Coldcard Wallet Flaw Allows Hacker to Steal 1,082 BTC Before Security Warning

iconCoinpedia
Share
AI summary iconSummary
BTC news today reports a firmware flaw in Coldcard wallets enabled a hacker to steal 1,082.65 BTC ($70.2M) from over 1,100 wallets. The exploit reduced entropy in Coldcard Mk3 seed generation from 128 to 40 bits. Stolen funds were moved to several wallets, with 562 BTC still frozen. Coinkite urged users to move funds to updated firmware wallets. This BTC update highlights the urgency for users to act quickly.

A firmware flaw that remained unnoticed for years has resulted in one of the largest Bitcoin hardware wallet thefts in recent months. More than 1,082 BTC, worth around $70 million, was quietly stolen from over 1,100 wallets before the wallet maker publicly warned users about the security issue.

Old Firmware Bug Allowed Hacker to Recreate Bitcoin Wallet Keys

According to research from Galaxy Research, the attacker drained 1,196 Bitcoin addresses between 01:10 and 01:51 UTC on July 30, emptying around 1,082.65 BTC within just 41 minutes. The attack happened almost 30 hours before wallet manufacturer Coinkite publicly warned users that certain Coldcard devices could be vulnerable.

Rather than hacking the devices directly, researchers believe the attacker recreated wallet private keys offline by exploiting a weakness in how some Coldcard wallets generated recovery seed phrases.

The attack targeted wallets created on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3, originally released in March 2021.

Galaxy Research noted that every transaction used the same unusually high 30 sat/vB transaction fee and left no change output, suggesting the attacker already possessed the private keys and simply automated the withdrawals.

How the Coldcard Bug Weakened Wallet Security

Security researchers explained that the issue began with a firmware update released in 2021.

Hardware wallets normally generate recovery phrases using a dedicated hardware random number generator, making wallet keys practically impossible to guess. However, engineers at Block found that a coding mistake accidentally disabled this hardware randomness on affected devices.

Instead, wallets relied on a software-based random number generator using predictable information such as the device serial number and internal clock.

This reduced the effective security of wallet seed phrases from the expected 128 bits of entropy to around 40 bits on affected Mk3 devices, making large-scale brute-force attacks possible with modern computing power.

Coinkite later expanded the warning to include certain Mk4, Mk5 and Coldcard Q firmware versions, where entropy was reduced to around 72 bits, although the company said newer hardware architecture significantly reduced the overall risk.

Millions in Bitcoin Remain Frozen

The stolen Bitcoin was quickly consolidated into several wallets, with researchers identifying one address that still holds more than 562 BTC. Other wallets contain 398 BTC, 89 BTC, and 32 BTC, with none of the funds moving after consolidation.

Coinkite has urged anyone who generated a recovery phrase on affected firmware to immediately move funds to a newly created wallet using the latest firmware.

The company also noted that users who protected their wallets with an additional BIP-39 passphrase face much lower risk because the extra passphrase adds another security layer beyond the compromised seed.

Security experts believe the attacker likely generated millions of possible wallet keys in advance and simply waited for matching wallets to appear on the Bitcoin network, warning that additional vulnerable wallets could still be at risk if owners do not migrate their funds.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.