Key facts
- A flaw in Coldcard hardware wallets allowed an attacker to steal approximately 594 bitcoin.
- The stolen bitcoin was valued at around $38 million.
- The attack affected about 500 single-signature wallets.
- The exploit occurred within a 25-minute window on Friday.
- The vulnerability stemmed from a firmware issue that bypassed hardware randomness for key generation.
- Coinkite has identified specific firmware versions and hardware models that are vulnerable.
An attacker exploited a critical flaw in Coldcard hardware wallets, successfully draining approximately 594 bitcoin, valued at $38 million, from around 500 single-signature wallets in a swift 25-minute operation. The vulnerability, identified by Block's security teams and reported to Coinkite, was introduced in Coldcard firmware version 4.0.0 in March 2021. This flaw caused the devices to bypass their hardware randomness generator and fall back to a predictable software-based key generation method, seeded by non-secret chip data like serial numbers and clock registers. The exploit occurred between 01:31 and 01:56 UTC on Friday, consolidating the stolen funds into a single address. Coinkite has issued warnings to users who generated seeds on Mk3 devices running firmware 4.0.1 or later, while noting that Mk4, Q, and Mk5 models appear unaffected. The incident highlights the risks associated with hardware wallet security and the importance of firmware updates. Despite the significant theft, the market price of bitcoin showed little visible impact.
