Bitcoin Cold Wallets Lose $70M in Attack That Never Touched Devices

iconCoinDesk
Share
AI summary iconSummary
Bitcoin breaking news: Over 1,000 bitcoin, valued at $70 million, was stolen from 1,196 wallets in 41 minutes on July 30. Galaxy Research tracked the theft, which used a Coldcard firmware flaw to generate weak random numbers. This let attackers guess private keys and move 1,082.65 BTC across six blocks between 01:10 and 01:51 UTC. Funds are now in four addresses. Coinkite warned Mk3 users, saying newer models are safe. Block’s Clay Garrett said the attacker used a paid blockchain data account to track addresses during the Bitcoin news event.

More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced.

Galaxy Research mapped the full event on Friday, finding 1,082.65 BTC swept between 01:10 and 01:51 UTC across six blocks, with three intervening blocks containing nothing, which suggests the transactions were broadcast in batches rather than continuously.

The proceeds sit in four addresses and have not moved. Early reporting captured only one of those addresses, which is why the figure has grown.

The size of the attack is much smaller than some of the bigger attacks this year, but the mechanism is what makes this unusually — and why the attack is such a big deal.

Most crypto theft involves getting to something. An exchange is breached, a contract is tricked, a key is phished off a laptop. The defence has always been distance, which is precisely what a hardware wallet sells. Keep the key on a device that never connects to the internet and, theoretically, there is nothing for an attacker to touch.

When a wallet is created, the device is supposed to pick a number so large and so unpredictable that guessing it is impossible.

That number is the seed, and every address and private key derives from it by fixed public rules. Coldcard's firmware was meant to draw that number from a dedicated hardware randomness generator. An internal build setting told it to skip that generator, and a check in a supporting library tested only whether the setting existed rather than whether it was switched on.

Key generation fell through to a basic software substitute seeded from the chip's serial number and its clock registers. This serial number is fixed factory metadata, and clock values are timing state an attacker can narrow down or measure on a device of their own.

The consequence was that the range of keys the device could ever produce collapsed from unimaginably vast to countable. Security teams found that generation of keys could be determined on the older Mk2 and Mk3 — numbers for different models of Coldcard — but on the Mk4, Q and Mk5, they put the range at roughly four billion possibilities.

Four billion is a large number to a person but a small one to a computer. An attacker generates candidate seeds on their own hardware, derives the addresses each would produce, and checks those addresses against the public blockchain, which anyone can download.

Every step of that runs on the attacker's machine. The victim's device is not involved at any point and could be powered off in a safe on another continent.

Galaxy's breakdown shows the process running. Of the drained wallets, 1,183 used the modern native segwit address format, seven used an older standard and six an older one still. Nobody targets a specific victim across three address formats at once.

That is systematic enumeration, checking each candidate seed against every path it might have produced. The operator can widen the search, refine it and return whenever they choose.

Galaxy warned further waves are likely if owners do not move their funds.

Nor can an owner determine whether they are exposed. There is no test to run against your own wallet that reveals whether your seed sits inside the reproducible range.

Coinkite, Coldcard's maker, has warned Mk3 owners and says its newer devices are unaffected, while Block's report places the Mk2, Mk4, Q and Mk5 in scope as well. Until that is resolved, anyone who generated a seed on the affected firmware has to assume the worst rather than verify it.

The attacker did make one mistake, however.

Block's Clay Garrett said on X that the operator used a paid account at a “well-known blockchain data provider” to query the source addresses during the sweeps, and that the provider's internal logs matched the suspected workflow with what he called extraordinary specificity, down to the number, timing and sequence of requests.

1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source… https://t.co/l5McyhhcNn

— Clay Garrett (@clay_garrett)

The provider appears to have been supplying ordinary services to requests that gave no indication of their purpose. Block has passed the information to authorities.

Cold storage promises that a key is unguessable. Everyone read it as a promise that a key is unreachable, and the cost of finding and exploiting flaws in the first kind keeps falling.

Anthropic published research on Tuesday showing one of its models halving the security of a candidate post-quantum algorithm in 60 hours, against a design that had survived two years of expert review.

Storing a key safely is now the easier half of the problem.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.