Key facts
- A bug in Coldcard's seed generation code allowed hackers to steal over $100 million in Bitcoin.
- The vulnerability affected approximately 7,300 users and 1,596 bitcoin.
- The flaw was introduced during a major software update in 2021 and went unnoticed for years.
- Bitcoin developer James O’Beirne identified the code changes as originating from Coinkite co-founder Peter Gray.
- The bug caused the wallet to use a less secure software generator for randomness instead of a dedicated hardware generator.
A significant security flaw in Coldcard hardware wallets has led to the theft of over $100 million in Bitcoin from approximately 7,300 users. The vulnerability, present for years, was not in the hardware's air-gapped nature but in the process used to generate the secret seed phrases that protect users' funds.
Jonathan Goodman, a Toronto entrepreneur, reported losing 18.25 bitcoin, valued at over $1.17 million at the time, on July 29, stating he had followed all recommended security practices. His loss was part of a larger series of attacks, with Galaxy Research estimating that 1,596 bitcoin were stolen. At least 15 different attackers were believed to be exploiting the flaw, which did not require physical access to the devices.
The core security premise of hardware wallets like Coldcard is that private keys never leave the secure chip. However, the bug in Coldcard's seed generation meant that the secrets were derived from a less robust source. This flaw was introduced during a major software update in 2021, identified by Bitcoin developer James O’Beirne, who traced the problematic code to a library developed under the pseudonym "switck." O’Beirne identified "switck" as Coinkite co-founder Peter Gray.
Instead of using a dedicated hardware random number generator, the wallet was configured to use a simpler software generator that relied on device and timing data. This information, not being completely random, allowed attackers to narrow down the possibilities and test seeds more effectively, ultimately compromising the security of users' funds.
