Coldcard Hardware Wallet Bug Allowed Hackers to Steal Over $88 Million in Bitcoin

yesterday / 06:43 7 sources negative

Key takeaways:

  • Stolen BTC liquidation could create minor price headwinds, but fear may drive users toward centralized exchanges.
  • Hardware wallet security concerns might accelerate multi-signature adoption, benefiting ecosystems like Safe (SAFE).
  • This flaw reinforces the case for regulated custody and Bitcoin ETFs, shifting capital away from direct self-storage.

A critical vulnerability in Coldcard hardware wallets, dating back to a 2021 software update, allowed attackers to guess bitcoin wallet keys and drain over 1,300 BTC—worth approximately $88.6 million at the time of reporting. The flaw, disclosed by manufacturer Coinkite on July 30, caused Mk2 and Mk3 models to generate seed phrases using a predictable software program instead of the device’s dedicated chip for true randomness. Newer Mk4, Mk5, and Q models mixed in some genuine randomness but still fell far short of the required 128 bits of entropy.

The issue originated when a coding error quietly switched seed generation to a pseudo-random number generator based mostly on internal clocks. A safeguard meant to detect this mistake checked only for the existence of a setting, not whether it was active, allowing the bug to remain undetected for years. Security researchers at Block later confirmed that effective randomness in affected seeds was as low as 40 bits—dramatically reducing the possible combinations and making brute-force attacks feasible.

By August 2, Galaxy Research had identified 4,500 addresses tied to the exploit, with losses continuing to climb. Coinkite released patched firmware (version 4.2.0 for Mk2/Mk3) but cautioned that updates do not fix already-generated weak seeds. Users who set up wallets without adding at least 50 dice rolls or a separate passphrase were urged to create new seeds and transfer funds. Competing wallet makers Ledger and Trezor quickly stated their devices were not affected, emphasizing their use of certified true random number generators and multiple independent entropy sources.

Coinkite’s open-source code, normally a security advantage, likely helped an attacker find the flaw via automated scanning—a method that the company itself had tried unsuccessfully weeks earlier. The incident underscores that hardware wallets rely heavily on secure firmware, and even physical isolation cannot compensate for software-level weaknesses. An ongoing investigation may yet revise the final theft tally and technical details.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.