Connect with us

AI Security

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Published

on

A vulnerability in Coldcard hardware wallets has been linked to a major Bitcoin theft campaign that drained more than 1,000 cryptocurrency addresses within minutes, exposing millions of dollars in digital assets to potential compromise.

Security researchers at Galaxy Research traced a large-scale Bitcoin sweep on July 30 that removed 1,082.65 BTC, worth approximately $70.2 million at the time, from 1,196 wallet addresses in just 41 minutes. The investigation connected the incident to a firmware-related weakness affecting certain Coldcard hardware wallet models developed by Canadian company Coinkite.

The issue originated from a 2021 firmware integration mistake that caused affected devices to generate wallet seeds using a deterministic software-based pseudorandom number generator (PRNG) instead of relying on the device’s dedicated hardware random number generator (RNG).

Weak Randomness Could Allow Offline Seed Recovery

Hardware wallets depend on strong randomness to generate private keys and recovery phrases. If the randomness source is predictable, attackers may be able to recreate possible wallet seeds without physically accessing the device.

According to researchers, an attacker with enough information about factors such as a device’s unique identifier, timing data, and previous random number generation activity could reproduce possible output sequences offline.

Attackers could then generate candidate wallet seeds, derive associated Bitcoin addresses, and compare them against publicly available blockchain records to identify wallets holding funds.

Researchers emphasized that no public evidence has shown an attacker directly reconstructing a victim’s seed phrase. However, the vulnerability created conditions where exposed wallets could potentially become vulnerable.

Emergency Firmware Update Released

Coinkite released emergency firmware updates for affected Coldcard models on July 31. However, the company warned that updating firmware does not fix seeds that were already generated using vulnerable versions.

Users whose recovery seeds may have been created during the affected firmware period are advised to:

  • Generate a new wallet seed using updated firmware.
  • Transfer Bitcoin holdings to the new wallet.
  • Avoid restoring old vulnerable seeds into updated devices.

Simply moving an affected seed to a newer wallet does not remove the underlying risk because the weakness exists in the original seed generation process.

Technical Cause Behind the Vulnerability

Researchers identified the root cause as a firmware configuration problem involving Coldcard’s random number generation implementation.

Coldcard’s production configuration disabled a hardware RNG setting while relying on a custom wrapper. A software check incorrectly detected the RNG feature as available, causing affected builds to use MicroPython’s fallback random generator instead.

The fallback system relied on device-specific information, including chip identifiers and timer values, but did not collect sufficient additional entropy after initialization.

Researchers estimated that affected models generated significantly weaker randomness compared with the expected security level of a standard Bitcoin recovery phrase.

Reported exposure ranges include:

  • Coldcard Mk3: Vulnerable versions 4.0.1 through 4.1.9, fixed in version 4.2.0.
  • Coldcard Mk4 and Mk5: Vulnerable versions before 5.6.0.
  • Coldcard Q: Vulnerable versions before 1.5.0Q.
  • Edge builds: Vulnerable versions before 6.6.0X for Mk4/Mk5 and before 6.6.0QX for Q.

The company noted that wallets created using at least 50 private and independent dice rolls are not affected by this specific weakness. Users who are unsure about their entropy source are encouraged to migrate funds to a newly generated wallet.

Passphrases and Multisignature Protection

Coinkite stated that a strong BIP-39 passphrase creates an additional layer of wallet separation because funds protected by the passphrase cannot be accessed using the seed words alone.

However, the company still recommends replacing potentially affected seeds.

Multisignature wallets may reduce risk if the signing devices are not all affected by the vulnerability. Other Coinkite products, including TAPSIGNER, OPENDIME, and SATSCARD, use separate software and are not impacted.

Additional Bitcoin Losses Under Investigation

Galaxy Research later identified additional suspected waves of Coldcard-related wallet sweeps. The firm increased its estimated total affected amount to 1,367.05 BTC, valued at approximately $88.6 million, across 4,585 addresses.

Researchers said some transaction patterns suggest certain theft waves may have involved the same operator, but they cautioned that blockchain analysis alone cannot prove that every affected address was generated using vulnerable Coldcard firmware.

Galaxy has reported hundreds of suspected attacker-controlled addresses to investigators, compliance organizations, and security teams.

The identity of the attacker remains unknown. Researchers also warned that blockchain transactions alone cannot always distinguish between malicious theft and legitimate wallet movements because both can appear similar on-chain.

Hardware Wallet Security Lessons

The Coldcard incident highlights the importance of secure random number generation in cryptocurrency systems. Even devices designed to protect private keys can become vulnerable when firmware errors weaken the process used to create wallet credentials.

Cryptocurrency users should keep wallet firmware updated, verify seed generation procedures, and consider migrating funds whenever a wallet-generation flaw is discovered.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO