrawals rather than targeting individuals.

Also Read | Tether Powers 2026 Growth With Record Profit and Reserves

Coldcard Wallet Warning Expands to More Devices

Security researchers identified the vulnerability that arose from a firmware upgrade released in 2021. The hardware wallets use a hardware random number generator for generating recovery phrases to make it extremely difficult to predict the keys.

However, researchers from Block have shown that a software glitch prevented this feature from being implemented, and so the wallets made use of a software random number generator that used predictable factors such as the serial number of the device and its internal clock.

This weakness led to the weakening of the recovery seed entropy from 128 bits to about 40 bits. This, according to researchers, opened up opportunities for performing brute force attacks in large numbers with current computing technology.

Coinkite later updated their warning to include some firmware of Mk4, Mk5, and Coldcard Q models but noted that new hardware models greatly mitigated the risk.

Users Urged to Move Funds Immediately

The stolen Bitcoins were subsequently consolidated into a few accounts. It has been noted that one such account contains more than 562 Bitcoins, whereas other accounts hold about 398, 89, and 32. The funds have not been moved since their consolidation.

Coinkite recommends that those who had created recovery phrases by means of the compromised firmware of the Coldcard Wallet switch to a new wallet operating under the latest firmware right away.

The company also stressed that those who had an extra BIP-39 passphrase turned on can feel secure, as the passphrase gives one extra level of protection apart from the recovery seed itself. The researchers also stated that other vulnerable wallets can be exploited.

Also Read | Solana Drives 2026 Quantum Resistance Via Alpenglow

This article contains market analysis and price predictions. These are not guarantees. Crypto markets are volatile. Always DYOR. Not financial advice.



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*