Firmware Bug Causes $38 Million Bitcoin Drain from Coldcard Wallets
Critical Firmware Bug in Coldcard Wallets Results in $38 Million Theft
A significant vulnerability in Coldcard’s firmware led to the drain of approximately 594 BTC, valued at about $38 million, from around 500 wallets. This incident occurred on July 31, 2026, within a mere 25 minutes.
Details of the Vulnerability
According to Coinkite, the manufacturer of Coldcard wallets, an attacker exploited a seed generation flaw that had existed since March 2021. This bug effectively reduced the entropy of Mk3 seeds from 128 bits to around 40 bits, rendering private keys vulnerable to brute force attacks.
The Impact of the Attack
The attack initiated at 2:14 a.m. UTC, when the attacker began to transfer cryptocurrencies out of Coldcard wallets. By 2:39 a.m., nearly 600 BTC had been consolidated into a single address. The theft was not facilitated through phishing, malware, or physical access, but rather due to the predictable nature of private key generation.
Technical Explanation of the Flaw
Coinkite revealed that the bug originated from a build error in the firmware. Specifically, during the seed generation process, the firmware erroneously utilized a software fallback instead of the intended hardware random number generator. This oversight allowed for the weakened seeds to be generated, which appeared valid but lacked the necessary security robustness.
Current Models Affected
Every model of Coldcard currently in use – including the Mk4, Q, and Mk5 – was found to have varying degrees of susceptibility. The Mk4 and other newer models yield less than 72 bits of entropy, which, while better than the Mk3, still falls far short of the standard.
Remediation and Steps for Users
Coinkite has urged users affected by this exploit to migrate their funds immediately. Unlike typical software fixes, updating the firmware does not rectify existing compromised seeds. Affected users must create new seeds and migrate their holdings to secure their assets.
Concerns Over Security and Trust
The incident raises crucial questions about the reliability of hardware wallets. If Coldcard, a favored choice among security-conscious users and institutions, could overlook such a critical flaw, the confidence in hardware wallets as a solitary security measure for significant holdings comes into question. Conducting security audits, even with AI assistance, requires rigorous and thorough human oversight to ensure vulnerabilities are adequately identified.
Conclusion
This breach signifies not just a financial loss but a potential shift in how users perceive hardware wallet trustworthiness. As the cryptocurrency space grows, safeguarding mechanisms must adapt and enhance to address emerging threats.
Source: crypto.news