Bitcoin cold wallets drained of $70M in firmware flaw attack
window 24h
IN SHORT
A significant exploit targeting Coldcard hardware wallets has resulted in the theft of approximately $70 million worth of Bitcoin. The attack exploited a firmware flaw that weakened seed generation, enabling attackers to reconstruct private keys and access funds in dormant wallets. Binance founder Changpeng Zhao, known as CZ, has advised cryptocurrency holders to diversify their assets across multiple wallets in light of this incident. The stolen funds, totaling over 1,000 Bitcoin, are currently held in four distinct addresses, and reports suggest the perpetrator may have used a major blockchain services provider.
✉Newsletter
PiQ Daily
Pick your topics. Get only what matters, on your cadence.
Key Numbers
$70 millionvalue of stolen Bitcoin
1,000+Bitcoin stolen
1,196Coldcard wallets exploited
Who's Involved
CZ
Binance founder advising on wallet diversification
Coldcard
Hardware wallet manufacturer affected by exploit
Bitcoin
Cryptocurrency stolen in the exploit
Coldcard Mk4
Specific hardware wallet model with vulnerability
1 / 2
Key facts
A firmware flaw in Coldcard hardware wallets was exploited.
The exploit targeted the seed generation process, weakening private key security.
Over 1,000 Bitcoin, valued at approximately $70 million, were stolen.
1,196 Coldcard hardware wallets were compromised.
The stolen funds are held in four distinct addresses.
Binance founder CZ advised crypto holders to diversify their wallets.
Reports suggest the thief may have used a prominent blockchain services provider.
The Coldcard Mk4 model is specifically mentioned as having the vulnerability.
A security vulnerability in Coldcard hardware wallets has led to the theft of over 1,000 Bitcoin, valued at approximately $70 million. The exploit targeted a firmware flaw within the Coldcard Mk4 devices, which compromised the seed generation process. This weakness allowed attackers to reconstruct private keys, enabling them to access and steal Bitcoin from dormant wallets. In total, 1,196 Coldcard hardware wallets were affected by this exploit.
Following the incident, Binance founder Changpeng Zhao, widely known as CZ, has advised cryptocurrency holders to diversify their holdings across multiple wallets. This recommendation aims to mitigate the risk of a single point of failure, as demonstrated by the Coldcard exploit. The stolen funds remain concentrated in four specific blockchain addresses. Reports also indicate that the individual or group responsible for the theft may have utilized a prominent blockchain services provider in their operations.
The discovery of this vulnerability has prompted users of Coldcard wallets to take immediate action, with many advised to move their Bitcoin to more secure storage solutions. The nature of the firmware flaw, which affected seed generation, highlights a critical security concern for hardware wallet users and underscores the importance of robust security protocols in cryptocurrency storage.
↳ Why This Matters
A security vulnerability in Coldcard hardware wallets has led to the theft of over 1,000 Bitcoin, valued at approximately $70 million. The exploit targeted a firmware flaw within the Coldcard Mk4 devices, which compromised the seed generation process. This weakness allowed attackers to reconstruct private keys, enabling them to access and steal Bitcoin from dormant wallets. In total, 1,196 Coldcard hardware wallets were affected by this exploit.
Frequently asked questions
Over 1,000 Bitcoin, valued at approximately $70 million, was stolen from 1,196 Coldcard wallets.
A firmware flaw in certain Coldcard hardware wallets allowed attackers to reconstruct private keys by making seed phrases computationally enumerable.
No, the attackers did not need to physically touch the devices to steal the funds.
Reports indicate that Mk2, Mk3, Mk4, Q, and Mk5 models are affected, though Coinkite has specifically warned Mk3 owners and stated newer devices are unaffected.
No, owners cannot reliably determine if their seed phrases were generated on vulnerable firmware.
What Happens Next
01Investigators continue to trace the attacker through blockchain data provider logs.
02Owners of affected Coldcard wallets are advised to assume their seeds may be compromised.
03Further attacks are possible if owners do not move their funds to new seeds.
Get the newsletter.
Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.