Block Traces $38M COLDCARD Bitcoin Theft to Blockchain Services Provider

iconCryptoBriefing
Share
AI summary iconSummary
Block’s engineering team has identified the attacker behind the $38M Bitcoin news theft from COLDCARD hardware wallets as a blockchain news services provider. The incident on July 30 saw 594 BTC drained from about 500 wallets in 25 minutes. A flawed firmware update from March 2021 exposed the hardware random number generator, enabling seed replication. Block and Coinkite disclosed the flaw urgently before releasing technical details. Coinkite urged users to create new seeds and move funds immediately.

Block’s engineering team has identified the entity behind the COLDCARD hardware wallet exploit, tracing the attacker to a blockchain services provider that was used during the theft.

The breach, which occurred on July 30, drained approximately 594 BTC, worth roughly $38M, from around 500 wallets in a 25-minute window between 01:31 and 01:56 UTC.

Advertisement

A five-year-old firmware bug made it all possible

The root cause traces back to a firmware update from March 2021, specifically version 4.0.0, which deactivated the hardware random number generator on affected COLDCARD devices. The hardware RNG was replaced with a predictable software fallback that used non-secret seed values, meaning an attacker who understood the flaw could replicate wallet seeds derived from device-specific metadata. The affected devices were primarily Mk3 models and some Mk2 units where seeds had been generated under the compromised firmware.

The attacker apparently sat on this knowledge for years, targeting dormant accounts. The 25-minute execution window suggests extensive preparation, with the attacker having pre-computed the vulnerable seeds and scripted the draining process.

Block and Coinkite coordinated urgent disclosure

Block’s engineers, working alongside Coinkite (the company that manufactures COLDCARD), traced the attacker’s on-chain activity to a blockchain services provider. The collaboration enabled what both parties described as urgent disclosure of the vulnerability before full technical details were made public.

Coinkite issued an immediate advisory for users of Mk3 and older models who had generated seeds under the compromised firmware versions. The company’s preliminary assessment indicated that newer models, including Mk4, Q, and Mk5, were not affected by the RNG flaw. The recommended action was to generate entirely new seeds on unaffected hardware and migrate all funds immediately.

What this means for hardware wallet users and the broader market

Bitcoin was trading above $64K during the incident, and the market impact was minimal. The firmware update that introduced the vulnerability was v4.0.0, applied in March 2021. Users who applied that update thought they were improving their security but were instead generating seeds with a compromised RNG.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.