S&P 500 5,278.40 +0.45% NASDAQ 16,755.02 +0.67% DOW JONES 38,886.57 +0.32% RUSSELL 2000 2,084.45 +0.15% VIX 13.42 -1.52% GOLD 2,348.30 +0.21% OIL (WTI) 78.62 +0.18% US 10Y 4.28% -0.04%
All articles Federal Reserve

Coldcard Wallet Flaw Exposed? Hacker Quietly Drains 1,082 BTC

Coldcard Wallet Flaw Exposed? Hacker Quietly Drains 1,082 BTC

A firmware flaw that remained unnoticed for years has resulted in one of the largest Bitcoin hardware wallet thefts in recent months. More than 1,082 BTC, worth around $70 million, was quietly stolen from over 1,100 wallets before the wallet maker publicly warned users about the security issue.

Old Firmware Bug Allowed Hacker to Recreate Bitcoin Wallet Keys

According to research from Galaxy Research, the attacker drained 1,196 Bitcoin addresses between 01:10 and 01:51 UTC on July 30, emptying around 1,082.65 BTC within just 41 minutes. The attack happened almost 30 hours before wallet manufacturer Coinkite publicly warned users that certain Coldcard devices could be vulnerable.

Rather than hacking the devices directly, researchers believe the attacker recreated wallet private keys offline by exploiting a weakness in how some Coldcard wallets generated recovery seed phrases.

The attack targeted wallets created on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3, originally released in March 2021.

Add Coinpedia as a trusted source in Google News

Galaxy Research noted that every transaction used the same unusually high 30 sat/vB transaction fee and left no change output, suggesting the attacker already possessed the private keys and simply automated the withdrawals.

How the Coldcard Bug Weakened Wallet Security

Security researchers explained that the issue began with a firmware update released in 2021.

Hardware wallets normally generate recovery phrases using a dedicated hardware random number generator, making wallet keys practically impossible to guess. However, engineers at Block found that a coding mistake accidentally disabled this hardware randomness on affected devices.

Instead, wallets relied on a software-based random number generator using predictable information such as the device serial number and internal clock.

This reduced the effective security of wallet seed phrases from the expected 128 bits of entropy to around 40 bits on affected Mk3 devices, making large-scale brute-force attacks possible with modern computing power.

Coinkite later expanded the warning to include certain Mk4, Mk5 and Coldcard Q firmware versions, where entropy was reduced to around 72 bits, although the company said newer hardware architecture significantly reduced the overall risk.

Millions in Bitcoin Remain Frozen

The stolen Bitcoin was quickly consolidated into several wallets, with researchers identifying one address that still holds more than 562 BTC. Other wallets contain 398 BTC, 89 BTC, and 32 BTC, with none of the funds moving after consolidation.

Coinkite has urged anyone who generated a recovery phrase on affected firmware to immediately move funds to a newly created wallet using the latest firmware.

The company also noted that users who protected their wallets with an additional BIP-39 passphrase face much lower risk because the extra passphrase adds another security layer beyond the compromised seed.

Security experts believe the attacker likely generated millions of possible wallet keys in advance and simply waited for matching wallets to appear on the Bitcoin network, warning that additional vulnerable wallets could still be at risk if owners do not migrate their funds.

Was this writing helpful?

Story Ends Here

Trust with CoinPedia:

Investment Disclaimer:

All opinions and insights shared represent the author’s own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.

Read the Next News

Eagle One Intelligence

The edge serious investors read.

Macro shifts, market structure, and the ideas worth tracking — straight to your inbox.

Note. For informational purposes only. Not financial advice. Past performance does not guarantee future results.