Coldcard Firmware Flaw: $38 Million Bitcoin Stolen in Massive Heist

Massive Coldcard Wallet Breach: Critical Firmware Flaw Leads to $38 Million Bitcoin Theft

The cryptocurrency world has been rocked by a sophisticated and swift cyberattack, resulting in the theft of approximately 594 Bitcoins, valued at over $38 million. The breach exploited a deeply hidden “random number generation flaw” within the firmware of Coldcard hardware wallets, allowing hackers to drain nearly 500 cold storage wallets in a mere 25 minutes.

Anatomy of a Lightning-Fast Heist

The audacious attack unfolded with alarming speed between 01:31 and 01:56 UTC on July 31st. In a breathtaking 25-minute window, spanning just three Bitcoin blocks, threat actors executed roughly 500 transactions. These transactions siphoned a staggering 1,324 Bitcoin Unspent Transaction Outputs (UTXOs) from approximately 500 distinct wallets, consolidating a total of 594 Bitcoins.

Following the initial sweep, a significant portion — around 562 Bitcoins — was moved to a single designated address, where it currently remains untouched. Investigations reveal that all targeted wallets were single-signature accounts, each holding more than 0.15 BTC. Intriguingly, many of these addresses had been dormant for years, with funds deposited between 2021 and the present. This timeline strikingly aligns with the period during which the underlying vulnerability is believed to have existed within the Coldcard system.

The Critical Flaw: A Betrayal of Randomness

Coldcard, developed by Canadian company Coinkite, is renowned as a Bitcoin-specific hardware wallet designed to enhance security by keeping private keys offline. Despite its reputation, a fundamental flaw compromised its core security mechanism: the generation of cryptographic keys.

Typically, when a hardware wallet generates a seed phrase (the master key to a user’s funds), it relies on a robust hardware-based random number generator (RNG) to produce highly unpredictable and unguessable sequences. However, a report from Block’s Bitcoin engineering and security team unearthed a shocking oversight in Coldcard’s firmware.

A specific configuration setting within the Coldcard system inexplicably instructed the device to bypass its built-in hardware RNG. Compounding this error, an auxiliary library designed to verify this setting merely checked for its “existence” rather than confirming if it was “activated.” This critical oversight effectively downgraded the vital task of key generation to a software-based alternative.

This software alternative, alarmingly, relied on easily obtainable, non-confidential information: the chip’s unique product serial number and the system’s current time. Since chip serial numbers are fixed factory data and system clock values can be deduced or measured across similar devices, attackers could drastically reduce the scope for brute-force attacks, making the “randomly” generated keys predictable and vulnerable.

Tracing the Vulnerability: A 2021 Firmware Update

Block’s security researchers meticulously traced the origin of this critical code alteration. They discovered that the problematic change was introduced on March 1, 2021, and subsequently pushed to a broad user base with the release of firmware version 4.0.0 that same month. This timeline directly correlates with the deposit dates of many of the stolen funds, suggesting the vulnerability has been silently active for years.

Who is Affected? Urgent Warning for Coldcard Users

Coldcard has released various models over the years, including Mk2, Mk3, Mk4, Q, and Mk5. Crucially, whether a specific device is vulnerable does not depend on its purchase date, but rather on the firmware version running on the device at the moment the wallet’s seed phrase was first generated.

Following the crisis, Coinkite issued an urgent warning, specifically advising users who generated seed phrases on Mk3 devices running firmware version 4.0.1 or higher to exercise extreme caution. Initial analyses suggest that newer models, such as the Mk4, Q, and Mk5, appear to be unaffected at this time, though users of all models should remain vigilant and await further updates from Coinkite.

Block’s Discovery and Public Disclosure

The Block team confirmed that they promptly reported their findings to Coinkite, which subsequently verified the vulnerability. Despite ongoing preliminary analysis and incomplete exploit testing by both parties, Block made the difficult decision to publicly disclose the report. This proactive measure was deemed necessary to alert the wider cryptocurrency community, given that the hackers’ exploitative actions had already commenced and were actively draining funds.

Beyond Seed Phrases: A Wider Security Concern

The ramifications of this flawed random number generator extend beyond just the primary wallet seed phrases. The same compromised RNG was also utilized in several other critical Coldcard functions, including:

  • Paper Wallet private key generation
  • Seed Split masking
  • Device Cloning Keys
  • Key Teleport features

This indicates that the true scope of the disaster, and the potential for further compromise, may be significantly broader than initially understood, affecting multiple layers of Coldcard’s security ecosystem.


Disclaimer: This article is for market information purposes only. All content and views are for reference only and do not constitute investment advice. It does not represent the views and positions of BlockTempo. Investors should make their own decisions and transactions. The author and BlockTempo will not bear any responsibility for direct or indirect losses incurred by investors’ transactions.

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these