All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Coldcard flaw drains 594 BTC in 25-minute sweep

Created at 31 Jul · 5:21 AM1 source↑ Market-relevant
IN SHORT

An attacker exploited a flaw in Coldcard hardware wallets, stealing approximately 594 bitcoin worth $38 million from about 500 single-signature wallets in under 30 minutes. The vulnerability, introduced in firmware 4.0.0 in March 2021, caused devices to use predictable software-based key generation instead of hardware randomness.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

594 BTCbitcoin stolen
$38 millionvalue of stolen bitcoin
500wallets drained
25 minutestimeframe of attack
March 2021firmware vulnerability introduced
4.0.0vulnerable firmware version
0.15 BTCminimum holdings in drained wallets

Who's Involved

Coldcard
hardware wallet manufacturer with a key generation flaw
Coinkite
maker of Coldcard hardware wallets, issuing warnings
Block
Bitcoin engineering and security teams that reported the flaw
Coldcard flaw drains 594 BTC in 25-minute sweep

↳ Why This Matters

This incident underscores the critical importance of hardware wallet security and the potential for sophisticated exploits to compromise digital assets, even those stored offline. It highlights the risks associated with specific firmware versions and the need for users to stay informed about security vulnerabilities.

Key facts

  • A flaw in Coldcard hardware wallets allowed an attacker to steal approximately 594 bitcoin.
  • The stolen bitcoin was valued at around $38 million.
  • The attack affected about 500 single-signature wallets.
  • The exploit occurred within a 25-minute window on Friday.
  • The vulnerability stemmed from a firmware issue that bypassed hardware randomness for key generation.
  • Coinkite has identified specific firmware versions and hardware models that are vulnerable.

An attacker exploited a critical flaw in Coldcard hardware wallets, successfully draining approximately 594 bitcoin, valued at $38 million, from around 500 single-signature wallets in a swift 25-minute operation. The vulnerability, identified by Block's security teams and reported to Coinkite, was introduced in Coldcard firmware version 4.0.0 in March 2021. This flaw caused the devices to bypass their hardware randomness generator and fall back to a predictable software-based key generation method, seeded by non-secret chip data like serial numbers and clock registers. The exploit occurred between 01:31 and 01:56 UTC on Friday, consolidating the stolen funds into a single address. Coinkite has issued warnings to users who generated seeds on Mk3 devices running firmware 4.0.1 or later, while noting that Mk4, Q, and Mk5 models appear unaffected. The incident highlights the risks associated with hardware wallet security and the importance of firmware updates. Despite the significant theft, the market price of bitcoin showed little visible impact.

Frequently asked questions

The flaw caused the wallet to skip its hardware randomness generator and use predictable software-based key generation seeded by non-secret chip data.

Approximately 594 bitcoin, valued at about $38 million, was stolen.

Users who generated seeds on Mk3 devices running firmware 4.0.1 or later are warned. Mk4, Q, and Mk5 models appear unaffected.

The theft appeared to have little visible impact on Bitcoin's market price.

What Happens Next

01Users are advised to check their Coldcard firmware versions and seed generation dates.
02Coinkite is expected to provide further analysis and potential mitigation steps.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

An attacker exploited a flaw in Coldcard hardware wallets.
The vulnerability was introduced in firmware 4.0.0 in March 2021.
The flaw caused devices to use predictable software-based key generation.
Approximately 594 bitcoin, valued at $38 million, was stolen.
The theft occurred from around 500 single-signature wallets.
The attack took place between 01:31 and 01:56 UTC on Friday.
The stolen bitcoin was consolidated into a single address.
Coinkite warned users who generated seeds on Mk3 devices running firmware 4.0.1 or later.

Sources

T1
Major bitcoin wallet flaw drains 594 BTC in 25-minute sweepCoinDesk

Related Stories

Coldcard warns users of potential seed risk; $38M Bitcoin wallet drain examined
31 Jul · 2:45 AM
Bitcoin Treasury Strategy Posts $8.2B Loss As BTC Price Suffered
30 Jul · 9:05 PM
Fake Flare Network Site Scams Investors Out of $8.5M in XRP
30 Jul · 9:57 AM
IBM Claims Quantum Advantage, Bitcoin Threat Remains Distant
30 Jul · 5:41 PM
Bitcoin ETFs See Smallest Monthly Inflows on Record
30 Jul · 11:27 AM