Coldcard Firmware Bug Drains 594.48 BTC From Hardware Wallets

iconNS3
Share
AI summary iconSummary
BTC news today reports a Coldcard firmware bug that led to the loss of 594.48 BTC, valued at roughly $38.3 million. NS3 found a broken RNG check affected multiple wallet models, making keys predictable based on serial numbers and internal clocks. Coinkite and Block's engineers confirmed weak randomness in devices running certain 2021-era firmware. Newer models still limit outcomes to around four billion combinations. Coinkite advises users to create new seeds on updated hardware immediately. Affected Mk3 users who generated a seed after firmware 4.0.1 are at risk, while Mk4, Q, and Mk5 are not, according to initial analysis. This BTC update highlights the urgent need for wallet security checks.

Key Point

A Coldcard firmware error disabled secure random number generation across multiple hardware wallet generations, and attackers have drained 594.48 BTC worth about $38.3 million. Coinkite and Block’s Bitcoin engineering team traced the bug to a broken RNG check that made wallet keys depend on predictable serial-number and internal-clock details. Devices running certain firmware released since 2021 get almost no real randomness, and newer models still narrow possible outcomes to about four billion combinations. Coinkite recommends affected users generate a brand new seed on updated hardware and move funds right away, because firmware updates cannot undo weak seeds. Coinkite said Mk3 users who generated a seed after firmware 4.0.1 may be at risk, while Mk4, Q and Mk5 are not affected based on early analysis.

Why it matters: Weak seed generation can turn self-custody into direct key-exposure risk and may reduce trust in hardware wallet security.

Market Sentiment

Bearish, Stress-on, Tech-driven, De-risking.

Reason: The confirmed drain of 594.48 BTC from affected Coldcard seeds creates direct custody-risk pressure for Bitcoin holders.

Similar Past Cases

In 2023, Trust Wallet fixed a browser-extension wallet-generation vulnerability that led to about $170,000 in user losses, and affected addresses created during the vulnerable window required user remediation. (The Block) Difference: The Trust Wallet case involved a browser extension, while the Coldcard case involves hardware wallet firmware and larger reported Bitcoin losses.

Ripple Effect

The main spillover channel is self-custody confidence, because weak seed generation can make a secure-looking wallet dependent on predictable data. If more affected firmware is confirmed, then the issue may spread from isolated wallets to broader hardware-wallet trust. Public-key exposure can also make the risk persist for funds derived from weak seeds.

Opportunities & Risks

Opportunities: When Coinkite and Block close their firmware review, then confirmation that fewer models are affected is a potential stabilization signal for hardware-wallet confidence. If an affected user has a seed generated on Mk3 after firmware 4.0.1, then rotating to a brand new seed on updated hardware reduces key-exposure risk.

Risks: If the review extends the affected firmware set, then reducing reliance on old seeds limits downside from delayed theft discovery. If funds remain on weak seeds after the fix, then the private-key risk may persist despite firmware updates.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.