A firmware flaw in Coldcard hardware wallets, manufactured by Canadian firm Coinkite, has been exploited, leading to significant Bitcoin theft. The vulnerability originated from a March 2021 integration error that incorrectly routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the intended STM32 hardware random number generator (RNG). This made seed phrases predictable, allowing attackers to potentially reproduce candidate output streams offline.
Digital asset research firm Galaxy Research identified an initial wave of transactions on July 30, draining approximately 1,082.65 BTC, valued at $70.2 million, from 1,196 addresses in 41 minutes. This attack occurred about 30 hours before Coinkite publicly disclosed the flaw. Galaxy Research later identified second and third waves, raising the estimated total to 1,367.05 BTC, worth approximately $88.6 million, stolen from 4,585 addresses. Some reports indicate the total stolen could be as high as $130 million.
The attackers used an automated tool, evidenced by every sweep paying an identical hardcoded fee rate of 30 satoshis per virtual byte and leaving no change output.
Coinkite shipped emergency firmware updates for all affected models and release tracks on July 31. However, installing the update does not repair an existing, compromised seed. Coinkite advises owners with exposed seeds to generate a new one on patched firmware and move their coins, as restoring an old seed to updated firmware or another wallet carries the weakness forward. The company also destroyed its remaining inventory of Coldcard devices following the reports of theft.
In the wake of the vulnerability disclosure and thefts, a new phishing campaign is impersonating Coldcard. These emails, sent from addresses like compliance@coldcardteamnews.com with subjects like "Hardware audit now available," claim a security audit is underway and direct users to fake websites. The campaign aims to trick users into installing ScreenConnect remote access software, potentially giving attackers control over victims' systems.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new phishing campaign is impersonating COLDCARD to trick users into installing ScreenConnect remote access software, capitalizing on recent fears surrounding a disclosed wallet vulnerability and Bitcoin theft. The campaign uses fake security audit emails and websites to deliver a batch file that installs the remote access tool, potentially allowing attackers to control victims' systems.
Multiple hacker groups have stolen approximately $130 million from Bitcoin owners using Coldcard hardware wallets by exploiting a flaw in how these offline devices generate seed phrases. This incident highlights a significant vulnerability in a product designed for secure offline cryptocurrency storage, impacting users who believed their assets were protected.
Coinkite, the maker of Coldcard Bitcoin hardware wallets, destroyed its remaining inventory of devices after a firmware vulnerability led to over $88 million in Bitcoin being stolen from customers. The company confirmed a previously known vulnerability from March 2021 was exploited, affecting 4,585 addresses and prompting the destruction of vulnerable units and release of a patched firmware.
A vulnerability in COLDCARD hardware wallet firmware, specifically an integration error in its random number generator (RNG) code, is suspected to have led to the theft of approximately $88.6 million in Bitcoin. The flaw caused the wallets to use a deterministic software generator instead of a secure hardware RNG, making seed phrases predictable and allowing attackers to drain funds from thousands of wallets.
A firmware flaw in Coldcard hardware wallets, specifically an error in seed generation, allowed an attacker to drain 1,082.65 BTC, valued at $70.2 million, from 1,196 addresses in 41 minutes. The vulnerability stemmed from a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator instead of the intended hardware random number generator. Coinkite has released emergency firmware updates, but affected users must generate new seeds and transfer their funds to secure them.