The Full Story of the Coldcard Theft: It Was Doomed in 2021 1️⃣ Timeline of the Theft: In March 2021, a Coldcard firmware update introduced a flaw in the random number generation. On the early morning of July 30, 2026, attackers emptied over a thousand wallets within 40 minutes, stealing more than 1,000 BTC. The community began noticing anomalies that day; Coinkite issued an emergency alert overnight. Over the following days, second and third waves of attacks emerged, bringing the total stolen amount to over 1,300 BTC—nearly $90 million. 2️⃣ Cause of the Theft: The core of any cold wallet is its 12- or 24-word recovery phrase. Normally, these words are generated using true randomness—so vast in possibilities that they’re as impossible to guess as individual stars in the universe. But since 2021, Coldcard had a critical flaw: It was supposed to use a hardware-based true random number generator, but due to a misconfiguration, it instead relied on a weak pseudo-random source. This weak source depended only on the device’s serial number and internal clock—offering a tiny, computationally feasible range of possibilities. Hackers precomputed all possible weak keys, then scanned the blockchain for addresses containing funds—and transferred them out immediately. Again… damn it.
炼金叔叔Share

Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.