Coldcard Firmware RNG Bug Linked to $88.6M BTC Heist — Users Urged to Migrate Seeds

iconChainGPT
Share
AI summary iconSummary
A Coldcard firmware RNG bug has been tied to a $88.6M BTC heist, with on-chain data showing 1,367.05 BTC drained from 4,585 addresses. The flaw, linked to a deterministic RNG fallback, impacted Coldcard Mk2 to Mk5 models with certain firmware versions. Coinkite has issued patches, urging users to generate new seeds and avoid reusing old ones. Researchers warn compromised seeds can’t be fixed, and users should migrate funds and store backups offline. With BTC price under pressure, altcoins to watch may see shifts as traders reassess risk.

Headline: Coldcard users urged to urgently migrate seeds after attackers drain an estimated $88.6M A high‑alert warning hit Coldcard hardware‑wallet users on Aug. 1 after on‑chain research tied multiple theft waves to seeds created by vulnerable Coldcard firmware. Dogecoin contributor Mishaboar told anyone who has ever used a Coldcard device to “migrate your funds to a new wallet immediately,” and not to reuse the old seed or enter recovery words into an internet‑connected computer. What researchers found - Galaxy Research’s latest on‑chain analysis identified three suspected attack waves that together moved 1,367.05 BTC (about $88.6 million) out of 4,585 addresses. That figure is an observed estimate, not yet confirmed by Coinkite, law enforcement, or every affected user. - The biggest wave removed 1,082.65 BTC from 1,196 addresses in roughly 41 minutes on July 30. A later wave swept about 208 BTC from 1,912 addresses, with the average balance per address falling to just over 0.1 BTC — suggesting attackers shifted focus from larger holdings to many smaller wallets. - Galaxy said each wave looked internally consistent with a single operator, but could not prove all waves were run by the same actor. The third wave used different collection techniques (separate destination addresses, batching multiple victims into single transactions and only checking the default derivation path). - Galaxy also warned its known patterns won’t catch every theft — other attackers could make valid transactions without repeating the observed fees, destination formats, or collection methods. Which Coldcard models and firmware are affected - Coinkite’s advisory narrows the issue to seeds created on: - Mk2 and Mk3 devices running firmware v4.0.1 through v4.1.9 - Mk4 and Mk5 devices with firmware before standard v5.6.0 or Edge v6.6.0X - Coldcard Q: fixed in standard v1.5.0Q and Edge v6.6.0QX - Mk1 devices are outside the identified firmware regression. TAPSIGNER, OPENDIME and SATSCARD are unaffected because they use different codebases. - Coinkite says its investigation is ongoing and will publish a formal technical report. Technical root cause - Block’s Bitcoin engineering and security team traced the flaw to a firmware integration error: when generating seeds the affected builds used a deterministic MicroPython fallback instead of the STM32 hardware random‑number generator. On Mk2 and Mk3 v4 firmware this fallback added essentially no cryptographic entropy. Later models received a limited secure‑element reseed, but earlier seeds remained weak. - Block emphasizes this is its current technical view and that it hasn’t empirically tested every device. What users should do now - Do not reuse your old Coldcard seed. Generate an entirely new seed on a patched device or a different wallet. - Install Coinkite’s fixed firmware for your model before creating any replacement seed. - Record and verify the new backup, check the receiving address on the device screen, and send a small test transaction first. Only transfer the remaining balance after confirming the test funds arrived. - Keep your old backup until the full migration is confirmed. - Never enter a seed phrase into an internet‑connected computer; store offline copies in separate secure locations to reduce exposure to phishing, malware, and cloud sync mistakes. - Mishaboar reiterated adding an extra BIP‑39 passphrase (25th/13th word on Coldcard) and strong passphrases helps, but Coinkite warns a passphrase does not repair an already‑compromised seed. Short or reused passphrases remain vulnerable. Limited exception and caveats - Coinkite said users who added at least 50 fair, independent and private dice rolls before the final seed words were produced (contributing ≥128 bits of independent entropy) may be safe. Anyone who entered fewer than 50 rolls, can’t remember the count, or exposed the roll sequence should migrate. - Patches fix future seed generation but cannot add entropy retroactively to seeds that were already created. Moving an insecure seed into another wallet preserves the weakness. Comments and wider implications - Bitcoin investor Anthony Pompliano noted the incident highlights how technically demanding secure self‑custody can be — the attackers reproduced private keys, but the Bitcoin protocol itself was not compromised. - The losses have also fueled discussion about institutional custody and spot‑Bitcoin ETFs as alternatives for investors who prefer not to manage private keys. What’s next - Coinkite has released firmware fixes for affected models and continues its investigation. Galaxy and other researchers may update address analysis as they find more victims. - Until investigations complete, the $88.6 million figure remains an on‑chain estimate rather than a confirmed total. If you own any Coldcard device, check Coinkite’s official advisory for your model and update firmware immediately before creating a new seed.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.